Data management system, publishing and subscribing method and apparatus based on distributed digital identity

The distributed digital identity management system based on blockchain technology solves the problems of data silos and insufficient data security in traditional data management systems, and realizes secure data sharing and efficient circulation.

CN119783166BActive Publication Date: 2025-12-12ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID SHANDONG ELECTRIC POWER COMPANY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411842039.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-12-12
Estimated Expiration
2044-12-13

AI Technical Summary

Technical Problem

Traditional data management systems face problems such as data silos, difficulties in data sharing, and insufficient data security.

Method used

A data management system based on distributed digital identity is adopted, which uses blockchain technology to assign a distributed identifier to each user, establishes a distributed digital identity, and achieves secure data sharing and efficient circulation through the collaborative work of data centers and circulation centers.

Benefits of technology

It enables secure data sharing and efficient circulation, solving the problems of data silos and insufficient data security in traditional data management systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119783166B_ABST
    Figure CN119783166B_ABST
Patent Text Reader

Abstract

The application provides a data management system, a publishing and subscribing method and device based on distributed digital identity. The system includes multiple data centers and a circulation center. The data center allocates a distributed identifier to a user, uploads the distributed identifier to a block chain to establish a distributed digital identity, and registers a storage account and a request account. The data center uploads metadata of user data to the block chain, and the circulation center verifies and publishes the metadata to a data directory. The request account sends a request according to the directory, and the circulation center forwards the request to the storage account. The data center corresponding to the storage account generates request result information and a data sharing mode, and the circulation center verifies and forwards the request result information and the data sharing mode to the request account. The request account establishes a connection with the data center corresponding to the storage account, verifies identity information through the block chain, and acquires user data according to the data sharing mode. The system uses the block chain technology, the distributed digital identity and collaborative work to realize safe data sharing and efficient circulation, and solves the problems of data islands, difficult sharing and insufficient security.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the field of data management, and particularly relates to a data management system based on distributed digital identity, and a publishing and subscribing method and device. BACKGROUND

[0002] With the rapid development of information technology, data has become an important resource in modern society. However, traditional data management systems often face problems such as data silos, difficulties in data sharing, and insufficient data security. SUMMARY

[0003] The present application aims to overcome the above-mentioned defects in the prior art, and provides a data management system based on distributed digital identity, and a publishing and subscribing method and device.

[0004] The present application provides a data management system based on distributed digital identity, comprising: a plurality of data centers and a circulation center;

[0005] The data center assigns a distributed identifier according to the digital certificate of the user corresponding to the data center, uploads the distributed identifier to a blockchain, and establishes a distributed digital identity for each user;

[0006] The data center registers an account for each user corresponding to the data center according to the distributed digital identity, and the account comprises: a storage account and a request account;

[0007] The data center obtains metadata of user data in the data center corresponding to the storage account, and uploads the metadata to the blockchain;

[0008] The circulation center obtains the metadata and verifies the metadata through the blockchain, and after verification, publishes the metadata to a data directory;

[0009] The request account sends request information according to the data directory, and forwards the request information to the storage account through the circulation center;

[0010] The data center corresponding to the storage account generates request result information and data sharing mode according to the request information;

[0011] The circulation center obtains and verifies the request result information and the data sharing mode through the blockchain, and after verification, forwards to the request account;

[0012] The request account establishes a connection with the data center corresponding to the storage account according to the request result information, the data center corresponding to the storage account performs blockchain verification on the identity information of the request account, and after the verification is passed, the request account acquires the user data of the data center corresponding to the storage account according to the data sharing mode.

[0013] Optionally, the data center comprises:

[0014] A distributed digital identity management system is configured to allocate a distributed identifier and upload the distributed identifier to a blockchain.

[0015] Optionally, the data center comprises:

[0016] A distributed access system is configured to register an account for each user of the data center according to the distributed digital identity, acquire metadata of the user in the data center corresponding to the storage account, upload the metadata to the blockchain, issue a request information according to the data directory, receive the request information sent by the circulation center, and receive the request result information and a data sharing mode forwarded by the circulation center.

[0017] Optionally, the data center comprises a data connector.

[0018] The data connector verifies the information of the request account through the blockchain according to the request result information, and acquires the user data stored in the data center corresponding to the storage account according to the data sharing mode after the verification is passed.

[0019] Optionally, the metadata comprises description information of data content and a transaction number for verifying data integrity and source.

