A data authorization method, device, equipment and storage medium based on blockchain
By designing data token smart contracts through blockchain technology, the problem of accurate authority authorization in data transactions is solved, the accurate expression and protection of the rights of all parties involved in the circulation of data assets is achieved, and the construction of a trusted data circulation platform is supported.
Patent Information
- Application Number
- CN202411019609.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-29
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-07-29
AI Technical Summary
In data transactions, how to accurately authorize permissions to each data participant to ensure that data ownership, usage rights and value are accurately managed and traded in digital form.
Through blockchain technology, we design data holding tokens, data usage tokens, data product holding tokens and data product usage tokens, and use smart contracts to accurately express the rights of each participant in the circulation of data assets, including data resource holder authentication, data product authentication and usage authorization processes.
It realizes the protection of the rights of all participants in data circulation, ensures the tamper-proof traceability and audit of the rights acquisition and transfer process, and supports the construction of a trusted data circulation platform.
Smart Images

Figure CN118709159B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data transaction technology, and in particular to a blockchain-based data authorization method, device, equipment, and storage medium. Background Art
[0002] Data tokenization is the process of converting data assets into digital tokens or certificates through distributed ledger technologies such as blockchain. Data tokens represent the ownership, usage rights, and value of data and allow these rights to be traded and managed in a digital form. The purpose of data tokenization is to promote the sharing and circulation of data while ensuring that data providers receive corresponding benefits and incentives.
[0003] Data transactions involve numerous parties, each with varying rights to use the data. Data tokens represent the ownership, usage rights, and value of data, allowing these rights to be traded and managed digitally. Therefore, the question of how to precisely authorize each data participant through data tokens remains unanswered. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a blockchain-based data authorization method, device, equipment, and storage medium that can accurately express the rights of each participant in the circulation of data assets. The specific solution is as follows:
[0005] In the first aspect, the present application discloses a blockchain-based data authorization method, which is applied to data users and includes:
[0006] By sending a data usage request for the target data resource to the data resource holder, the data resource holder authenticates the data usage request through the blockchain and generates a corresponding data usage token after the authentication is passed;
[0007] Acquire target data resources based on the data usage token, and process the target data resources to obtain target data products;
[0008] After the target data product is authenticated by a preset data registration agency to generate a corresponding data certificate, the data certificate is stored on the blockchain;
[0009] Obtain the product application requirements for the target data product sent by the data product user, verify the product application requirements, and then authorize the data product user to use the data product based on the corresponding verification result and the data certificate.
[0010] Optionally, the data resource holder authenticates the data use request through blockchain and generates a corresponding data use token after the authentication is passed, including:
[0011] Using the data resource holder to call the data holding token in the data use request through the blockchain, and authenticating the data holding token;
[0012] If the data holding token is authenticated, the data resource holder will derive the corresponding data usage token through the data holding token.
[0013] Optionally, the data holding token is defined and generated by the preset data registration agency through the metadata of the target data resource sent by the data resource holder.
[0014] Optionally, after authenticating the target data product by a preset data registration agency to generate a corresponding data certificate, the data certificate is stored on a blockchain, including:
[0015] Sending the product information of the target data product to a preset data registration agency, and conducting a data product compliance assessment on the target data product through the preset data registration agency;
[0016] If the target data product passes the data product compliance assessment, the corresponding data product compliance certificate is obtained and stored on the blockchain;
[0017] A corresponding data product token is generated based on the data product compliance certificate, and the mapping relationship between the target data product and the target data resource is stored in the data product token.
[0018] Optionally, obtaining a product application requirement for the target data product sent by a data product user, verifying the product application requirement, and then authorizing the data product user to use the data product based on the corresponding verification result and the data certificate includes:
[0019] Obtaining product application requirements for the target data product sent by the data product user and verifying the product application requirements;
[0020] If the product application requirement verification is passed, the corresponding data product usage token will be derived from the data product token to authorize the user of the data product to use it.
[0021] Optionally, if the product application requirement verification is passed, after authorizing the user of the data product by deriving a corresponding data product usage token from the data product token, the process further includes:
[0022] Generate a data signature through the data product user, and send an access token application to a preset authentication center based on the data signature and the data product usage token;
[0023] Verify the data signature and the data product usage token to the blockchain through the preset authentication center;
[0024] If the verification is successful, a target access token is generated by the preset authentication center and sent to the data product user so that the data product user can access the target data product through the target access token.
