Data exchange method and device for trusted data space and medium
By introducing verifiable registry and distributed digital stewards of trusted data spaces in traditional technology, problems such as identity authentication and data sovereignty management in data exchange in traditional technology are solved, and data exchange is achieved across large-scale and across systems.
Patent Information
- Application Number
- CN202411980141.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2044-12-31
AI Technical Summary
In traditional technology, the centralized system architecture lacks effective support for identity authentication, data sovereignty management, and data circulation management involved in large-scale and cross-system interconnection, resulting in difficulty in data sharing and hindering the circulation and value of data.
By establishing a verifiable registry and distributed digital steward of trusted data space, the identity authentication of all parties and the registration of the subject ID of the data space are realized, the end-to-end encrypted connection pipeline is established, and encrypted data exchange is completed.
It realizes safe, trustworthy and controllable exchange of data across a large range and across systems, guarantees data privacy and sovereignty, and improves the efficiency and security of data circulation.
Smart Images

Figure CN119966632A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of trusted data space construction, and more specifically, to a data exchange method, device and medium for a trusted data space. Background Art
[0002] With the development of the digital age, digital applications have gradually penetrated into all aspects of public life and business operations. Concepts such as digital economy, data elements, and data circulation in data element markets have been proposed one after another. However, traditional technologies and centralized system architectures lack effective support for identity authentication, data sovereignty management, and data circulation management involved in large-scale, cross-system interconnection of data. This has led to problems such as the inability to share or unwillingness to share, which has hindered the circulation of data and limited the value of data. Summary of the invention
[0003] In view of the deficiencies in the prior art, the present invention provides a data exchange method, device and medium in a trusted data space.
[0004] According to one aspect of the present invention, a data exchange method in a trusted data space is provided, comprising:
[0005] Establish a verifiable registry and distributed digital steward for the trusted data space, where the verifiable registry uses blockchain networks or files according to the application scenario;
[0006] Register data space subject IDs for various entities in the trusted data space through distributed digital stewards, and issue identity credentials to various entities based on the data space subject IDs through a third-party authentication system, where the various entities include data providers, data consumers, and data developers;
[0007] Based on the identity credentials and private keys of each party in the distributed digital butler, mutual recognition of identities between the parties is achieved and an association relationship is established;
[0008] Write the metadata required by the data provider or data developer to publish data into the verifiable registry, and establish the data space data ID of the metadata based on the data space subject ID and metadata of the data publisher;
[0009] By establishing connections between distributed digital butlers, an end-to-end encrypted connection pipeline is formed, and encrypted data exchange is completed based on the connection channel.
[0010] Optionally, the verifiable registry includes an identity template, a data template, a distributed identification template, and a verifiable credential template, the distributed digital butler includes identity management, private key management, data policy management, and communication protocols, and the distributed digital butler includes multiple forms such as mobile terminals, service terminals, cloud terminals, and edge terminals, wherein
[0011] Various entities in the trusted digital space participate in the trusted data space through their distributed digital stewards. The distributed digital stewards provide the following functions for their entities to participate in the trusted digital space, including identity authentication management, access authorization and control, data usage policy agreement, data security exchange, data history management, data discovery, data policy execution, data transactions, communication protocol execution, and data rule execution.
[0012] Optionally, the distributed digital steward registers the data space subject ID for each party in the trusted data space, including:
[0013] Writing the distributed identity document into the verifiable registry based on the distributed identity template;
[0014] Based on the distributed identification template, the data space subject ID is registered for all parties in the trusted data space through the distributed digital butler.
[0015] Optionally, a third-party authentication system is used to issue identity credentials to each party based on the data space subject ID, including:
[0016] Based on the verifiable credential template, identity credentials are issued to each party through a third-party authentication system according to the data space subject ID of each party.
[0017] Optionally, establishing an end-to-end encrypted connection channel between the linking party and the linked party according to the search results, including:
[0018] Determine the linking party and the linked party that need to establish a connection channel based on the search results;
[0019] Establish an end-to-end encrypted connection channel between the linking party and the linked party.