[0020] Optionally, the request result information comprises an approval result of the request information by the storage account and transaction information of uploading the request information to the blockchain by the storage account.

[0021] Optionally, the plurality of data centers and the circulation center each comprise a data circulation layer and a blockchain layer.

[0022] The data circulation layer comprises a distributed identity management system, a distributed access system and a data connector.

[0023] The blockchain layer comprises one node of a blockchain.

[0024] The application further provides a data publishing method based on a distributed digital identity, comprising:

[0025] According to the data center corresponding to the user's digital certificate distribution distributed identifier, the distributed identifier is uploaded to the block chain, and the distributed digital identity of each user is established;

[0026] According to the distributed digital identity, the account of each user is registered;

[0027] Obtain the metadata of the user data in the data center corresponding to the registered account, and upload the metadata to the block chain;

[0028] The metadata is verified through the block chain, and the metadata is published in the data directory after the verification is passed.

[0029] Optionally, the metadata includes description information of the user data, and transaction number for verifying data integrity and source.

[0030] Optionally, the data directory is used for users to publish, retrieve and manage metadata of data.

[0031] The application also provides a data subscription method based on distributed digital identity, comprising:

[0032] According to the request information, request result information and data sharing mode returned according to the request information are obtained;

[0033] According to the request result information, connect the data center, and the data center verifies the request account information through the block chain, and obtains the user data according to the data sharing mode after the verification is passed.

[0034]

[0035] Optionally, the request result information includes: the approval result of the data center corresponding to the storage account to the request information and the transaction information of the storage account uploading the request information to the block chain.

[0036] The application also provides a data publishing device based on distributed digital identity, comprising:

[0037] Memory;

[0038] ​A processor is configured to retrieve a computer executable program of the data publishing method based on the distributed digital identity from the memory, and execute: distributing a distributed identifier to each user according to a digital certificate of the user in a data center, uploading the distributed identifier to a block chain, and establishing a distributed digital identity of each user; registering an account for each user according to the distributed digital identity; obtaining metadata of user data in the data center corresponding to the registered account, and uploading the metadata to the block chain; verifying the metadata through the block chain, and publishing the metadata to a data directory after the verification.

[0039] The application further provides a data subscription device based on a distributed digital identity, comprising:

[0040] A memory;

[0041] A processor is configured to retrieve a computer executable program of the data subscription method based on the distributed digital identity from the memory, and execute: issuing request information according to a data directory; obtaining request result information and a data sharing mode returned according to the request information; connecting a data center according to the request result information, and obtaining user data according to the data sharing mode after the data center verifies the request account information through the block chain.

[0042] The application further provides a storage medium, comprising: a computer executable program stored for executing steps of the data publishing method based on the distributed digital identity.

[0043] The application further provides a storage medium, comprising: a computer executable program stored for executing steps of the data subscription method based on the distributed digital identity.

[0044] The application has the following beneficial effects:

[0045] The application provides a data management system based on distributed digital identity, comprising: a plurality of data centers and a circulation center; the data center distributes a distributed identifier according to the digital certificate of the user corresponding to the data center, uploads the distributed identifier to a block chain, and establishes a distributed digital identity of each user; the data center registers an account for each user corresponding to the data center according to the distributed digital identity, the account comprising: a storage account and a request account; the data center obtains metadata of user data in the data center corresponding to the storage account, and uploads the metadata to the block chain; the circulation center obtains the metadata and verifies the metadata through the block chain, and publishes the metadata to a data directory after verification; the request account sends request information according to the data directory, and forwards the request information to the storage account through the circulation center; the data center corresponding to the storage account generates request result information and a data sharing mode according to the request information; the circulation center obtains and verifies the request result information and the data sharing mode through the block chain, and forwards them to the request account after verification; the request account establishes a connection with the data center corresponding to the storage account according to the request result information, the data center corresponding to the storage account performs block chain verification on the identity information of the request account, and the request account obtains user data of the data center corresponding to the storage account according to the data sharing mode after verification. By using the block chain technology, the distributed digital identity, and the collaborative work of the data center and the circulation center, the application realizes the safe sharing and efficient circulation of data, and solves the problems of data island, difficult data sharing and insufficient data security in the traditional data management system. BRIEF DESCRIPTION OF DRAWINGS

[0046] Figure 1 It is a data management system based on distributed digital identity in the application;