[0025] Optionally, the data product user accesses the target data product through the target access token, including:
[0026] The data product user carries the target access token to initiate an access request for the target data product to the data product server;
[0027] Verifying the validity of the target access token through the data product server;
[0028] If the verification is successful, the data product server sends an access link to the target data product to the data product user, so that the data product user can obtain the target data product through the access link.
[0029] In a second aspect, the present application discloses a blockchain-based data authorization device, which is applied to data users and includes:
[0030] A request authentication module is used to send a data use request for a target data resource to a data resource holder so that the data resource holder can authenticate the data use request through the blockchain and generate a corresponding data use token after the authentication is passed;
[0031] A product processing module, configured to obtain target data resources based on the data usage token, and process the target data resources to obtain target data products;
[0032] A product authentication module is used to authenticate the target data product through a preset data registration agency to generate a corresponding data certificate, and then store the data certificate on the blockchain;
[0033] The permission issuing module is used to obtain the product application requirements for the target data product sent by the data product user, verify the product application requirements, and then authorize the use of the data product user based on the corresponding verification results and the data certificate.
[0034] In a third aspect, the present application discloses an electronic device, comprising:
[0035] Memory, used to store computer programs;
[0036] A processor is configured to execute the computer program to implement the aforementioned blockchain-based data authorization method.
[0037] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the aforementioned blockchain-based data authorization method.
[0038] It can be seen that in this application, first, a data use request for the target data resource is sent to the data resource holder so that the data resource holder can authenticate the data use request through the blockchain and generate a corresponding data use token after the authentication is passed; based on the data use token, the target data resource is obtained, and the target data resource is processed to obtain the target data product; after the target data product is authenticated by the preset data registration agency to generate the corresponding data certificate, the data certificate is stored on the chain; the product application requirements for the target data product sent by the data product user are obtained, and the product application requirements are verified, and then the data product user is authorized to use based on the corresponding verification results and the data certificate. By using blockchain smart contracts to accurately express the rights of each participant in the circulation of data assets, the rights of each participant in the data circulation are protected, and the blockchain is used to achieve tamper-proof traceability and auditing of the rights acquisition and transfer process, providing an important method and model reference for supporting the construction of a trusted data circulation platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0040] Figure 1 This is a flowchart of a blockchain-based data authorization method disclosed in this application;
[0041] Figure 2 A specific data authorization token derivation flow chart disclosed in this application;
[0042] Figure 3 This is a flowchart of a specific blockchain-based data authorization method disclosed in this application;
[0043] Figure 4 A specific data authorization token derivation flow chart disclosed in this application;
[0044] Figure 5 This is a flowchart of a specific blockchain-based data authorization method disclosed in this application;
[0045] Figure 6 This is a schematic diagram of the structure of a blockchain-based data authorization device disclosed in this application;
[0046] Figure 7 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0047] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0048] Data transactions involve numerous parties, each with varying rights to use the data. Data tokens represent the ownership, usage rights, and value of data, allowing these rights to be traded and managed digitally. Therefore, this application will specifically introduce a data authorization method.
[0049] See also Figure 1 As shown, the embodiment of the present application discloses a data authorization method based on blockchain, which is applied to data users, including:
[0050] Step S11: Send a data usage request for the target data resource to the data resource holder so that the data resource holder can authenticate the data usage request through the blockchain and generate a corresponding data usage token after the authentication is passed.
[0051] In this embodiment, it should be noted that, Figure 2As shown, the data holder (seller) holds the rights to a dataset (data resource) and can grant the data user (data vendor) the right to use that dataset. Data users (data vendors) use the licensed dataset to develop data products and automatically obtain the rights to own and operate the data products. Data product users (buyers) obtain the rights to use data products from data users (data vendors) through data transactions or applications. For example, for article or book data, the data holder (seller) holds the rights to own the article or book data and can grant the data user (data vendor) the rights to use it. Data users (data vendors) use the licensed article or book data to develop reading platforms and automatically obtain the rights to own and operate the reading platforms. Data product users (buyers) obtain the rights to use the reading platforms from data users (data vendors) through data transactions or applications.
