A data sharing method

By generating authentication credentials using SIM cards and blockchain technology to encrypt and share data, the security and trust issues in cross-platform data sharing are resolved, enabling secure transmission of target data between users.

CN119316835BActive Publication Date: 2026-04-28CHINA MOBILE INTERNET CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE INTERNET CO LTD
Filing Date
2024-10-14
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

During cross-platform data sharing, data is easily subject to malicious modification or deletion, making it difficult to guarantee security and trustworthiness.

Method used

By leveraging the decentralized and immutable characteristics of SIM cards and blockchain technology, authentication credentials are generated through blockchain nodes to encrypt and share data, ensuring that only the blockchain nodes and the target user's SIM card can decrypt the data.

Benefits of technology

It enables secure and reliable data sharing between the first and second users, preventing data from being modified or deleted during cross-platform sharing and improving the security and reliability of data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119316835B_ABST
    Figure CN119316835B_ABST
Patent Text Reader

Abstract

The application discloses a data sharing method, which can realize safe and reliable data sharing based on a blockchain technology. The data sharing method comprises the following steps: in the case that a first user requests to share target data, a SIM card of the first user acquires a first authentication credential from a blockchain node, the first authentication credential being generated by the blockchain node based on an authentication key and user information of a second user stored in the blockchain; the SIM card of the first user encrypts the target data based on the first authentication credential and a private key of the first user, and obtains a first ciphertext; and the SIM card of the first user sends the first ciphertext to a SIM card of the second user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of mobile communication technology, and in particular to a data sharing method. Background Technology

[0002] With the rapid development of mobile communication technology, users transmit and share a large amount of information in their daily lives and work. For example, they can share data to various instant messaging software and social platforms through the share button of an application (APP). However, during the sharing process, especially in cross-platform sharing, data is easily maliciously modified or deleted, making it difficult to guarantee security and trustworthiness. Summary of the Invention

[0003] The purpose of this application is to provide a data sharing method that enables secure and reliable data sharing based on blockchain technology.

[0004] To achieve the above objectives, the embodiments of this application adopt the following technical solutions:

[0005] In a first aspect, embodiments of this application provide a data sharing method applied to a first user's SIM card, the method comprising:

[0006] When the first user requests to share target data, a first authentication credential is obtained from the blockchain node; the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain.

[0007] The target data is encrypted based on the first authentication credential and the first user's private key to obtain the first ciphertext;

[0008] The first ciphertext is sent to the second user's SIM card.

[0009] Secondly, embodiments of this application provide a data sharing method applied to a blockchain node, the method comprising:

[0010] Obtain the authentication key and user information of the second user from the blockchain. The second user is the user who is to receive the target data shared by the first user.

[0011] The user information of the second user is encrypted based on the authentication key to obtain the first authentication credential;

[0012] The first authentication credential is sent to the first user's SIM card. The first authentication credential is used by the first user's SIM card to encrypt the target data and then send it to the second user's SIM card.

[0013] Thirdly, embodiments of this application provide a data sharing method applied to a second user's SIM card, the method comprising:

[0014] Receive first ciphertext from the SIM card of the first user; the first ciphertext is obtained by encrypting target data by the SIM card of the first user based on the first authentication credential and the private key of the first user, and the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain;

[0015] A second authentication credential is generated based on the authentication key and user information of the second user stored locally on the second user's SIM card.

[0016] The first ciphertext is decrypted based on the second authentication credential and the first user's public key to obtain the target data.

[0017] Fourthly, embodiments of this application provide a data sharing device applied to a first user's SIM card, the device comprising:

[0018] The first acquisition module is used to acquire a first authentication credential from a blockchain node when the first user requests to share target data; the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain;

[0019] The first encryption module is used to encrypt the target data based on the first authentication credential and the first user's private key to obtain the first ciphertext;

[0020] The first sending module is used to send the first ciphertext to the SIM card of the second user.

[0021] Fifthly, embodiments of this application provide a data sharing device applied to a blockchain node, the device comprising:

[0022] The second acquisition module is used to acquire the authentication key and user information of the second user from the blockchain. The second user is the user who is to receive the target data shared by the first user.

[0023] The second encryption module is used to encrypt the user information of the second user based on the authentication key to obtain the first authentication credential;

[0024] The second sending module is used to send the first authentication credential to the first user's SIM card. The first authentication credential is used by the first user's SIM card to encrypt the target data and then send it to the second user's SIM card.

[0025] Sixthly, embodiments of this application provide a data sharing device applied to a second user's SIM card, the device comprising:

[0026] The first receiving module is used to receive the first ciphertext from the SIM card of the first user; the first ciphertext is obtained by encrypting target data by the SIM card of the first user based on the first authentication credential and the private key of the first user, and the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain;

[0027] The third encryption module is used to generate a second authentication credential based on the authentication key and user information of the second user stored locally on the second user's SIM card;

[0028] The first decryption module is used to decrypt the first ciphertext based on the second authentication credential and the first user's public key to obtain the target data.

[0029] Seventhly, embodiments of this application provide a SIM card, including:

[0030] processor;

[0031] Memory used to store the processor's executable instructions;

[0032] The processor is configured to execute the instructions to implement the data sharing method as provided in the first aspect.

[0033] Eighthly, embodiments of this application provide a blockchain node, including:

[0034] processor;

[0035] Memory used to store the processor's executable instructions;

[0036] The processor is configured to execute the instructions to implement the data sharing method as provided in the second aspect.

[0037] Ninthly, embodiments of this application provide a SIM card, including:

[0038] processor;

[0039] Memory used to store the processor's executable instructions;

[0040] The processor is configured to execute the instructions to implement the data sharing method provided by the third aspect.

[0041] In a tenth aspect, embodiments of this application provide a computer-readable storage medium that, when instructions in the storage medium are executed by a processor of an electronic device, enables the electronic device to perform a data sharing method as provided in the first, second, or third aspect.

[0042] Eleventhly, embodiments of this application provide a computer program product, the computer program product including a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps in the data sharing methods provided in the first, second or third aspects.

