A data rights confirmation method, data management method and system
Through blockchain technology and distributed digital identity identifier encryption data ownership confirmation method, the problem of data interoperability and mutual recognition between different platforms is solved, and the data security, privacy and simplified authentication process are achieved, which is suitable for complex data trading markets.
Patent Information
- Application Number
- CN202411384546.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-09-30
AI Technical Summary
Existing data rights confirmation methods are difficult to communicate and recognize between different platforms, cannot be applied to complex data trading markets, and have data silos and complex authentication processes.
A blockchain-based data ownership confirmation system is used to encrypt data through the distributed digital identity identifier and global parameters of the authorized agency to generate data ciphertext, and the hash value of the data plaintext is embedded in the distributed digital identity and uploaded to the blockchain to achieve transparency and security of data ownership declaration.
It enables simple and convenient intercommunication and mutual recognition of data between different platforms, simplifies the authentication process, ensures data security and privacy, and supports fine-grained access control.
Smart Images

Figure CN119272305B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data ownership confirmation, and more specifically, relates to a data ownership confirmation method, a data management method and a system. Background Art
[0002] With the rapid development of internet technology and the advancement of informatization, data security and privacy protection have become critical issues that require urgent resolution. Because existing data rights registration and publication rely on the traditional management model of "manual registration and expert review," it is unable to address digital attacks such as tampering and substitution. The existing data trading market continues to be plagued by difficulties in controlling data rights and interests and the concealment of infringements. Therefore, it is urgent to research a data rights confirmation method to provide practical and feasible technical safeguards to address the diverse stakeholders involved and the complex nature of data ownership in the data trading market.
[0003] In order to solve the above problems, existing data rights confirmation methods often encrypt the rights confirmation data before confirmation. Although it can ensure the security and privacy of the data output process, the rights confirmation records obtained by this method require joint confirmation by multiple parties during the authentication process on other platforms. For example, the platform needs to jointly authenticate the rights confirmation records with the authorized agency during the authentication process. The entire process is relatively complicated, and the rights confirmation records are difficult to communicate and recognize between different platforms, which easily forms data islands and cannot be applied to complex data trading markets. Summary of the Invention
[0004] In response to the above-mentioned defects or improvement needs of the prior art, the present invention provides a data rights confirmation method, a data management method and a system, the purpose of which is to enable the obtained rights confirmation records to be easily and conveniently communicated and mutually recognized between different platforms while ensuring the security and privacy of the data.
[0005] To achieve the above objectives, in a first aspect, the present invention provides a data rights confirmation method, which is applied to a data rights confirmation system based on blockchain; the data rights confirmation system includes: a client, an authorization agency, a blockchain, and a data storage server;
[0006] Data ownership confirmation methods include:
[0007] The data owner obtains the distributed digital identity identifier from the authorized agency and requests the global parameters required for encryption from the authorized agency through the client;
[0008] The data owner embeds his or her own and the authorized institution's distributed digital identity identifiers as attributes into the preset access policy. The data owner encrypts the ownership confirmation data using the preset access policy with global parameters and attributes embedded, obtaining the data ciphertext. The client submits the data ciphertext to the authorized institution and initiates a rights confirmation request.
[0009] After receiving the data ciphertext and the confirmation request, the authorized agency uses its own attribute key to decrypt the data ciphertext and review the obtained data plaintext; when the review is passed, the hash value of the data plaintext is extracted, a distributed digital identity is generated for the data plaintext, the hash value is embedded in the distributed digital identity of the data plaintext and uploaded to the blockchain; the distributed digital identity identifiers of the data owner and the data plaintext are embedded in the data ownership statement and uploaded to the blockchain; the data ciphertext is stored in the data storage server; the data owner is informed of the completion of the confirmation through the client; when the review fails, the data owner is informed of the failure of the confirmation through the client.
[0010] Further preferably, the preset access policy includes: access rights, usage scope and time limit of the ownership confirmation data uploaded by the data owner.