[0052] In this application, based on ERC-1155, four token smart contracts are designed: dNFTcontract, duNFTcontract, pNFTcontract, and puNFTcontract, representing data holding tokens, data usage tokens, data product holding tokens, and data product usage tokens, respectively. Based on ERC-1155, the SBT and derivative (tracing) features are added. The "subject" attributes and permission control logic of the four tokens are defined as follows: dNFT: Data holder (holder), who has the right to transfer their own dNFTs and generate (mint) corresponding duNFTs; duNFT: Data user (user), who has the right to use duNFTs to generate corresponding dataset access tokens (JWTs); pNFT: Data user (user), who has the right to transfer their own pNFTs and generate (mint) corresponding puNFTs; puNFT: Data product demander, who has the right to use puNFTs to generate corresponding data product access tokens (JWTs).
[0053] In this embodiment, the data resource holder authenticates the data use request via blockchain and generates a corresponding data use token upon successful authentication. This process involves: utilizing the data resource holder to invoke the data holder token in the data use request via blockchain and authenticating the data holder token; if the data holder token authentication succeeds, the data resource holder derives a corresponding data use token from the data holder token. The data holder token is defined and generated by the preset data registration authority using the metadata of the target data resource sent by the data resource holder. In this embodiment, a dataset is a data resource. The holder (holder_did) field in the dataset defines the user who holds ownership of the dataset and is maintained by the registration authority (or data exchange). From a blockchain perspective, the registration authority mints a "data holder token (dNFT)" and sends the dNFT to the data holder. Specifically, the data holder token is defined and generated by the preset data registration authority using the metadata of the target data resource sent by the data resource holder. Specifically, the implementation logic for data resource ownership involves the registrar user accessing the dataset management interface and adding a new dataset using the "Add Dataset" action. On the "Add Dataset" page, the user enters the dataset metadata and defines the holder. The form is submitted to the dataset management backend. The registrar user's private key, s, is accessed. The current system time (milliseconds since 1970) is used as a random number (nonce) challenge, and the nonce is digitally signed using the private key, s. A call is then made to the data holding token contract (dNFTcontract) using parameters such as the registrar user, nonce, signature on the nonce, token name (dataset name), token symbol, and data holder. The registrar user's did (dID) is hard-coded in the dNFTcontract implementation code. This verifies whether the caller's identity matches the registrar user's did (dID). If the did (dID) differs, the contract execution terminates. The digital identity authentication contract is invoked using the registrar user's did (dID), nonce, and signature on the nonce as parameters. The verification primarily verifies the validity of the nonce's digital signature. A true return indicates successful authentication; a false return terminates the contract. Execute the mint() function of the ERC-1155 token to generate a new data token, set the holder_did to the receiving address of the new token, and obtain the token ID. Insert the token ID and other data token information into the data token table; insert the dataset metadata into the datasets table.
[0054] In this embodiment, the data resource holder uses the data holding token in the data use request through the blockchain and authenticates the data holding token. If the data holding token is authenticated, the data resource holder derives the corresponding data usage token from the data holding token. "Data Resource Use Authorization" is a function used by data holders to grant data resource (dataset) usage rights to data users. Once a data user has obtained the right to use a dataset, they can develop data products using the data in the dataset. From a blockchain perspective, the data holder derives a "Data Use Token (duNFT)" from the "Data Holding Token" and sends the duNFT to the data user. Specifically, the data user accesses the "Data Resource Use Application" interface and adds a request to use a dataset. The dataset holder can see this data use application in the "Data Resource Use Authorization" interface. If the holder approves the request, a call is initiated to the "Data Resource Use Authorization" function backend to add a new authorization record. In the backend implementation of the "Data Resource Use Authorization" function, the keystore table is first accessed to obtain the data holder's private key s. The current system time (milliseconds since 1970) is used as a random number challenge, and the nonce is digitally signed using the private key s. A call is made to the Data Usage Token Contract (duNFTcontract) using parameters such as the data holder (holder_did), nonce, nonce signature, token name (dataset name), token symbol, data user ID (user_did), and parent_token ID. The code implementation of the "Data Usage Contract (duNFTcontract)" verifies the identity of holder_did and ownership of the parent_token ID by calling the ownerOf() function of dNFTcontract to obtain the owner of the parent_tokenID token. If the holder_did and the obtained owner are not equal, the contract terminates. The digital identity authentication contract is called using the holder_did, nonce, and the signature of the nonce as parameters. This primarily verifies the validity of the nonce digital signature. A return of true indicates successful authentication; a return of false indicates a holder_did authentication failure, and the contract terminates. Execute the mint() function of the ERC-1155 token to generate a new data token, set user_did to the receiving address of the new token, and obtain the token ID. It should be noted that duNFTcontract adds the parent_token ID attribute to the ERC-1155 token, making it a new type of token.Insert the newly minted data token information such as token ID into the "data token (dataNFTS)" table; insert the authorization information such as data user and dataset metadata into the "data usage rights (usage_rights)" table.
