A method for trading efficient and regulated data products and their derivative services

By introducing trusted equity tags, homomorphic signatures, and zero-knowledge proof technologies into the data trading system, security and privacy issues in the data trading system are resolved, enabling effective supervision and privacy protection of data transactions, and ensuring the authenticity of data sources and the correctness of derivative services.

CN118154306BActive Publication Date: 2025-11-14UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410198999.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-22
Publication Date
2025-11-14
Estimated Expiration
2044-02-22

AI Technical Summary

Technical Problem

Existing data trading systems present security and privacy issues during cross-domain data transfers. In particular, with the assistance of data exchanges, raw data may be resold without authorization, and data privacy is difficult to effectively protect in derivative service transactions.

Method used

By adopting efficient and regulated methods for trading data products and their derivative services, public and private keys are generated through system initialization, and trusted equity tags, homomorphic signatures, and zero-knowledge proof technologies are used to ensure the security and privacy of data transactions.

Benefits of technology

It has achieved effective regulation of the primary data trading market, protected data privacy, and ensured the authenticity of data sources and the correctness of derivative services in the secondary data trading market, providing a trusted link between data products and derivative services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118154306B_ABST
    Figure CN118154306B_ABST
Patent Text Reader

Abstract

This invention discloses an efficient and regulated method for trading data products and their derivative services, relating to the field of data trading technology and applied to a data trading system. The data trading system includes original data sellers, data service providers, data service buyers, and a data exchange. The method includes a system initialization phase, an original data product trading phase, and a data derivative service trading phase. In the original data product trading phase, the rights label and signature of the data product are sent to the data exchange as transaction evidence. In the data derivative service trading phase, using homomorphic signatures and zero-knowledge proof technology, the data service provider provides the data service buyer with proof of the correctness of the derivative service and proof of the authenticity of the data source. While ensuring the privacy of data products, this invention achieves efficient regulation of the data product and derivative service trading process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data transaction technology, and in particular to a method for trading efficient and regulated data products and their derivative services. Background Technology

[0002] Data has become a fundamental strategic resource for the nation and a basic factor of production for society, and is the most critical element in developing the digital economy. Currently, the government has introduced a series of policies and systems emphasizing the orderly advancement of the data factor market, promoting its high-quality development, and providing new impetus for the development of the digital economy. Cross-domain transfer of data assets is key to promoting the healthy and sustainable development of the data factor market. Currently, cross-domain transfer of data assets can be summarized in two aspects: first, in the primary data trading market, the seller of raw data sells raw data products to the buyer; second, in the secondary data trading market, the buyer of the raw data, i.e., the data service provider, uses the purchased data to provide data-derived services to the data service purchaser.

[0003] To achieve the two aforementioned cross-domain data asset transfer models, the most widely used approach currently involves stakeholders engaging in raw data transactions and data-derived service transactions with the assistance of data exchanges. However, the cross-domain transfer of data assets facilitated by exchanges still faces serious security and privacy issues, specifically in the following two aspects.

[0004] In the nascent data market, existing data trading systems (such as the AWS Data Exchange platform) require data products to be traded to be stored in plaintext on the exchange to enable oversight of data product transactions. However, exchanges may resell these data products without the data owners' knowledge, profiting illegally. An intuitive approach is to encrypt the data before storing it on the exchange, which effectively prevents malicious data exchanges from stealing data, but this leaves the data exchange unable to monitor related transactions.

[0005] In secondary data trading markets, data derivative services can also be traded with the assistance of data exchanges. The data exchanges verify the verifiability of the original data source and the accuracy of the derivative calculations to the buyers of the data derivative services. However, to protect the interests of both the sellers of the derivative services and the sellers of the original data, data privacy must be protected during the data derivative service transaction process. This means ensuring that the buyers of the derivative services and the data exchanges cannot extract any additional information about the data product beyond the derivative services themselves.