[0011] Further preferably, the above data ownership confirmation method further includes the following steps performed after the ownership confirmation is completed:
[0012] The data owner submits a request to the authorized agency through the client to obtain a verifiable certificate for the ownership data;
[0013] After receiving the request, the authorized agency obtains the data ownership statement of the confirmed data from the blockchain, and uses its own private key to digitally sign it, constructing a verifiable credential including the digital signature, the data ownership statement of the confirmed data and its own distributed digital identity identifier, and sends it to the data owner through the client; extracts the hash value of the verifiable credential, and uploads the hash value of the verifiable credential to the blockchain for evidence storage.
[0014] In a second aspect, the present invention provides a data rights confirmation system, including a client, an authorization agency, a blockchain, and a data storage server:
[0015] The client, the authorization agency and the blockchain execute the data rights confirmation method provided in the first aspect of the present invention.
[0016] In a third aspect, the present invention provides a data management method, which is applied to a data management system; the data management system includes: a client, N authorization agencies, a blockchain, and a data storage server; N ≥ 1;
[0017] The above-mentioned data management method includes:
[0018] When the data owner verifies the data ownership, the client, the first authorization agency, and the blockchain execute the data ownership verification method provided by the first aspect of the present invention; wherein the first authorization agency is any one of the N authorization agencies;
[0019] When a data user requests to use data, the data user requests the second authorization agency through the client to obtain his or her own attribute key, and downloads the data ciphertext from the data storage server through the second authorization agency, and uses his or her own attribute key to decrypt the data ciphertext. When his or her own attributes meet the preset access policy in the data ciphertext, the decryption is successful and the data plaintext is obtained; otherwise, the decryption fails; the second authorization agency is any one of the N authorization agencies.
[0020] Further preferably, the above data management method further includes:
[0021] When a verifier proposes to verify the authenticity of a verifiable certificate for a piece of ownership data:
[0022] The verifier sends a verifiable certificate to a third-party authority through the client; the third-party authority is any authority among the N authorities;
[0023] After receiving the verifiable certificate, the third authorized agency parses the digital signature, the distributed digital identity identifier of the authorized agency that performed the data ownership confirmation operation, and the data ownership statement from the verifiable certificate, and queries the blockchain to see if the authorized agency that performed the data ownership confirmation operation has the qualification to issue the certificate;
[0024] If the certificate is issued, the authenticity of the digital signature obtained by parsing is verified. If the verification is successful, the hash value of the verifiable certificate is extracted and compared with the hash value of the verifiable certificate retrieved through the blockchain. If the comparison is consistent, the verification result of the verifiable certificate is authentic; if the comparison is inconsistent, the verification result of the verifiable certificate is not authentic is obtained; if the verification fails, the verification result of the verifiable certificate is not authentic is obtained;
[0025] If there is no certificate issuing qualification, the verification result obtained is that the verifiable certificate is not authentic;
[0026] Verifying the authenticity of the digital signature obtained through parsing includes:
[0027] Using the parsed digital signature and data ownership statement, the public key of the authorized agency performing the rights confirmation operation is calculated and compared with the public key of the authorized agency performing the rights confirmation operation obtained through blockchain query. When the comparison is consistent, the verification is considered to be successful; otherwise, the verification fails.
[0028] Further preferably, the above data management method further includes:
[0029] When a user registers an identity, the user sends a request to the fourth authority to create a distributed digital identity through the client;
[0030] After receiving the request, the fourth authorization agency generates a distributed digital identity for the user and uploads the user's distributed digital identity to the blockchain;
[0031] Among them, users include: data owners, data users and verifiers; the fourth authorization agency is any authorization agency among the N authorization agencies.
[0032] In a third aspect, the present invention provides a data management system, comprising: a client, N authorization agencies, a blockchain, and a data storage server; N ≥ 1;
[0033] The client, N authorized institutions, and blockchain are used to execute the data management method provided in the third aspect of the present invention.