[0020] Optionally, establishing an end-to-end encrypted connection channel between the linking party and the linked party includes:
[0021] The distributed digital steward of the linked party publishes an invitation link containing its data space subject ID, where the invitation link is used by the distributed digital steward of the linking party to verify whether the data space subject ID of the linked party is valid;
[0022] If the data space subject ID of the linked party is valid, the distributed digital butler of the linked party sends a negotiation request with its own data space subject ID and private key signature to the linked party. The linked party finds the distributed identification document in the verifiable registry through the linking party subject ID and verifies the private key signature to verify whether the data space subject ID of the linked party is valid;
[0023] When the data space subject ID of the linking party is valid, the key negotiation between the linking party and the linked party is completed to establish an end-to-end channel;
[0024] Based on the end-to-end channel, the linking party and the linked party request each other's identity credentials, present and verify the identity credentials through the distributed digital butler, and establish an end-to-end encrypted connection channel between the linking party and the linked party if the verification is successful.
[0025] Optionally, a connection is established between distributed digital butlers to form an end-to-end encrypted connection pipeline, and encrypted data exchange is completed based on the connection channel, including:
[0026] When the data consumer or data developer retrieves available data through metadata or data space data ID, an end-to-end encrypted connection channel is established between the linking party and the linked party based on the search results, and data exchange between the linking party and the linked party is completed based on the connection channel.
[0027] According to another aspect of the present invention, there is provided a data exchange device of a trusted data space, comprising:
[0028] Establish a module for establishing a verifiable registry and distributed digital steward of a trusted data space, where the verifiable registry uses a blockchain network or file according to the application scenario;
[0029] The registration module is used to register the data space subject ID for various subjects of the trusted data space through the distributed digital steward, and issue identity credentials to various subjects based on the data space subject ID through the third-party authentication system, where the various subjects include data providers, data consumers and data developers;
[0030] The mutual recognition module is used to realize the mutual recognition of identities among the parties and establish association relationships based on the identity credentials and private keys of the parties in the distributed digital butler;
[0031] Establish a module for writing metadata required by a data provider or data developer to publish data into a verifiable registry, and establish a data space data ID of the metadata based on the data space subject ID and metadata of the data publisher;
[0032] The exchange module is used to establish connections between distributed digital butlers to form an end-to-end encrypted connection pipeline, and complete encrypted data exchange based on the connection channel.
[0033] Optionally, the verifiable registry includes an identity template, a data template, a distributed identification template, and a verifiable credential template, the distributed digital butler includes identity management, private key management, data policy management, and communication protocols, and the distributed digital butler includes multiple forms such as mobile terminals, service terminals, cloud terminals, and edge terminals, wherein
[0034] Various entities in the trusted digital space participate in the trusted data space through their distributed digital stewards. The distributed digital stewards provide the following functions for their entities to participate in the trusted digital space, including identity authentication management, access authorization and control, data usage policy agreement, data security exchange, data history management, data discovery, data policy execution, data transactions, communication protocol execution, and data rule execution.
[0035] Optionally, the registration module registers the data space subject ID for each subject of the trusted data space through the distributed digital steward, including:
[0036] A writing submodule, used to write a distributed identity document into a verifiable registry based on a distributed identity template;
[0037] The registration submodule is used to register the data space subject ID for each party in the trusted data space through the distributed digital butler based on the distributed identification template.
[0038] Optionally, the registration module issues identity credentials to each party based on the data space subject ID through a third-party authentication system, including:
[0039] The issuing submodule is used to issue identity credentials to various parties based on the verifiable credential template and through a third-party authentication system according to the data space subject ID of each party.
[0040] Optionally, the exchange module establishes an end-to-end encrypted connection channel between the linking party and the linked party according to the search result, including:
[0041] A determination submodule, used to determine the linking party and the linked party for which a connection channel needs to be established according to the search results;
[0042] A submodule is established to establish an end-to-end encrypted connection channel between the linking party and the linked party.
