System and method for data exchange using trusted authorization mechanism based on polynomial commitment multi-access
Through a trusted authorization mechanism based on Polynomial Commitment Multiple Access (PCMA), non-fungible PCMA tokens are generated, which solves the trust problem in data transactions, realizes data quality management before buyer evaluation and seller data protection, and simplifies data privacy management.
Patent Information
- Application Number
- CN202480001870.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2024-07-05
- Filing Date
- 2024-09-11
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-09-11
AI Technical Summary
Existing data transactions lack an effective and trusted authorization mechanism, making it difficult for buyers and sellers to establish trust. Sellers worry about their data being copied and refuse to pay, while buyers find it difficult to evaluate the authenticity and quality of data before paying.
A trusted authorization mechanism based on Polynomial Commitment Multiple Access (PCMA) is adopted to generate non-fungible PCMA tokens through the data owner module, data user module and data exchange module for data evaluation and transaction, ensuring data privacy and quality management.
It enables buyers to evaluate data before payment, prevents sellers’ data from being leaked, simplifies data privacy management, and establishes a trusted data transaction mechanism.
Smart Images

Figure CN119384836B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to data exchange technology, and in particular to a system and method for data exchange, which adopts a trusted authorization mechanism based on polynomial commitment multiple access (PCMA). Background Art
[0002] Today, data is considered one of the most important factors of production, alongside human capital, land, and finance. Consequently, people view data as a high-value commodity and are increasingly willing to pay for it. Key players in the data market include data users (e.g., buyers), data owners (e.g., sellers), and data exchange centers (e.g., data trading centers).
[0003] However, most data transactions require a certain level of trust. For example, sellers worry that buyers could easily copy valuable data without paying. Furthermore, buyers want to evaluate the data before purchasing. This raises the question of how to establish a mutual trust mechanism to facilitate data transactions. Ideally, buyers should be able to evaluate the entire data set before paying. The seller's data should not be disclosed to potential buyers until the transaction is complete.
[0004] Therefore, an improved trusted authorization mechanism is needed to simplify the management of data privacy, authenticity, and quality, and to facilitate smoother transactions between buyers and sellers in data transactions. Summary of the Invention
[0005] According to a first aspect of the present invention, a system for facilitating data exchange using a trusted authorization mechanism based on Polynomial Commitment Multiple Access (PCMA) is provided. The system includes a data owner module, a data user module, and a data exchange module. The data owner module is electrically or wirelessly coupled to an owner terminal for data communication with the owner terminal. The data owner module is configured to encrypt a data set comprising multiple data sets on the owner terminal using a key and generate an identifier, a hash value, and a ciphertext for each data set. The data user module is electrically or wirelessly coupled to a user terminal for data communication with the user terminal. The data user module is configured to submit at least one request from the user terminal to the data owner module for accessing and evaluating the data set. The data owner module is further configured to review the request from the data user module. In response to this, the data owner module can authorize at least one data set in the data set, or the data owner module can deny any request and not authorize any requested data set in the data set. The data exchange module is electrically or wirelessly coupled to a data exchange center and is in data communication with the data exchange center. The Data Exchange Module is configured to generate a single PCMA token based on the identity of a user registered with the Data Exchange Module, an identifier for a dataset, a hash value of the authorized dataset, and a ciphertext of a key used to encrypt the dataset. The Data Exchange Module constructs the PCMA token using a polynomial commitment mechanism such that the token maintains a constant size regardless of changes in the amount of authorized data. The Data Exchange Module utilizes the commitment algorithm of the polynomial commitment mechanism as the encryption protocol for the PCMA token to ensure that any potentially original sensitive information used to construct the PCMA token cannot be recovered. The Data Exchange Module is also configured to transmit the PCMA token to the Data User Module for submission by the user upon requesting data evaluation.