[0034] In general, the above technical solutions conceived by the present invention can achieve the following beneficial effects:
[0035] 1. The present invention provides a data rights confirmation method, which embeds the distributed digital identity identifier of the authorization agency as an attribute into the preset access policy to stipulate that the authorization agency has the right to decrypt data and review the plain text of the data, and embeds the distributed digital identity identifier of the data owner as an attribute into the preset access policy to clarify the ownership of the confirmed data, and then uses the preset access policy with global parameters and attributes embedded to encrypt the confirmed data, and submits the obtained data ciphertext to the authorization agency for confirmation, thereby avoiding the risk of data leakage in the confirmation process and ensuring the security and privacy of the data; at the same time, the data ownership statement obtained thereby directly carries the distributed digital identity identifier information of the authorization agency, so that in the subsequent authentication process of the data ownership statement, there is no need to jointly authenticate the authorization agency that performs data confirmation. It is only necessary to obtain the information of the authorization agency that performs data confirmation from the data ownership statement to achieve authentication, which simplifies the authentication process and enables the data ownership statement to be easily and conveniently interoperable and mutually recognized between different platforms, and is suitable for complex data trading markets.
[0036] 2. Furthermore, the data ownership confirmation method provided by the present invention has a preset access policy including: access rights, usage scope and time limit of the ownership confirmation data uploaded by the data owner, which can independently stipulate the usage of the data. In this way, in the subsequent data access process, users do not need to rely on a centralized service provider to ensure that only authorized users can access the data, thus realizing distributed access control, reducing single points of failure, and increasing the security of subsequent data access.
[0037] 3. Furthermore, in the data ownership confirmation method provided by the present invention, when the data owner makes a request to the authorized agency to obtain a verifiable certificate for the ownership confirmation data, the authorized agency, while generating the verifiable certificate, also extracts the hash value of the verifiable certificate and uploads the hash value of the verifiable certificate to the blockchain for evidence storage; the purpose of this design is that, on the one hand, the storage cost of the blockchain is relatively high, and directly storing the certificate data will affect the performance, while the hash value of the verifiable certificate is only a string of fixed length, which greatly reduces the amount of data; on the other hand, any change to the data will change the value of the hash summary, so it is possible to verify whether the verifiable certificate has been tampered with by only the hash value of the verifiable certificate without saving the verifiable certificate.
[0038] 4. The present invention provides a data management method. When the data owner confirms the data ownership, the data ownership confirmation method provided by the present invention is used to perform the confirmation operation. Under the premise of ensuring the security and privacy of the data, the obtained ownership confirmation records can be easily and conveniently communicated and recognized between different platforms; when the data user requests to use the data, the data ciphertext is decrypted based on the data user's attribute key. Only data users who meet the preset access policy can complete the decryption, realizing fine-grained access control without the need for complex key management processes.
[0039] 5. Furthermore, the data management method provided by the present invention, when the verifier proposes to verify the authenticity of the verifiable certificate of a certain ownership data, parses the digital signature, the distributed digital identity identifier of the authorized agency that performs the ownership operation on the ownership data, and the data ownership statement from the verifiable certificate, and queries the blockchain to see whether the authorized agency that performs the ownership operation has the qualification to issue certificates. The digital signature is then used to verify the authenticity of the certificate, and then the certificate verification method of the blockchain is used to verify the information of the certificate on the chain. The authenticity of the verifiable certificate is guaranteed by layer-by-layer verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 A flowchart of a data rights confirmation method provided by an embodiment of the present invention;
[0041] Figure 2 A diagram of the data rights confirmation process provided by an embodiment of the present invention;
[0042] Figure 3 A schematic diagram of the structure of a data management system provided by an embodiment of the present invention;
[0043] Figure 4 A schematic diagram of the data management process provided by an embodiment of the present invention;
[0044] Figure 5A diagram of the process of verifying the authenticity of a verifiable credential for certain ownership confirmation data provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0045] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the present invention and are not intended to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below may be combined with each other as long as they do not conflict with each other.
[0046] To achieve the above objectives, in a first aspect, the present invention provides a data rights confirmation method, which is applied to a data rights confirmation system based on blockchain; the data rights confirmation system includes: a client, an authorization agency, a blockchain, and a data storage server;
[0047] like Figure 1 As shown, the above-mentioned data ownership confirmation methods include:
[0048] The data owner obtains the distributed digital identity identifier from the authorized agency and requests the global parameters required for encryption from the authorized agency through the client. The global parameters include the mathematical domain and parameters used for encryption and decryption.