[0043] Optionally, create submodules, including:
[0044] A publishing unit, used to publish an invitation link containing the data space subject ID of the linked party through the distributed digital steward of the linked party, wherein the invitation link is used by the distributed digital steward of the linking party to verify whether the data space subject ID of the linked party is valid;
[0045] The sending unit is used to send a negotiation request with its own data space subject ID and private key signature to the linked party through the distributed digital butler of the linking party when the data space subject ID of the linked party is valid. The linked party finds the distributed identification document in the verifiable registry through the linking party subject ID and verifies the private key signature to verify whether the data space subject ID of the linking party is valid;
[0046] The first establishing unit is used to complete the key negotiation between the linking party and the linked party to establish an end-to-end channel when the data space subject ID of the linking party is valid;
[0047] The second establishing unit is used for the linking party and the linked party to request each other's identity credentials based on an end-to-end channel, and to present and verify the identity credentials through the distributed digital butler, and to establish an end-to-end encrypted connection channel between the linking party and the linked party if the verification is successful.
[0048] Optionally, the switching module includes:
[0049] The exchange submodule is used to establish an end-to-end encrypted connection channel between the linking party and the linked party according to the search results when the data consumer or data developer retrieves available data through metadata or data space data ID, and complete the data exchange between the linking party and the linked party based on the connection channel.
[0050] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the storage medium stores a computer program, and the computer program is used to execute the method described in any one of the above aspects of the present invention.
[0051] According to another aspect of the present invention, an electronic device is provided, comprising: a processor; a memory for storing instructions executable by the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in any one of the above aspects of the present invention.
[0052] Therefore, the blockchain-based trusted data space system provided by the present invention improves the security of templates through digital fingerprints and access control mechanisms; the credibility of the blockchain enables multiple parties to carry out distributed identification verification capabilities based on a verifiable registry; the traceability of the blockchain records the historical changes of template iterations, making contract records credible and auditable; smart contracts realize the automated execution of contract business logic, quickly generate templates that meet business needs, and improve the efficiency of the contract signing process. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:
[0054] Figure 1 is a flow chart of a data exchange method of a trusted data space provided by an exemplary embodiment of the present invention;
[0055] Figure 2 is a schematic diagram of the structure of a trusted data space provided by an exemplary embodiment of the present invention;
[0056] Figure 3is a schematic diagram of the structure of a data exchange device of a trusted data space provided by an exemplary embodiment of the present invention;
[0057] Figure 4 This is a structure of an electronic device provided by an exemplary embodiment of the present invention. DETAILED DESCRIPTION
[0058] Below, the exemplary embodiments according to the present invention will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments of the present invention, and it should be understood that the present invention is not limited to the exemplary embodiments described here.
[0059] It should be noted that the relative arrangement of components and steps, the numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present invention unless specifically stated otherwise.
[0060] Those skilled in the art can understand that the terms "first" and "second" in the embodiments of the present invention are only used to distinguish different steps, devices or modules, etc., and neither represent any specific technical meaning nor indicate the necessary logical order between them.
[0061] It should also be understood that, in the embodiments of the present invention, “plurality” may refer to two or more than two, and “at least one” may refer to one, two or more than two.
[0062] It should also be understood that any component, data or structure mentioned in the embodiments of the present invention can generally be understood as one or more, unless explicitly limited or otherwise indicated in the context.
[0063] In addition, the term "and / or" in the present invention is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in the present invention generally indicates that the associated objects before and after are in an "or" relationship.
[0064] It should also be understood that the description of the various embodiments of the present invention focuses on the differences between the various embodiments, and the same or similar aspects thereof can be referenced to each other, and for the sake of brevity, they will not be described one by one.
[0065] At the same time, it should be understood that for the convenience of description, the sizes of the various parts shown in the drawings are not drawn according to the actual proportional relationship.
[0066] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the invention, its application, or uses.
[0067] Technologies, methods, and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and equipment should be considered part of the specification.