[0006] According to a second aspect of the present invention, a method for facilitating data exchange is provided, which uses a trusted authorization mechanism based on PCMA, including the following steps: a data owner module encrypts a data set including multiple data sets of an owner terminal using a key; the data owner module generates an identifier, a hash value and a ciphertext of the key for each data set; a data user module submits at least one request from a user terminal to the data owner module to evaluate the data set; the data owner module checks the request from the data user module and authorizes at least one data set in the data set, or the data owner module rejects any request and does not authorize any of the requested data sets in the data set; the data exchange module generates A single PCMA token is generated based on the user identity registered in the data exchange module, the identifier of the data set, the hash value of the authorized data set, and the ciphertext of the key used to encrypt the data set; the data exchange module constructs the PCMA token using a polynomial commitment mechanism so that it maintains the same constant size regardless of changes in the amount of authorized data, wherein the data exchange module utilizes the commitment algorithm of the polynomial commitment mechanism as the encryption protocol of the PCMA token to ensure that any potential original sensitive information used to construct the PCMA token cannot be restored therefrom; and the data exchange module sends the PCMA token to the data user module for the user terminal to submit the PCMA token when requesting data evaluation.
[0007] In various embodiments of the present invention, buyers can obtain evaluation results for all data before payment, while sellers can ensure that the data will not be leaked to potential buyers. In addition, to simplify data privacy management, buyers only need to submit a public token to request access to multiple data sets. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] The embodiments of the present invention are described in more detail below with reference to the accompanying drawings, in which:
[0009] Figure 1 According to an embodiment of the present invention, a schematic architecture diagram of a system using a trusted authorization mechanism based on Polynomial Commitment Multiple Access (PCMA) is presented;
[0010] Figure 2 A schematic diagram illustrating the interaction between sellers, buyers, and an exchange center in a system according to an embodiment of the present invention is provided;
[0011] Figure 3 According to an embodiment of the present invention, a flow chart of generating a PCMA token is presented;
[0012] Figure 4 According to an embodiment of the present invention, a detailed operational flow chart of data verification and evaluation steps S50, S60, S70, S80 and S90 is presented;
[0013] Figure 5 According to an embodiment of the present invention, a flow chart of a polynomial commitment process of a data exchange module in a data verification procedure is presented;
[0014] Figure 6 According to an embodiment of the present invention, a schematic diagram of a data authentication module executing a data authentication procedure through a deployed smart contract is shown;
[0015] Figure 7 A schematic diagram of how to use the system to detect and reject a buyer's request in a scenario where a wrong or stolen token is used is provided according to an embodiment of the present invention; and
[0016] Figure 8 The present invention provides a schematic diagram of how the system can ensure that the data sent is identical to the evaluation data after the buyer makes payment. DETAILED DESCRIPTION
[0017] In the following description, systems and methods are presented as preferred examples that use a trusted authorization mechanism based on polynomial commitment multiple access (PCMA) for data exchange. Those skilled in the art will appreciate that modifications, including additions and / or substitutions, may be made without departing from the scope and spirit of the invention. Specific details may be omitted so as not to obscure the invention; however, this disclosure is written to enable those skilled in the art to practice the teachings herein without undue experimentation.
[0018] The following will refer to Figure 1 To facilitate data exchange (or transactions) between a buyer and a seller (or multiple buyers and multiple sellers) through an exchange center, a system 100 is created. The system 100 can provide a platform based on a trusted authorization mechanism combined with a single PCMA token to achieve trustworthiness, security, and user-friendliness.
[0019] In short, before paying the data exchange fee, the buyer can obtain at least one evaluation result for the data of interest and access and evaluate multiple data sets using a single PCMA token. Furthermore, before the buyer pays the data exchange fee, the seller can maintain data confidentiality, ensuring that the buyer does not receive any specific data information. Then, after the buyer pays the data exchange fee, the buyer is guaranteed to receive the same data as the evaluation data. PCMA tokens are central to implementing a trusted authorization mechanism in data exchange transactions; PCMA tokens and the components of system 100 are further described below.