[0049] The data owner embeds his or her own and the authorized institution's distributed digital identity identifiers as attributes into the preset access policy. The data owner encrypts the ownership confirmation data using the preset access policy with global parameters and attributes embedded, obtaining the data ciphertext. The client submits the data ciphertext to the authorized institution and initiates a rights confirmation request.
[0050] After receiving the data ciphertext and the request for confirmation of ownership, the authorized agency uses its own attribute key to decrypt the data ciphertext and review the obtained data plaintext; when the review is passed, the hash value of the data plaintext is extracted, a distributed digital identity is generated for the data plaintext, the hash value is embedded in the distributed digital identity of the data plaintext and uploaded to the blockchain to achieve the binding of data and distributed digital identity; the distributed digital identity identifiers of the data owner and the data plaintext are embedded in the data ownership statement and uploaded to the blockchain to ensure the transparency and security of ownership through the consensus mechanism; the data ciphertext is stored in the data storage server; the data owner is informed of the completion of the confirmation of ownership through the client; when the review fails, the data owner is informed of the failure of the confirmation of ownership through the client.
[0051] The specific process diagram of the above process is as follows Figure 2 shown.
[0052] In one optional embodiment, after the authorized institution has reviewed and approved the decrypted plaintext data, it extracts a hash value from the plaintext data, generates a distributed digital identity for the plaintext data, embeds the hash value into the distributed digital identity of the plaintext data, and uploads it to the blockchain. After the upload is complete, a record containing the data location is generated for data retrieval. Finally, a record is generated for the data owner's ownership confirmation information, such as the data name, data type, and usage scenario. This allows subsequent verifiers to locate the data location from this record when reviewing the data and access the data using the data storage server's external interface. The process for generating the data's distributed digital identity is identical to the process for generating the data owner's distributed digital identity described above and will not be further described. Finally, a smart contract records the data owner's ownership information, i.e., the data ownership claim, on the blockchain. It should be noted that there are various methods for extracting hash values, including algorithms such as SHA-1, SHA-3, SHA-256, and BLAKE2. Preferably, in one optional embodiment, the authorized institution uses the SHA-256 algorithm to generate a data fingerprint, i.e., a hash value of the plaintext data.
[0053] In an optional implementation, the main process of encrypting the ownership confirmation data includes:
[0054] The initialization process is performed by the authority: the authority is responsible for generating the global parameters and master keys required for encryption. The global parameters include the mathematical domains and parameters used for encryption and decryption, while the master key is used for subsequent key derivation and verification.
[0055] The key generation process is also performed by the authority: an attribute key is generated for each user (such as data owner, user), which is associated with a set of attributes of the user. The generation of attribute keys depends on the master key generated during the initialization process;
[0056] Encryption process: When encrypting data, the data owner defines a preset access policy, which is a string in a specific format that describes which attribute combinations can decrypt the data. Based on this, the data owner embeds the distributed digital identity identifiers of himself and the authorized institution as attributes into the preset access policy. This preset access policy is encrypted together with the ownership confirmation data to form the data ciphertext. The encryption process uses global system parameters and the preset access policy with embedded attributes to encrypt the ownership confirmation data, generating data ciphertext, ensuring that only keys that meet the requirements of the preset access policy can decrypt the data. When a user holding an attribute key attempts to decrypt the ciphertext, the user will check whether the attributes in the key meet the access policy in the ciphertext. If so, the data will be decrypted; if not, the decryption process will fail and the data will remain encrypted.
[0057] It should be noted that data owners can also set other attributes in the preset access policy, such as data access rights, usage scope, time limit, etc., to independently determine how the data is used. Specifically, in one optional implementation, the preset access policy includes: access rights, usage scope, and time limit for the ownership confirmation data uploaded by the data owner.
[0058] This invention supports user-defined access policies and distributes keys based on attributes, reducing the complexity of key management. Keys only need to be generated based on attributes, eliminating the need for complex key management processes. Users can use a single attribute key to decrypt all data that meets the access policy, eliminating the need to generate separate decryption keys for each encryption task. It also supports dynamic permission changes: when user attributes change, only their attributes need to be updated, without the need to redistribute keys.