[0006] However, current data trading and derivative service trading schemes based on data exchanges have not solved the aforementioned security and privacy issues. Summary of the Invention

[0007] The purpose of this invention is to overcome the shortcomings of the prior art and provide an efficient and regulated method for trading data products and their derivative services.

[0008] The objective of this invention is achieved through the following technical solution:

[0009] An efficient and regulated method for trading data products and their derivative services is applied to a data trading system, which includes the original data seller. Data service providers Data service purchasers and data exchange The method specifically includes the following steps:

[0010] S1: System initialization phase: Initialize the system according to the system's security parameters, determine the system's public parameters, and generate the public and private keys required by the system.

[0011] S2: Raw Data Product Transaction Stage

[0012] S21: Data Service Provider To the seller of the original data Purchase raw data The two parties to the transaction are at the data exchange. With assistance, the rights and attributes of the original data were discussed. Original data seller To data exchange Request the original data rights attributes Credible rights label ;

[0013] S22: Original Data Seller and data service providers Jointly on credible rights labels Sign the document and have both parties sign it. credible rights and interests labels Send to data exchange As evidence of the transaction;

[0014] S23: When selling raw data products, the seller of the raw data Calculate the homomorphic signature of the raw data to be sold and send it to the data service provider. ;

[0015] S3: Data Derivative Services Transaction Phase

[0016] S31: Data Service Provider and data service buyers Negotiated data-derived service functions ,in Data service providers calculate And proof of data source and calculation correctness ;

[0017] S32: Data service purchaser Verification passed The validity of the data service provider is verified. Whether to use raw data seller The provided raw dataset provides the correct data derivation services;

[0018] Step S1 includes the following steps:

[0019] S11, According to safety parameters Determine the common parameter set ,in It is an elliptic curve of order 1. The additive group whose generator is ; It is a safe hash function; Is the order as The group, whose generators are respectively ; It is a bilinear mapping; It is a safe hash function; It is a pseudo-random function. For key space;

[0020] The specific process of step S23 is as follows:

[0021] S231: Original Data Seller For each data Calculate tags ,for ;

[0022] S232: Original Data Seller Select uniformly , , and calculate

[0023]

[0024] S233: Original Data Seller The private key is The public key is ;

[0025] S234: For Original data seller Calculate pairs Sign

[0026] ,

[0027] And output signature ;

[0028] S235: Original Data Seller Original data and signature Send to data service provider .

[0029] Furthermore, step S1 also includes the following steps:

[0030] S12: Original Data Seller Uniform selection and calculate Original data seller Generate a pair Zero-knowledge proof of the discrete logarithm; data exchange Accepted after verification As the original data seller The public key for signing;

[0031] S13: Data service purchaser Uniform selection and calculate Data service purchasers Generate a pair Zero-knowledge proof of the discrete logarithm; data exchange Accepted after verification As a data service purchaser The signature public key is used to generate the original data seller and data service buyers Public and private keys signed by both parties .

[0032] Furthermore, the specific process of step S22 is as follows:

[0033] S221: Original Data Seller Generate a key pair for use in the Paillier algorithm. ,in , Two large prime numbers, ; and calculate ;

[0034] S222: Original Data Seller Will Send to data service provider and to data service providers prove Satisfying Relationship:

[0035]

[0036]

[0037] S223: Original Data Seller Uniform selection And calculate , generating an effect A zero-knowledge proof of the discrete logarithm is obtained, and the proof information is sent to the data service provider. ;

[0038] S224: Data service provider Upon receiving the proof information, verification will be performed; if the verification fails, the process will be terminated.

