Data element circulation method and device based on block chain and DID, equipment and medium

By using blockchain and DID technology in the circulation of data elements, DID identification and converting data formats, the problem of low security in circulation of data elements is solved, and efficient, secure and trustworthy sharing of data resources is achieved.

CN119989380APending Publication Date: 2025-05-13CHINA MERCHANTS INVESTMENT DEVELOPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510059781.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing data factor circulation technology has the problem of low security, especially in the sharing and flow of data resources, and it is impossible to realize a standardized, universal and unified data sharing platform, resulting in insufficient data security.

Method used

The data element circulation method based on blockchain and DID is adopted, and the meta-information data of data resources is extracted, DID identification is generated, and the data format is converted into a data format of verification credentials, and stored in the directory chain platform to realize traceability, auditability and trustworthy authorization of data resources.

Benefits of technology

The security improvement in the data element flow process is achieved, ensuring the integrity, confidentiality and security of data resources in the flow process, and realizing the trust and auditability of data sharing through the immutable characteristics of blockchain and the decentralized characteristics of DID.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989380A_ABST
    Figure CN119989380A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data transmission, and discloses a block chain and DID-based data element circulation method, device and equipment and a medium, and the method comprises the steps: extracting meta-information data corresponding to a data resource, and generating a DID identifier corresponding to the data resource according to the meta-information data; storing the data resource to a first local storage corresponding to a data element producer according to the converted data format of the verification voucher, and importing the data resource into a voucher template; performing data authorization on a data element user according to the data request; sending the data resources stored in the first local storage to a data element user through a data gateway and a data transmission condition; and analyzing the DID identifier corresponding to the data resource in the second local storage, analyzing the DID document corresponding to the data resource in the second local storage in the data element producer according to the analyzed DID identifier, and circulating the analyzed DID document to the data element user. According to the invention, the security of data element circulation can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a data element circulation method, device, equipment and medium based on blockchain and DID. Background Art

[0002] As an indispensable data resource in production and operation activities, data elements must be shared and circulated between producers and users. The problems faced in the process of sharing and circulating data elements include: how to standardize the data resources that vary greatly from industry to industry for unified modeling, management and use, how to achieve traceable and auditable trusted authorization of data between producers and users, and how to ensure the integrity, confidentiality and security of data elements during circulation.

[0003] At present, data transmission and circulation technology usually requires data producers and users to agree on data sharing agreements on their own, and implement a data sharing platform based on centralized storage to complete the sharing and circulation of data resources. In actual applications, producers and users agree on the expression format of data elements on their own, and there is no unified standard for data models, no interoperability, and no standardized, universal and unified data sharing platform, which reduces the security of data element circulation. Summary of the invention

[0004] The present invention provides a data element circulation method, device, equipment and medium based on blockchain and DID, the main purpose of which is to solve the problem of low security when circulating data elements.

[0005] To achieve the above objectives, the present invention provides a data element circulation method based on blockchain and DID, comprising:

[0006] Extracting metadata corresponding to the pre-acquired data resource, generating a DID identifier corresponding to the data resource according to a preset DID specification and the metadata, and converting the data format of the data resource into a preset data format of the verification credential according to the DID identifier;

[0007] Store the data resource in the first local storage corresponding to the data element producer according to the converted verification credential data format, import the data resource into a preset credential template, generate a product catalog, and store the product catalog in the catalog chain platform;

[0008] When receiving a data request from a data element user for a product catalog stored in the catalog chain platform, performing data authorization on the data element user according to the data request;

[0009] After the data element user obtains authorization, a data sharing task is created according to the data request, and the data sharing task is uploaded to the directory chain platform;

[0010] According to the data sharing task in the target chain platform, the data resources stored in the first local storage are sent to the data element user through the preset data gateway and the data transmission conditions, and the data resources sent to the data element user are stored in the second local storage corresponding to the data element user;

[0011] Parse the DID identifier corresponding to the data resource in the second local storage, parse the DID document corresponding to the data resource in the second local storage of the data element producer according to the parsed DID identifier, and circulate the parsed DID document to the data element user.

[0012] Optionally, converting the data format of the data resource into a preset data format of the verification credential according to the DID identifier includes:

[0013] Identify the target data element in the data resource according to the DID identifier;

[0014] Extracting field data corresponding to the target data element according to the data format of the target data element;

[0015] Extracting the credential field data corresponding to the verification credential according to the preset verification credential data format;

[0016] Perform field attribute mapping on the field data and the voucher field data to obtain a field mapping relationship;

[0017] The target data element corresponding to the field data is mapped to the credential field data through the field mapping relationship, and the data format of the data resource is converted into a preset data format of the verification credential according to the mapped field data.

[0018] Optionally, the step of importing the data resource into a preset voucher template to generate a product catalogue includes:

[0019] Extracting a target data field corresponding to the data resource;

[0020] Mapping the target data field to the voucher subject field in a preset voucher template;

[0021] Generates the product catalog by mapping the target data fields in the document body fields.

[0022] Optionally, before receiving a data request from a data element user for a product catalog stored in the catalog chain platform, the method further includes:

[0023] Determining a data resource model according to the product catalog;

[0024] According to the data resource demand of the data element user, query whether there is a target data resource corresponding to the data resource demand in the data resource model;

[0025] When the target data resource exists in the data resource model, the data request is generated.