[0059] In an optional implementation manner, the above-mentioned data ownership confirmation method further includes the following steps performed after the ownership confirmation is completed:
[0060] The data owner submits a request to the authorized agency through the client to obtain a verifiable certificate for the ownership data;
[0061] After receiving the request, the authorized agency obtains the data ownership statement of the confirmed data from the blockchain, and uses its own private key to digitally sign it, constructing a verifiable credential including the digital signature, the data ownership statement of the confirmed data and its own distributed digital identity identifier, and sends it to the data owner through the client; extracts the hash value of the verifiable credential, and uploads the hash value of the verifiable credential to the blockchain for evidence storage.
[0062] Specifically, in one implementation, a digital signature, a data ownership statement for the confirmed data, and a distributed digital identity identifier of the authorized institution are directly combined to form a verifiable credential. In another implementation, a unique identifier for the verifiable credential is generated as an ID, and the digital signature, the data ownership statement for the confirmed data, the distributed digital identity identifier of the authorized institution, the ID, and metadata such as the generation time and expiration time are packaged to form a complete verifiable credential.
[0063] Specifically, when issuing a verifiable credential, the authorized agency first confirms the ownership information on the blockchain, then packages the data owner's distributed identity identifier, the data's distributed identity identifier, the authorized agency's distributed identity identifier, the credential's generation time, and its expiration time. The authorized agency's private key generates a digital signature on the packaged information through a cryptographic algorithm. Finally, all of the information is packaged into a verifiable credential and returned to the data owner in the form of a text document. The authorized agency also generates a hash digest for the verifiable credential and records the hash digest on the blockchain for evidence storage. The purpose of saving the hash digest is that, on the one hand, the storage cost of the blockchain is high, and directly storing the credential data will affect performance. The hash digest is only a fixed-length hexadecimal string, which greatly reduces the amount of data. On the other hand, the hash digest is generated by the original data through a cryptographic algorithm. Any change to the data will change the value of the hash digest. Therefore, it is possible to verify whether the verifiable credential has been tampered with by using only the hash digest without saving the verifiable credential.
[0064] In an optional implementation manner, the data ownership confirmation method further includes: performing a pre-performed identity registration operation of the data owner;
[0065] When a data owner registers an identity, the data owner sends a request to the authority to create a distributed digital identity through the client;
[0066] After receiving the request, the authorized agency generates a distributed digital identity for the user and uploads the user's distributed digital identity to the blockchain;
[0067] Specifically, in this embodiment, when creating a data owner's distributed digital identity, the authorized institution uses a cryptographic algorithm to generate a private key and a public key. The public key is embedded in the user's distributed digital identity and uploaded to the blockchain. The private key is returned to the data owner, who then keeps it. The data owner's attribute information is recorded in the distributed digital identity. In one specific embodiment, the authorized institution uses a cryptographic algorithm to create a public-private key pair for the data owner. The public key is represented by an Ethereum wallet address. As part of the distributed digital identity, the authorized institution calls a smart contract to register it on the blockchain. The private key is a hexadecimal string. The private key is used to verify the data owner's distributed digital identity and create digital signatures. The private key is kept by the data owner to prevent leakage.
[0068] In summary, this invention strengthens the protection of data copyrights and ensures the immutability and transparency of the ownership confirmation process. Furthermore, it enables fine-grained access control without relying on a centralized organization, thus strengthening data security management.
[0069] In a second aspect, the present invention provides a data rights confirmation system, including a client, an authorization agency, a blockchain, and a data storage server:
[0070] The client, the authorization agency and the blockchain execute the data rights confirmation method provided in the first aspect of the present invention.
[0071] The relevant technical solution is the same as the data ownership confirmation method provided in the first aspect of the present invention, and will not be described in detail here.