[0039] S225: Data Service Provider Uniform selection And calculate Calculate pairs Zero-knowledge proof of the discrete logarithm, output And sent to the original data seller ;

[0040] S226: Data service provider calculate , For a point on the elliptic curve, writing ,calculate ;

[0041] S227: Data service provider Uniform selection and and calculate ,

[0042] ,

[0043] ,

[0044] ,

[0045] ;

[0046] S228: Data service provider Will Send to the original data seller ;

[0047] S229: Original Data Seller calculate , For a point on the elliptic curve, writing ,calculate ;

[0048] S2210: Original Data Seller calculate and Select and The minimum value in ;

[0049] S2211: Original Data Seller verify Is it true? If it is true, then... It is a valid signature; output the signature. Otherwise, the agreement will be terminated;

[0050] S2212: Original Data Seller Signature and tags Send to data exchange Data exchange storage and As evidence of data transactions.

[0051] Furthermore, in step S31, the data derivative service provider Using raw data subset of For data service buyers Provide derivative services, data service provider With data service buyers The derived service function obtained through negotiation is Data service providers By purchasing data services prove Satisfying Relationships This is to prove the correctness of the derivative service calculation.

[0052] Furthermore, the specific process of step S31 is as follows:

[0053] S311: Data Service Provider Prove the following relation:

[0054] ;

[0055] Wherein, domain It is a public collection. It is A polynomial that satisfies ; Metapolynomial By defining the domain Sure, Representing vectors and The inner product;

[0056] The steps include: 1) Calculation ;

[0057] 2) Calculation ;

[0058] 3) Construction Metapolynomial ,in It is the domain The Lagrange polynomial on, at this point, for any ,satisfy , The following relationship needs to be proven:

[0059]

[0060] 4) Uniform selection As a private key and calculate As a general public string, It is the maximum degree of the polynomial; let ;

[0061] 5) Calculate the proof relationship of and : , ;

[0062] 6) Calculation ,against The polynomials generate polynomials of degree 2 respectively. , , ,in The coefficients are all uniformly and randomly selected;

[0063] 7) Calculate the pair The promises are respectively , , ;

[0064] 8) Calculation ,in ;

[0065] 9) Calculation as well as

[0066] ,

[0067] ;

[0068] 10) Output ;

[0069] 11) Output proof ;

[0070] S312: Data service provider calculate and Calculate pairs and The promise, namely ;

[0071] S313: Data service provider Calculation for Homomorphic signatures And prove that it satisfies the following relationship

[0072] ;

[0073] S314: Data service provider calculate and calculate Calculate pairs The promise, namely ;

[0074] S315: Without leakage and In this case, data service providers Prove the following relation ;

[0075] Includes the following steps:

[0076] 1) Calculation ;

[0077] 2) Select uniformly and consistently ,calculate and ;

[0078] 3) Uniform selection ;

[0079] 4) Calculation ,

[0080] ,

[0081] ,

[0082] ,

[0083] ,

[0084] ,

[0085] ,

[0086] 5) Output proof ;

[0087] S316: Data Service Provider Calculation for Homomorphic signatures And prove that it satisfies the following relationship

[0088] ;

[0089] S317: Data Service Provider Output proof for data-derived services The results of the calculation of derivative services and proof Send to data service purchasers .

[0090] Furthermore, the data service provider Calculation for Homomorphic signatures The specific steps are as follows:

[0091] S3131: Seller with known original data for The signature is Data service providers calculate ;

[0092] S3132: Targeting Computational zero-knowledge proof, proof Satisfy the following relationship

[0093] ,

[0094] The relationship ;

[0095] S3133: Calculation ;

[0096] S3134: Output homomorphic signature .

[0097] Furthermore, the data service provider Calculation for Homomorphic signatures The specific steps are as follows:

[0098] S3161: Computation of Zero-Knowledge Proofs ;

[0099] S3162: Seller with known original data for The signature is ,calculate ;

[0100] S3163: Calculation ;

[0101] S3164: Output homomorphic signature .

[0102] Furthermore, the specific process of S32 is as follows:

[0103] S321: Data service purchaser calculate ,calculate ;

[0104] S322: Data service purchaser verify and ,in :verify If the condition is not met, the calculation is stopped; ,verify , Check if it is valid; if not, stop.

[0105] S323: Data service purchaser verify and Validity: Calculation , , ,verify , Check if it is valid; if not, stop.