[0068] It should be noted that like reference numerals and letters refer to similar items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0069] Embodiments of the present invention can be applied to electronic devices such as terminal devices, computer systems, servers, etc., which can operate with many other general or special computing system environments or configurations. Examples of well-known terminal devices, computing systems, environments and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, servers, etc. include, but are not limited to: personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network personal computers, small computer systems, large computer systems, and distributed cloud computing technology environments including any of the above systems, etc.
[0070] Electronic devices such as terminal devices, computer systems, servers, etc. can be described in the general context of computer system executable instructions (such as program modules) executed by computer systems. Generally, program modules can include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks or implement specific abstract data types. Computer systems / servers can be implemented in a distributed cloud computing environment, where tasks are performed by remote processing devices linked through a communication network. In a distributed cloud computing environment, program modules can be located on local or remote computing system storage media including storage devices.
[0071] Exemplary Methods
[0072] Figure 1 FIG. 1 is a flow chart of a data exchange method of a trusted data space provided by an exemplary embodiment of the present invention. This embodiment can be applied to electronic devices, such as Figure 1 As shown, the data exchange method 100 of the trusted data space includes the following steps:
[0073] Step 101, establishing a verifiable registry and a distributed digital steward of a trusted data space, wherein the verifiable registry is a blockchain network;
[0074] Step 102: registering data space subject IDs for various parties in the trusted data space through the distributed digital steward, and issuing identity credentials for various parties based on the data space subject IDs through a third-party authentication system, wherein the various parties include: data providers, data consumers, and data developers;
[0075] Step 103, mutual recognition of identities among the parties is achieved based on the identity credentials and private keys of the parties in the distributed digital butler, and an association relationship is established;
[0076] Step 104, write the metadata required by the data provider or data developer to publish the data into the verifiable registry, and establish the data space data ID of the metadata based on the data space subject ID and metadata of the data publisher;
[0077] Step 105, establish connections between distributed digital butlers to form an end-to-end encrypted connection pipeline, and complete encrypted data exchange based on the connection channel.
[0078] Specifically, the purpose of the present invention is to provide a method for constructing a trusted data space infrastructure to solve the problems of data exchange relying on a third party, failing to guarantee user data sovereignty, and data privacy under the existing centralized technology system. By constructing a distributed digital butler through decentralized technology, it has the capabilities of identity mutual recognition and authentication, identity-based secure connection channels, and global data access control strategies. It has the characteristics of not relying on a third party, protecting privacy, and improving data exchange security. To achieve the above purpose, the overall architecture of the trusted data space infrastructure is as follows: Figure 2 As shown, the steps of the data exchange method of the trusted data space implemented based on the trusted data space are as follows:
[0079] 1. Build a verifiable registry blockchain network for trusted data space operators and third-party certification agencies, design identity authentication templates and write them into blockchain ledgers for use by identity issuers, holders, and verifiers. The verifiable registry uses blockchain networks, files, or other methods depending on the application scenario.
[0080] 2. Deploy distributed digital stewards (or distributed data stewards) for people, organizations, objects and virtual resources participating in the data space, such as data provider entities, consumer entities and developer entities. Each party completes the registration of the data space subject ID (including decentralized identification DID) through the digital steward, and obtains identity credentials through a third-party organization in the network. The distributed digital stewards are held by various entities in the trusted digital space, including mobile terminals, service terminals, cloud terminals, edge terminals and other forms. Each distributed digital steward accesses a verifiable registry through the Internet; various entities in the trusted digital space participate in the trusted data space through their distributed digital stewards, and the distributed digital stewards provide the following functions for their entities to participate in the trusted digital space, including but not limited to identity authentication management, access authorization and control, data usage policy agreement, data security exchange, data history management, data discovery, data policy execution, data transaction, communication protocol execution, and data rule execution.
[0081] 3. The data space subject ID is realized through DID technology, and its DID text is written into the blockchain to provide ID verification capabilities for all parties in the data space.