[0047] Figure 2 It is a user registration diagram of data management based on distributed digital identity in the application;

[0048] Figure 3 It is a data subscription diagram based on distributed digital identity in the application;

[0049] Figure 4 It is a data release diagram based on distributed digital identity in the application;

[0050] Figure 5 It is a data release process diagram based on distributed digital identity in the application;

[0051] Figure 6 It is a data subscription process diagram based on distributed digital identity in the application. DETAILED DESCRIPTION

[0052] Exemplary embodiments of the present disclosure will be described in greater detail below with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it is understood that various forms of the present disclosure are implemented without being limited by the embodiments set forth herein. Rather, the embodiments are provided so that the present disclosure can be more thoroughly understood, and the scope of the present disclosure is fully conveyed to those skilled in the art.

[0053] Referring to Figures 1-3 The data management system based on distributed digital identity includes a plurality of data centers and a circulation center.

[0054] Specifically, the data management system based on distributed digital identity adopts a two-layer architecture design, which is a blockchain layer and a data circulation layer.

[0055] The blockchain layer is the core, which is connected by a self-discovery network to ensure that each node is automatically discovered and connected. This layer is mainly used for consensus and ledger synchronization of blockchain transactions to ensure that all transactions are correctly recorded and synchronized to all nodes.

[0056] The data circulation layer is responsible for the whole process of data from publishing to using, and data security sharing. It is built on the blockchain layer and uses the trust mechanism provided by the blockchain layer to realize efficient circulation and secure sharing of data.

[0057] There is only one circulation center, which is responsible for global data circulation and supervision. The circulation center deploys a data circulation center system for storing and managing data directories and publishing data metadata storage. In addition, the data circulation center also contains a blockchain node that participates in the transaction verification process as a witness to ensure the legality and consistency of transactions.

[0058] There are multiple data centers deployed in enterprises and institutions for local data management and data publishing operations.

[0059] The data center includes:

[0060] 1. Distributed digital identity management system: used for the application and management of user digital identity, ensuring that each user has a unique and tamper-proof distributed digital identity.

[0061] 2. Distributed access system: used for data publishing, data authorization, and other data local management operations, providing a convenient data management interface.

[0062] 3. Data connector: the data connector is used for digital identity authentication for data sharing and provides a secure point-to-point data sharing channel to ensure the security and privacy of data during sharing.

[0063] 4. Blockchain node: used to provide transaction entry, and broadcast, ordering, packaging of transactions, as well as transaction verification, transaction execution and multi-party consensus. Further, the data center flexibly selects whether to deploy a blockchain node according to its own governance needs and resource conditions.

[0064] The data center assigns a distributed identifier (DID) to the user corresponding to the data center according to the digital certificate of the user, uploads the distributed identifier (DID) to the blockchain, and establishes a distributed digital identity for each user.

[0065] Specifically, in the distributed digital identity management system, the user first has a digital certificate. This digital certificate is issued by the government or official service platform, and is used to prove the authenticity of the user's identity information. For example, in some areas, users apply for personal digital certificates through specific government service platforms.

[0066] After the user has a digital certificate, he submits an application to the distributed digital identity management system to obtain a distributed digital identity (distributed identifier (DID)). During the application process, the user submits his digital certificate and other necessary identity information for the system to verify and audit the identity.

[0067] The system will review the user's application and, after confirming that the user's identity information is true and valid, will assign the user a unique distributed identifier (DID). This distributed identifier (DID) is a string of identifiers that represents the user's digital identity and has global uniqueness. Through the distributed identifier (DID), the user performs identity verification and data sharing operations in the distributed system.

[0068] After the distributed digital identity management system assigns a distributed identifier (DID) to the user, it records the distributed identifier (DID) information on the blockchain. The blockchain is a decentralized distributed ledger with features such as immutability and transparency. Specifically, the user's distributed identifier (DID), distributed identifier (DID) document (containing key information and verification methods related to distributed identifier (DID) verification), and other related information are recorded on the blockchain. In this way, when the user performs identity verification or data sharing, other nodes verify the user's identity and permissions by querying the information on the blockchain.

[0069] According to the distributed digital identity, an account is registered for each of the users, including a storage account and a request account corresponding to each of the data centers.

[0070] In a distributed digital identity management system, a user has successfully applied for and obtained his own distributed digital identity (DID) through a digital certificate.