[0043] The above-described technical solutions adopted in the embodiments of this application can achieve the following beneficial effects:

[0044] Leveraging the decentralized and immutable characteristics of SIM cards and blockchain technology, secure and reliable data sharing between a first user and a second user is achieved, enhancing data sharing security and preventing data tampering or modification during cross-platform sharing. Specifically, when a first user requests to share target data, the first user's SIM card obtains a first authentication credential for the sharing from a blockchain node. This first authentication credential, along with the first user's private key, is used to encrypt the target data, resulting in a first ciphertext, which is then sent to the second user's SIM card. The authentication credential is obtained by the blockchain node encrypting the user information of both the first and second users based on the second user's authentication key stored in the blockchain. Due to the decentralized and immutable nature of blockchain, and the fact that only the second user's SIM card possesses the second user's authentication key and user information (besides the blockchain node), only the blockchain node and the second user's SIM card can obtain the first authentication credential and thus retrieve the target data from the first ciphertext. This achieves encrypted sharing of target data between the first and second users, preventing modification or deletion during the sharing process and improving the security and reliability of data sharing, especially cross-platform data sharing. Attached Figure Description

[0045] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0046] Figure 1 A schematic diagram illustrating the implementation environment to which a data sharing method provided in this application is applicable;

[0047] Figure 2 A flowchart illustrating a data sharing method provided in one embodiment of this application;

[0048] Figure 3 A schematic diagram of a first sharing interface provided for one embodiment of this application;

[0049] Figure 4 A schematic diagram of a second sharing interface provided for one embodiment of this application;

[0050] Figure 5 A schematic diagram of cover content provided for one embodiment of this application;

[0051] Figure 6 A flowchart illustrating a data sharing method provided for another embodiment of this application;

[0052] Figure 7 A flowchart illustrating a data sharing method provided in yet another embodiment of this application;

[0053] Figure 8 A flowchart illustrating a data sharing method provided in yet another embodiment of this application;

[0054] Figure 9 A schematic diagram of the structure of a data sharing device provided in one embodiment of this application;

[0055] Figure 10 A schematic diagram of the structure of a data sharing device provided for another embodiment of this application;

[0056] Figure 11 A schematic diagram of the structure of a data sharing device provided in yet another embodiment of this application;

[0057] Figure 12 A schematic diagram of the structure of a SIM card is provided for one embodiment of this application;

[0058] Figure 13 This is a schematic diagram of the structure of a blockchain node provided in one embodiment of this application. Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0060] The terms "first," "second," etc., used in this specification and claims are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein. Furthermore, in this specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0061] As mentioned earlier, cross-platform data sharing can easily lead to malicious modification or deletion of data content, making it difficult to guarantee security.

[0062] In view of this, this application proposes a data sharing method that utilizes the decentralized and immutable characteristics of SIM cards and blockchain technology to achieve secure and reliable data sharing between a first user and a second user, improving the security of data sharing and avoiding the problem of data tampering or modification during cross-platform sharing. Specifically, when the first user requests to share target data, the first user's SIM card obtains a first authentication credential for this sharing from the blockchain node, and uses the first authentication credential and the first user's private key to encrypt the target data to obtain a first ciphertext, which is then sent to the second user's SIM card. The authentication credential is obtained by the blockchain node encrypting the user information of the first user and the user information of the second user based on the authentication key of the second user stored in the blockchain. Because the blockchain has decentralized and immutable characteristics, and only the second user's SIM card possesses the second user's authentication key and user information besides the blockchain node, only the blockchain node and the second user's SIM card can obtain the first authentication credential, and thus obtain the target data from the first ciphertext. Therefore, encrypted sharing of target data between the first user and the second user is achieved, preventing the target data from being modified or deleted during the sharing process, improving the security and reliability of data sharing, especially the security and reliability of cross-platform data sharing.

[0063] The technical solutions provided by the various embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0064] To facilitate understanding of the technical solutions provided in the embodiments of this application, firstly, in conjunction with Figure 1 The implementation environment to which the technical solutions provided in the embodiments of this application are applicable will be described. It should be understood that the technical solutions provided in the embodiments of this application are applied to... Figure 1 The implementation environment shown is merely an illustrative example and should not be construed as a limitation on the implementation environment to which this technical solution is applicable.

[0065] like Figure 1As shown, the implementation environment to which the technical solution provided in this application is applicable includes: a first user's SIM (Subscriber Identity Module) card, a second user's SIM card, a media platform, and a blockchain.

[0066] The SIM card can be a Super SIM card, which serves as a carrier for card applications, receives and executes commands, and sends pop-up notifications. Applications are deployed on the SIM card, and its functions can be implemented through these applications.

[0067] Media platforms, such as social media platforms, can serve as a platform for data sharing between a first user and a second user. The first user's SIM card can share their data to the media platform, and the second user's SIM card can access the media platform to obtain the data shared by the first user. In practical applications, there can be multiple second users, thus achieving a "one-to-many" sharing model.

[0068] Blockchain is used to store a large amount of user information, public keys, and authentication keys. Due to its decentralized and immutable characteristics, blockchain makes the transmission and storage of this information more secure, efficient, and reliable. Smart contracts are deployed within the blockchain. A smart contract is a protocol that uses a computer program to automatically execute a contract. Based on the decentralized, immutable, and intelligent characteristics of blockchain, it uses a programming language to translate contract terms into executable code, thereby achieving automated contract execution. In this embodiment, smart contracts can be used to implement operations related to encrypted data sharing.

[0069] In one implementation, when a first user requests to share target data with a second user, a blockchain node can invoke a smart contract to retrieve the second user's authentication key and user information from the blockchain. Based on these, it generates a corresponding authentication credential and sends it to the first user's SIM card. The first user's SIM card then encrypts the target data using the authentication credential and the first user's private key, and shares it with the second user's SIM card through a media platform. The blockchain node can also invoke a smart contract to share the first user's public key with the second user's SIM card, allowing the second user's SIM card to decrypt and obtain the target data.

[0070] Because blockchain is decentralized and immutable, and only the second user's SIM card, apart from the blockchain node, possesses the second user's authentication key and user information, only the blockchain node and the second user's SIM card can obtain the first authentication credential, and thus obtain the target data from the first ciphertext.

[0071] In this embodiment, the blockchain node can be any computer or device capable of accessing the blockchain. As an example, both the first terminal device that inserts the first user's SIM card and the second terminal device that inserts the second user's SIM card can be blockchain nodes. In this case, the first terminal device is responsible for providing authentication credentials for the first user's SIM card, and the second terminal device is responsible for providing the first user's public key, etc., for the second user's SIM card.

[0072] The data sharing method provided in this application embodiment utilizes the communication and data interaction between the SIM card of the first user, the SIM card of the second user, the media platform, and the blockchain nodes of the blockchain to achieve secure and reliable data sharing between the first user and the second user.

[0073] Please see Figure 2 The following is a flowchart illustrating a data sharing method provided in one embodiment of this application. The method is applied to a first user's SIM card and includes the following steps:

[0074] S202, in the event that the first user requests to share the target data, obtain the first authentication credential from the blockchain node.

[0075] As an example, the first user's SIM card displays an interface containing the target data through its built-in application. When the user receives a click on the share button for the "target data" through the interface, it is determined that the first user has requested to share the target data.

[0076] The first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain. The second user refers to the user who is to receive the target data. The user information of the second user may include, but is not limited to, the second user's name and user identifier.

[0077] In this embodiment of the application, the above-mentioned S202 can be implemented in various ways.