[0072] In a third aspect, the present invention provides a data management method, which is applied to a data management system; Figure 3 As shown, the data management system includes: a client, N authorized agencies, a blockchain, and a data storage server; N ≥ 1;
[0073] like Figure 4 As shown, the above data management method includes:
[0074] When the data owner verifies the data ownership, the client, the first authorization agency, and the blockchain execute the data ownership verification method provided by the first aspect of the present invention; wherein the first authorization agency is any one of the N authorization agencies;
[0075] When a data user requests to use data, the data user requests the second authorization agency through the client to obtain his or her own attribute key, and downloads the data ciphertext from the data storage server through the second authorization agency, and uses his or her own attribute key to decrypt the data ciphertext. When his or her own attributes meet the preset access policy in the data ciphertext, the decryption is successful and the data plaintext is obtained; otherwise, the decryption fails; the second authorization agency is any one of the N authorization agencies.
[0076] In an alternative embodiment, Figure 5 As shown, the above data management method further includes:
[0077] When a verifier proposes to verify the authenticity of a verifiable certificate for a piece of ownership data:
[0078] The verifier sends a verifiable certificate to a third-party authority through the client; the third-party authority is any authority among the N authorities;
[0079] After receiving the verifiable certificate, the third authorized agency parses the digital signature, the distributed digital identity identifier of the authorized agency that performed the data ownership confirmation operation, and the data ownership statement from the verifiable certificate, and queries the blockchain to see if the authorized agency that performed the data ownership confirmation operation has the qualification to issue the certificate;
[0080] If the certificate is issued, the authenticity of the digital signature obtained by parsing is verified. If the verification is successful, the hash value of the verifiable certificate is extracted and compared with the hash value of the verifiable certificate retrieved through the blockchain. If the comparison is consistent, the verification result of the verifiable certificate is authentic; if the comparison is inconsistent, the verification result of the verifiable certificate is not authentic is obtained; if the verification fails, the verification result of the verifiable certificate is not authentic is obtained;
[0081] If there is no certificate issuing qualification, the verification result obtained is that the verifiable certificate is not authentic;
[0082] Verifying the authenticity of the digital signature obtained through parsing includes:
[0083] Using the parsed digital signature and data ownership statement, the public key of the authorized agency performing the rights confirmation operation is calculated and compared with the public key of the authorized agency performing the rights confirmation operation obtained through blockchain query. When the comparison is consistent, the verification is considered to be successful; otherwise, the verification fails.
[0084] It should be noted that in the above process, the third authorization agency first parses the distributed digital identity identifier and digital signature of the issuing party (the authorization agency that performs the title confirmation operation on the title confirmation data) from the verifiable certificate and queries the issuing party through the blockchain to see whether it has the qualification to issue the certificate. It then uses the digital signature to verify the authenticity of the certificate, and then uses the certificate verification method of the blockchain to verify the information on the certificate chain, and further verify the authenticity of the verifiable certificate.
[0085] The information contained in the verifiable certificate can support the verifier to independently complete the certificate verification, but it requires certain knowledge. Therefore, the verifier often hands over the verifiable certificate to the authorized agency for proxy verification. The verification process is: first check the declaration part of the verifiable certificate, especially the ownership information in the declaration, then extract the message that needs signature verification from the verifiable certificate and hash the message to generate the hash value of the message, then use the message and signature to recover the signer's Ethereum address from the signature, check whether the signer is consistent with the issuer field described in the certificate and verify whether the issuer is qualified through the smart contract, and finally check and compare the hash value of the verifiable certificate stored on the chain through the smart contract to further ensure that the certificate cannot be tampered with.
[0086] In an optional implementation manner, the data management method further includes:
[0087] When a user registers an identity, the user sends a request to the fourth authority to create a distributed digital identity through the client;
[0088] After receiving the request, the fourth authorization agency generates a distributed digital identity for the user and uploads the user's distributed digital identity to the blockchain;
[0089] Among them, users include: data owners, data users and verifiers; the fourth authorization agency is any authorization agency among the N authorization agencies.
