Data usage method and system
By creating distributed digital identities and using data call-outs in the blockchain network, combined with smart contracts and privacy computing technology, the problem of illegal abuse in data circulation and monetization is solved, and safe and accurate data sharing and protection are achieved.
Patent Information
- Application Number
- CN202411987389.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2044-12-31
AI Technical Summary
Data circulation and monetization can easily get out of control, leading to illegal abuse and threatening the security of personal information.
Create a distributed digital identity in the data space of the blockchain network, match the target distributed digital identity through data call commands, and use smart contracts to respond to authorization or not, to achieve accurate data authorization, and combine privacy computing technology to ensure data security.
It realizes secure data sharing without a trusted third party, protects user privacy, prevents data abuse and leakage, and ensures that data rights and interests are not violated.
Smart Images

Figure CN119903553B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a data use method and system. Background Art
[0002] As a new production factor, the circulation and transaction of data are key drivers of the development of the digital economy. However, the security of personal information is receiving increasing attention.
[0003] In related technologies, the circulation and monetization of data make it easier for data to get out of control and lead to illegal abuse. Summary of the Invention
[0004] The main purpose of the present invention is to provide a data utilization method and system to solve the deficiencies in the related art.
[0005] In order to achieve the above-mentioned purpose, according to the first aspect of the present invention, a data usage method is provided, which creates a distributed digital identity in the data space after obtaining an authentication request; obtains a data usage request sent by a user, and generates a data call for the user based on the usage request; matches multiple target distributed digital identities that are consistent with the data call for orders from the created distributed digital identities, and allows users of each target distributed digital identity to respond to the data call for orders to authorize or not.
[0006] Optionally, when users of multiple target distributed digital identities authorize the data call order, the user of each target distributed digital identity provides data of different dimensions to the data call order.
[0007] Optionally, matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities includes: matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities through a smart contract.
[0008] Optionally, matching multiple target distributed digital identities that comply with the data call order from the created distributed digital identities through a smart contract includes: determining the data dimension indicated by the data call order; and determining multiple target distributed digital identities that can provide data of the data dimension through a smart contract.
[0009] Optionally, after the users of each target distributed digital identity provide data of different dimensions to the data call order, the method includes: generating a data product required by the user based on the data call order and the data of different dimensions.
[0010] Optionally, the processing result of the data product is fed back to the user pointed to by the corresponding data call order.
[0011] According to the second aspect of the present invention, a data usage system is provided, comprising: a distributed digital identity creation unit, for creating a distributed digital identity in a data space after obtaining an authentication request; a data call order generation unit, for obtaining a data usage request sent by a user, and generating a data call order corresponding to the user based on the usage request; a processing unit, for matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities, and for users of each target distributed digital identity to respond to the data call order to determine whether to authorize or not.
[0012] Optionally, after the user of the at least one target distributed digital identity authorizes the data call order, users of different target distributed digital identities provide data of different dimensions to the data call order.
[0013] Optionally, matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities includes: matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities through a smart contract.
[0014] Optionally, matching multiple target distributed digital identities that comply with the data call order from the created distributed digital identities through a smart contract includes: determining the data dimension indicated by the data call order; and determining multiple target distributed digital identities that can provide data of the data dimension through a smart contract.
[0015] This embodiment provides a data usage method and apparatus, wherein the method includes, after receiving an authentication request, creating a distributed digital identity in a data space; obtaining a data usage request sent by a user, and generating a data call corresponding to the user based on the usage request; matching multiple target distributed digital identities that comply with the data call from the created distributed digital identity, and allowing users of each target distributed digital identity to respond to the data call to authorize or not. In the absence of a trusted third party, the secure multi-party computation (SMC) process of computing data from all parties makes "data available but invisible," thereby ensuring the data security of all parties and allowing their own data to be securely provided to users without leaving the domain. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0017] Figure 1is a flow chart of a data usage method according to an embodiment of the present invention; DETAILED DESCRIPTION
[0018] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0019] It should be noted that the terms "first," "second," and the like in the specification and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate for the embodiments of the present invention described herein. In addition, the terms "including," "having," and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or apparatuses.
