A data exchange method, device and medium of a trusted data space
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- AISINO CORPORATION
- Filing Date
- 2024-12-31
- Publication Date
- 2026-08-07
AI Technical Summary
[0002]随着数字时代的发展,数字化应用逐步渗透到大众生活、企业经营的各个方面,数字经济、数据要素、数据要素市场数据流通等理念相继提出,然而传统技术、中心化系统架构缺乏对数据在大范围、跨系统互联互通中涉及的身份认证、数据主权管理、数据流通管理方面的有效支撑
[0052]从而,本发明提供的基于区块链的可信数据空间系统,通过数字指纹和访问控制机制,提高模板的安全性;区块链的可信性为多方基于可验证注册表开展分布式标识验证能力;区块链的可追溯性记录了模板迭代的历史变动,使合同记录可信且可审计;智能合约实现合同业务逻辑自动化执行,快速生成符合业务需求的模板,提高了合同签署过程的效率。
Smart Images

Figure CN119966632B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of trusted data space construction technology, and more specifically, to a trusted data space data exchange method, apparatus and medium. Background Technology
[0002] With the development of the digital age, digital applications have gradually permeated all aspects of people's lives and business operations. Concepts such as the digital economy, data elements, data element markets, and data circulation have been proposed. However, traditional technologies and centralized system architectures lack effective support for identity authentication, data sovereignty management, and data circulation management involved in large-scale, cross-system interconnection and interoperability of data. This leads to problems of inability and unwillingness to share data, hindering data circulation and limiting the realization of data value. Summary of the Invention
[0003] To address the shortcomings of existing technologies, this invention provides a data exchange method, apparatus, and medium for a trusted data space.
[0004] According to one aspect of the present invention, a data exchange method for a trusted data space is provided, comprising:
[0005] Establish a verifiable registry and distributed digital steward for a trusted data space, where the verifiable registry can be a blockchain network or a file, depending on the application scenario;
[0006] The distributed digital steward registers data space entity IDs for various entities in the trusted data space, and issues identity credentials to each entity based on the data space entity IDs through a third-party authentication system. These entities include data providers, data consumers, and data developers.
[0007] Based on the identity credentials and private keys of each party in the distributed digital steward, mutual identity recognition is achieved between the parties, and a relationship is established.
[0008] Write the metadata required for data providers or data developers to publish data into a verifiable registry, and establish a data space data ID for the metadata based on the data space entity ID of the data publisher and the metadata.
[0009] By establishing connections between distributed digital stewards, an end-to-end encrypted connection pipeline is formed, and encrypted data exchange is completed based on the connection channel.
[0010] Optionally, the verifiable registry includes identity templates, data templates, distributed identifier templates, and verifiable credential templates; the distributed digital steward includes identity management, private key management, data policy management, and communication protocols; and the distributed digital steward includes various forms such as mobile, server, cloud, and edge.
[0011] Various entities in the trusted digital space participate in the trusted data space through its distributed digital steward. The distributed digital steward provides the following functions for its entities to participate in the trusted digital space, including identity authentication management, access authorization and control, data usage policy agreement, data security exchange, data history management, data discovery, data policy execution, data transaction, communication protocol execution, and data rule execution.
[0012] Optionally, a distributed digital steward registers data space entity IDs for various entities within the trusted data space, including:
[0013] Write distributed identifier documents into a verifiable registry based on a distributed identifier template;
[0014] Based on distributed identifier templates, a distributed digital steward registers data space entity IDs for all parties involved in the trusted data space.
[0015] Optionally, identity credentials may be issued to each party based on the data space entity ID through a third-party authentication system, including:
[0016] Based on verifiable credential templates, identity credentials are issued to each party through a third-party authentication system according to the data space entity ID of each party.
[0017] Optionally, an end-to-end encrypted connection channel is established between the linking party and the linked party based on the search results, including:
[0018] Based on the search results, determine the linking party and the linked party that need to establish a connection channel;
[0019] Establish an end-to-end encrypted connection channel between the linking party and the linked party.
[0020] Optionally, establishing an end-to-end encrypted connection channel between the linking party and the linked party includes:
[0021] The linked party's distributed digital steward publishes an invitation link containing its data space subject ID, whereby the linking party's distributed digital steward verifies whether the linked party's data space subject ID is valid.