[0071] When the user wants to use the distributed access system, he uses his digital identity to register an account in the system. The user first accesses the login or registration page of the distributed access system. On the registration page, choose the way to register using digital identity. The user enters his own distributed identifier (DID) on the registration page and provides verification information related to the distributed identifier (DID).

[0072] When the user submits the registration information, the distributed access system will interact with the distributed digital identity management system to verify the authenticity of the distributed identifier (DID) and verification information provided by the user. The system will query the user's distributed identifier (DID) information through the blockchain, and check whether the verification information provided by the user is consistent with the record on the blockchain. If the system is verified, the user's digital identity is confirmed to be real and effective, then the distributed access system will create a new account for the user, and bind the account information with the user's distributed identifier (DID).

[0073] After completing the account registration and activation, the user uses his own digital identity (DID) and password or other verification methods to log in to the distributed access system. For the convenience of description, the following content will be referred to as the storage account for publishing data, and the request account for subscribing data.

[0074] The storage account obtains the metadata of the user data in the data center corresponding to the storage account, and uploads the metadata to the blockchain.

[0075] The storage account plays a key role, which is responsible for managing the user data stored in the data center and ensuring that the metadata of the data can be safely and reliably uploaded to the blockchain.

[0076] The user first comprehensively manages the data stored in the data center. This includes data classification, organization, backup, and permission settings, etc. The user configures different access permissions and sharing methods for different data sets according to his own needs, to ensure the security and availability of the data.

[0077] On the basis of data management, the user configures the sharing method of the data. This includes determining which data to share, with whom to share, the scope and conditions of sharing, etc. The user achieves this goal by setting data access permissions, data sharing protocols, etc.

[0078] Data metadata is a description of the data content, which contains the name, type, format, size, creation time, modification time, and other key information of the data. Users extract the metadata of the data from the data center. These metadata will be used in subsequent data sharing and supervision processes.

[0079] After extracting the data metadata, the user uploads the data metadata to the blockchain using their own distributed digital identity (Distributed Identifier, DID).

[0080] The user first packages the data metadata into a transaction and attaches their own distributed identifier (DID) as the initiator of the transaction. Then, the user sends this transaction to the blockchain network. The nodes in the blockchain network will verify and reach consensus on the transaction to ensure its authenticity and validity. Once the transaction is confirmed and written to the blockchain, the user will receive a transaction number as proof of the successful transaction.

[0081] When the user successfully uploads the data metadata to the blockchain, a transaction number is returned. This transaction number is unique and represents the user's data metadata upload operation on the blockchain. The user uses this transaction number to query and track the status and changes of their data metadata on the blockchain.

[0082] The circulation center obtains the metadata and verifies it through the blockchain. After verification, the metadata is published to the data directory.

[0083] The user pushes the data metadata and the transaction number obtained from the blockchain to the data circulation center. Data metadata is a description of the data content, including the name, type, format, size, creation time, and other key information of the data. The transaction number is a unique proof obtained by the user when uploading the data metadata to the blockchain, used to prove the authenticity and validity of the data metadata.

[0084] The user submits the data metadata and transaction number to the circulation center through the API interface or Web interface provided by the data circulation center.

[0085] After receiving the data metadata and transaction number submitted by the user, the data circulation center will first perform verification. The verification process includes two aspects:

[0086] Transaction number verification: The data circulation center will query the blockchain to check whether the transaction number submitted by the user exists and is valid. This ensures that the data metadata submitted by the user has indeed been uploaded to the blockchain and has not been tampered with or deleted.

[0087] User Digital Identity Verification: The data circulation center also verifies the user's digital identity (Distributed Identifier (DID)). This is achieved by checking whether the Distributed Identifier (DID) submitted by the user matches the Distributed Identifier (DID) recorded on the blockchain. This ensures that the user submitting the data metadata is legitimate and has the corresponding authority.

[0088] If the data circulation center verifies the transaction number submitted by the user and the user's digital identity, it publishes the data metadata submitted by the user into the data directory. The data directory is a platform that centrally stores and manages data metadata, allowing other users or systems to discover and access data through searching and browsing.

[0089] The request account sends request information according to the data directory to the storage account through the circulation center.

[0090] In the distributed data sharing and circulation system, the request account (i.e. the user or system that wants to access data) interacts with the storage account (i.e. the owner or manager of the data) through the data circulation center to obtain the required data.