[0090] Specifically, in this embodiment, when creating a user's distributed digital identity, the authorized institution uses a cryptographic algorithm to generate a private key and a public key. The public key is embedded in the distributed digital identity and uploaded to the blockchain. The private key is returned to the user and saved by the user. The user's attribute information is recorded in the distributed digital identity. In one specific embodiment, the authorized institution uses a cryptographic algorithm to create a public-private key pair for the user. The public key is represented by an Ethereum wallet address. As part of the distributed digital identity, the authorized institution calls a smart contract to register the public key on the blockchain. The private key is a hexadecimal string. The private key is used to verify the user's distributed digital identity and create digital signatures. The private key is kept by the user and prevented from being leaked.
[0091] It should be noted that the first authorization agency, the second authorization agency, the third authorization agency and the fourth authorization agency may be the same or different, and there is no limitation here.
[0092] In a third aspect, the present invention provides a data management system, comprising: a client, N authorization agencies, a blockchain, and a data storage server; N ≥ 1;
[0093] The client, N authorized institutions, and blockchain are used to execute the data management method provided in the third aspect of the present invention.
[0094] Among them, the user can act as the owner of the data, that is, the initiator of the ownership confirmation operation, encrypt the data to generate data ciphertext and submit it to the authorization agency, and use verifiable credentials to prove ownership; or as a data user, download the data ciphertext and obtain the attribute key from the authorization agency. Only the user attributes with ownership meet the access policy to complete the decryption operation; or as the verifier of ownership, submit a verifiable certificate to the authorization agency to verify the authenticity of ownership.
[0095] The authorized institution is directly connected to the blockchain and stores the user's business information on the blockchain. The authorized institution also has a distributed digital identity and can endorse the user's data ownership. At the same time, the authorized institution also assumes the role of generating and publishing the global parameters required for user encryption and the attribute keys required for decryption.
[0096] Blockchain can store distributed digital identities and verifiable credential information, assisting authorized agencies in completing credential verification and attribute key generation operations;
[0097] The data storage server is responsible for storing the user's encrypted data and providing upload and download interfaces for authorized agencies.
[0098] The relevant technical solution is the same as the data management method provided in the third aspect of the present invention, and will not be described in detail here.
[0099] In summary, the present invention provides a data rights confirmation method, a data management method, and a system for data rights confirmation. Distributed digital identities feature cross-platform authentication and privacy protection. The data rights confirmation process no longer relies solely on centralized identity providers. Users can independently manage their identities and selectively disclose some private data. This eliminates data silos and enables unified data management and sharing. Attribute-based encryption is introduced to ensure data security. During the rights confirmation process, users do not need to trust authorized institutions or worry about data leaks, while achieving fine-grained access control over data.
[0100] The present invention combines distributed digital identity and ciphertext policy attribute-based encryption, introduces distributed digital identity as an attribute, and stores the distributed digital identity of users and data as well as rights information on the blockchain. During encryption, users independently determine the access policy, and during decryption, user attributes are read from the blockchain to generate a decryption key. Only users who meet the access policy can complete decryption, realizing fine-grained access control. At the same time, it avoids the risk of data leakage during the right confirmation process, ensuring the tamper-proof and transparency of the right confirmation process; users do not need to trust centralized service providers to ensure that only authorized users can access the data, realizing distributed access control to reduce single points of failure and increase the security of the system.
[0101] It will be easily understood by those skilled in the art that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A data rights confirmation method, characterized in that: Applied to blockchain-based data ownership confirmation system; The data rights confirmation system includes: a client, an authorization agency, a blockchain and a data storage server; The data rights confirmation method includes: The data owner obtains the distributed digital identity identifier of the authorization agency and requests the authorization agency to obtain the global parameters required for encryption through the client; The data owner embeds the distributed digital identity identifiers of himself and the authorized institution as attributes into the preset access policy; encrypts the ownership confirmation data using the preset access policy with the embedded global parameters and attributes to obtain data ciphertext; submits the data ciphertext to the authorized institution through the client and initiates a rights confirmation request; After receiving the data ciphertext and the confirmation request, the authorization agency uses its own attribute key to decrypt the data ciphertext and reviews the obtained data plaintext; when the review is passed, the hash value of the data plaintext is extracted, a distributed digital identity is generated for the data plaintext, the hash value is embedded in the distributed digital identity of the data plaintext and uploaded to the blockchain; the distributed digital identity identifier of the data owner and the data plaintext is embedded in the data ownership statement and uploaded to the blockchain; the data ciphertext is stored in the data storage server; the data owner is informed of the completion of the confirmation through the client; when the review fails, the data owner is informed of the failure of the confirmation through the client.