[0022] If the linked party's data space subject ID is valid, the linked party's distributed digital steward sends a negotiation request to the linked party, which includes its own data space subject ID and private key signature. The linked party finds the distributed identification document in the verifiable registry using the linked party's subject ID and verifies the private key signature, thereby verifying whether the linked party's data space subject ID is valid.
[0023] If the data space subject ID of the linking party is valid, complete the key negotiation between the linking party and the linked party to establish an end-to-end channel;
[0024] Based on the end-to-end channel, the linking party and the linked party request each other's identity credentials, present and verify the identity credentials through the distributed digital steward, and establish an end-to-end encrypted connection channel between the linking party and the linked party if the verification is successful.
[0025] Optionally, an end-to-end encrypted connection channel is formed by establishing connections between distributed digital stewards, and encrypted data exchange is completed based on the connection channel, including:
[0026] When a data consumer or data developer retrieves available data through metadata or data space data ID, an end-to-end encrypted connection channel is established between the linking party and the linked party based on the retrieval results, and data exchange between the linking party and the linked party is completed based on the connection channel.
[0027] According to another aspect of the present invention, a data exchange apparatus for a trusted data space is provided, comprising:
[0028] A module is established to create a verifiable registry and a distributed digital steward for a trusted data space, wherein the verifiable registry adopts either a blockchain network or a file, depending on the application scenario;
[0029] The registration module is used to register data space entity IDs for various entities in the trusted data space through a distributed digital steward, and to issue identity credentials to each entity based on the data space entity IDs through a third-party authentication system. The entities include data providers, data consumers, and data developers.
[0030] The mutual recognition module is used to establish mutual recognition of identities and establish association relationships between the entities in the distributed digital steward based on their identity credentials and private keys.
[0031] The module is used to write the metadata required by the data provider or data developer to publish the data into a verifiable registry, and to create the data space data ID of the metadata based on the data space subject ID of the data publisher and the metadata.
[0032] The exchange module is used to establish connections between distributed digital stewards, forming an end-to-end encrypted connection pipeline, and to complete encrypted data exchange based on the connection channel.
[0033] Optionally, the verifiable registry includes identity templates, data templates, distributed identifier templates, and verifiable credential templates; the distributed digital steward includes identity management, private key management, data policy management, and communication protocols; and the distributed digital steward includes various forms such as mobile, server, cloud, and edge.
[0034] Various entities in the trusted digital space participate in the trusted data space through its distributed digital steward. The distributed digital steward provides the following functions for its entities to participate in the trusted digital space, including identity authentication management, access authorization and control, data usage policy agreement, data security exchange, data history management, data discovery, data policy execution, data transaction, communication protocol execution, and data rule execution.
[0035] Optionally, the registration module registers data space entity IDs for various entities within the trusted data space through a distributed digital steward, including:
[0036] The write submodule is used to write distributed identifier documents into a verifiable registry based on a distributed identifier template;
[0037] The registration submodule is used to register data space entity IDs for various entities in the trusted data space based on distributed identifier templates through the distributed digital steward.
[0038] Optionally, the registration module issues identity credentials to each party based on the data space entity ID through a third-party authentication system, including:
[0039] The issuance submodule is used to issue identity credentials to each party based on a verifiable credential template and through a third-party authentication system according to the data space entity ID of each party.
[0040] Optionally, the exchange module establishes an end-to-end encrypted connection channel between the linking party and the linked party based on the search results, including:
[0041] The determination submodule is used to determine the linker and the linked party that need to establish a connection channel based on the search results;
[0042] Establish a submodule to create an end-to-end encrypted connection channel between the linking party and the linked party.
[0043] Optionally, submodules may be created, including:
[0044] The publishing unit is used to publish an invitation link containing the data space subject ID of the linked party through the distributed digital steward, wherein the invitation link is used by the linking party's distributed digital steward to verify whether the data space subject ID of the linked party is valid.
[0045] The sending unit is used to send a negotiation request, including its own data space subject ID and private key signature, to the linked party through the linked party's distributed digital steward, provided that the linked party's data space subject ID is valid. The linked party finds the distributed identification document in the verifiable registry through the linked party's subject ID and verifies the private key signature, thereby verifying whether the linked party's data space subject ID is valid.
[0046] The first establishment unit is used to complete the key negotiation between the linking party and the linked party to establish an end-to-end channel, provided that the data space subject ID of the linking party is valid.