[0082] 4. Identity credentials are implemented through VC technology. A third-party certification agency issues an identity VC (including verifiable credentials VC) bound to the data space subject ID to the applicant to complete the authentication of the identity in the data space.
[0083] 5. The distributed digital butler is held and controlled by each participant in the data space. The private key and identity VC associated with the data space subject ID are stored in the digital butler. The digital butler is used to establish the relationship between the subject in the real society and the digital subject in the data space.
[0084] 6. Based on the above steps, each data space subject completes mutual recognition among the subjects through its distributed digital steward.
[0085] 7. Distributed digital butler uses DID technology to realize an end-to-end encrypted connection channel based on the mutual recognition of data space subject IDs. The steps include:
[0086] 1). The linked party’s distributed digital steward publishes an invitation link containing its subject ID, and the linking party’s digital steward verifies the validity of its ID through the invitation link;
[0087] 2). The digital butler of the linking party sends a link with its own subject ID and a key negotiation request. The linked party receives the request, verifies the validity of the ID, completes the key negotiation and establishes an end-to-end channel;
[0088] 3). Both parties request each other's identity in the link, and both parties present their identity VC through the digital butler. After both parties verify the identity VC, the end-to-end link is established.
[0089] 8. The data consumer or developer in the data space publishes the metadata required for data application in the space, and the metadata is written into the blockchain network for data providers in the data space to review.
[0090] 9. The data providers in the data space publish the data they need to share as data space data IDs based on their own data and metadata in the data space, complete the data targets within the data space, and provide management methods for subsequent data discovery and data exchange.
[0091] 10. Data consumers and developers retrieve available data through metadata and data ID, and submit data usage requests to data providers. The data provider issues data application credentials to them. Consumers or developers link to the provider's digital steward to present the credentials to obtain data.
[0092] 11. The above steps complete the data exchange between various entities in the data space based on the digital butler.
[0093] The key technical points of the present invention are:
[0094] 1. Build a decentralized multi-party digital ID verification system based on distributed digital identity technology to realize cryptography-based ID management in a decentralized system scenario.
[0095] 2. Build verifiable credentials based on distributed identity to implement an identity system.
[0096] 3. Build an end-to-end secure channel based on distributed digital identity technology.
[0097] 4. Build data management and access control capabilities based on distributed identity and verifiable credentials.
[0098] Therefore, the blockchain-based trusted data space system provided by the present invention improves the security of templates through digital fingerprints and access control mechanisms; the traceability of the blockchain records the historical changes of template iterations, making contract records credible and auditable; smart contracts realize the automated execution of contract business logic, quickly generate templates that meet business needs, and improve the efficiency of the contract signing process.
[0099] Exemplary Devices
[0100] Figure 3 FIG. 1 is a schematic diagram of a data exchange device in a trusted data space provided by an exemplary embodiment of the present invention. Figure 3 As shown, the device 300 includes:
[0101] Establishing module 310, for establishing a verifiable registry and a distributed digital steward of a trusted data space, wherein the verifiable registry adopts a blockchain network or a file according to an application scenario;
[0102] A registration module 320 is used to register data space subject IDs for various subjects of the trusted data space through a distributed digital butler, and issue identity credentials to various subjects based on the data space subject ID through a third-party authentication system, where the various subjects include data providers, data consumers, and data developers;
[0103] The mutual recognition module 330 is used to realize the mutual recognition of identities among the parties and establish an association relationship based on the identity credentials and private keys of the parties in the distributed digital butler;
[0104] Establishing module 340, used to write metadata required by a data provider or a data developer to publish data into a verifiable registry, and establish a data space data ID of the metadata based on the data space subject ID and metadata of the data publisher;
[0105] The exchange module 350 is used to establish connections between distributed digital butlers to form an end-to-end encrypted connection pipeline, and complete encrypted data exchange based on the connection channel.