[0106] S324: Data service purchaser Verify signature Validity: Calculation ;verify and Check if it is valid; if not, stop.

[0107] S325: Data service purchaser Verify signature Validity: Calculation ;verify as well as Check if it is valid; if not, stop.

[0108] The beneficial effects of this invention are:

[0109] 1) For the primary data trading market, the solution provided by this embodiment of the invention is as follows: the original data seller first negotiates the data rights with the buyer, then requests the rights label of the original data from the data exchange, the original data seller and the buyer sign the rights label at the same time, and finally send the signature and rights label to the data exchange as transaction evidence, thereby realizing effective supervision of relevant data trading behavior in the primary data trading market.

[0110] 2) For the secondary data trading market, this invention utilizes homomorphic signature and zero-knowledge proof technology. Data service providers (i.e., the original data buyers in the primary market) can provide data service purchasers with proof of the correctness of derivative services and proof of the authenticity of the data source. This invention protects data privacy during the data derivative service transaction process. Attached Figure Description

[0111] Figure 1 A flowchart illustrating the transaction method for data products and their derivative services provided in this embodiment of the invention. Detailed Implementation

[0112] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0113] The problems this invention aims to solve are: first, how to generate data product rights labels involving and recognized by the original data seller, data service provider (original data buyer), and data exchange while ensuring data product privacy, so as to serve as evidence for subsequent data product transactions and support transaction supervision; and second, in the secondary data trading market assisted by the exchange, how to ensure data privacy while enabling data derivative service providers to prove the authenticity of the data source and the correctness of the data derivative services to derivative service purchasers, thereby achieving a trustworthy link between data products and derivative services.

[0114] See Figure 1 The present invention provides a technical solution:

[0115] An efficient and regulated method for trading data products and their derivative services is applied to a data trading system, which includes the original data seller. Data service providers Data service purchasers and data exchange The method specifically includes the following steps: S1: System initialization phase: Initialize the system according to the system's security parameters, determine the system's public parameters, and generate the public and private keys required by the system;

[0116] S11, According to safety parameters Determine the common parameter set ,in It is an elliptic curve of order 1. The additive group whose generator is ; It is a safe hash function; Is the order as The group, whose generators are respectively ; It is a bilinear mapping; It is a safe hash function; It is a pseudo-random function. For key space;

[0117] S2: Raw Data Product Transaction Stage

[0118] S21: Data Service Provider To the seller of the original data Purchase raw data The two parties to the transaction are at the data exchange. With assistance, the rights and attributes of the original data were discussed. Original data seller To data exchange Request the original data rights attributes Credible rights label ;

[0119] S22: Original Data Seller and data service providers At the same time, the credible rights label Sign the document and have both parties sign it. credible rights label Send to data exchange As evidence of the transaction;

[0120] S23: When selling raw data products, the seller of the raw data Calculate the homomorphic signature of the raw data to be sold and send it to the data service provider. ;

[0121] S3: Data Derivative Services Transaction Phase

[0122] S31: Service Provider and data service buyers Negotiated data-derived service functions ,in Service Provider calculate And proof of data source and calculation correctness ;

[0123] S32: Service Purchaser Verification passed Validity, verification service provider Whether to use raw data seller The provided raw dataset offers the correct data derivation services.

[0124] Preferably, step S1, the system initialization phase, specifically comprises:

[0125] S12: Original Data Seller Uniform selection and calculate Original data seller Generate a pair Zero-knowledge proof of the discrete logarithm; data exchange Accepted after verification As the original data seller The public key for signing;

[0126] S13: Data service purchaser Uniform selection and calculate Data service purchasers Generate a pair Zero-knowledge proof of the discrete logarithm; data exchange Accepted after verification As a data service purchaser The signature public key is used to generate the original data seller and data service buyers Public and private keys signed by both parties .