[0020] System 100 includes a data owner module 110, a data user module 120, a data exchange module 130, an evaluation generator module 140, and a data authentication module 150. The data owner module 110 can communicate data with an owner terminal T1 (e.g., a seller's interface) via electrical or wireless coupling. The data owner module 110 is configured to execute user instructions. The data user module 120 can communicate data with a user terminal T2 (e.g., a buyer's interface) via electrical or wireless coupling. The data user module 120 is configured to execute user instructions. The data exchange module 130 can communicate data with a data exchange center EX via electrical or wireless coupling. In some embodiments, the data exchange center EX can be built into the data exchange module 130, so that the features or functions of the data exchange center EX can be processed or executed by the data exchange module 130, and the data exchange module 130 can serve as the web server interface of the exchange center. The evaluation generator module 140 is used to provide a trusted execution environment (TEE) area and perform an evaluation process during the transaction process; the data proof module 150 is used to deploy smart contracts for data proof.
[0021] These components can communicate with each other to complete trusted and authorized data exchange transactions.
[0022] exist Figure 2 The provided schematic diagram illustrates the interactions among sellers, buyers, and the exchange center within system 100. The seller is the data owner and utilizes the interface available at the owner terminal T1. The data owner module 110 is configured to receive user instructions from the owner terminal T1 and execute corresponding functions. The buyer is the individual or entity seeking data for sale and utilizes the interface available at the user terminal T2. The data user module 120 is configured to receive user instructions from the user terminal T2 and execute corresponding functions.
[0023] First, the seller and the buyer log in to the exchange program at the data exchange center EX. The seller uploads one or more data sets to the exchange center through the data owner module 110, where the data set includes one or more data sets. As a non-limiting example, the data set may include an MRI (Magnetic Resonance Imaging) data set. In one embodiment, during the upload phase, the data owner module 110 uses a key to encrypt multiple data sets in the data set, thereby generating an identifier, hash value, and ciphertext for each data set, and uploads these to the data exchange module 130 of the data exchange center EX; for example, this information may be stored in the server of the data exchange module 130. The buyer can view the listed information on the dashboard of the exchange center. When the buyer is interested in purchasing the target data set, the buyer can submit a request to evaluate the data set to the seller.
[0024] Subsequently, the interaction method is started, which includes steps S10, S20, S30, S40, S50, S60, S70, S80, S90, and S100.
[0025] In step S10, the buyer requests access to and evaluation of multiple datasets (e.g., data_1, ..., data_n) provided by a seller through the data user module 120. In one embodiment, the buyer requests access to and evaluation of multiple datasets provided by different sellers (i.e., the buyer can access and evaluate datasets from different sellers by submitting a single request). The buyer's request is directed to the data owner module 110, which in turn notifies the seller through the data exchange module 130.
[0026] In step S20, the seller checks the request from the data user module 120 through the data owner module 110 and determines whether to authorize the request from the buyer, for example, the seller authorizes the buyer to access part or all of the data sets. This interaction can be performed through the exchange center of the data exchange center EX. In one embodiment, the number of the seller's multiple data sets is M, and the number of data sets the seller authorizes to the buyer is N, where N and M are positive integers, and N is less than or equal to M. For example, the buyer requests the seller to authorize four of its data sets, but the seller only authorizes three of its data sets. Figure 2In the diagram, the tag "buyer_id" is the user identity recognized by the exchange center; the tag "data_i" is the identifier of the dataset; and the tag "cred_i" is a hash value calculated from three elements: the hash value of the dataset "data_i" authorized by the seller, the ciphertext of the encryption key used to encrypt the dataset "data_i", and the random number (i.e., salt value) generated by the data exchange center EX. In addition, in one embodiment, the data owner (i.e., the seller) can use a key to encrypt the dataset in the data set; in addition, the data owner can encrypt the encryption key using a public key from the TEE (e.g., through the assessment generator module 140).
[0027] In steps S30 and S40, the exchange center creates a PCMA token for the buyer and sends it to the data user module 120 via the data exchange module 130. The data exchange module 130 can create the PCMA token based on the buyer's request and the seller's authorization.
[0028] Specifically, Figure 3 The flowchart shown gives an example of PCMA token generation. Assume that the buyer (i.e., tag “Buyer_id_1”) requests access to four datasets (i.e., tags “data_1, data_2, data_3, data_4”), and the seller only authorizes the first three datasets (i.e., tags “data_1, data_2, data_3”). Correspondingly, the tags “(Buyer_id_1|data_1|cred_1)”, “(Buyer_id_2|data_2|cred_2)”, and “(Buyer_id_3|data_3|cred_3)” represent the three authorized datasets.