[0055] Step S12: Acquire target data resources based on the data usage token, and process the target data resources to obtain target data products.
[0056] In this embodiment, the target data resource is acquired based on the data usage token and processed to obtain the target data product. Specifically, the data user processes the dataset, such as by encapsulating it into a data service (Rest API, an application programming interface), generating a data analysis report, or creating a desensitized dataset, thereby obtaining a new data product.
[0057] Step S13: After the target data product is authenticated by a preset data registration agency to generate a corresponding data certificate, the data certificate is stored on the chain.
[0058] In this embodiment, data products are developed by data users using datasets. Data users then own the data products they develop, confirmed by a registration authority (sometimes acting on their behalf through a data exchange). Data product development may utilize multiple datasets, resulting in a mapping relationship between the data product and the datasets (data resources, raw data). This mapping relationship is also reflected in the "data product holding token (pNFT)." Specifically, an array (parent_token ID) is defined in the pNFT to store this mapping relationship. From a blockchain perspective, the registration authority mints the "data product holding token" and sends the pNFT to the data product holder.
[0059] In this embodiment, after the target data product is authenticated by the preset data registration agency to generate the corresponding data certificate, the data certificate is stored on the chain, including: sending the product information of the target data product to the preset data registration agency, and performing a data product compliance assessment on the target data product through the preset data registration agency; if the target data product passes the data product compliance assessment, then obtaining the corresponding data product compliance certificate, and storing the data product compliance certificate on the chain; generating a corresponding data product token based on the data product compliance certificate, and storing the mapping relationship between the target data product and the target data resource in the data product token. Specifically, the data user enters the "Data Product Registration" page to register the data product, such as registering the data service address, uploading analysis reports or desensitized data sets, etc.; registering the list of data sets used by this data product. The registration agency user inquires about the data product to be confirmed, contacts the assessment agency to conduct a "data product compliance assessment", obtains the data product compliance certificate and uploads it to the data platform. The registration authority user enters the "Issue Data Product Asset Certificate" interface and enters the newly added asset certificate information in the form, including the data product holder (user_did, i.e., the data user). The form is submitted to the "Issue Data Product Asset Certificate" backend. The backend implementation logic for "Issue Data Product Asset Certificate" first accesses the keystore table to obtain the registration authority user's private key s. The current system time (milliseconds since 1970) is used as a random number (nonce) challenge, and the nonce is digitally signed using the private key s. Next, the data usage token ID array corresponding to this data product is retrieved from the product datasets (product_datasets) and data usage rights (usage_rights) tables, denoted as parent_token ID[]. Finally, a call request is initiated to the data product holding token contract (pNFTcontract) using the registration authority user's didi, nonce, signature of the nonce, token name (data product name), token symbol, data product holder (user_did), and parent_token ID[]. The code implementation of the "Data Product Token Holding Contract (pNFTcontract)" includes: the registration agency user didi has been hard-coded in the dNFTcontract implementation code in advance, and it is verified whether the caller identity is the same as the registration agency user didi. If the didi is different, the contract execution is terminated.The digital identity authentication contract is called with the registrar's user ID, nonce, and the signature of the nonce as parameters. This primarily verifies the validity of the nonce signature. If true is returned, authentication is successful; if false is returned, the contract terminates. The contract verifies the data user user_did's data usage rights (i.e., ownership of parent_token ID[]) for each dataset in the product dataset array: The ownerOf() function of duNFTcontract is called to obtain the owner of the parent_token ID tokens for all datasets used in the data product. If user_did is not equal to the obtained owner, the contract terminates. The ERC-1155 token's mint() function is executed to generate a new data token (pNFT). The user_did is set to the receiving address of the new token to obtain the token ID. The data token information, including the token ID, is inserted into the data token (dataNFTS) table; and the newly added data product information is inserted into the data products (data_products) table.