[0127] Among them, the original data seller Generate a pair The zero-knowledge proof of the discrete logarithm is as follows: The original data seller... Uniform selection ,calculate , as well as Original data seller Will Send to data exchange Data Exchange receive ,calculate ,verify If it is valid, then accept it. As The public key for signing. Data service purchaser. right The zero-knowledge proof process for the discrete logarithm is consistent with the process described above.

[0128] The cryptographic primitives involved in the embodiments of this invention are as follows:

[0129] (1) Paillier encryption algorithm ,in Indicates the use of a public key and randomly selected random numbers Encrypted messages And output ciphertext , Indicates the use of private key Decrypting the ciphertext Received message in plaintext .

[0130] (2) Commitment Plan ,in This indicates that the parameters for calculating the commitment are output based on the safety parameters. , Indicates output pair promise And the parameters used to open the commitment , Indicates use Open the promise ,verify Is it right? If a valid commitment is made, output 1; otherwise, output 0.

[0131] (3) Regarding the relationship Zero-knowledge proof schemes ,in This indicates initialization based on security parameters. This indicates that the output is a zero-knowledge proof. ,prove Satisfying Relationships , Indicates verification To determine if a statement is valid, output 1 if it passes the verification, otherwise output 0.

[0132] (4) For a set of relations A concise non-interactive zero-knowledge proof scheme ,in Indicates based on safety parameters and Output common parameters , Indicates a specific type of relationship Output a pair of keys , Indicates that for satisfying Specific example output proof , Indicates verification Check if it is valid. If valid, output 1; otherwise, output 0.

[0133] Furthermore, the specific process of step S22 is as follows:

[0134] S221: Original Data Seller Generate a key pair for use in the Paillier algorithm. ,in , Two large prime numbers, ; and calculate ;

[0135] S222: Original Data Seller Will Send to data service provider and to data service providers prove Satisfying Relationship:

[0136]

[0137] ;

[0138] S223: Original Data Seller Uniform selection And calculate , generating an effect A zero-knowledge proof of the discrete logarithm is obtained, and the proof information is sent to the data service provider. ;

[0139] S224: Data service provider Upon receiving the proof information, verification will be performed; if the verification fails, the process will be terminated.

[0140] S225: Data Service Provider Uniform selection And calculate Calculate pairs Zero-knowledge proof of the discrete logarithm, output And sent to the original data seller ;

[0141] S226: Data service provider calculate , For a point on the elliptic curve, writing ,calculate ;

[0142] S227: Data service provider Uniform selection and and calculate

[0143] ,

[0144] ,

[0145] ,

[0146] ,

[0147] ;

[0148] S228: Data service provider Will Send to the original data seller ;

[0149] S229: Original Data Seller calculate , For a point on the elliptic curve, writing ,calculate ;

[0150] S2210: Original Data Seller calculate and Select and The minimum value in ;

[0151] S2211: Original Data Seller verify Is it true? If it is true, then... It is a valid signature; output the signature. Otherwise, the agreement will be terminated;

[0152] S2212: Original Data Seller Signature and tags Send to data exchange Data exchange storage and As evidence of data transactions.

[0153] During the sale of raw data products, in order to ensure the authentication of the raw data products and the verifiability of the data source in data-derived service transactions, The specific process of calculating the homomorphic signature for the original data being sold, step S23, is as follows:

[0154] S231: Original Data Seller For each data Calculate tags ,for ;

[0155] S232: Original Data Seller Select uniformly , , and calculate

[0156] ;

[0157] S233: Original Data Seller The private key is The public key is ;

[0158] S234: For Original data seller Calculate pairs Sign

[0159] ,

[0160] And output signature ;

[0161] S235: Original Data Seller Original data and signature Send to data provider .

[0162] Preferably, in step S31, the data derivative service provider Using raw data subset of For data service buyers Provide derivative services, data service provider With data service buyers The derived service function obtained through negotiation is Data service providers By purchasing data services prove Satisfying Relationships This is to prove the correctness of the derivative service calculation.