[0047] The second establishment unit is used to establish an end-to-end encrypted connection channel between the linking party and the linked party based on the end-to-end channel, whereby the linking party and the linked party request each other's identity credentials, present and verify the identity credentials through the distributed digital steward, and establish the end-to-end encrypted connection channel between the linking party and the linked party if the verification is successful.
[0048] Optionally, the switching module includes:
[0049] The exchange submodule is used to establish an end-to-end encrypted connection channel between the linking party and the linked party based on the search results when the data consumer or data developer retrieves available data through metadata or data space data ID, and to complete the data exchange between the linking party and the linked party based on the connection channel.
[0050] According to another aspect of the present invention, a computer-readable storage medium is provided, the storage medium storing a computer program for performing the methods described in any of the above aspects of the present invention.
[0051] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: a processor; a memory for storing executable instructions of the processor; the processor being configured to read the executable instructions from the memory and execute the instructions to implement the method described in any of the preceding aspects of the present invention.
[0052] Therefore, the blockchain-based trusted data space system provided by this invention improves template security through digital fingerprints and access control mechanisms; the trustworthiness of the blockchain enables multiple parties to conduct distributed identifier verification based on a verifiable registry; the traceability of the blockchain records the historical changes of template iterations, making contract records trustworthy and auditable; smart contracts enable the automated execution of contract business logic, quickly generating templates that meet business needs, and improving the efficiency of the contract signing process. Attached Figure Description
[0053] Exemplary embodiments of the present invention can be more fully understood by referring to the following figures:
[0054] Figure 1 This is a flowchart illustrating a data exchange method for a trusted data space provided in an exemplary embodiment of the present invention;
[0055] Figure 2 This is a schematic diagram of the structure of a trusted data space provided in an exemplary embodiment of the present invention;
[0056] Figure 3This is a schematic diagram of the structure of a data exchange device for a trusted data space provided in an exemplary embodiment of the present invention;
[0057] Figure 4 This is the structure of an electronic device provided in an exemplary embodiment of the present invention. Detailed Implementation
[0058] Hereinafter, exemplary embodiments according to the present invention will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments of the present invention. It should be understood that the present invention is not limited to the exemplary embodiments described herein.
[0059] It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values of the components and steps described in these embodiments do not limit the scope of the invention.
[0060] Those skilled in the art will understand that the terms "first," "second," etc., in the embodiments of the present invention are only used to distinguish different steps, devices, or modules, and do not represent any specific technical meaning, nor do they indicate a necessary logical order between them.
[0061] It should also be understood that in the embodiments of the present invention, "multiple" can refer to two or more, and "at least one" can refer to one, two or more.
[0062] It should also be understood that any component, data or structure mentioned in the embodiments of the present invention can generally be understood as one or more unless explicitly defined or given contrary instructions in the context.
[0063] Furthermore, the term "and / or" in this invention is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this invention generally indicates that the preceding and following related objects have an "or" relationship.
[0064] It should also be understood that the description of the various embodiments in this invention emphasizes the differences between the various embodiments, and the similarities or similarities can be referred to each other. For the sake of brevity, they will not be described in detail.
[0065] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.
[0066] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the invention or its application or use.
[0067] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, they should be considered part of the specification.
[0068] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.
[0069] The embodiments of this invention can be applied to electronic devices such as terminal devices, computer systems, and servers, and can operate together with a wide range of other general-purpose or special-purpose computing system environments or configurations. Well-known examples of terminal devices, computing systems, environments, and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, and servers include, but are not limited to: personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments including any of the above systems, etc.
[0070] Electronic devices such as terminal devices, computer systems, and servers can be described in the general context of computer system executable instructions (such as program modules) executed by a computer system. Typically, program modules can include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks or implement specific abstract data types. Computer systems / servers can be implemented in distributed cloud computing environments, where tasks are executed by remote processing devices linked through communication networks. In distributed cloud computing environments, program modules can reside on local or remote computing system storage media, including storage devices.