[0078] In one embodiment, S202 includes the following steps:

[0079] S221, if the first user requests to share the target data, the first sharing interface is displayed.

[0080] The first sharing interface includes a first option for sharing encrypted target data. Optionally, the first sharing interface may also include a second option for sharing unencrypted target data. The first sharing interface can take various suitable forms, such as, but not limited to, pop-ups, cards, drawer navigation, bottom navigation bars, etc., which are not limited in this embodiment. As an example, the first user's SIM card can assemble an active command DisplayText through a built-in application to display the first sharing interface.

[0081] For example, Figure 3 A first sharing interface in the form of a pop-up window is shown, which includes the descriptive text "Do you want to share with encryption?", a first option "Yes" and a second option "No".

[0082] S222, in response to the selection of the first option, the second sharing interface is displayed.

[0083] The second sharing interface includes at least one relationship category. This relationship category can include, but is not limited to, friends, colleagues, close friends, and relatives.

[0084] The second sharing interface can take various suitable forms, such as, but not limited to, pop-ups, cards, drawer navigation, bottom navigation bars, etc., and this application embodiment does not limit this. As an example, the first user's SIM card can assemble an active command Displaytext through a built-in application to obtain at least one relationship category from locally stored relationship categories, and display a second sharing interface containing the obtained relationship category through the command Displaytext. For example, Figure 4 A second sharing interface in the form of a pop-up window is shown, which includes four relationship categories: friends, colleagues, close friends, and relatives.

[0085] It's important to note that before activating the data sharing function, the first user's SIM card can display a configuration interface, allowing the first user to configure relationship categories. For example, the first user can set the relationship category with users B and D to "friends," with user F to "family / friends," with user C to "colleagues," and with user E to "close friends," etc. Furthermore, the first user's SIM card stores the relationship categories set locally, but does not store the actual relationship data. Thus, even if the first user's SIM card is lost, only the relationship categories are lost, without any leakage of specific relationship data or other private information.

[0086] S223, in response to a selection operation for at least one relation category, sends the selected first relation category to the blockchain node.

[0087] The first relationship category is used to indicate that users whose relationship with the first user belongs to the first relationship category are designated as second users.

[0088] S224, receive the first authentication credential returned by the blockchain node.

[0089] For example, the blockchain stores specific user relationship data. After receiving the first relationship category, the blockchain node determines the user whose relationship with the first user belongs to the first relationship category from the user relationship data stored in the blockchain as the second user. Based on the user information and authentication key of the second user stored in the blockchain, the node generates the first authentication credential and returns it to the SIM card of the first user.

[0090] by Figure 4 Taking the second sharing interface shown as an example, when a trigger operation (such as clicking) is received for a "friend", the blockchain node determines user B and user D as the second users based on the user relationship data stored in the blockchain, and obtains user information of user B and user D from the blockchain to form a user information set R. A ={User B's user information, User D's user information}. Simultaneously, the blockchain node also retrieves User B's authentication key and User D's authentication key from the blockchain. Furthermore, based on User B's authentication key and user information, the blockchain node generates the first authentication credential HE corresponding to User B. B Based on user D's authentication key and user information, the first authentication credential HE corresponding to user D is generated. D And send the first authentication credentials corresponding to user B and user D to the first user's SIM card. Thus, the first user's SIM card can, based on the first authentication credentials HE... B The target data is encrypted with the first user's private key and shared with user B's SIM card, as well as based on the first authentication credential HE. D The target data is encrypted using the first user's private key and then shared with user D's SIM card.

[0091] In the above implementation, the first user's SIM card displays selectable relationship categories to the first user, and obtains the first authentication credential from the blockchain node based on the selected first relationship category. Compared with the method of the first user directly selecting the second user, this not only avoids the leakage of the second user's user information during transmission, but also enables batch and flexible selection of the second user.

[0092] In another embodiment, S202 above includes the following steps: when a first user requests to share target data, display the first sharing interface; in response to the selection operation of the first option, display a third sharing interface, the third sharing interface including multiple users that can share; in response to the selection operation of multiple users, identify the selected user as the second user, send the user identifier of the selected second user to the blockchain node, and receive the first authentication credential returned by the blockchain node.

[0093] The foregoing illustrates a partial implementation of S202. It should be understood that S202 can also be implemented in other ways, and this application does not limit this implementation.

[0094] It is worth noting that, in this embodiment, the blockchain node can be any computer or device capable of accessing the blockchain. As an example, the blockchain node includes a first terminal device into which a first user's SIM card is inserted. In this case, the first user's SIM card obtains a first authentication credential from the first terminal device.

[0095] S204. The target data is encrypted based on the first authentication credential and the first user's private key to obtain the first ciphertext.

[0096] In this embodiment of the application, S204 can be implemented in various ways.

[0097] In one embodiment, S204 includes the following steps: encrypting the target data based on the private key of the first user to obtain the second ciphertext; inserting the first authentication credential into the data header of the second ciphertext to obtain the first ciphertext.

[0098] Specifically, the first user's SIM card stores a pair of public keys pre-generated for the first user. and private key The first user's public key is uploaded to the blockchain for storage through a blockchain node, while the first user's private key is stored locally on the SIM card and is not visible to the outside world, meaning "the private key does not leave the card".

[0099] The first user's SIM card uses the first user's private key. Encrypt the target data W to obtain the second ciphertext. , Then, the first authentication credential is inserted into the header of the second ciphertext through embedding, thus obtaining the first ciphertext.

[0100] In the above implementation, the first authentication credential and the encrypted target data can be obfuscated, increasing the difficulty for the first authentication credential and even the target data to be cracked, which is conducive to improving the security of data sharing.

[0101] In another embodiment, S204 includes the following steps: encrypting the first authentication credential and the target data based on the first user's private key, and concatenating the encrypted first authentication credential and the encrypted target data to obtain the first ciphertext.

[0102] The foregoing illustrates a partial implementation of S204. It should be understood that S204 can also be implemented in other ways, and this application does not limit this implementation.

[0103] S206, the first ciphertext is sent to the second user's SIM card.

[0104] In one implementation, the first user's SIM card can directly send the first encrypted message to the second user's SIM card via the media platform's server.

[0105] In another embodiment, the first user's SIM card generates a content cover of the target data based on key information of the target data; the content cover and the first encrypted text are sent to the media platform for display, so that the media platform can send the first encrypted text to the second user's SIM card in response to the second user's trigger operation on the content cover.

[0106] The key information may include keywords describing the content of the target data. For example, if the target data is a landscape photo, the key information may include the keyword "landscape photo". The first user's SIM card generates cover content based on this keyword and sends it to the media platform for display. The cover content may contain the keyword and also the first user's user identifier. The second user's SIM card accesses the media platform to obtain the cover content, and in response to the second user's triggering action on the cover content (such as the second user clicking the view button), sends a request to the media platform. In response to the request, the media platform sends the first encrypted message to the second user's SIM card.