[0163] Preferably, the specific process of step S31 is as follows:

[0164] S311: Data Service Provider Prove the following relation:

[0165] ;

[0166] Wherein, domain It is a public collection. It is A polynomial that satisfies ; Metapolynomial By defining the domain Sure, Representing vectors and The inner product;

[0167] The Metapolynomial satisfy:

[0168] a) For any ,like ,but ,otherwise ;

[0169] b) Given , Available Calculated within a time period;

[0170] c) Each polynomial The order is the largest. , making Size is negligible.

[0171] Data service providers The proof process includes the following steps:

[0172] 1) Calculation ;

[0173] 2) Calculation ;

[0174] 3) Construction Metapolynomial ,in It is the domain The Lagrange polynomial on, at this point, for any ,satisfy , The following relationship needs to be proven:

[0175] ;

[0176] 4) Uniform selection As a private key and calculate As a general public string, It is the maximum degree of the polynomial; let ;

[0177] 5) Calculate the proof relationship of and : , ;

[0178] 6) Calculation ,against The polynomials generate polynomials of degree 2 respectively. , , ,in The coefficients are all uniformly and randomly selected;

[0179] 7) Calculate the pair The promises are respectively , , ;

[0180] 8) Calculation ,in ;

[0181] 9) Calculation as well as

[0182] ,

[0183] ;

[0184] 10) Output ;

[0185] 11) Output proof ;

[0186] S312: Data service provider calculate and Calculate pairs and The promise, namely ;

[0187] S313: Data service provider Calculation for Homomorphic signatures And prove that it satisfies the following relationship

[0188] ;

[0189] S314: Data service provider calculate and calculate Calculate pairs The promise, namely ;

[0190] S315: Without leakage and In this case, data service providers Prove the following relation

[0191] ;

[0192] Includes the following steps:

[0193] 1) Calculation ;

[0194] 2) Select uniformly and consistently ,calculate and ;

[0195] 3) Uniform selection ;

[0196] 4) Calculation

[0197] ,

[0198] ,

[0199] ,

[0200] ,

[0201] ,

[0202] ,

[0203] ,

[0204] 5) Output proof ;

[0205] S316: Data Service Provider Calculation for Homomorphic signatures And prove that it satisfies the following relationship

[0206]

[0207] S317: Data Service Provider Output proof for data-derived services The results of the calculation of derivative services and proof Send to data service purchasers .

[0208] A key feature of this invention is that it supports arbitrary NP-complete computations (verifiable computational problems in polynomial time) during the data derivative service transaction phase, meaning that data service providers... You can ask the service purchaser Provides NP-hard computation services and generates corresponding proofs. .

[0209] Furthermore, the data service provider Calculation for Homomorphic signatures The specific steps are as follows:

[0210] S3131: Seller with known original data for The signature is Data service providers calculate ;

[0211] S3132: Targeting Computational zero-knowledge proof, proof Satisfy the following relationship

[0212]

[0213] The relationship ;

[0214] S3133: Calculation ;

[0215] S3134: Output homomorphic signature .

[0216] Furthermore, the data service provider Calculation for Homomorphic signatures The specific steps are as follows:

[0217] S3161: Computation of Zero-Knowledge Proofs ;

[0218] S3162: Seller with known original data for The signature is ,calculate ;

[0219] S3163: Calculation ;

[0220] S3164: Output homomorphic signature .

[0221] Preferably, the specific process of S32 is as follows:

[0222] S321: Data service purchaser calculate ,calculate ;

[0223] S322: Data service purchaser verify and ,in :verify If the condition is not met, the calculation is stopped; ,verify , Check if it is valid; if not, stop.

[0224] S323: Data service purchaser verify and Validity: Calculation , , ,verify , Check if it is valid; if not, stop.

[0225] S324: Data service purchaser Verify signature Validity: Calculation ;verify and Check if it is valid; if not, stop.