[0020] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments of the present invention can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0021] According to an embodiment of the present invention, a data processing method is provided, which is applied to the data space of a blockchain network, such as Figure 1 As shown, it includes the following steps 101 to 103:
[0022] Step 101: After receiving the authentication request, a distributed digital identity is created in the data space.
[0023] In this step, the data space refers to the data space of the blockchain network. Within the blockchain network's data space, users with different authenticated identities have their own independent user data space. The blockchain network's data space is provided to users through a platform, where users can perform authentication operations, data requests, data authorization operations, and so on. Upon first accessing the data space, users can authenticate within the platform. Identity creation, storage, and verification are achieved through distributed ledger technologies such as blockchain, ultimately creating a unique distributed digital identity for each platform user. Distributed digital identities do not rely on a single central authority for identity authentication and management. Users have full control over their distributed digital identities and can decide when, where, and to whom their identity information and data are disclosed.
[0024] Step 102: Obtain a data usage request sent by a user, and generate a data call for the user based on the request.
[0025] In this step, data users can request data through the blockchain network data space platform. Upon receiving the request, the data space platform automatically creates a data call for the data user and obtains a corresponding digital identity, which can also be a distributed digital identity. This data call includes the user's virtual digital identity (DID). Users' requests vary, meaning their data requirements vary in dimension. Therefore, each data call is a model for a data product. Within the blockchain network data space, the user's data product is formed around this data call using the LLM and VLM models, as well as privacy-preserving computing and smart contract technologies. Different data calls can result in different data products.
[0026] Data call orders from different users can form different data products, and the formation of different data products requires data of different data dimensions. These data may be mastered by one or more users. Through data call orders, data with the dimensions required by the required users can be matched.
[0027] Step 103: Match multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities, and allow users of each target distributed digital identity to respond to the data call order to authorize or not.
[0028] In this step, after the data call is generated, the distributed digital identities of multiple data providers that can provide the required data are matched based on the data call, and the data call is broadcast to users who match the multiple distributed identities. These users can authorize a response to the data call, or not authorize a response.
[0029] As an optional implementation of this embodiment, when users of multiple target distributed digital identities authorize the data call order, the user of each target distributed digital identity provides data of different dimensions to the data call order.
[0030] In this optional implementation, after the target distributed digital identity is matched, the user of the target distributed digital identity provides data of different dimensions on demand to the data call, such as identity A providing data of the first dimension through the data space, identity B providing data of the first and second dimensions through the data space, and so on.
[0031] Through the above method, multiple data rights holder roles can be quickly and jointly authorized to a data call-out order, and the authorization is only for the data dimensions required for the call-out order. It is a precise authorization without excessive authorization of user data dimensions.
[0032] As an optional implementation method of this embodiment, matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities includes: matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities through a smart contract.
[0033] In this optional implementation, the data dimensions required for each data call are different, and the data dimensions that different providers can provide are also different. Therefore, users who meet the requirements of the data call are automatically matched through the on-chain smart contract.
[0034] This optional implementation method makes the data available but invisible during the secure multi-party computation process. The term "invisible" here refers to the computational process. For example, the data dimension of whether different users have data call-outs is executed through smart contracts, making the process invisible.
[0035] As an optional implementation method of this embodiment, matching multiple target distributed digital identities that comply with the data call order from the created distributed digital identities through a smart contract includes: determining the data dimension indicated by the data call order; and determining multiple target distributed digital identities that can provide the data dimension data through a smart contract.
[0036] In this optional implementation, as previously mentioned, different data callouts require different data dimensions. After determining the required data dimensions, a smart contract matches the required data dimensions with the user data space of the authenticated user. If the final match is greater than a set value, such as 80%, the user is considered a match and meets the requirements of the data callout. Their corresponding identity becomes the target distributed digital identity. A broadcast can then be sent to these users, requesting authorization for their user data space. Once the target distributed identity user authorizes the model, the data callout can use this user data for privacy-preserving computing and integrated data products.