[0107] For example, a media platform can be an instant messaging platform. Figure 5 As shown, the instant messaging platform sends the cover content to the instant messaging window between the second user and the first user. In response to the second user's viewing of the cover content, the second user's SIM card sends a request to the media platform. In response to the request, the media platform sends the first encrypted message to the second user's SIM card.

[0108] In the above implementation, the first user's SIM card first shares the first encrypted text and the cover content of the target data to the media platform. When the second user requests to view the cover content, the media platform sends the first encrypted text to the second user's SIM card, which increases the second user's autonomy and flexibility in accepting the sharing.

[0109] The data sharing method provided in this application embodiment, when a first user requests to share target data, involves the first user's SIM card obtaining a first authentication credential for the sharing from a blockchain node. The first authentication credential and the first user's private key are then used to encrypt the target data into a first ciphertext, which is then sent to the second user's SIM card. The authentication credential is obtained by the blockchain node encrypting the user information of both the first and second users based on the second user's authentication key stored in the blockchain. Because the blockchain is decentralized and immutable, and only the second user's SIM card possesses the second user's authentication key and user information besides the blockchain node, only the blockchain node and the second user's SIM card can obtain the first authentication credential, and thus retrieve the target data from the first ciphertext. This achieves encrypted sharing of target data between the first and second users, preventing modification or deletion of the target data during the sharing process, and improving the security and reliability of data sharing, especially cross-platform data sharing.

[0110] Please refer to Figure 6 The following is a flowchart illustrating a data sharing method provided in one embodiment of this application. The method is applied to a blockchain node and includes the following steps:

[0111] S602, obtain the authentication key of the second user and the user information of the second user from the blockchain.

[0112] The second user is the user who will receive the target data shared by the first user. The blockchain stores a large amount of user information, public keys, and authentication keys. Due to the decentralized and immutable nature of the blockchain, the transmission and storage of this information become more secure, efficient, and reliable.

[0113] In one implementation, upon receiving the user identifier of the second user sent by the SIM card of the first user, the blockchain node invokes a smart contract to retrieve the authentication key and user information of the second user from the blockchain.

[0114] In another implementation, when a blockchain node receives a first relationship category sent by the first user's SIM card, it invokes a smart contract to retrieve user information of users whose relationship with the first user belongs to the first relationship category from the blockchain, as the user information of the second user, and retrieves the authentication key of the second user from the blockchain.

[0115] For example, a blockchain stores user information, authentication keys, public keys, and relationship categories between users A through F. Assume user A, and the relationship category between user A, user B, and user D is "friends." If a blockchain node receives a message from user A's SIM card with the first relationship category "friends," it retrieves user information and authentication keys for users B and D from the blockchain.

[0116] Through the above implementation method, the first user's SIM card and the blockchain node do not need to transmit specific user information and user relationship data, but only the relationship category, which can avoid the leakage of privacy information and further improve the security of the data sharing process.

[0117] S604, encrypt the user information of the second user based on the authentication key of the second user to obtain the first authentication credential.

[0118] In this embodiment, S604 can be implemented in various appropriate ways.

[0119] In one implementation, the number of authentication keys is at least two. In this case, S604 above includes the following steps:

[0120] S641, determine a first authentication key and a second authentication key from at least two authentication keys.

[0121] As an example, two authentication keys can be randomly selected from at least two authentication keys, with one of the authentication keys being used as the first authentication key and the other as the second authentication key.

[0122] S642, based on the first authentication key, encrypt the user information of the first user to obtain the fourth ciphertext.

[0123] Encrypting user information using an authentication key can be achieved using various encryption algorithms commonly used in the field, such as including but not limited to DES (Data Encryption Standard), 3DES (Triple DES), and AES (Advanced Encryption Standard). This application does not limit the specific encryption algorithms used.

[0124] S643, based on the second authentication key, encrypt the user information of the second user to obtain the fifth ciphertext.

[0125] S644, based on the fourth and fifth ciphertexts, generates the first authentication credential.

[0126] As an example, the fourth and fifth ciphertexts are concatenated to obtain the sixth ciphertext; then, a hash operation is performed on the sixth ciphertext, and the resulting hash value is used as the first authentication credential for the second user.

[0127] As another example, the fourth and fifth ciphertexts are concatenated, and the concatenated ciphertext is used as the first authentication credential for the second user.

[0128] In the above implementation, the first authentication key and the second authentication key determined from at least two authentication keys have high randomness. The two authentication keys are used to encrypt two pieces of user information respectively to obtain two ciphertexts. The first authentication credential is then generated based on the two ciphertexts, which can increase the difficulty of cracking the first authentication credential and thus further improve the security of data sharing.

[0129] The foregoing illustrates a partial implementation of S604. It should be understood that S604 can also be implemented in other ways, and this application embodiment does not limit this. For example, the second user's authentication key can be used to encrypt only the second user's user information to obtain the first authentication credential. Alternatively, the second user's authentication key can be used to encrypt the second user's user information, and then the encryption result can be re-encrypted using the second user's public key to obtain the first authentication credential.

[0130] It is worth noting that the first authentication credential corresponds one-to-one with the second user. That is, when there are multiple second users, the blockchain node encrypts the user information of each second user based on that user's authentication key to obtain the first authentication credential corresponding to that second user.

[0131] S606 sends the first authentication credential to the first user's SIM card.

[0132] The first authentication credential is used by the first user's SIM card to encrypt the target data and then send it to the second user's SIM card.

[0133] In another embodiment, following S606 above, the method provided in this application embodiment may further include: responding to a decryption request from a second user's SIM card, invoking a smart contract, encrypting the first user's public key based on the second user's public key to obtain a third ciphertext; and returning the third ciphertext to the second user's SIM card. Since the second user's private key is only stored in the second user's SIM card, only the second user's SIM card can decrypt the first user's public key, preventing unauthorized access to the first user's public key and subsequent cracking of the target data, thereby further improving the security of data sharing.

[0134] In another embodiment, the blockchain node may also directly return the first user's public key to the second user's SIM card in response to the second user's SIM card decryption request.

[0135] The data sharing method provided in this application embodiment, when a first user requests to share target data, involves the first user's SIM card obtaining a first authentication credential for the sharing from a blockchain node. The first authentication credential and the first user's private key are then used to encrypt the target data into a first ciphertext, which is then sent to the second user's SIM card. The authentication credential is obtained by the blockchain node encrypting the user information of both the first and second users based on the second user's authentication key stored in the blockchain. Because the blockchain is decentralized and immutable, and only the second user's SIM card possesses the second user's authentication key and user information besides the blockchain node, only the blockchain node and the second user's SIM card can obtain the first authentication credential, and thus retrieve the target data from the first ciphertext. This achieves encrypted sharing of target data between the first and second users, preventing modification or deletion of the target data during the sharing process, and improving the security and reliability of data sharing, especially cross-platform data sharing.