[0091] The following takes user A as the request account and user B as the storage account for detailed description.

[0092] As a data requester, user A first obtains the data directory from the data circulation center. The data directory is a platform that centrally stores and manages data metadata, containing key information such as data name, type, format, storage location, access rights, etc. User A pulls the data directory through the API interface or Web interface provided by the data circulation center.

[0093] When pulling the data directory, user A provides his own digital identity (Distributed Identifier (DID)) or authenticated access credentials to ensure the legitimacy of his identity and the security of the data.

[0094] The data circulation center returns the corresponding data directory according to the identity and authority of user A.

[0095] After obtaining the data directory, user A browses the data metadata in it and finds the data of interest. Then, user A makes an access application for these data. The access application usually includes information such as data name, type, format, access rights, as well as user A's identity proof and access purpose, etc.

[0096] User A submits the access application through the interface or API interface provided by the data circulation center. When submitting the application, user A ensures the accuracy and completeness of the application information so that the data owner can accurately understand the access requirements.

[0097] The access application submitted by user A is pushed to the data circulation center. The data circulation center, as an intermediate circulation platform for data, is responsible for receiving, processing and forwarding access applications. After receiving the access application, the data circulation center will conduct preliminary verification and screening to ensure that it meets the rules and conditions of data sharing and circulation.

[0098] After preliminary verification and screening, the data circulation center forwards the access application to the data owner user B.

[0099] The circulation center obtains and verifies the request result information and data sharing method issued by the storage account according to the request information through the blockchain, and forwards it to the request account after verification.

[0100] User B, as the owner or manager of the data, has the right to decide the access rights and conditions of the data. The data circulation center sends the detailed information of the access application to user B, so that user B can understand the identity, access purpose and data demand of the applicant.

[0101] After receiving the access application, user B decides whether to agree to the access request of the applicant according to his own will and the access rights of the data. If user B agrees to the access request, the data circulation center will further process the request and grant the applicant the corresponding data access rights. If user B refuses the access request, the data circulation center will notify the applicant and explain the reason.

[0102] If user B agrees to the access request of user A, user B will chain the relevant information of the access request, that is, record it on the blockchain.

[0103] When chaining the access request, user B will generate a unique transaction number to identify this data access request. User B will return the transaction number to the data circulation center for subsequent verification and tracking.

[0104] The circulation center obtains and verifies the request result information and data sharing method through the blockchain, and forwards it to the request account after verification.

[0105] Specifically, after user B agrees to the access request and chains the message, the distributed access system corresponding to user B will start processing the access request. The distributed access system is a system responsible for data access control, permission management, data transmission and other functions. It will process the access request of user A according to the access rights and data sharing method set by user B.

[0106] During the processing, the distributed access system checks the identity and authority of user A through blockchain verification to ensure that it meets the access conditions. Then, the distributed access system generates the processing result of the access request, including whether the data is successfully accessed, the content of the accessed data, the time of access, and other key information. At the same time, the distributed access system also determines the sharing method of the data, such as direct download, online viewing, API interface access, etc.

[0107] The distributed access system returns the processing result of the access request and the data sharing method to the data circulation center. As an intermediate circulation platform for data, the data circulation center will be responsible for receiving and processing these result information.

[0108] After receiving the processing result of the access request and the data sharing method returned by the distributed access system, the data circulation center will verify it. During the verification process, the data circulation center will check the validity of the transaction number to ensure the authenticity and integrity of the access request. At the same time, the data circulation center will also check the compliance of the processing result and the data sharing method to ensure that it meets the rules and conditions of data sharing and circulation.

[0109] If the verification is passed, the data circulation center will push the processing result of the access request and the data sharing method to the data applicant user A.

[0110] The request account establishes a connection with the data center corresponding to the storage account according to the request result information, and the data center corresponding to the storage account performs blockchain verification on the identity information of the request account. After the verification is passed, the request account obtains the user data of the data center corresponding to the storage account according to the data sharing method.

[0111] Specifically, user A receives the request result information through the interface or API interface provided by the data circulation center. These information usually includes the identification of the storage account, the data access authority, the data sharing method and other key information. User A verifies the authenticity and legality of the storage account through blockchain technology according to these information.

[0112] If user A successfully verifies the information of the storage account, then according to the data access authority and data sharing method provided in the request result information, user A obtains the user data stored in the data center corresponding to user B.