[0071] Exemplary methods
[0072] Figure 1 This is a schematic flowchart of a data exchange method for a trusted data space provided in an exemplary embodiment of the present invention. This embodiment can be applied to electronic devices, such as... Figure 1 As shown, the data exchange method 100 for a trusted data space includes the following steps:
[0073] Step 101: Establish a verifiable registry and a distributed digital steward for the trusted data space, wherein the verifiable registry is a blockchain network;
[0074] Step 102: Register the data space entity ID for each party in the trusted data space through the distributed digital steward, and issue identity credentials for each party based on the data space entity ID through a third-party authentication system. The parties include: data providers, data consumers, and data developers.
[0075] Step 103: Based on the identity credentials and private keys of each entity in the distributed digital steward, mutual identity recognition is achieved among the entities, and a relationship is established.
[0076] Step 104: Write the metadata required for the data provider or data developer to publish the data into a verifiable registry, and establish the data space data ID of the metadata based on the data space entity ID of the data publisher and the metadata.
[0077] Step 105: Establish a connection between distributed digital stewards to form an end-to-end encrypted connection pipeline, and complete encrypted data exchange based on the connection channel.
[0078] Specifically, the purpose of this invention is to provide a method for constructing a trusted data space infrastructure, addressing issues such as reliance on third parties for data exchange, inability to guarantee user data sovereignty, and data privacy under existing centralized technology systems. By constructing a distributed digital steward using decentralized technology, it possesses capabilities such as mutual identity authentication, identity-based secure connection channels, and global data access control policies, exhibiting characteristics of independence from third parties, privacy protection, and improved data exchange security. To achieve the above objectives, the overall architecture of the trusted data space infrastructure is as follows: Figure 2 As shown, the steps of the data exchange method based on the trusted data space are as follows:
[0079] 1. Build a verifiable registry blockchain network for trusted data space operators and third-party certification authorities, design identity authentication templates and write them into the blockchain ledger for use by identity issuers, holders, and verifiers. The verifiable registry can be implemented using blockchain networks, files, or other methods depending on the application scenario.
[0080] 2. Deploy distributed digital stewards (or distributed data stewards) for people, organizations, things, and virtual resources participating in the data space, such as data providers, consumers, and developers. Each party registers its data space entity ID (including decentralized identifier DID) through the digital steward and obtains identity credentials through a third-party institution in the network. The distributed digital stewards are held by various entities within the trusted digital space, including mobile, server, cloud, and edge devices. Each distributed digital steward accesses a verifiable registry via the internet. Various entities participate in the trusted data space through their distributed digital stewards, which provide the following functions for their participation: including but not limited to identity authentication management, access authorization and control, data usage policy agreement, secure data exchange, data history management, data discovery, data policy execution, data transaction, communication protocol execution, and data rule execution.
[0081] 3. The main ID of the data space is realized through DID technology, and its DID document is written into the blockchain to provide ID verification capabilities for all parties in the data space.
[0082] 4. Identity credentials are implemented through VC technology. A third-party certification authority issues an identity VC (including verifiable credential VC) to the applicant, which is bound to the main ID of the data space, to complete the authentication of the identity in the data space.
[0083] 5. The distributed digital steward is held and controlled by each participant in the data space. The private key and identity VC associated with the main ID of the data space are stored in the digital steward. The digital steward is used to establish the relationship between the main body in the real society and the digital main body in the data space.
[0084] 6. Based on the above steps, each data space entity completes mutual recognition through its distributed digital steward.
[0085] 7. The distributed digital steward utilizes DID technology to implement an end-to-end encrypted connection channel based on mutual recognition of data space subject IDs. The steps include:
[0086] 1) The linked party's distributed digital steward publishes an invitation link containing its main ID, and the linking party's digital steward verifies the validity of its ID through the invitation link;
[0087] 2) The linking digital manager sends a link request with its own entity ID and key negotiation request. The linked party receives the request, verifies the validity of the ID, completes key negotiation, and establishes an end-to-end channel.
[0088] 3) Both parties request each other's identity in the link. Both parties present their identity VC through the digital steward. After both parties verify the identity VC, the end-to-end link is established.
[0089] 8. Data consumers or developers in the data space publish the metadata required for data applications within the space, and the metadata is written into the blockchain network for data providers in the data space to access.
[0090] 9. Data providers in the data space publish the data they need to share as data space data IDs based on their own data and the metadata in the data space, thus completing the data targets within the data space and providing management methods for subsequent data discovery and data exchange.
[0091] 10. Data consumers and developers retrieve available data through metadata and data IDs, and submit data usage requests to data providers. Data providers issue data application credentials, and consumers or developers connect to the provider's digital steward to present the credentials and obtain the data.