[0136] Please refer to Figure 7 The following is a flowchart illustrating a data sharing method provided in one embodiment of this application. The method is applied to a second user's SIM card and includes the following steps:

[0137] S702 receives the first ciphertext from the first user's SIM card.

[0138] The first ciphertext is obtained by encrypting the target data using the first user's SIM card, the first authentication credential, and the first user's private key. The first authentication credential is generated by the blockchain node based on the second user's authentication key and user information stored in the blockchain.

[0139] S704 generates a second authentication credential based on the authentication key and user information of the second user stored locally on the second user's SIM card.

[0140] The specific implementation of S704 described above is the same as Figure 6 The specific implementation of S604 in the illustrated embodiment is similar and will not be described again.

[0141] S706, based on the second authentication credential and the first user's public key, decrypts the first ciphertext to obtain the target data.

[0142] In the embodiments of this application, the above-described S706 can be implemented in various appropriate ways.

[0143] In one embodiment, the first ciphertext is obtained by inserting a first authentication credential into the header of the second ciphertext, and the second ciphertext is obtained by encrypting the target data based on the first user's private key. In this case, S706 includes: obtaining the first authentication credential and the second ciphertext from the first ciphertext; if the first authentication credential and the second authentication credential are consistent, sending a decryption request to the blockchain node, wherein the decryption request is used to request the first user's public key; and decrypting the second ciphertext based on the first user's public key returned by the blockchain node to obtain the target data.

[0144] Considering that the number of authentication keys is at least two, the generation of the first authentication credential is random. To avoid misjudgment, if the first authentication credential and the second authentication credential are inconsistent, the operation of generating the second authentication credential and comparing it with the first authentication credential is repeated. If they match again, the second user is determined to be an access user allowed by the first user. If they do not match again, the second user is determined not to be an access user allowed by the first user.

[0145] For example, suppose user B's SIM card receives the first ciphertext from user A's SIM card, and obtains the first authentication credential HE from the header of the first ciphertext. B User B's authentication keys include authentication key E1 and authentication key E2.

[0146] During the initial comparison, User B's SIM card used authentication key E1 to encrypt User A's user information, resulting in the fourth ciphertext E. 1-1 The authentication key is used to encrypt user B's user information to obtain the fifth ciphertext E. 1-2 Regarding the fourth ciphertext E 1-1 And the fifth ciphertext E 1-2 The pieces are then stitched together to obtain the stitched result. E1-0 Then, the splicing result E 1-0 Perform a hash operation to obtain the second authentication credential, HE. B-1 If the second authentication certificate HE B-1 With the first certification certificate HE B If they match, it is determined that user B is an authorized user of user A. Then, user B's SIM card sends a decryption request to the blockchain node to obtain user A's public key, in order to retrieve the target data shared by user A from the first ciphertext. If the second authentication credential HE... B-1 If the verification certificate does not match the first verification certificate, the second comparison process will begin.

[0147] During the second comparison, user B's SIM card used authentication key E2 to encrypt user A's user information to obtain the fourth ciphertext E. 2-1 The fifth ciphertext E is obtained by encrypting user B's user information using the authentication key E1.2-2 Regarding the fourth ciphertext E 2-1 And the fifth ciphertext E 2-2 The splicing is performed to obtain the splicing result E. 2-0 Then, the splicing result E 2-0 Perform a hash operation to obtain a new second authentication match HEB-2. If the second authentication credential HE... B-2 With the first certification certificate HE B If they match, it is determined that the user is an authorized user of user A. Then, user B's SIM card sends a decryption request to the blockchain node to obtain user A's public key, in order to retrieve the target data shared by user A from the first ciphertext. If the second authentication credential HE... B-2 If the authentication credentials do not match the first authentication credentials, it is determined that user B is not a user allowed by user A, and the operation ends.

[0148] It is worth noting that if the blockchain node returns a third ciphertext obtained by encrypting the first user's public key with the second user's public key, the second user's SIM card will obtain the second user's private key locally, use the second user's private key to decrypt the third ciphertext, and obtain the first user's public key.

[0149] In another embodiment, S706 includes the following steps: sending a decryption request to the blockchain node and receiving the public key of the first user returned by the blockchain node; then, based on the encryption / decryption method pre-negotiated with the first user's SIM card, using the second authentication credential and the first user's public key to decrypt the first ciphertext; if decryption is successful, the target data is obtained; if decryption fails, the above operation of generating the second authentication credential and decrypting the first ciphertext is repeated until a preset decryption stop condition is met, at which point the operation ends. The decryption stop condition can be set according to actual needs, such as reaching a decryption count threshold, etc., and this embodiment does not limit this.

[0150] In another embodiment, the second user's SIM card also discards the first user's public key after the operation ends, in order to prevent the first user's public key from being obtained by unauthorized persons, thereby further improving the security of the target data.

[0151] The data sharing method provided in this application embodiment, when a first user requests to share target data, involves the first user's SIM card obtaining a first authentication credential for the sharing from a blockchain node. The first authentication credential and the first user's private key are then used to encrypt the target data into a first ciphertext, which is then sent to the second user's SIM card. The authentication credential is obtained by the blockchain node encrypting the user information of both the first and second users based on the second user's authentication key stored in the blockchain. Because the blockchain is decentralized and immutable, and only the second user's SIM card possesses the second user's authentication key and user information besides the blockchain node, only the blockchain node and the second user's SIM card can obtain the first authentication credential, and thus retrieve the target data from the first ciphertext. This achieves encrypted sharing of target data between the first and second users, preventing modification or deletion of the target data during the sharing process, and improving the security and reliability of data sharing, especially cross-platform data sharing.

[0152] To facilitate understanding of the data sharing method provided in the embodiments of this application, the following is combined with... Figure 8 The document provides a detailed explanation of the interaction process between the first user's SIM card, the second user's SIM card, the media platform, and the user terminal. Figure 8 This is a flowchart illustrating a data sharing method according to an embodiment of this application. The flowchart depicts a specific implementation of interaction between a first user's SIM card, a second user's SIM card, a blockchain, and a media platform. Figure 8 As shown, the method includes the following steps:

[0153] S801, when the first user's SIM card requests to share target data, a first sharing interface is displayed. The first sharing interface includes a first option. The first option is used to share encrypted target data.

[0154] S802, the first user's SIM card responds to the selection of the first option and displays the second sharing interface.

[0155] The second sharing interface includes at least one relationship category.

[0156] S803, the first user's SIM card responds to the selection operation of at least one relation category by sending the selected first relation category to the blockchain node.

[0157] The first relationship category is used to indicate that users whose relationship with the first user belongs to the first relationship category are designated as second users.