[0226] S325: Data service purchaser Verify signature Validity: Calculation ;verify as well as Check if the condition is met; if not, the process is terminated.

[0227] This invention utilizes homomorphic signatures and zero-knowledge proofs to enable data service providers (i.e., the original data buyers in the primary market) to provide data service purchasers with proof of the correctness of derivative services and proof of the authenticity of the data source. This invention protects data privacy during data derivative service transactions.

[0228] The above description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the concept described herein through the above teachings or related technologies or knowledge. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.

Claims

1. A highly efficient and regulated method for trading data products and their derivative services, characterized in that: Applied to data trading systems, which include original data sellers Data service providers Data service purchasers and data exchange The method specifically includes the following steps: S1: System initialization phase: Initialize the system according to the system's security parameters, determine the system's public parameters, and generate the public and private keys required by the system. S2: Raw Data Product Transaction Stage S21: Data Service Provider To the seller of the original data Purchase raw data The two parties to the transaction are at the data exchange. With assistance, the rights and attributes of the original data were discussed. Original data seller To data exchange Request the original data rights attributes Credible rights label ; S22: Original Data Seller and data service providers Jointly on credible rights labels Sign the document and have both parties sign it. credible rights label Send to data exchange As evidence of the transaction; S23: When selling raw data products, the seller of the raw data Calculate the homomorphic signature of the raw data to be sold and send it to the data service provider. ; S3: Data Derivative Services Transaction Phase S31: Data Service Provider and data service buyers Negotiated data-derived service functions ,in Data service providers calculate And proof of data source and calculation correctness ; S32: Data service purchaser Verification passed The validity of the data service provider is verified. Whether to use raw data seller The provided raw dataset provides the correct data derivation services; Step S1 includes the following steps: S11, According to safety parameters Determine the common parameter set ,in It is an elliptic curve of order 1. The additive group whose generator is ; It is a safe hash function. Is the order as The group, whose generators are respectively ; It is a bilinear mapping; It is a secure hash function; It is a pseudo-random function. For key space; The specific process of step S23 is as follows: S231: Original Data Seller For each data Calculate labels ,for ; S232: Original Data Seller Select uniformly , , and calculate ; S233: Original Data Seller The private key is The public key is ; S234: For Original data seller Calculate pairs Sign and output signature. ; S235: Original Data Seller Original data and signature Send to data service provider .

2. The efficient and regulatory data product and its derivative service trading method according to claim 1, characterized in that: Step S1 further includes the following steps: S12: Original Data Seller Uniform selection and calculate Original data seller Generate a pair Zero-knowledge proof of the discrete logarithm; data exchange Accepted after verification As the original data seller The public key for signing; S13: Data service purchaser Uniform selection and calculate Data service purchasers Generate a pair Zero-knowledge proof of the discrete logarithm; data exchange Accepted after verification As a data service purchaser The signature public key is used to generate the original data seller's signature public key. and data service buyers Public and private keys signed by both parties .

3. The efficient and regulatory data product and its derivative service trading method according to claim 2, characterized in that: The specific process of step S22 is as follows: S221: Original Data Seller Generate a key pair for use in the Paillier algorithm. ,in , Two large prime numbers, ; and calculate ; S222: Original Data Seller Will Send to data service provider and to data service providers prove Satisfying Relationship: ; S223: Original Data Seller Uniform selection And calculate , generating an effect A zero-knowledge proof of the discrete logarithm is obtained, and the proof information is sent to the data service provider. ; S224: Data service provider Upon receiving the proof information, verification will be performed; if the verification fails, the process will be terminated. S225: Data service provider Uniform selection And calculate Calculate pairs Zero-knowledge proof of the discrete logarithm, output And sent to the original data seller ; S226: Data service provider calculate , For a point on the elliptic curve, writing ,calculate ; S227: Data service provider Uniform selection and and calculate , , , , , S228: Data service provider Will Send to the original data seller ; S229: Original Data Seller calculate , For a point on the elliptic curve, writing ,calculate ; S2210: Original Data Seller calculate and Select and The minimum value in ; S2211: Original Data Seller verify Is it true? If it is true, then... It is a valid signature; output the signature. Otherwise, the agreement will be terminated; S2212: Original Data Seller Signature and tags Send to data exchange Data exchange storage and As evidence of data transactions.