[0060] Step S14: obtaining the product application requirements for the target data product sent by the data product user, verifying the product application requirements, and then authorizing the data product user to use the data product based on the corresponding verification result and the data certificate.
[0061] In this embodiment, "Data Product Use Authorization" is a feature used by data product holders (i.e., data users) to grant data product use rights. Once a data product user has obtained data product use rights, they can use the data product through methods such as calling APIs, downloading data reports, and downloading de-identified datasets. From a blockchain perspective, a data product holder uses a "data product holding token (pNFT)" to derive a "data product use token (puNFT)" and then sends the puNFT to the data product user.
[0062] In this embodiment, the method of obtaining a product application requirement for the target data product sent by a data product user, verifying the product application requirement, and then authorizing the data product user to use the product based on the corresponding verification result and the data certificate includes: obtaining a product application requirement for the target data product sent by the data product user, and verifying the product application requirement; if the product application requirement is verified, authorizing the data product user to use the data product by deriving a corresponding data product usage token from the data product token.
[0063] It can be seen that in this embodiment, Figure 3As shown, first, a data use request for the target data resource is sent to the data resource holder, so that the data resource holder can authenticate the data use request through the blockchain and generate a corresponding data use token after the authentication is passed; based on the data use token, the target data resource is obtained and processed to obtain the target data product; after the target data product is authenticated by a preset data registration agency to generate a corresponding data certificate, the data certificate is stored on the chain; the product application requirements for the target data product sent by the data product user are obtained and verified, and then the data product user is authorized to use the data product based on the corresponding verification results and the data certificate. By using blockchain smart contracts to accurately express the rights of each participant in the data asset circulation, the rights of each participant in the data circulation are protected, and the blockchain is used to achieve tamper-proof traceability and auditing of the rights acquisition and transfer process, providing an important method and model reference for supporting the construction of a trusted data circulation platform.
[0064] In the above embodiment, Figure 4 As shown, the subdivision rights of data assets and their derivative relationships are introduced in detail. In this embodiment, the data access process is introduced in detail.
[0065] See also Figure 5 As shown, the embodiment of the present application discloses a specific data access method, which is applied to a data user, including:
[0066] Step S21: Generate a data signature through the data product user, and send an access token application to the preset authentication center based on the data signature and the data product usage token.
[0067] In this embodiment, the data product user application accesses the keystore table and obtains the data product user's private key s. It then uses the current system time (the number of milliseconds since 1970) as a random number (nonce) challenge and digitally signs the nonce using the private key s. The data product user application then requests a JWT token from the authentication center using the demander_did, nonce, nonce signature, and tokenID as parameters.
[0068] Step S22: Verify the data signature and the data product usage token to the blockchain through the preset authentication center.
[0069] In this embodiment, the authentication center calls the ownerOf() function of puNFTcontract with the token ID as a parameter to obtain the owner of the token and other token information. If the demander_did is not equal to the owner, the authentication center returns the message "Failed to request the JWT token". The authentication center uses the demander_did, nonce, and the signature of the nonce as parameters to call the digital identity authentication contract, mainly to verify the validity of the nonce digital signature. If it returns true, it means that the authentication is successful; if it returns false, it means that the demander_did authentication failed, and the authentication center returns the message "Failed to request the JWT token".
[0070] Step S23: If the verification is successful, a target access token is generated through the preset authentication center, and the target access token is sent to the data product user.
[0071] In this application, if the verification is successful, the authentication center constructs a JWT token, where the token attributes are iss={authentication center}, sub={demander_did}, aud={data product online service}, etc. The authentication center returns the JWT token to the data product user application.
[0072] Step S24: The data product user carries the target access token and initiates an access request for the target data product to the data product server, and verifies the validity of the target access token through the data product server.
[0073] In this embodiment, a data product user application initiates a data product usage request to the "Data Product Online Service" with a JWT token. This request is typically an HTTPS API call, data report download, or decrypted dataset download. The JWT is placed in the HTTPS header. The Data Product Online Service verifies the validity of the JWT token, such as whether the timestamp (exp) has expired and whether the digital signature is valid. If the JWT token is invalid, the data product service is denied.
[0074] Step S25: If the verification is successful, the data product server sends an access link of the target data product to the data product user, so that the data product user can obtain the target data product through the access link.