[0029] In phase A, the hash values of the dataset are first extracted. The label "Hash_i" is the hash value of the label (Buyer_id_1|data_i|cred_i), where i=1,…,n. In this example, n=3. In phase B, each hash value "Hash_i" is mapped to a point (x_i, y_i) on the elliptic curve, such as the labels "(x_1, y_1)", "(x_2, y_2)", and "(x_3, y_3)". In phase C, based on these three points, the Lagrange interpolation method is used to generate the polynomial In stage D, in the polynomial Calculation Commitment And set it as PCMA token; in subsequent procedures, PCMA token can be used to request data evaluation.
[0030] In this way, the data exchange module can generate a single PCMA token, and its generation basis is based on the user identity registered in the data trading platform (i.e., the user identity registered in the data exchange module 130, such as the tag "Buyer_id_1"), the identifier of the data set (such as the tags "data_1, data_2, data_3"), the hash value of the authorized data set, and the ciphertext of the encryption key used to encrypt the data set.
[0031] With this configuration, data exchange module 130 can construct PCMA tokens using a polynomial commitment mechanism. This allows the PCMA token to maintain a constant size regardless of the amount of data authorized by the PCMA token, thereby facilitating a compact representation of multiple authorizations (e.g., hundreds or more) (e.g., less than or equal to approximately 300 bytes). Furthermore, data exchange module 130 can utilize the commitment algorithm of the polynomial commitment mechanism as the encryption protocol for the PCMA tokens, ensuring that any potentially original sensitive information used to construct the PCMA tokens cannot be recovered from them. This allows the PCMA tokens to be publicly used and stored while also protecting data privacy.
[0032] In one embodiment, the PCMA Token is non-fungible (e.g., a non-fungible token (NFT)), and therefore publicly accessible to Web3 users. For example, the PCMA Token can be recorded on a blockchain by the data exchange module 130, making information about the PCMA Token public and accessible so that anyone (e.g., a user of any exchange) can view the status and history of the PCMA Token via the internet.
[0033] Thereafter, the PCMA token may be sent / returned to the buyer (Buyer_id_1) through the data exchange module 130 and the data user module 120.
[0034] refer to Figure 2 and Figure 4 ,in Figure 4 A flowchart according to an embodiment of the present invention is shown, including steps S50, S60, S70, S80 and S90, which are used for detailed operations of data verification and evaluation.
[0035] In step S50, the buyer requests data evaluation through the data user module 120. In one embodiment, the buyer may submit a single PCMA token (i.e., a calculated commitment) to the data exchange module 130 through the data user module 120. ) and the identity of the dataset (e.g., "data_1, data_2, data_3, data_4") to request at least one evaluation result for the dataset. In this example, the identity of the dataset "data_4" was submitted by the buyer but was not authorized by the seller.
[0036] In step S60, the data exchange module 130 responds to the data user module 120 and verifies each queried data set using the PCMA token. Specifically, the data exchange module 130 verifies the PCMA token (i.e., the calculated commitment) sent from the buyer. ), then perform the verification process for each "data_i" (where i = 1, 2, 3, 4). Next, since the points generated by the data set "data_i" (where i = 1, 2, 3) belong to the polynomial Therefore, these data sets can pass the verification. On the contrary, since the data set "data_4" did not obtain the authorization of the data owner module 110 in the previous step, the point (x_4, y_4) generated by the data set "data_4" is not in the polynomial In one embodiment, once all data sets are not authorized, resulting in the polynomial If there is no corresponding point on the graph, it means that the verification has completely failed, causing the process to be terminated.
[0037] Figure 5 A schematic diagram of the process of the data exchange module 130 generating a polynomial commitment for verification is shown. The schematic diagram provides an example of how the data exchange module 130 generates a commitment based on a given polynomial and how the data exchange module 130 performs verification, which includes steps S110, S120, S130, and S140.