[0037] As an optional implementation method of this embodiment, after the users of each target distributed digital identity provide data of different dimensions to the data call order, the method includes: generating the data product required by the user based on the data call order and the data of different dimensions.
[0038] In this optional implementation method, the data call is used through the LLM model and VLM model as well as privacy computing technology and smart contract technology to form a data product with the data dimensions that the user wants.
[0039] As an optional implementation method of this embodiment, the processing result of the data product is fed back to the user pointed to by the corresponding data call order.
[0040] In this optional implementation, the authorized user provides data to the data call order, and the calculation results can be obtained after using the data. The final calculation results can be fed back to the user data space corresponding to the identity based on the identity corresponding to different data call orders.
[0041] In this embodiment, the data call-out is carried out on the blockchain network, and all calculations and authorization behaviors are traceable; users control data and authorization through digital identities (DIDs), and the authorization behavior is guaranteed to be authentic and trustworthy. The entire behavior is an authorization process for data providers and data users; ultimately, data usage only obtains data models authorized by the data call-out, which effectively protects users' personal privacy data from abuse, leakage, and infringement of data rights.
[0042] After the model results are fed back to the data user, rebates can be given based on the target distributed identity of the data provider.
[0043] This embodiment achieves many-to-one authorization through a data call; the entire authorization process is a direct act of the data provider and the data user; the data authorization environment is secure and trustworthy; the data call and digital identity (DID) ensure simplicity in authorization; and precise authorization eliminates over-authorization of data. Leveraging blockchain and privacy computing technologies, the data call on the blockchain is primarily targeted at situations where there is no trusted third party. The secure multi-party computation process of all parties' data makes "data available but invisible," thereby ensuring data security for all parties and allowing data to be securely provided to applications without leaving the domain.
[0044] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0045] According to an embodiment of the present invention, a data usage device is also provided, including a distributed digital identity creation unit for creating a distributed digital identity in a data space after obtaining an authentication request; a data call order generation unit for obtaining a data usage request sent by a user, and generating a data call order corresponding to the user based on the usage request; and a processing unit for matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities, and for users of each target distributed digital identity to respond to the data call order to determine whether to authorize or not.
[0046] As an optional implementation of this embodiment, after the user of the at least one target distributed digital identity authorizes the data call order, users of different target distributed digital identities provide data of different dimensions to the data call order.
[0047] As an optional implementation method of this embodiment, matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities includes: matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities through a smart contract.
[0048] As an optional implementation method of this embodiment, matching multiple target distributed digital identities that comply with the data call order from the created distributed digital identities through a smart contract includes: determining the data dimension indicated by the data call order; and determining multiple target distributed digital identities that can provide the data dimension data through a smart contract.
[0049] As an optional implementation of this embodiment, after the users of each target distributed digital identity provide data of different dimensions to the data call order, the method includes: generating the data product required by the user based on the data call order and the data of different dimensions.
[0050] As an optional implementation method of this embodiment, the processing result of the data product is fed back to the user pointed to by the corresponding data call order.
[0051] Although the present invention has been described in detail above using general descriptions and specific embodiments, it will be apparent to those skilled in the art that modifications and improvements may be made thereto. Therefore, such modifications and improvements, without departing from the spirit of the present invention, are intended to be within the scope of protection claimed herein.