[0158] S804, the blockchain node, based on the first relationship category, calls the smart contract to obtain the user information and authentication key of the second user whose relationship with the first user belongs to the first relationship category from the blockchain, and generates the first authentication credential based on the second user's user information and authentication key and returns it to the SIM card of the first user.

[0159] S805, the first user's SIM card encrypts the target data based on the first authentication credential and the first user's private key to obtain the first ciphertext.

[0160] S806, the first user's SIM card generates a content cover of the target data based on the key information of the target data.

[0161] S807: The first user's SIM card sends the content cover and first encrypted message to the media platform.

[0162] S808, in response to the second user's viewing operation of the content cover, the second user's SIM card sends a request to the media platform to obtain the first encrypted text.

[0163] S809, in response to the acquisition request, the media platform sends the first encrypted message to the second user's SIM card.

[0164] S810, the second user's SIM card generates a second authentication credential based on the second user's authentication key and user information stored locally on the second user's SIM card.

[0165] S811, the second user's SIM card obtains the first authentication credential and the second ciphertext from the first ciphertext.

[0166] S812, if the first authentication credential matches the second authentication credential, the second user's SIM card sends a decryption request to the blockchain node.

[0167] The decryption request is used to request the public key of the first user.

[0168] S813, in response to the decryption request, the blockchain node calls the smart contract, uses the second user's public key to encrypt the first user's public key to obtain the third ciphertext, and returns the third ciphertext to the second user's SIM card.

[0169] S814, the second user's SIM card uses the second user's private key to decrypt the third ciphertext and obtain the first user's public key.

[0170] S815, the second user's SIM card uses the second authentication credential to decrypt the second ciphertext and obtain the target data.

[0171] This enables encrypted sharing of target data between the first and second users, preventing the target data from being modified or deleted during the sharing process, and improving the security and reliability of data sharing, especially the security and reliability of cross-platform data sharing.

[0172] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0173] Based on the same inventive concept, embodiments of this application also provide a data sharing device. Please see Figure 9 This is a schematic diagram of the structure of a data sharing device 900 provided in one embodiment of this application. The device 900 is applied to a first user's SIM card. In one software implementation, the data sharing device 900 includes:

[0174] The first acquisition module 910 is used to acquire a first authentication credential from a blockchain node when the first user requests to share target data; the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain;

[0175] The first encryption module 920 is used to encrypt the target data based on the first authentication credential and the first user's private key to obtain the first ciphertext;

[0176] The first sending module 930 is used to send the first ciphertext to the SIM card of the second user.

[0177] In another embodiment, the first acquisition module is used for:

[0178] When the first user requests to share the target data, a first sharing interface is displayed. The first sharing interface includes a first option, which is used to share the encrypted target data.

[0179] In response to the selection of the first option, a second sharing interface is displayed, the second sharing interface including at least one relationship category;

[0180] In response to the selection operation of the at least one relationship category, a first relationship category is sent to the blockchain node, the first relationship category being used to indicate that a user whose relationship with the first user belongs to the first relationship category is designated as the second user;

[0181] Receive the first authentication credential returned by the blockchain node.

[0182] In another embodiment, the first encryption module is used to:

[0183] The target data is encrypted using the first user's private key to obtain the second ciphertext;

[0184] Insert the first authentication credential into the header of the second ciphertext to obtain the first ciphertext.

[0185] In another embodiment, the first sending module is used to:

[0186] Based on the key information of the target data, generate a cover page for the target data.

[0187] The content cover and the first encrypted text are sent to the media platform for display, so that the media platform can send the first encrypted text to the second user's SIM card in response to the second user's trigger operation on the content cover.

[0188] Obviously, the data sharing device in the embodiments of this specification can be used as described above. Figure 2 The execution entity of the data sharing method shown can therefore realize the data sharing method in Figure 2 The functions implemented are the same, so they will not be described in detail here.

[0189] Based on the same inventive concept, embodiments of this application also provide a data sharing device. Please see Figure 10 This is a schematic diagram illustrating the structure of a data sharing device 1000 according to an embodiment of this application. The device 1000 is applied to a blockchain node. In one software implementation, the data sharing device 1000 includes:

[0190] The second acquisition module 1010 is used to acquire the authentication key of the second user and the user information of the second user from the blockchain. The second user is the user who is to receive the target data shared by the first user.

[0191] The second encryption module 1020 is used to encrypt the user information of the second user based on the authentication key to obtain the first authentication credential;

[0192] The second sending module 1030 is used to send the first authentication credential to the SIM card of the first user. The first authentication credential is used by the SIM card of the first user to encrypt the target data and then send it to the SIM card of the second user.

[0193] In another embodiment, the second acquisition module is used to:

[0194] Upon receiving the first relationship category sent by the first user's SIM card, the smart contract is invoked to retrieve user information of users whose relationship with the first user belongs to the first relationship category from the blockchain, which is used as the second user's user information, and the authentication key of the second user is retrieved from the blockchain.

[0195] In another embodiment, the second encryption module is further configured to respond to the decryption request of the second user's SIM card by invoking a smart contract to encrypt the first user's public key based on the second user's public key to obtain a third ciphertext;

[0196] The second sending module is also configured to return the third ciphertext to the second user's SIM card;

[0197] The decryption request is sent to the blockchain node by the second user's SIM card when the second user's SIM card receives the first ciphertext. The first ciphertext is obtained by the first user's SIM card encrypting the target data based on the first authentication credential and the first user's private key. The first user's public key is used to obtain the target data from the first ciphertext.

[0198] In another embodiment, the number of authentication keys is at least two;

[0199] The second encryption module is used for:

[0200] Determine a first authentication key and a second authentication key from at least two of the authentication keys;

[0201] The user information of the first user is encrypted based on the first authentication key to obtain the fourth ciphertext;

[0202] The user information of the second user is encrypted based on the second authentication key to obtain the fifth ciphertext;

[0203] Based on the fourth ciphertext and the fifth ciphertext, a first authentication credential is generated.

[0204] Obviously, the data sharing device in the embodiments of this specification can be used as described above. Figure 6 The execution entity of the data sharing method shown can therefore realize the data sharing method in Figure 6 The functions implemented are the same, so they will not be described in detail here.

[0205] Based on the same inventive concept, embodiments of this application also provide a data sharing device. Please see Figure 11This is a schematic diagram of the structure of a data sharing device 1100 provided in one embodiment of this application. The device 1100 is applied to a second user's SIM card. In one software implementation, the data sharing device 1100 includes:

[0206] The first receiving module 1110 is used to receive the first ciphertext from the SIM card of the first user; the first ciphertext is obtained by the first user's SIM card encrypting target data based on the first authentication credential and the first user's private key, and the first authentication credential is generated by the blockchain node based on the second user's authentication key and user information stored in the blockchain;

[0207] The third encryption module 1120 is used to generate a second authentication credential based on the authentication key and user information of the second user stored locally on the second user's SIM card.