[0092] 11. Complete the data exchange between the various entities in the data space based on the digital steward through the above steps.
[0093] The key technical point of this invention is:
[0094] 1. Construct a decentralized multi-party digital ID verification system based on distributed digital identity technology to realize cryptographic ID management in decentralized system scenarios.
[0095] 2. Construct a distributed identity system to implement verifiable credentials based on the identity system.
[0096] 3. Construct an end-to-end secure channel based on distributed digital identity technology.
[0097] 4. Build data management and access control capabilities based on distributed identity and verifiable credentials.
[0098] Therefore, the blockchain-based trusted data space system provided by this invention improves template security through digital fingerprints and access control mechanisms; the traceability of the blockchain records the historical changes of template iterations, making contract records trustworthy and auditable; smart contracts enable the automated execution of contract business logic, quickly generating templates that meet business needs, and improving the efficiency of the contract signing process.
[0099] Exemplary device
[0100] Figure 3 This is a schematic diagram of the structure of a data exchange device for a trusted data space provided in an exemplary embodiment of the present invention. Figure 3 As shown, the device 300 includes:
[0101] Module 310 is established to create a verifiable registry and a distributed digital steward for a trusted data space. The verifiable registry may be a blockchain network or a file, depending on the application scenario.
[0102] Registration module 320 is used to register data space entity IDs for various entities in the trusted data space through the distributed digital steward, and to issue identity credentials to each entity based on the data space entity IDs through a third-party authentication system. The entities include data providers, data consumers and data developers.
[0103] The mutual recognition module 330 is used to realize mutual recognition of identities and establish association relationships between the entities in the distributed digital steward based on their identity credentials and private keys.
[0104] Module 340 is established to write the metadata required for data providers or data developers to publish data into a verifiable registry, and to establish the data space data ID of the metadata based on the data space subject ID of the data publisher and the metadata.
[0105] The exchange module 350 is used to establish a connection between distributed digital stewards, forming an end-to-end encrypted connection pipeline, and to complete encrypted data exchange based on the connection channel.
[0106] Optionally, the verifiable registry includes identity templates, data templates, distributed identifier templates, and verifiable credential templates; the distributed digital steward includes identity management, private key management, data policy management, and communication protocols; and the distributed digital steward includes various forms such as mobile, server, cloud, and edge.
[0107] Various entities in the trusted digital space participate in the trusted data space through its distributed digital steward. The distributed digital steward provides the following functions for its entities to participate in the trusted digital space, including identity authentication management, access authorization and control, data usage policy agreement, data security exchange, data history management, data discovery, data policy execution, data transaction, communication protocol execution, and data rule execution.
[0108] Optionally, the registration module 320 registers data space entity IDs for various entities in the trusted data space through a distributed digital steward, including:
[0109] The write submodule is used to write distributed identifier documents into the verifiable registry based on the distributed identifier template.
[0110] The registration submodule is used to register data space entity IDs for each party in the trusted data space through the distributed digital steward based on the distributed identifier template.
[0111] Optionally, in the registration module 320, an identity credential is issued to each party based on the data space subject ID through a third-party authentication system, including:
[0112] The issuance submodule is used to issue identity credentials to each party based on a verifiable credential template and through a third-party authentication system according to the data space entity ID of each party.
[0113] Optionally, the exchange module 350 establishes an end-to-end encrypted connection channel between the linking party and the linked party based on the search results, including:
[0114] The determination submodule is used to determine the linker and the linked party that need to establish a connection channel based on the search results;
[0115] Establish a submodule to create an end-to-end encrypted connection channel between the linking party and the linked party.
[0116] Optionally, submodules may be created, including:
[0117] The publishing unit is used to publish an invitation link containing the data space subject ID of the linked party through the distributed digital steward, wherein the invitation link is used by the linking party's distributed digital steward to verify whether the data space subject ID of the linked party is valid.
[0118] The sending unit is used to send a negotiation request, including its own data space subject ID and private key signature, to the linked party through the linked party's distributed digital steward, provided that the linked party's data space subject ID is valid. The linked party finds the distributed identification document in the verifiable registry through the linked party's subject ID and verifies the private key signature, thereby verifying whether the linked party's data space subject ID is valid.