[0038] Step S110 is about the data exchange module 130 generating The setup process steps are as follows: Step S120 is performed by the data exchange module 130. The commitment process steps, where The data is public and will be sent to the data user module 120 for the buyer to use. Step S130 is performed by the data exchange module 130. The witness process steps, where In addition, the data exchange module 130 gives the buyer's request record a label (Buyer_id_1, (data_i, cred_i), ).
[0039] Step S140 is to output a result signal of the verification process step, which is executed by the data exchange module 130, wherein output "1" indicates that the verification is successful and the authorization is approved; output "0" indicates that the verification fails and the authorization is rejected.
[0040] Reference again Figure 2 and Figure 4 Since the result of step S60 is "yes" and the data set "data_1, data_2, data_3" has passed the verification, the data set is fed into the evaluation process in step S70. Once the PCMA token submitted by the data user module is successfully verified by the data exchange module 130 (i.e., passed the verification), the evaluation generator module 140 will perform the evaluation process for each authorized data set in the TEE area.
[0041] In one embodiment, during the evaluation process, a commonly recognized data evaluation process (recognized by the buyer, seller, and exchange) can be used to evaluate the data content of the data set within the TEE area. The evaluation generator module can have an algorithm or AI model combined with the evaluation process, thereby allowing the commonly recognized data evaluation process to be executed based on the algorithm or AI model. In some practical cases, the commonly recognized evaluation process can be a program that has been verified in reality, such as quality control of medical images, natural language detection of language data, or similar applications. In one embodiment, the evaluation generator module 140 can execute the evaluation process according to the executable protocol, thereby allowing the signed executable file of the evaluation process to evaluate the authorized data set within the TEE area, while the unsigned executable file in the evaluation process is prohibited from evaluating the authorized data set within the TEE area, thereby protecting the privacy of the data product within the TEE area.
[0042] In various embodiments, the TEE area of the assessment generator module 140 can be operated by the seller through the data owner module 110, or by the exchange center through the data exchange module 130. More specifically, in the initial step, the seller can use the key "datakey_i" to encrypt the data set with the identifier "data_i". Then, after verification by the PCMA token, the encrypted data set is decrypted using the key "datakey_i" within the TEE area, and a mutually agreed assessment process is performed on the decrypted data set. There are two ways to do this. In one embodiment, the seller can choose to set up his own TEE area (that is, the TEE area of the assessment generator module 140 is operated by the seller) so that neither the exchange center nor the buyer can access the original data in the decrypted identifier "data_i" data set. In an alternative embodiment, the seller may also choose to entrust the exchange center to host the data evaluation service for the identifier "data_i" data set (i.e., the TEE area of the evaluation generator module 140 is operated by the exchange center), wherein the method involved is to use the public key of the TEE area to encrypt the key "datakey_i" and send the ciphertext of the encrypted key "datakey_i" to the exchange center.
[0043] In this way, when using TEE, it can be ensured that the TEE area is only associated with the evaluation results, and the original data in the TEE area will never be leaked to untrusted parties, thereby protecting the seller's data.
[0044] In step S80, the evaluation generator module 140 sends the evaluation results of each authorized dataset from the TEE area to the data user module 120, which means that the buyer receives the results from the exchange center. After that, the buyer can decide whether to purchase the dataset from the seller based on the evaluation results generated by the mutually agreed evaluation algorithm.
[0045] In step S90, if the buyer decides to pay for the dataset, the buyer sends a corresponding message to the seller via the exchange center. In one embodiment, the data owner module 110 and the data user module 120 are configured to establish a communication path from the owner terminal T1 to the user terminal T2 via the data exchange center EX. This communication path is used for data transmission from the owner terminal T1 to the user terminal T2 and for payment from the user terminal T2 to the owner terminal T1.
[0046] After receiving payment from the buyer, the seller can then send a data set (e.g., "data_1, data_2, data_3") that matches the data hash of the PCMA token. In one embodiment, the exchange uses the data exchange module 130 as an intermediary platform, enabling sellers and buyers to automatically complete the transaction. However, if the buyer decides to refuse payment, the transaction fails and the process is aborted.