[0106] Optionally, the verifiable registry includes an identity template, a data template, a distributed identification template, and a verifiable credential template, the distributed digital butler includes identity management, private key management, data policy management, and communication protocols, and the distributed digital butler includes multiple forms such as mobile terminals, service terminals, cloud terminals, and edge terminals, wherein
[0107] Various entities in the trusted digital space participate in the trusted data space through their distributed digital stewards. The distributed digital stewards provide the following functions for their entities to participate in the trusted digital space, including identity authentication management, access authorization and control, data usage policy agreement, data security exchange, data history management, data discovery, data policy execution, data transactions, communication protocol execution, and data rule execution.
[0108] Optionally, the registration module 320 registers data space subject IDs for various subjects of the trusted data space through a distributed digital steward, including:
[0109] A writing submodule, used to write a distributed identification document into the verifiable registry based on a distributed identification template;
[0110] The registration submodule is used to register data space subject IDs for various entities in the trusted data space through the distributed digital steward based on the distributed identification template.
[0111] Optionally, the registration module 320 issues identity credentials to each party based on the data space subject ID through a third-party authentication system, including:
[0112] The issuing submodule is used to issue identity credentials to various parties based on the verifiable credential template and through a third-party authentication system according to the data space subject ID of each party.
[0113] Optionally, the exchange module 350 establishes an end-to-end encrypted connection channel between the linking party and the linked party according to the search result, including:
[0114] A determination submodule, used to determine the linking party and the linked party for which a connection channel needs to be established according to the search results;
[0115] A submodule is established to establish an end-to-end encrypted connection channel between the linking party and the linked party.
[0116] Optionally, create submodules, including:
[0117] A publishing unit, used to publish an invitation link containing the data space subject ID of the linked party through the distributed digital steward of the linked party, wherein the invitation link is used by the distributed digital steward of the linking party to verify whether the data space subject ID of the linked party is valid;
[0118] The sending unit is used to send a negotiation request with its own data space subject ID and private key signature to the linked party through the distributed digital butler of the linking party when the data space subject ID of the linked party is valid. The linked party finds the distributed identification document in the verifiable registry through the linking party subject ID and verifies the private key signature to verify whether the data space subject ID of the linking party is valid;
[0119] The first establishing unit is used to complete the key negotiation between the linking party and the linked party to establish an end-to-end channel when the data space subject ID of the linking party is valid;
[0120] The second establishing unit is used for the linking party and the linked party to request each other's identity credentials based on an end-to-end channel, and to present and verify the identity credentials through the distributed digital butler, and to establish an end-to-end encrypted connection channel between the linking party and the linked party if the verification is successful.
[0121] Optionally, the switching module 350 includes:
[0122] The exchange submodule is used to establish an end-to-end encrypted connection channel between the linking party and the linked party according to the search results when the data consumer or data developer retrieves available data through metadata or data space data ID, and complete the data exchange between the linking party and the linked party based on the connection channel.
[0123] Exemplary Electronic Devices
[0124] Figure 4 This is a structure of an electronic device provided by an exemplary embodiment of the present invention. Figure 4 As shown, the electronic device 40 includes one or more processors 41 and a memory 42 .
[0125] The processor 41 may be a central processing unit (CPU) or other forms of processing units having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.
[0126] The memory 42 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory (cache), etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 41 may run the program instructions to implement the methods of the software programs of the various embodiments of the present invention described above and / or other desired functions. In one example, the electronic device may also include: an input device 43 and an output device 44, which are interconnected via a bus system and / or other forms of connection mechanisms (not shown).
[0127] In addition, the input device 43 may also include, for example, a keyboard, a mouse, etc.
[0128] The output device 44 can output various information to the outside, and can include, for example, a display, a speaker, a printer, a communication network and a remote output device connected thereto.
[0129] Of course, to simplify, Figure 4 Only some of the components related to the present invention in the electronic device are shown, and components such as a bus, an input / output interface, etc. are omitted. In addition, the electronic device may further include any other appropriate components according to specific application conditions.
[0130] Exemplary computer program products and computer-readable storage media
[0131] In addition to the above-mentioned methods and devices, an embodiment of the present invention may also be a computer program product, which includes computer program instructions, which, when executed by a processor, enable the processor to execute the steps of the method according to various embodiments of the present invention described in the above-mentioned "Exemplary Method" section of this specification.