2. The data ownership confirmation method according to claim 1, characterized in that: The preset access policy includes: access rights, usage scope and time limit of the ownership confirmation data.
3. The data ownership confirmation method according to claim 1 or 2, characterized in that: Also includes: The following steps are performed after the title confirmation is completed: The data owner submits a request to the authorization agency through the client to obtain a verifiable certificate for the ownership confirmation data; After receiving the request, the authorization agency obtains the data ownership statement of the ownership confirmation data from the blockchain, and uses its own private key to digitally sign it, constructing a verifiable credential including the digital signature, the data ownership statement of the ownership confirmation data and its own distributed digital identity identifier, and sends it to the data owner through the client; extracts the hash value of the verifiable credential, and uploads the hash value of the verifiable credential to the blockchain for evidence storage.
4. A data rights confirmation system, characterized in that: include: Client, authority, blockchain and data storage server: The client, the authorization agency and the blockchain execute the data rights confirmation method described in any one of claims 1-3.
5. A data management method, characterized in that: Application in data management systems; The data management system includes: a client, N authorized institutions, a blockchain and a data storage server; N≥1; The data management method comprises: When the data owner verifies the data ownership, the client, the first authorization agency, and the blockchain execute the data ownership confirmation method according to any one of claims 1 to 3; the first authorization agency is any one of the N authorization agencies; When a data user requests to use data, the data user requests the second authorization agency through the client to obtain his own attribute key, and downloads the data ciphertext from the data storage server through the second authorization agency, and uses his own attribute key to decrypt the data ciphertext. When his own attributes meet the preset access policy in the data ciphertext, the decryption is successful and the data plaintext is obtained; otherwise, the decryption fails; the second authorization agency is any one of the N authorization agencies.
6. The data management method according to claim 5, characterized in that: Also includes: When a verifier proposes to verify the authenticity of a verifiable certificate for a piece of ownership data: The verifier sends a verifiable credential to a third authority through the client; the third authority is any one of the N authorities; After receiving the verifiable credential, the third authorized institution parses the digital signature, the distributed digital identity identifier of the authorized institution that performed the authentication operation on the authentication data, and the data ownership statement from the verifiable credential, and queries the blockchain to determine whether the authorized institution that performed the authentication operation has the qualification to issue certificates. If the certificate is issued, the authenticity of the digital signature obtained by parsing is verified. If the verification is successful, the hash value of the verifiable credential is extracted and compared with the hash value of the verifiable credential retrieved through the blockchain. If the comparison is consistent, a verification result is obtained that the verifiable credential is authentic; if the comparison is inconsistent, a verification result is obtained that the verifiable credential is not authentic; if the verification fails, a verification result is obtained that the verifiable credential is not authentic; If there is no certificate issuing qualification, the verification result that the verifiable certificate is not authentic is obtained; The verification of the authenticity of the digital signature obtained by the analysis includes: The public key of the authorized agency performing the confirmation operation is calculated using the parsed digital signature and data ownership statement, and compared with the public key of the authorized agency performing the confirmation operation obtained through the blockchain query. When the comparison is consistent, the verification is determined to be successful; otherwise, the verification fails.
7. The data management method according to claim 5 or 6, characterized in that: Also includes: When a user registers an identity, the user sends a request to create a distributed digital identity to the fourth authority through the client; After receiving the request, the fourth authorization agency generates a distributed digital identity for the user and uploads the user's distributed digital identity to the blockchain; The users include: data owners, data users and verifiers; the fourth authorization agency is any one of the N authorization agencies.
8. A data management system, characterized in that: include: Client, N authorized institutions, blockchain and data storage server; N≥1; The client, the N authorization agencies, and the blockchain are used to execute the data management method described in any one of claims 5 to 7.
Citation Information
Patent Citations
Encrypted file right confirmation method, device and system based on block chain attributes
CN115906181A
Smart home monitoring data security management method based on block chain
CN117294496A