[0047] In step S100, upon receiving the purchased data set, the buyer may optionally activate a data authentication program. In one embodiment, the data authentication program is created via a smart contract deployed by an exchange or another designated third party. For example, data authentication module 150 may be provided by the exchange and included in system 100.
[0048] like Figure 6 As shown, the data authentication module 150 executes a data authentication procedure through a deployed smart contract. The data authentication module 150 can obtain the PCMA token, the hash value of the purchased dataset, and at least one evaluation score of the evaluation result as input sources. During the data authentication procedure, the data authentication module 150 constructs a point on the elliptic curve for each acquired / input dataset and then verifies whether all points belong to the polynomial represented by the acquired / input single PCMA token. The data authentication procedure can be executed in the TEE area and is intended to authenticate / evaluate whether each purchased dataset is the same as the dataset originally listed by the seller.
[0049] In one embodiment, the data authentication module 150 outputs a positive signal only when the hash value of the data set is the same as the hash value provided by the data owner module 110 from the data owner terminal T1, and all points are in the polynomial represented by the single PCMA token, thereby indicating that the data content received by the buyer is the same as the target object evaluated by the TEE area in the previous step. In another embodiment, if the hash value of the data set is different from the hash value initially listed by the data owner module 110 from the data owner terminal T1, the data authentication module 150 outputs a negative signal. The signal provided by the data authentication module 150 can serve as an indication to the buyer whether the transaction proceeded as expected.
[0050] Figure 7 FIG2 is a schematic diagram illustrating how to use the system to detect and reject buyer requests with incorrect or stolen tokens according to an embodiment of the present invention. As previously described, the data exchange module 130 can use the identity of the requester (e.g., the real buyer or other speculator) to construct a point on the elliptic curve and verify whether this point lies on the polynomial represented by the provided PCMA token. Since the PCMA token (i.e., the commitment token) ) embeds the authorization identity as the tag “Buyer_id_1” instead of the tag “Buyer_id_2”, so that the request of an unauthorized user (i.e., the buyer with the tag “Buyer_id_2”) can be detected and rejected.
[0051] Figure 8 The following is a schematic diagram illustrating how, according to an embodiment of the present invention, the system ensures that the data sent after payment is made by the buyer is identical to the data evaluated. As previously described, the PCMA token includes the identifier of the dataset and its hash value. If the seller delivers a different dataset after payment, the data hash value will not meet the requirements and will therefore fail PCMA token verification. This verification process can be automated using smart contracts deployed by system 100.
[0052] Through this configuration, the system of the present invention provides a single PCMA token construction method that maintains a consistent constant size and is publicly accessible to enable authorization of multiple protected datasets, thereby establishing a trusted authorization mechanism between data buyers, sellers, and exchange centers. Furthermore, the system utilizes a TEE environment to construct a trusted data product evaluation and coordination mechanism, enabling a mutually agreed-upon evaluation process for multiple protected datasets while protecting data privacy. Furthermore, the system also achieves automated and systematic data transaction integrity authentication for multiple datasets through smart contracts and a single PCMA token.
[0053] This disclosure provides a simple example to demonstrate how PCMA tokens are generated. However, in other embodiments of the present invention, the provided technology can also support authorization of multiple data sets, as long as the coefficients of the resulting polynomial can be used It can be represented as , where p is a large prime number.
[0054] The functional units and modules of the apparatus and methods according to the embodiments disclosed herein can be implemented using computing devices, computer processors or electronic circuits, including but not limited to application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), microcontrollers and other programmable logic devices configured or programmed according to the teachings of the present disclosure. Practitioners in the software or electronics fields can easily prepare computer instructions or software codes executed in computing devices, computer processors or programmable logic devices based on the teachings of the present disclosure.
[0055] All or part of the methods according to the embodiments may be executed in one or more computing devices, including server computers, personal computers, laptop computers, mobile computing devices such as smartphones and tablet computers.