[0119] The first establishment unit is used to complete the key negotiation between the linking party and the linked party to establish an end-to-end channel, provided that the data space subject ID of the linking party is valid.
[0120] The second establishment unit is used to establish an end-to-end encrypted connection channel between the linking party and the linked party based on the end-to-end channel, whereby the linking party and the linked party request each other's identity credentials, present and verify the identity credentials through the distributed digital steward, and establish the end-to-end encrypted connection channel between the linking party and the linked party if the verification is successful.
[0121] Optionally, the switching module 350 includes:
[0122] The exchange submodule is used to establish an end-to-end encrypted connection channel between the linking party and the linked party based on the search results when the data consumer or data developer retrieves available data through metadata or data space data ID, and to complete the data exchange between the linking party and the linked party based on the connection channel.
[0123] Exemplary electronic devices
[0124] Figure 4 This is the structure of an electronic device provided in an exemplary embodiment of the present invention. For example... Figure 4 As shown, the electronic device 40 includes one or more processors 41 and a memory 42.
[0125] The processor 41 may be a central processing unit (CPU) or other form of processing unit with data processing and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.
[0126] The memory 42 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 41 may execute the program instructions to implement the methods of the software programs of the various embodiments of the present invention described above, and / or other desired functions. In one example, the electronic device may also include an input device 43 and an output device 44, these components being interconnected via a bus system and / or other forms of connection mechanisms (not shown).
[0127] In addition, the input device 43 may also include, for example, a keyboard, a mouse, etc.
[0128] The output device 44 can output various information to the outside. The output device 44 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc.
[0129] Of course, for the sake of simplicity, Figure 4 Only some of the components of this electronic device relevant to the present invention are shown, omitting components such as buses, input / output interfaces, etc. In addition, the electronic device may include any other suitable components depending on the specific application.
[0130] Exemplary computer program products and computer-readable storage media
[0131] In addition to the methods and apparatus described above, embodiments of the present invention may also be computer program products, which include computer program instructions that, when executed by a processor, cause the processor to perform the steps in the methods according to various embodiments of the present invention described in the "Exemplary Methods" section above.
[0132] The computer program product can be written in any combination of one or more programming languages to perform the operations of the embodiments of the present invention. The programming languages include object-oriented programming languages such as Java and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0133] Furthermore, embodiments of the present invention may also be computer-readable storage media storing computer program instructions thereon, which, when executed by a processor, cause the processor to perform the steps of the methods according to various embodiments of the present invention described in the "Exemplary Methods" section above.
[0134] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.
[0135] The basic principles of the present invention have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in the present invention are merely examples and not limitations, and should not be considered as essential features of each embodiment of the present invention. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the present invention to the necessity of employing the aforementioned specific details.
[0136] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For system embodiments, since they largely correspond to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0137] The block diagrams of devices, systems, devices, and systems involved in this invention are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, systems, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.
[0138] The methods and systems of the present invention may be implemented in many ways. For example, they may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order of steps for the methods is for illustrative purposes only, and the steps of the methods of the present invention are not limited to the order specifically described above unless otherwise specifically stated. Furthermore, in some embodiments, the present invention may also be implemented as a program recorded on a recording medium, the program comprising machine-readable instructions for implementing the methods according to the present invention. Thus, the present invention also covers recording media storing programs for performing the methods according to the present invention.
[0139] It should also be noted that in the systems, apparatus, and methods of the present invention, the components or steps can be disassembled and / or recombined. These disassemblies and / or recombinations should be considered equivalents of the present invention. The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the invention. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the invention. Therefore, the invention is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.
[0140] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of the invention to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. A data exchange method for a trusted data space, characterized in that, include: Establish a verifiable registry and distributed digital steward for a trusted data space, wherein the verifiable registry adopts a blockchain network or files depending on the application scenario; The distributed digital steward registers data space entity IDs for various entities in the trusted data space, and issues identity credentials to each entity based on the data space entity IDs through a third-party authentication system. The entities include data providers, data consumers, and data developers. Based on the identity credentials and private keys of each party in the distributed digital steward, mutual identity recognition is achieved among the parties, and a relationship is established. Write the metadata required for the data provider or the data developer to publish the data into the verifiable registry, and establish the data space data ID of the metadata based on the data space subject ID of the data publisher and the metadata; By establishing connections between the distributed digital stewards, an end-to-end encrypted connection channel is formed, and encrypted data exchange is completed based on the connection channel.