[0113] The data center corresponding to user B is a platform that centrally stores and manages data, which provides functions such as data storage, backup, recovery, etc. User A accesses the data center through the interface provided by the data connector in the data center corresponding to user B, and the data connector in the data center corresponding to user B verifies the identity information of user A, then user A obtains the required data according to his own authority and demand.

[0114] During the process of obtaining data, user A ensures the integrity and security of the data to prevent tampering or leakage of the data. At the same time, user A also complies with the rules and conditions of data sharing and circulation to ensure the legality and compliance of the data.

[0115] In addition to directly accessing the data center, user A also views and processes request result information through the interface or API interface provided by the data circulation center. The data circulation center serves as an intermediate circulation platform for data, providing functions such as receiving, verifying, forwarding, and displaying data metadata.

[0116] User A establishes a data connection with data connector B of the data source in order to carry out subsequent data transmission and interaction. Data connector B is a tool or system responsible for data connection, transmission, and conversion, which can seamlessly connect the data of the data source with the system or application of user A.

[0117] User A provides their digital identity and access credentials to data connector B so that data connector B can verify their identity and permissions. Digital identity is an identity verification method based on blockchain technology that ensures the authenticity and security of user identity.

[0118] After receiving the connection request from user A, data connector B obtains the approval result and verifies the digital identity of user A through blockchain technology. The approval result usually includes user A's access permissions, data sharing methods, and other key information.

[0119] If user A's digital identity verification is successful, data connector B will establish a data connection with user A and allow them to access the required data. At the same time, data connector B will configure the parameters and rules of data transmission and interaction according to user A's permissions and requirements.

[0120] If user A's digital identity verification fails, data connector B will reject the connection request and notify user A accordingly. User A can provide correct digital identity and access credentials or contact the administrator of the data source to resolve the identity verification problem.

[0121] Please refer to Figure 4 The present application also provides a data publishing method based on distributed digital identity, which realizes safe, efficient, and compliant data publishing by using distributed digital identity (Distributed Identifier (DID)) technology.

[0122] S101, assign a distributed identifier (DID) to each user according to the digital certificate of the data center, upload the distributed identifier (DID) to the blockchain, and establish the distributed digital identity of each user.

[0123] The data center obtains the digital certificate of the user.

[0124] Based on the digital certificate, a distributed digital identity (DID) is generated for each user. The distributed identifier (DID) is a decentralized identity with uniqueness, security and verifiability. The generated distributed identifier (DID) is uploaded to the blockchain, taking advantage of the tamper-proof and decentralized characteristics of the blockchain to establish the distributed digital identity of each user.

[0125] S102, register an account for each user according to the distributed digital identity.

[0126] Based on the user's distributed identifier (DID), an account is registered for each user on the data center or related platform. The account is associated with the user's distributed identifier (DID), ensuring the uniqueness and traceability of the user's identity.

[0127] S103, the registered account obtains the metadata of the user data in the data center corresponding to the registered account, and uploads the metadata to the blockchain.

[0128] After registering the account, the user or the data center will obtain the metadata of the user data in the data center corresponding to the registered account. Metadata is data about data, including data description, structure, source, permission and other information.

[0129] The obtained metadata is uploaded to the blockchain. This step is to take advantage of the verification and storage capabilities of the blockchain to ensure the authenticity and integrity of the metadata.

[0130] S104, verify the metadata through the blockchain, and publish the metadata to the data directory after verification.

[0131] The smart contract or verification mechanism on the blockchain will verify the uploaded metadata. The verification content includes the integrity, correctness of the format, permission setting and other information of the metadata.

[0132] If the metadata passes the verification, that is, it meets the preset verification rules and standards, the metadata will be considered legal and effective. After the verification, the metadata is published to the data directory. The data directory is a platform for centralized display and management of data metadata, which is accessed and queried by authorized users or applications.

[0133] Further, the metadata includes description information of the data content, and transaction number for verifying the integrity and source of the data.

[0134] Further, the data directory is used for users to publish, retrieve and manage metadata of data.

[0135] Please refer toFigure 5 As shown, the present application also provides a data subscription method based on distributed digital identity, aiming to provide a safe, efficient and distributed digital identity-based data subscription mechanism. Users issue demand requests for data through a data directory, and then verify the returned request result information and storage account information using blockchain technology to ensure the authenticity of the data and the reliability of the source. Once verified, the user can obtain the required data.