[0208] The first decryption module 1130 is used to decrypt the first ciphertext based on the second authentication credential and the first user's public key to obtain the target data.

[0209] In another embodiment, the first ciphertext is obtained by inserting the first authentication credential into the header of the second ciphertext, and the second ciphertext is obtained by encrypting the target data based on the first user's private key;

[0210] The first decryption module is used for:

[0211] Obtain the first authentication credential and the second ciphertext from the first ciphertext;

[0212] If the first authentication credential matches the second authentication credential, a decryption request is sent to the blockchain node. The decryption request is used to request the public key of the first user.

[0213] The second ciphertext is decrypted based on the public key of the first user returned by the blockchain node to obtain the target data.

[0214] Obviously, the data sharing device in the embodiments of this specification can be used as described above. Figure 7 The execution entity of the data sharing method shown can therefore realize the data sharing method in Figure 7 The functions implemented are the same, so they will not be described in detail here.

[0215] Figure 12 This is a schematic diagram of the structure of a SIM card according to one embodiment of this application. Please refer to it. Figure 12At the hardware level, the SIM card includes a processor, and optionally also an internal bus, network interface, and memory. The memory may include RAM, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the SIM card may also include other hardware required for other services.

[0216] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 12 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0217] Memory is used to store programs. Specifically, programs may include program code, which includes computer operation instructions. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0218] The processor reads the corresponding computer program from non-volatile memory into main memory and then runs it, forming a data sharing mechanism at the logical level. The processor executes the program stored in memory and specifically performs the following operations:

[0219] When a first user requests to share target data, a first authentication credential is obtained from the blockchain node; the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain.

[0220] The target data is encrypted based on the first authentication credential and the first user's private key to obtain the first ciphertext;

[0221] The first ciphertext is sent to the second user's SIM card.

[0222] Alternatively, it can be used to perform the following operations:

[0223] Receive first ciphertext from the first user's SIM card; the first ciphertext is obtained by the first user's SIM card encrypting target data based on the first authentication credential and the first user's private key, and the first authentication credential is generated by the blockchain node based on the second user's authentication key and user information stored in the blockchain;

[0224] A second authentication credential is generated based on the authentication key and user information of the second user stored locally on the second user's SIM card.

[0225] The first ciphertext is decrypted based on the second authentication credential and the first user's public key to obtain the target data.

[0226] The above is as stated in this application. Figure 2 or Figure 7 The data sharing device disclosed in the illustrated embodiments can be applied to or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0227] The SIM card can also perform... Figure 2 The method, and implement the data sharing device in Figure 2 The SIM card may also perform the functions of the illustrated embodiment, or alternatively, perform the following functions: Figure 7The method, and implement the data sharing device in Figure 7 The functions of the embodiments shown are not described in detail here.

[0228] Of course, in addition to software implementation, the SIM card of this application does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0229] Figure 13 This is a schematic diagram of the structure of a blockchain node according to an embodiment of this application. Please refer to it. Figure 13 At the hardware level, the blockchain node includes a processor, and optionally also an internal bus, network interface, and memory. The memory may include RAM, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the blockchain node may also include other hardware required for other business operations.

[0230] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 13 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0231] Memory is used to store programs. Specifically, programs may include program code, which includes computer operation instructions. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0232] The processor reads the corresponding computer program from non-volatile memory into main memory and then runs it, forming a data sharing mechanism at the logical level. The processor executes the program stored in memory and specifically performs the following operations:

[0233] Obtain the authentication key and user information of the second user from the blockchain. The second user is the user who is to receive the target data shared by the first user.

[0234] The user information of the second user is encrypted based on the authentication key to obtain the first authentication credential;

[0235] The first authentication credential is sent to the first user's SIM card. The first authentication credential is used by the first user's SIM card to encrypt the target data and then send it to the second user's SIM card.

[0236] The above is as stated in this application. Figure 6 The data sharing device disclosed in the illustrated embodiments can be applied to or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0237] This blockchain node can also perform... Figure 6 The method, and implement the data sharing device in Figure 6 The functions of the embodiments shown are not described in detail here.

[0238] Of course, in addition to software implementation, the blockchain node of this application does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0239] This application also proposes a computer-readable storage medium that stores one or more programs, the programs including instructions that, when executed by a SIM card comprising multiple applications, enable the SIM card to perform... Figure 2 The method of the illustrated embodiment is specifically used to perform the following operations:

[0240] When the first user requests to share target data, a first authentication credential is obtained from the blockchain node; the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain.

[0241] The target data is encrypted based on the first authentication credential and the first user's private key to obtain the first ciphertext;

[0242] The first ciphertext is sent to the second user's SIM card.

[0243] This application also proposes a computer-readable storage medium that stores one or more programs, the programs including instructions that, when executed by a blockchain node comprising multiple applications, enable the blockchain node to perform... Figure 6 The method of the illustrated embodiment is specifically used to perform the following operations:

[0244] Obtain the authentication key and user information of the second user from the blockchain. The second user is the user who is to receive the target data shared by the first user.

[0245] The user information of the second user is encrypted based on the authentication key to obtain the first authentication credential;

[0246] The first authentication credential is sent to the first user's SIM card. The first authentication credential is used by the first user's SIM card to encrypt the target data and then send it to the second user's SIM card.

[0247] This application also proposes a computer-readable storage medium that stores one or more programs, the programs including instructions that, when executed by a SIM card comprising multiple applications, enable the SIM card to perform... Figure 7 The method of the illustrated embodiment is specifically used to perform the following operations:

[0248] Receive first ciphertext from the SIM card of the first user; the first ciphertext is obtained by encrypting target data by the SIM card of the first user based on the first authentication credential and the private key of the first user, and the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain;

[0249] A second authentication credential is generated based on the authentication key and user information of the second user stored locally on the second user's SIM card.

[0250] The first ciphertext is decrypted based on the second authentication credential and the first user's public key to obtain the target data.

[0251] This application also provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps in the data sharing method provided in this application.

[0252] In summary, the above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

[0253] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0254] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0255] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0256] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

Claims

1. A data sharing method, characterized in that, The method, applied to a SIM card for a first user, includes: When the first user requests to share target data, a first authentication credential is obtained from the blockchain node; the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain. The target data is encrypted based on the first authentication credential and the first user's private key to obtain the first ciphertext. The first ciphertext is obtained by adding the first authentication credential to the encrypted target data after the target data is encrypted based on the first user's private key. The first ciphertext is sent to the second user's SIM card.