[0056] Embodiments may include computer storage media, transient and non-transitory memory devices having computer instructions or software code stored therein, which may be used to program or configure a computing device, computer processor, or electronic circuit to perform any of the processes of the present invention. The storage media, transient and non-transitory memory devices may include, but are not limited to, floppy disks, optical disks, Blu-ray disks, DVDs, CD-ROMs, magneto-optical disks, ROMs, RAMs, flash memory devices, or any type of medium or device suitable for storing instructions, code, and / or data.
[0057] Each functional unit and module according to various embodiments may also be implemented in a distributed computing environment and / or a cloud computing environment, where all or part of the machine instructions are executed in a distributed manner by one or more processing devices interconnected by a communication network, such as an intranet, a wide area network (WAN), a local area network (LAN), the Internet, and other forms of data transmission media.
[0058] The foregoing description of the present invention has been provided for purposes of illustration and description. It is not intended to be exhaustive or to limit the invention to the precise forms disclosed. Many modifications and variations will be apparent to those skilled in the art. The embodiments were chosen and described in order to best explain the principles of the invention and its practical application, thereby enabling others skilled in the art to understand the invention in various embodiments and with various modifications as are suited to particular uses.
Claims
1. A system for data exchange using a trusted authorization mechanism based on Polynomial Commitment Multiple Access (PCMA), characterized in that: The system comprises: a data owner module electrically or wirelessly coupled to the data owner terminal for data communication with the data owner terminal, and configured to encrypt a data set comprising a plurality of data sets of the data owner terminal using a key, and generate an identifier and a hash value for each of the data sets; a data user module electrically or wirelessly coupled to a user terminal for data communication with the user terminal and configured to submit at least one request from the user terminal to the data owner module to evaluate the data set, wherein the data owner module is further configured to check the request from the data user module to authorize at least one of the data sets in the data set, or the data user module rejects any request and does not authorize any of the requested data sets in the data set; and a data exchange module electrically or wirelessly coupled to a data exchange center for data communication with the data exchange center, and configured to generate a single PCMA token based on a user identity registered with the data exchange module, the identifier of the data set, and the hash value of the authorized data set, wherein the data exchange module constructs the PCMA token using a polynomial commitment mechanism so that the PCMA token maintains a constant size regardless of changes in the amount of authorized data, and the data exchange module utilizes a commitment algorithm of the polynomial commitment mechanism as an encryption protocol for the PCMA token to ensure that any potential original sensitive information used to construct the PCMA token cannot be recovered therefrom; The data exchange module is further configured to send the PCMA token to the data user module so that the user terminal can submit the PCMA token when requesting data evaluation.
2. The system according to claim 1, wherein: The data user module is configured to submit the PCMA token and the identifier of the data set to the data exchange module to request at least one evaluation result, and the data exchange module is configured to verify each queried data set using the PCMA token in response to the request from the data user module.
3. The system according to claim 2, characterized in that It also includes an evaluation generator module, which is configured to provide a trusted execution environment (TEE) area, and once the PCMA token submitted from the data user module is successfully verified by the data exchange module, an evaluation process is performed on each authorized data set in the TEE area, wherein the evaluation generator module is also configured to send the evaluation result of each authorized data set to the data user module.
4. The system according to claim 3, characterized in that The assessment generator module has an algorithm or AI model integrated with the assessment process.
5. The system according to claim 3, wherein: The evaluation generator module executes the evaluation process according to the executable protocol, so that the signed executable file of the evaluation process is allowed to evaluate the authorized data set within the TEE area, and the unsigned executable file in the evaluation process is prohibited from evaluating the authorized data set within the TEE area.
6. The system according to claim 3, wherein: The data owner module and the data user module are jointly configured to construct a communication path from the data owner end to the user end, and the communication path is used for a data transmission path from the data owner end to the user end, and for a payment path from the user end to the data owner end.
7. The system according to claim 6, characterized in that The system further includes a data authentication module configured to deploy a smart contract and obtain the PCMA token, the hash value of the data set from the user terminal, and at least one evaluation score of the evaluation result as input sources, and the data authentication module performs a data authentication procedure in the following manner: constructing a point on the elliptic curve for each authorized set of data; and Verify that all points belong to the polynomial represented by a single PCMA token.