[0136] S201, issuing request information according to a data directory.

[0137] The user first accesses the data directory, which is a platform that centrally displays and manages data metadata, containing information such as the description, structure, source, and permissions of various data. The user selects the data set or data item of interest in the data directory according to their own needs and generates corresponding request information. The request information usually contains the identification of the data, the scope of the required data, the format requirements, and the user's identity information, etc.

[0138] S202, obtaining and verifying the request result information and data sharing method returned according to the request information through blockchain.

[0139] The user submits the generated request information to the data directory system or the relevant data processing center. After receiving the request, the data directory system or the data processing center will generate request result information according to the data permission settings and availability. The request result information contains key information such as whether the user's request is met, the specific location of the data, and access permissions.

[0140] The data directory system or the data processing center uploads the request result information to the blockchain and uses the blockchain's tamper-proof and decentralized characteristics to verify the request result information. The user confirms the authenticity and validity of the request result information through the public information on the blockchain or a specific verification interface.

[0141] S203, connecting the data center according to the request result information, the data center verifying the request account information through the blockchain, and obtaining the user data according to the data sharing method after verification.

[0142] Once the request result information is verified, the user obtains the storage account information to obtain the required data from the storage account. The storage account information usually includes the identification of the storage account, access permissions, data location, etc.

[0143] In order to ensure the authenticity and reliability of the request account information, the data center corresponding to the storage account verifies the request account information using blockchain technology. This is done by querying the relevant records on the blockchain or using a smart contract for verification.

[0144] After the request account information verification passes, the user obtains the required data from the storage account according to the data location and access permission provided in the storage account information. The data obtaining process may involve data decryption, format conversion and other steps to ensure the availability and accuracy of the data.

[0145] Further, the request result information includes: the approval result of the storage account on the request information and the transaction information of the storage account uploading the request information to the blockchain.

[0146] The application also provides a data publishing device based on distributed digital identity, comprising:

[0147] a memory;

[0148] a processor for calling the computer executable program of the above-mentioned data publishing method based on distributed digital identity from the memory to perform: distributing a distributed identifier according to the digital certificate of the user corresponding to the data center, uploading the distributed identifier to the blockchain, and establishing the distributed digital identity of each user; registering an account for each user according to the distributed digital identity; obtaining the metadata of the user data in the data center corresponding to the registered account, uploading the metadata to the blockchain; verifying the metadata through the blockchain, and publishing the metadata to the data directory after the verification passes.

[0149] The application also provides a data subscription device based on distributed digital identity, comprising:

[0150] a memory;

[0151] a processor for calling the computer executable program of the above-mentioned data subscription method based on distributed digital identity from the memory to perform: issuing request information according to the data directory; obtaining request result information and data sharing mode returned according to the request information; connecting the data center according to the request result information, and obtaining user data according to the data sharing mode after the data center verifies the request account information through the blockchain.

[0152] The application also provides a storage medium, comprising: a computer executable program stored for performing the steps of the above-mentioned data publishing method based on distributed digital identity.

[0153] The application also provides a storage medium, comprising: a computer executable program stored for performing the steps of the above-mentioned data subscription method based on distributed digital identity.

[0154] Although the present application is disclosed with reference to the embodiments above, it is not intended to limit the scope of the present application, and any changes and modifications made by those skilled in the art without departing from the spirit and scope of the present application are intended to be within the scope of the present application.

Claims

1. A distributed digital identity based data management system, characterized in that, Comprising: a plurality of data centers and a circulation center; the data center assigns a distributed identifier to the user corresponding to the data center according to the digital certificate of the data center, uploads the distributed identifier to the block chain, and establishes the distributed digital identity of each user; the data center registers an account for each user corresponding to the data center according to the distributed digital identity, and the account includes: a storage account and a request account; the data center obtains the metadata of the user data in the data center corresponding to the storage account, and uploads the metadata to the block chain; the circulation center obtains the metadata and verifies the metadata through the block chain, and publishes the metadata to the data directory after verification; the request account sends request information according to the data directory, and forwards the request information to the storage account through the circulation center; the data center corresponding to the storage account generates request result information and data sharing mode according to the request information; the circulation center obtains and verifies the request result information and the data sharing mode through the block chain, and forwards them to the request account after verification; the request account establishes a connection with the data center corresponding to the storage account according to the request result information, and the data center corresponding to the storage account verifies the identity information of the request account through the block chain, and the request account obtains the user data of the data center corresponding to the storage account according to the data sharing mode after verification.