2. The method according to claim 1, characterized in that, The verifiable registry includes identity templates, data templates, distributed identifier templates, and verifiable credential templates. The distributed digital steward includes identity management, private key management, data policy management, and communication protocols. Furthermore, the distributed digital steward includes various forms such as mobile, server, cloud, and edge devices. Various entities in the trusted digital space participate in the trusted data space through its distributed digital steward. The distributed digital steward provides the following functions for its entities to participate in the trusted digital space, including identity authentication management, access authorization and control, data usage policy agreement, data security exchange, data history management, data discovery, data policy execution, data transaction, communication protocol execution, and data rule execution.
3. The method according to claim 2, characterized in that, The distributed digital steward registers data space entity IDs for each party in the trusted data space, including: The distributed identifier document is written into the verifiable registry based on the distributed identifier template. Based on the distributed identifier template, the distributed digital steward registers data space entity IDs for each party in the trusted data space.
4. The method according to claim 2, characterized in that, The third-party authentication system issues identity credentials to each party based on the data space subject ID, including: Based on the verifiable credential template, the third-party authentication system issues the identity credentials to each party according to the data space subject ID of each party.
5. The method according to claim 1, characterized in that, Based on the search results, an end-to-end encrypted connection channel is established between the linking party and the linked party, including: Based on the search results, determine the linking party and the linked party that need to establish a connection channel; Establish an end-to-end encrypted connection channel between the linking party and the linked party.
6. The method according to claim 5, characterized in that, Establishing an end-to-end encrypted connection channel between the linking party and the linked party includes: The linked party's distributed digital steward publishes an invitation link containing its data space subject ID, wherein the invitation link is used by the linking party's distributed digital steward to verify whether the linked party's data space subject ID is valid. If the data space subject ID of the linked party is valid, the linked party's distributed digital steward sends a negotiation request with its own data space subject ID and private key signature to the linked party. The linked party finds the distributed identification document in the verifiable registry using the linked party's subject ID and verifies the private key signature to verify whether the linked party's data space subject ID is valid. If the data space subject ID of the linking party is valid, complete the key negotiation between the linking party and the linked party to establish an end-to-end channel; Based on the end-to-end channel, the linking party and the linked party request each other's identity credentials, present and verify the identity credentials through the distributed digital steward, and establish an end-to-end encrypted connection channel between the linking party and the linked party if the verification is successful.
7. The method according to claim 1, characterized in that, By establishing connections between the distributed digital stewards, an end-to-end encrypted connection channel is formed, and encrypted data exchange is completed based on the connection channel, including: When the data consumer or the data developer retrieves available data through metadata or data space data ID, an end-to-end encrypted connection channel is established between the linking party and the linked party based on the retrieval results, and data exchange between the linking party and the linked party is completed based on the connection channel.
8. A data exchange device for a trusted data space, characterized in that, include: A module is established to create a verifiable registry and a distributed digital steward for a trusted data space, wherein the verifiable registry adopts a blockchain network or a file depending on the application scenario; The registration module is used to register data space entity IDs for various entities in the trusted data space through the distributed digital steward, and to issue identity credentials for each entity based on the data space entity IDs through a third-party authentication system. The entities include data providers, data consumers, and data developers. The mutual recognition module is used to realize mutual recognition of identities between the entities in the distributed digital steward based on their identity credentials and private keys, and to establish association relationships. A module is established to write the metadata required for the data provider or the data developer to publish the data into the verifiable registry, and to establish the data space data ID of the metadata based on the data space subject ID of the data publisher and the metadata. The exchange module is used to establish an end-to-end encrypted connection channel between the linking party and the linked party based on the retrieval results when the data consumer or the data developer retrieves available data through metadata or data space data ID, and to complete the data exchange between the linking party and the linked party based on the connection channel.
9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program for performing the method described in any one of claims 1-7.
10. An electronic device, characterized in that, The electronic device includes: processor; Memory used to store the processor's executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in any one of claims 1-7.
Citation Information
Patent Citations
Mobile platform distributed digital identity authentication method and device and medium
CN116886357A
System and method for a decentralized portable information container supporting privacy protected digital information credentialing, remote administration, local validation, access control and remote instruction signaling utilizing blockchain distributed ledger and container wallet technologies
US20210374693A1