8. The system according to claim 7, characterized in that The data authentication module outputs a positive signal only when the hash value of the data set is identical to the hash value provided by the data owner module from the data owner side and all the points are in the polynomial represented by the single PCMA token.
9. The system according to claim 7, wherein: If the hash value of the data set provided by the data owner terminal is different from the hash value provided by the data owner module, the data authentication module outputs a negative signal.
10. The system according to claim 1, wherein: The number of the requested data sets is M, the number of the data sets authorized to the user terminal is N, and N is less than or equal to M, where N and M are positive integers.
11. A method for data exchange using a trusted authorization mechanism based on Polynomial Commitment Multiple Access (PCMA), characterized in that: The method comprises: Through the data owner module, the data set containing multiple data sets on the data owner side is encrypted using a key; Generate an identifier and a hash value for each of the data sets through the data owner module; submitting, through a data user module, at least one request from a user terminal to the data owner module to evaluate the data set; Checking, by the data owner module, the request from the data user module and authorizing at least one of the data sets, or rejecting, by the data owner module, the request for any of the requested data sets of any unauthorized data set; generating, by a data exchange module, a single PCMA token based on the identity of the client, the identifier of the dataset, and the hash value of the authorized dataset; The PCMA token is constructed by the data exchange module using a polynomial commitment mechanism to maintain a constant size regardless of changes in the amount of data authorized by the PCMA token, and the data exchange module utilizes a commitment security algorithm of the polynomial commitment mechanism as an encryption protocol for the PCMA token to ensure that any potential original sensitive information used to construct the PCMA token cannot be recovered therefrom; and The PCMA token is sent to the data user module through the data exchange module, so that the user terminal can submit the PCMA token when requesting data evaluation.
12. The method according to claim 11, characterized in that Also includes: submitting, via the data user module, the PCMA token and the identifier of the dataset to the data exchange module to request at least one evaluation result; as well as Each queried data set is authenticated using the PCMA token via the data exchange module and in response to a request from the data user module.
13. The method according to claim 12, characterized in that Also includes: Provides a Trusted Execution Environment (TEE) area through the Assessment Generator module; Once the data exchange module successfully verifies the PCMA token submitted by the data user module, the evaluation generator module performs an evaluation process on each authorized data set within the TEE area; as well as The evaluation result of each authorized data set is sent to the data user module through the evaluation generator module.
14. The method according to claim 13, characterized in that The assessment generator module has an algorithm or AI model integrated with the assessment process.
15. The method according to claim 13, characterized in that The evaluation generator module executes the evaluation process according to the executable protocol, so that the signed executable file of the evaluation process is allowed to be used to evaluate the authorized data set within the TEE area, and the unsigned executable file in the evaluation process is prohibited from being used to evaluate the authorized data set within the TEE area.
16. The method according to claim 13, characterized in that Also includes: Through the data owner module and the data user module, a communication path is jointly constructed from the data owner end to the user end via the data exchange center. The communication path is used for the data transmission path from the data owner end to the user end, and the payment path from the user end to the data owner end.
17. The method according to claim 16, characterized in that Also includes: Deploy smart contracts through the data authentication module; The data authentication module obtains the PCMA token, the hash value of the data set from the user terminal, and at least one evaluation score of the evaluation result and uses them as input sources. The data authentication module performs a data authentication procedure in the following manner: constructing a point on the elliptic curve for each authorized set of data; and Verify that all points belong to the polynomial represented by a single PCMA token.
18. The method according to claim 17, characterized in that Also includes: The data authentication module outputs a positive signal only when the hash value of the data set is identical to the hash value provided by the data owner module from the data owner side and all the points are in the polynomial represented by the single PCMA token.
19. The method according to claim 17, wherein Also includes: If the hash value of the data set provided by the data owner terminal is different from the hash value provided by the data owner module, the data authentication module outputs a negative signal.
20. The method according to claim 11, characterized in that The number of the requested data sets is M, the number of the data sets authorized to the user terminal is N, and N is less than or equal to M, where N and M are positive integers.
Citation Information
Patent Citations
Attribute searchable encryption system and method based on block chain
CN116450746A
Private data security sharing method based on block chain
CN117692227A