2. The data management system based on distributed digital identity according to claim 1, characterized in that, The data center comprises: a distributed digital identity management system for assigning a distributed identifier and uploading the distributed identifier to a block chain.

3. The data management system based on distributed digital identity according to claim 1, characterized in that, The data center comprises: a distributed access system for registering an account for each user corresponding to the data center according to the distributed digital identity, obtaining metadata of the user corresponding to the storage account in the data center, uploading the metadata to the block chain, sending request information according to the data directory, receiving the request information sent by the circulation center, and receiving the request result information and data sharing mode forwarded by the circulation center.

4. The data management system based on distributed digital identity according to claim 1, characterized in that, The data center comprises a data connector; the data connector verifies the information of the request account through the block chain according to the request result information, and obtains the user data stored in the data center corresponding to the storage account according to the data sharing mode after verification.

5. The data management system based on distributed digital identity according to claim 1, characterized in that, The metadata includes description information of data content and transaction number for verifying data integrity and source.

6. The data management system based on distributed digital identity according to claim 1, characterized in that, The request result information includes: the approval result of the request information by the storage account and the transaction information of uploading the request information to the block chain by the storage account.

7. The data management system based on distributed digital identity according to claim 1, characterized in that, The data center and the circulation center each comprise a data circulation layer and a block chain layer; the data circulation layer comprises a distributed identity management system, a distributed access system and a data connector; the block chain layer comprises a node of the block chain.

8. A data publishing method based on distributed digital identity, characterized in that, Comprising: assigning a distributed identifier to the user corresponding to the data center according to the digital certificate of the data center, uploading the distributed identifier to the block chain, and establishing the distributed digital identity of each user; According to the distributed digital identity, an account is registered for each user, the account including a storage account and a request account; Metadata of user data in the data center corresponding to the account is obtained, and the metadata is uploaded to the blockchain; The metadata is verified through the blockchain, and after verification, the metadata is published to a data directory; The request account sends request information according to the data directory, and forwards the request information to the storage account; The data center corresponding to the storage account generates request result information and a data sharing mode according to the request information; The request result information and the data sharing mode are verified through the blockchain, and after verification, they are forwarded to the request account; The request account establishes a connection with the data center corresponding to the storage account according to the request result information, the data center corresponding to the storage account performs blockchain verification on the identity information of the request account, and after verification, the request account obtains user data of the data center corresponding to the storage account according to the data sharing mode.

9. The method of claim 8, wherein, The metadata includes description information of the user data and a transaction number for verifying data integrity and source.

10. The method of claim 8, wherein, The data directory is used for user to publish, retrieve and manage metadata of data.

11. A data publishing device based on distributed digital identity, characterized by, It includes: a memory; a processor configured to retrieve a computer executable program of the data publishing method based on the distributed digital identity according to any one of claims 8-10 from the memory, and execute: distributing a distributed identifier to each user according to a digital certificate of the data center corresponding to the user, uploading the distributed identifier to the blockchain, and establishing a distributed digital identity for each user; According to the distributed digital identity, an account is registered for each user, the account including a storage account and a request account; 12. A storage medium, characterized by Metadata of user data in the data center corresponding to the account is obtained, and the metadata is uploaded to the blockchain; The metadata is verified through the blockchain, and after verification, the metadata is published to a data directory; The request account sends request information according to the data directory, and forwards the request information to the storage account; The data center corresponding to the storage account generates request result information and a data sharing mode according to the request information; The request result information and the data sharing mode are verified through the blockchain, and after verification, they are forwarded to the request account; The request account establishes a connection with the data center corresponding to the storage account according to the request result information, the data center corresponding to the storage account performs blockchain verification on the identity information of the request account, and after verification, the request account obtains user data of the data center corresponding to the storage account according to the data sharing mode. It includes: a memory; a processor configured to retrieve a computer executable program of the data publishing method based on the distributed digital identity according to any one of claims 8-10 from the memory, and execute: distributing a distributed identifier to each user according to a digital certificate of the data center corresponding to the user, uploading the distributed identifier to the blockchain, and establishing a distributed digital identity for each user;

Citation Information

Patent Citations

  • Data management method, device and equipment

    CN112967054A

  • Block chain-based shared data processing method, system, device and product

    CN118245458A