4. The efficient and regulated data product and its derivative service trading method according to claim 3, characterized in that: In step S31, the data derivative service provider Using raw data subset of For data service buyers Provide derivative services, data service provider With data service buyers The derived service function obtained through negotiation is Data service providers By purchasing data services prove Satisfying Relationships This is to prove the correctness of the derivative service calculation.

5. The efficient and regulated data product and its derivative service trading method according to claim 4, characterized in that: The specific process of step S31 is as follows: S311: Data Service Provider Prove the following relation: ; Wherein, domain It is a public collection. It is A polynomial that satisfies ; Metapolynomial By defining the domain Sure, Representing vectors and The inner product; Includes the following steps: 1) Calculation ; 2) Calculation ; 3) Construction Metapolynomial , in It is the domain The Lagrange polynomial on, at this point, for any ,satisfy , The following relationship needs to be proven: ; 4) Uniform selection As a private key and calculate As a general public string, It is the maximum degree of the polynomial; let ; 5) Calculate and prove the relationship of and : , ; 6) Calculation ,against The polynomials generate polynomials of degree 2 respectively. , , ,in The coefficients are all uniformly and randomly selected; 7) Calculate the pair The promises are respectively , , ; 8) Calculation ,in ; 9) Calculation as well as ; ; 10) Output ; 11) Output proof ; S312: Data service provider calculate and ,calculate and The promise, namely ; S313: Data service provider Calculation for Homomorphic signatures And prove that it satisfies the following relationship ; S314: Data service provider calculate and calculate Calculate pairs The promise, namely ; S315: Without leakage and In this case, data service providers Prove the following relation ; Includes the following steps: 1) Calculation ; 2) Select uniformly and consistently ,calculate and ; 3) Uniform selection ; 4) Calculation , , , , , , , 5) Output proof ; S316: Data Service Provider Calculation targeting Homomorphic signatures And prove that it satisfies the following relationship ; S317: Data Service Provider Output proof for data-derived services The results of the calculation of derivative services and proof Send to data service purchasers .

6. The efficient and regulated data product and its derivative service trading method according to claim 5, characterized in that: The data service provider Calculation targeting Homomorphic signatures The specific steps are as follows: S3131: Seller with known original data for The signature is Data service providers calculate ; S3132: Targeting Computational zero-knowledge proof, proof Satisfy the following relationship ; The relationship ; S3133: Calculation ; S3134: Output homomorphic signature .

7. The efficient and regulated data product and its derivative service trading method according to claim 6, characterized in that: The data service provider Calculation targeting Homomorphic signatures The specific steps are as follows: S3161: Computation of Zero-Knowledge Proofs ; S3162: Seller with known original data for The signature is ,calculate ; S3163: Calculation ; S3164: Output homomorphic signature .

8. The efficient and regulated data product and its derivative service trading method according to claim 7, characterized in that: The specific process of S32 is as follows: S321: Data service purchaser calculate ,calculate ; S322: Data service purchaser verify and ,in :verify If the condition is not met, the calculation is stopped; ,verify , Check if it is valid; if not, stop. S323: Data service purchaser verify and Validity: Calculation , , ,verify , Check if it is valid; if not, stop. S324: Data service purchaser Verify signature Validity: Calculation ;verify and Check if it is valid; if not, stop. S325: Data service purchaser Verify signature Validity: Calculation ;verify as well as Check if the condition is met; if not, the process is terminated.

Citation Information

Patent Citations

  • Data product transaction method supporting privacy protection and credible supervision

    CN116188008A

  • Data transmission method based on certificateless homomorphic network coding signature in Internet of Things

    CN117319048A