[0075] In this embodiment, if the JWT token is valid, the "Data Product Online Service" returns the data product, typically in the form of an HTTPS API response, a data report download response, or a desensitized dataset download response. After obtaining the data product, the user application can use the data product content for subsequent business operations.
[0076] As can be seen, in this embodiment, the current system time is used as a challenge nonce to generate a digital signature. The puNFT is then sent to the "Authentication Center" to request a JWT token. The authentication center verifies the demander's identity and puNFT ownership on the blockchain. The authentication center generates a JWT token and returns it to the data product user application, which then uses the JWT token to access the data product. By leveraging blockchain smart contracts to precisely define the rights of each participant in data asset circulation, the rights of all participants in the data circulation process are protected. The blockchain also enables tamper-proof traceability and auditability of the acquisition and transfer of rights, providing an important method and model reference for supporting the construction of a trusted data circulation platform.
[0077] refer to Figure 6 The embodiment of the present application further discloses a data authorization device based on blockchain, which is applied to data users and includes:
[0078] The request authentication module 11 is used to send a data use request for a target data resource to the data resource holder so that the data resource holder can authenticate the data use request through the blockchain and generate a corresponding data use token after the authentication is passed;
[0079] A product processing module 12 is used to obtain target data resources based on the data usage token and process the target data resources to obtain target data products;
[0080] The product authentication module 13 is used to authenticate the target data product through a preset data registration agency to generate a corresponding data certificate, and then store the data certificate on the blockchain;
[0081] The permission issuing module 14 is used to obtain the product application requirements for the target data product sent by the data product user, verify the product application requirements, and then authorize the data product user to use the data product based on the corresponding verification results and the data certificate.
[0082] It can be seen that in this embodiment, by using blockchain smart contracts to accurately express the rights of each participant in the circulation of data assets, the rights of each participant in the data circulation are protected, and the blockchain is used to achieve tamper-proof traceability and auditing of the process of obtaining and transferring rights, providing important methods and model references for supporting the construction of a trusted data circulation platform.
[0083] In some specific embodiments, the request authentication module 11 may specifically include:
[0084] a data holding token authentication unit, configured to utilize the data resource holder to call the data holding token in the data use request through the blockchain and authenticate the data holding token;
[0085] The first token derivation unit is configured to, if the data holding token is authenticated, enable the data resource holder to derive a corresponding data usage token from the data holding token.
[0086] In some specific embodiments, the product authentication module 13 may specifically include:
[0087] A product evaluation unit, configured to send product information of the target data product to a preset data registration agency, and perform a data product compliance evaluation on the target data product through the preset data registration agency;
[0088] A product specification certification unit is used to obtain the corresponding data product compliance certificate if the target data product passes the data product compliance assessment, and store the data product compliance certificate on the blockchain;
[0089] A mapping relationship storage unit is used to generate a corresponding data product token based on the data product compliance certificate, and store the mapping relationship between the target data product and the target data resource in the data product token.
[0090] In some specific embodiments, the permission issuing module 14 may specifically include:
[0091] A demand verification unit, configured to obtain a product application demand for the target data product sent by a data product user and verify the product application demand;
[0092] The second token derivation unit is configured to derive a corresponding data product usage token from the data product token to authorize the user of the data product if the product application requirement verification is passed.
[0093] In some specific embodiments, the blockchain-based data authorization device may further include:
[0094] An access application module, configured to generate a data signature through the data product user, and send an access token application to a preset authentication center based on the data signature and the data product usage token;
[0095] A qualification verification module, configured to verify the data signature and the data product usage token to the blockchain through the preset authentication center;
[0096] The data access module is used to generate a target access token through the preset authentication center if the verification is passed, and send the target access token to the data product user so that the data product user can access the target data product through the target access token.
[0097] In some specific embodiments, the data access module may specifically include:
[0098] An access request application unit, configured to obtain a data product user and carry the target access token to initiate an access request for the target data product to the data product server;
[0099] a token verification unit, configured to verify the validity of the target access token through the data product server;
[0100] The product access unit is configured to send an access link of the target data product to the data product user through the data product server if the verification is successful, so that the data product user can obtain the target data product through the access link.
[0101] Furthermore, the embodiment of the present application also discloses an electronic device, Figure 7 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram should not be considered as any limitation to the scope of application of the present application.
[0102] Figure 7 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the blockchain-based data authorization method disclosed in any of the aforementioned embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0103] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0104] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0105] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, and can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of implementing the blockchain-based data authorization method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 may further include a computer program capable of completing other specific tasks.