2. The method according to claim 1, characterized in that, The step of obtaining the first authentication credential from the blockchain node when the first user requests to share the target data includes: When the first user requests to share the target data, a first sharing interface is displayed. The first sharing interface includes a first option, which is used to share the encrypted target data. In response to the selection of the first option, a second sharing interface is displayed, the second sharing interface including at least one relationship category; In response to the selection operation of the at least one relationship category, a first relationship category is sent to the blockchain node, the first relationship category being used to indicate that a user whose relationship with the first user belongs to the first relationship category is designated as the second user; Receive the first authentication credential returned by the blockchain node.

3. The method according to claim 1, characterized in that, The first ciphertext is obtained by encrypting the target data based on the first authentication credential and the first user's private key, including: The target data is encrypted using the first user's private key to obtain the second ciphertext; Insert the first authentication credential into the header of the second ciphertext to obtain the first ciphertext.

4. The method according to claim 1, characterized in that, The step of sending the first ciphertext to the SIM card of the second user includes: Based on the key information of the target data, generate a cover page for the target data. The content cover and the first encrypted text are sent to the media platform, so that the media platform can send the first encrypted text to the second user's SIM card in response to the second user's trigger operation on the content cover.

5. A data sharing method, characterized in that, Applied to blockchain nodes, the method includes: Obtain the authentication key and user information of the second user from the blockchain. The second user is the user who is to receive the target data shared by the first user. The user information of the second user is encrypted based on the authentication key to obtain the first authentication credential; The first authentication credential is sent to the first user's SIM card. The first authentication credential is used by the first user's SIM card to encrypt the target data and then send it to the second user's SIM card. The encryption of the target data includes: encrypting the target data based on the first user's private key, and adding the first authentication credential to the encrypted target data.

6. The method according to claim 5, characterized in that, The step of obtaining the second user's authentication key and the second user's user information from the blockchain includes: Upon receiving the first relationship category sent by the first user's SIM card, the smart contract is invoked to retrieve user information of users whose relationship with the first user belongs to the first relationship category from the blockchain, which is used as the second user's user information, and the authentication key of the second user is retrieved from the blockchain.

7. The method according to claim 6, characterized in that, After sending the first authentication credential to the first user's SIM card, the method further includes: In response to the second user's SIM card decryption request, the smart contract is invoked to encrypt the first user's public key based on the second user's public key, resulting in a third ciphertext; The third ciphertext is returned to the second user's SIM card; The decryption request is sent to the blockchain node by the second user's SIM card when the second user's SIM card receives the first ciphertext. The first ciphertext is obtained by the first user's SIM card encrypting the target data based on the first authentication credential and the first user's private key. The first user's public key is used to obtain the target data from the first ciphertext.

8. The method according to claim 5, characterized in that, The number of authentication keys is at least two; The step of encrypting the user information of the second user based on the authentication key to obtain the first authentication credential includes: Determine a first authentication key and a second authentication key from at least two of the authentication keys; The user information of the first user is encrypted based on the first authentication key to obtain the fourth ciphertext; The user information of the second user is encrypted based on the second authentication key to obtain the fifth ciphertext; Based on the fourth ciphertext and the fifth ciphertext, a first authentication credential is generated.

9. A data sharing method, characterized in that, The method, applied to a SIM card for a second user, includes: Receive first ciphertext from the SIM card of the first user; the first ciphertext is obtained by encrypting the target data based on the first user's private key using the SIM card of the first user, and then adding a first authentication credential to the encrypted target data. The first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain. A second authentication credential is generated based on the authentication key and user information of the second user stored locally on the second user's SIM card. The first ciphertext is decrypted based on the second authentication credential and the first user's public key to obtain the target data.

10. The method according to claim 9, characterized in that, The first ciphertext is obtained by inserting the first authentication credential into the header of the second ciphertext, and the second ciphertext is obtained by encrypting the target data based on the first user's private key; The step of decrypting the first ciphertext based on the second authentication credential and the first user's public key to obtain the target data includes: Obtain the first authentication credential and the second ciphertext from the first ciphertext; If the first authentication credential matches the second authentication credential, a decryption request is sent to the blockchain node. The decryption request is used to request the public key of the first user. The second ciphertext is decrypted based on the public key of the first user returned by the blockchain node to obtain the target data.

11. A data sharing device, characterized in that, The device includes a SIM card for use with a first user. The first acquisition module is used to acquire a first authentication credential from a blockchain node when the first user requests to share target data; the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain; The first encryption module is used to encrypt the target data based on the first authentication credential and the private key of the first user to obtain the first ciphertext. The first ciphertext is obtained by adding the first authentication credential to the encrypted target data after encrypting the target data based on the private key of the first user. The first sending module is used to send the first ciphertext to the SIM card of the second user.

12. A data sharing device, characterized in that, The device, applied to a blockchain node, includes: The second acquisition module is used to acquire the authentication key and user information of the second user from the blockchain. The second user is the user who is to receive the target data shared by the first user. The second encryption module is used to encrypt the user information of the second user based on the authentication key to obtain the first authentication credential; The second sending module is used to send the first authentication credential to the SIM card of the first user. The first authentication credential is used by the first user's SIM card to encrypt the target data and then send it to the SIM card of the second user. The encryption of the target data includes: encrypting the target data based on the first user's private key, and adding the first authentication credential to the encrypted target data.

13. A data sharing device, characterized in that, The device includes a SIM card for a second user. The first receiving module is used to receive the first ciphertext from the SIM card of the first user; the first ciphertext is obtained by encrypting the target data based on the first user's private key using the SIM card of the first user, and then adding the first authentication credential to the encrypted target data; the first authentication credential is generated by the blockchain node based on the authentication key and user information of the second user stored in the blockchain. The third encryption module is used to generate a second authentication credential based on the authentication key and user information of the second user stored locally on the second user's SIM card; The first decryption module is used to decrypt the first ciphertext based on the second authentication credential and the first user's public key to obtain the target data.

14. A SIM card, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the data sharing method as described in any one of claims 1 to 4 or the data sharing method as described in any one of claims 9 to 10.

15. A blockchain node, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the data sharing method as claimed in any one of claims 5 to 8.

16. A computer-readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is able to perform the data sharing method as described in any one of claims 1 to 4; or, when the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is able to perform the data sharing method as described in any one of claims 5 to 8; or, when the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is able to perform the data sharing method as described in any one of claims 9 to 10.

17. A computer program product, characterized in that, The computer program product includes a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps of the data sharing method as claimed in any one of claims 1 to 4; or, the computer program operable to cause a computer to perform some or all of the steps of the data sharing method as claimed in any one of claims 5 to 8; or, the computer program operable to cause a computer to perform some or all of the steps of the data sharing method as claimed in any one of claims 9 to 10.

Citation Information

Patent Citations

  • System and method for user-controllable sharing of authorization for private data

    US20230351035A1

  • Subscription onboarding using a verified digital identity

    US20230413060A1