[0132] The computer program product may be written in any combination of one or more programming languages to write program code for performing the operations of the embodiments of the present invention, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0133] In addition, an embodiment of the present invention may also be a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, enable the processor to execute the steps of the method according to various embodiments of the present invention described in the above “Exemplary Method” section of this specification.
[0134] The computer readable storage medium can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can include, for example, but is not limited to, a system, system or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0135] The basic principle of the present invention is described above in conjunction with specific embodiments. However, it should be pointed out that the advantages, strengths, effects, etc. mentioned in the present invention are only examples and not limitations, and it cannot be considered that these advantages, strengths, effects, etc. must be possessed by each embodiment of the present invention. In addition, the specific details disclosed above are only for the purpose of illustration and facilitation of understanding, rather than limitation, and the above details do not limit the present invention to being implemented by adopting the above specific details.
[0136] Each embodiment in this specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system embodiment, since it basically corresponds to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0137] The block diagrams of the devices, systems, equipment, and systems involved in the present invention are only illustrative examples and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagram. As will be appreciated by those skilled in the art, these devices, systems, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open words, referring to "including but not limited to", and can be used interchangeably with them. The words "or" and "and" used here refer to the words "and / or" and can be used interchangeably with them, unless the context clearly indicates otherwise. The word "such as" used here refers to the phrase "such as but not limited to", and can be used interchangeably with it.
[0138] The method and system of the present invention may be implemented in many ways. For example, the method and system of the present invention may be implemented by software, hardware, firmware or any combination of software, hardware, firmware. The above order of steps for the method is only for illustration, and the steps of the method of the present invention are not limited to the order specifically described above, unless otherwise specifically stated. In addition, in some embodiments, the present invention may also be implemented as a program recorded in a recording medium, which includes machine-readable instructions for implementing the method according to the present invention. Thus, the present invention also covers a recording medium storing a program for executing the method according to the present invention.
[0139] It should also be noted that in the system, device and method of the present invention, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. The above description of the disclosed aspects is provided to enable any technician in the field to make or use the present invention. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined here can be applied to other aspects without departing from the scope of the present invention. Therefore, the present invention is not intended to be limited to the aspects shown here, but in accordance with the widest range consistent with the principles and novel features disclosed here.
[0140] The above description has been given for the purpose of illustration and description. In addition, this description is not intended to limit the embodiments of the present invention to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions and sub-combinations thereof.
Claims
1. A data exchange method in a trusted data space, characterized in that: include: Establish a verifiable registry and distributed digital steward of a trusted data space, where the verifiable registry uses a blockchain network or files depending on the application scenario; Registering data space subject IDs for various subjects in the trusted data space through the distributed digital steward, and issuing identity credentials for various subjects based on the data space subject ID through a third-party authentication system, where the various subjects include data providers, data consumers, and data developers; According to the identity credentials and private keys of the various parties in the distributed digital butler, mutual recognition of identities between the various parties is achieved, and an association relationship is established; Writing the metadata required by the data provider or the data developer to publish data into the verifiable registry, and establishing the data space data ID of the metadata based on the data space subject ID of the data publisher and the metadata; By establishing connections between the distributed digital butlers, an end-to-end encrypted connection pipeline is formed, and encrypted data exchange is completed based on the connection channel.
2. The method according to claim 1, characterized in that: The verifiable registry includes an identity template, a data template, a distributed identification template and a verifiable credential template. The distributed digital butler includes identity management, private key management, data policy management and communication protocol. The distributed digital butler includes multiple forms such as mobile terminal, server terminal, cloud terminal and edge terminal. Various entities in the trusted digital space participate in the trusted data space through their distributed digital stewards. The distributed digital stewards provide the following functions for their entities to participate in the trusted digital space, including identity authentication management, access authorization and control, data usage policy agreement, data security exchange, data history management, data discovery, data policy execution, data transactions, communication protocol execution, and data rule execution.