[0106] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when executed by a processor, the computer program implements the aforementioned blockchain-based data authorization method. The specific steps of this method can be referred to the corresponding content disclosed in the aforementioned embodiments and will not be repeated here.
[0107] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.
[0108] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0109] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0110] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0111] The above is a detailed introduction to the technical solution provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for those skilled in the art, according to the ideas of the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A data authorization method based on blockchain, characterized in that: Applicable to data users, including: By sending a data usage request for the target data resource to the data resource holder, the data resource holder authenticates the data usage request through the blockchain and generates a corresponding data usage token after the authentication is passed; Acquire target data resources based on the data usage token, and process the target data resources to obtain target data products; After the target data product is authenticated by a preset data registration agency to generate a corresponding data certificate, the data certificate is stored on the blockchain; Obtain the product application requirements for the target data product sent by the data product user, verify the product application requirements, and then authorize the data product user to use the data product based on the corresponding verification result and the data certificate.
2. The data authorization method based on blockchain according to claim 1 is characterized in that: The data resource holder authenticates the data use request through the blockchain and generates a corresponding data use token after the authentication is passed, including: Using the data resource holder to call the data holding token in the data use request through the blockchain, and authenticating the data holding token; If the data holding token is authenticated, the data resource holder will derive the corresponding data usage token through the data holding token.
3. The data authorization method based on blockchain according to claim 2 is characterized in that: The data holding token is defined and generated by the preset data registration agency through the metadata of the target data resource sent by the data resource holder.
4. The blockchain-based data authorization method according to any one of claims 1 to 3, characterized in that: After the target data product is authenticated by a preset data registration agency to generate a corresponding data certificate, the data certificate is stored on the chain, including: Sending the product information of the target data product to a preset data registration agency, and conducting a data product compliance assessment on the target data product through the preset data registration agency; If the target data product passes the data product compliance assessment, the corresponding data product compliance certificate is obtained and stored on the blockchain; A corresponding data product token is generated based on the data product compliance certificate, and the mapping relationship between the target data product and the target data resource is stored in the data product token.
5. The data authorization method based on blockchain according to claim 4 is characterized in that: The obtaining of a product application requirement for the target data product sent by a data product user, verifying the product application requirement, and then authorizing the data product user to use the data product based on the corresponding verification result and the data certificate includes: Obtaining product application requirements for the target data product sent by the data product user and verifying the product application requirements; If the product application requirement verification is passed, the corresponding data product usage token will be derived from the data product token to authorize the user of the data product to use it.
6. The data authorization method based on blockchain according to claim 5, characterized in that: If the product application requirement verification is passed, then after authorizing the user of the data product by deriving the corresponding data product usage token from the data product token, the process further includes: Generate a data signature through the data product user, and send an access token application to a preset authentication center based on the data signature and the data product usage token; Verify the data signature and the data product usage token to the blockchain through the preset authentication center; If the verification is successful, a target access token is generated by the preset authentication center and sent to the data product user so that the data product user can access the target data product through the target access token.
7. The data authorization method based on blockchain according to claim 6, characterized in that: The data product user accesses the target data product through the target access token, including: The data product user carries the target access token to initiate an access request for the target data product to the data product server; Verifying the validity of the target access token through the data product server; If the verification is successful, the data product server sends an access link to the target data product to the data product user, so that the data product user can obtain the target data product through the access link.
8. A data authorization device based on blockchain, characterized in that: Applicable to data users, including: A request authentication module is used to send a data use request for a target data resource to a data resource holder so that the data resource holder can authenticate the data use request through the blockchain and generate a corresponding data use token after the authentication is passed; A product processing module, configured to obtain target data resources based on the data usage token, and process the target data resources to obtain target data products; A product authentication module is used to authenticate the target data product through a preset data registration agency to generate a corresponding data certificate, and then store the data certificate on the blockchain; The permission issuing module is used to obtain the product application requirements for the target data product sent by the data product user, verify the product application requirements, and then authorize the use of the data product user based on the corresponding verification results and the data certificate.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the blockchain-based data authorization method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that Used to store a computer program, which, when executed by a processor, implements the blockchain-based data authorization method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Token management method, supply chain financial system and electronic device
CN110443701A
Token generation method, supply chain financial system and electronic equipment
CN110458700A