Claims
1. A data usage method, characterized in that: The method is applied to the data space of the blockchain network, including: After receiving the authentication request, a distributed digital identity is created in the data space. The data space refers to the data space of the blockchain network. In the data space of the blockchain network, users with different authenticated identities have their own independent user data space. The data space of the blockchain network can be provided to users in the form of a platform, and users can perform specified operations on the platform. When a user uses the data space for the first time, he or she will be authenticated in the data space platform. During authentication, the identity can be created, stored and verified through distributed ledger technology, ultimately creating a unique distributed digital identity for the platform user. The distributed digital identity does not rely on a single central agency for identity authentication and management, and the user has full control over his or her own distributed digital identity. Obtain the data usage request sent by the user, and generate a data call for the user based on the usage request, wherein the data call includes the user's virtual digital identity DID. The user's demand requests are different, that is, the data demand dimensions are not the same, so each data call is a model of a data product. In the blockchain network data space, around the data call, through the LLM model and VLM model as well as privacy computing technology and smart contract technology, the user's data product is formed. Different data calls can form different data products; data calls from different users can form different data products, and the formation of different data products requires data of different data dimensions. These data may be mastered by one or more users. Through the data call, data that can provide the required dimensions of the required users can be matched. Multiple target distributed digital identities that are consistent with the data call order are matched from the created distributed digital identities, and users of each target distributed digital identity are provided to respond to the data call order to determine whether to authorize or not; when users of multiple target distributed digital identities authorize the data call order, users of each target distributed digital identity provide data of different dimensions to the data call order.
2. The data usage method according to claim 1, characterized in that: Matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities includes: A plurality of target distributed digital identities that are consistent with the data call order are matched from the created distributed digital identities through a smart contract.
3. The data usage method according to claim 2, characterized in that: Matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities through the smart contract includes: Determining the data dimension indicated by the data call order; Multiple target distributed digital identities that can provide the data dimension data are determined through smart contracts.
4. The data using method according to claim 1, wherein: After the users of each target distributed digital identity provide data of different dimensions to the data call command, the following data are included: Based on the data call and the data of different dimensions, the data products required by the user are generated.
5. The data using method according to claim 4, characterized in that: Feedback the processing results of the data product to the user pointed to by the corresponding data call order.
6. A data utilization system, characterized in that: include: A distributed digital identity creation unit is used to create a distributed digital identity in the data space after receiving an authentication request. The data space refers to the data space of the blockchain network. In the data space of the blockchain network, users with different authenticated identities have their own independent user data space. The data space of the blockchain network can be provided to users in the form of a platform, and users can perform specified operations on the platform. When a user uses the data space for the first time, they authenticate themselves on the data space platform. During authentication, the identity can be created, stored, and verified through distributed ledger technology, ultimately creating a unique distributed digital identity for the platform user. The distributed digital identity does not rely on a single central agency for identity authentication and management, and users have full control over their distributed digital identity. A data call order generation unit is used to obtain a data usage request sent by a user, and generate a data call order corresponding to the user based on the usage request, wherein the data call order includes the user's virtual digital identity DID. The user's demand requests are different, that is, the data demand dimensions are different, so each data call order is a model of a data product. In the blockchain network data space, around the data call order, the user's data product is formed through the LLM model and VLM model as well as privacy computing technology and smart contract technology. Different data call orders can form different data products; data call orders from different users can form different data products, and forming different data products requires data of different data dimensions. Such data may be mastered by one or more users. The data call order can be used to match data that can provide the dimensions required by the required user; A processing unit is used to match multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities, and provide users of each target distributed digital identity with a response to whether to authorize the data call order; when the user of at least one target distributed digital identity authorizes the data call order, users of different target distributed digital identities provide data of different dimensions to the data call order.
7. The data utilization system according to claim 6, wherein: Matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities includes: A plurality of target distributed digital identities that are consistent with the data call order are matched from the created distributed digital identities through a smart contract.
8. The data utilization system according to claim 7, wherein: Matching multiple target distributed digital identities that are consistent with the data call order from the created distributed digital identities through the smart contract includes: Determining the data dimension indicated by the data call order; Multiple target distributed digital identities that can provide the data dimension data are determined through smart contracts.
Citation Information
Patent Citations
Unified authorization method and system based on block chain and distributed digital identity
CN115622765A
Multi-participant supervision data management method
CN119128951A