3. The method according to claim 2, characterized in that Registering data space subject IDs for various subjects of the trusted data space through the distributed digital steward includes: Writing the distributed identification document into the verifiable registry based on the distributed identification template; Based on the distributed identification template, the data space subject ID is registered for each party of the trusted data space through the distributed digital butler.
4. The method according to claim 2, characterized in that: The third-party authentication system issues identity credentials to each party based on the data space subject ID, including: Based on the verifiable credential template, the identity credential is issued to each party subject according to the data space subject ID of each party subject through the third-party authentication system.
5. The method according to claim 1, characterized in that Establishing an end-to-end encrypted connection channel between the linking party and the linked party based on the search results, including: Determine the linking party and the linked party that need to establish a connection channel according to the search results; An end-to-end encrypted connection channel is established between the linking party and the linked party.
6. The method according to claim 5, characterized in that Establishing an end-to-end encrypted connection channel between the linking party and the linked party, including: The distributed digital steward of the linked party issues an invitation link containing its data space subject ID, wherein the invitation link is used by the distributed digital steward of the linking party to verify whether the data space subject ID of the linked party is valid; If the data space subject ID of the linked party is valid, the distributed digital butler of the linked party sends a negotiation request with its own data space subject ID and private key signature to the linked party. The linked party finds the distributed identification document in the verifiable registry through the linking party subject ID and verifies the private key signature to verify whether the data space subject ID of the linked party is valid; When the data space subject ID of the linking party is valid, completing key negotiation between the linking party and the linked party to establish an end-to-end channel; Based on the end-to-end channel, the linking party and the linked party request each other's identity credentials, and present and verify the identity credentials through the distributed digital butler, and establish an end-to-end encrypted connection channel between the linking party and the linked party if the verification is successful.
7. The method according to claim 1, characterized in that By establishing a connection between the distributed digital butlers, an end-to-end encrypted connection pipeline is formed, and encrypted data exchange is completed based on the connection channel, including: When the data consumer or the data developer retrieves available data through metadata or data space data ID, an end-to-end encrypted connection channel is established between the linking party and the linked party based on the search results, and based on the connection channel, data exchange between the linking party and the linked party is completed.
8. A data exchange device for a trusted data space, characterized in that: include: Establish a module for establishing a verifiable registry and a distributed digital steward of a trusted data space, wherein the verifiable registry uses a blockchain network or a file according to the application scenario; A registration module, used to register data space subject IDs for various subjects of the trusted data space through the distributed digital butler, and issue identity credentials to various subjects based on the data space subject ID through a third-party authentication system, where the various subjects include data providers, data consumers, and data developers; A mutual recognition module, used to realize mutual recognition of identities among various entities and establish association relationships according to the identity credentials and private keys of various entities in the distributed digital butler; An establishment module, used for writing metadata required by the data provider or the data developer to publish data into the verifiable registry, and establishing a data space data ID of the metadata based on the data space subject ID of the data publisher and the metadata; The exchange module is used to establish an end-to-end encrypted connection channel between the linking party and the linked party according to the search results when the data consumer or the data developer retrieves available data through metadata or data space data ID, and complete the data exchange between the linking party and the linked party based on the connection channel.
9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and the computer program is used to execute the method according to any one of claims 1 to 7.
10. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is used to read the executable instructions from the memory and execute the instructions to implement the method described in any one of claims 1 to 7.
Citation Information
Patent Citations
Mobile platform distributed digital identity authentication method and device and medium
CN116886357A
System and method for a decentralized portable information container supporting privacy protected digital information credentialing, remote administration, local validation, access control and remote instruction signaling utilizing blockchain distributed ledger and container wallet technologies
US20210374693A1
Decentralized Identity on Blockchain for a Multi-sided Network
US20230259918A1
Cited By
Multi-party data cooperative exchange method, system, device, medium and product
CN120768572A
Method and system for processing data based on multi-party cooperative network
CN121619148A
Data exchange method of a trusted data space
CN122621404A