[0026] Optionally, the performing data authorization on the data element user according to the data request includes:

[0027] Encrypt the data request using the private key of the data element user, and send the encrypted data request to the directory chain platform;

[0028] Utilize the directory chain platform to parse the public key of the data element user in the identity DID identifier corresponding to the data element user;

[0029] Using the public key to verify the encrypted data request in the target chain platform to obtain a verification result;

[0030] When the verification result is verification failure, the data authorization of the data element user is rejected. When the verification result is verification success, the data element user is approved and authorized.

[0031] Optionally, the sending of the data resource stored in the first local storage to the data element user through the preset data gateway and the data transmission condition includes:

[0032] Read the data resources stored in the first local storage through the data gateway corresponding to the data element producer;

[0033] Encrypt the read data resources in the data gateway corresponding to the data element producer;

[0034] Execute data transmission according to the data transmission conditions, and when executing data transmission, send the encrypted data resource to the data gateway corresponding to the data element user;

[0035] The data resources sent to the data gateway are verified using the private key of the data element user. Once the verification is successful, the data resources sent to the data gateway are written to the second local storage.

[0036] Optionally, the step of parsing the DID document corresponding to the data resource in the second local storage of the data element producer according to the parsed DID identifier includes:

[0037] Identify the target DID document corresponding to the DID in the second local storage according to the parsed DID;

[0038] Receive a document parsing request corresponding to the target DID document using a preset DID off-chain parser;

[0039] The document attribute information corresponding to the target DID document is parsed according to the document parsing request.

[0040] In order to solve the above problems, the present invention also provides a data element circulation device based on blockchain and DID, the device comprising:

[0041] A data format conversion module, used to extract metadata data corresponding to a pre-acquired data resource, generate a DID identifier corresponding to the data resource according to a preset DID specification and the metadata data, and convert the data format of the data resource into a preset data format of a verification credential according to the DID identifier;

[0042] A product catalog generation module, used to store the data resource in the first local storage corresponding to the data element producer according to the converted verification credential data format, import the data resource into a preset credential template, generate a product catalog, and store the product catalog in the catalog chain platform;

[0043] A data authorization module, for, upon receiving a data request from a data element user for a product catalog stored in the catalog chain platform, performing data authorization on the data element user according to the data request;

[0044] A data sharing task creation module, used to create a data sharing task according to the data request after the data element user obtains authorization, and upload the data sharing task to the directory chain platform;

[0045] A data resource transmission module is used to trigger the data transmission condition according to the data sharing task in the target chain platform, send the data resources stored in the first local storage to the data element user through the preset data gateway and the data transmission condition, and store the data resources sent to the data element user in the second local storage corresponding to the data element user;

[0046] The document parsing module is used to parse the DID identifier corresponding to the data resource in the second local storage, parse the DID document corresponding to the data resource in the second local storage of the data element producer according to the parsed DID identifier, and circulate the parsed DID document to the data element user.

[0047] In order to solve the above problem, the present invention further provides an electronic device, the electronic device comprising:

[0048] at least one processor; and,

[0049] a memory communicatively connected to the at least one processor; wherein,

[0050] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the above-mentioned blockchain and DID-based data element circulation method.

[0051] In order to solve the above problems, the present invention also provides a computer-readable storage medium, in which at least one computer program is stored. The at least one computer program is executed by a processor in an electronic device to implement the above-mentioned blockchain and DID-based data element circulation method.

[0052] The embodiment of the present invention uses DID and VC to make unified data modeling for data element resources, which is compatible with various types of data, and the data resources have interoperability, so as to realize the unified circulation of different data elements; the whole process of data element release, application, authorization, and shared circulation is recorded in the blockchain account book, and based on the centralized and tamper-proof characteristics of the blockchain, the trust, auditability, and traceability of data circulation and sharing are realized; the trusted confirmation of the data element circulation process is separated from the shared transmission of data resources, so as to realize the trustworthiness of the sharing process while ensuring the efficiency, confidentiality, and security of data transmission; the data resource content supports the DID identification description of different platforms, and the DID document parsing of various types of data resources is unified through the off-chain DID parser, and the interconnection and interoperability in the closed-loop data element circulation system process. Therefore, the data element circulation method, device, equipment, and medium based on blockchain and DID proposed by the present invention can solve the problem of low security when circulating data elements. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 A system architecture diagram of a data element circulation method based on blockchain and DID provided in one embodiment of the present invention;

[0054] Figure 2 A system schematic diagram of a data element circulation method based on blockchain and DID provided in one embodiment of the present invention;

[0055] Figure 3 A flowchart of a data element circulation method based on blockchain and DID provided in one embodiment of the present invention;

[0056] Figure 4 An interactive sequence diagram of data element circulation provided by an embodiment of the present invention;

[0057] Figure 5A functional module diagram of a data element circulation device based on blockchain and DID provided in one embodiment of the present invention;

[0058] Figure 6 A schematic diagram of the structure of a computer device in one embodiment of the present invention;

[0059] Figure 7 FIG. 4 is another schematic diagram of the structure of a computer device in one embodiment of the present invention.

[0060] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0061] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0062] The embodiment of the present application provides a data element circulation method based on blockchain and DID. The execution subject of the data element circulation method based on blockchain and DID includes but is not limited to at least one of the electronic devices such as the server, terminal, etc. that can be configured to execute the method provided by the embodiment of the present application. In other words, the data element circulation method based on blockchain and DID can be executed by software or hardware installed on a terminal device or a server device, and the software can be a blockchain platform. The server includes but is not limited to: a single server, a server cluster, a cloud server or a cloud server cluster, etc. The server can be an independent server, or it can be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (Content Delivery Network, CDN), and big data and artificial intelligence platforms.

[0063] Reference Figure 1 As shown, it is a system architecture diagram of a method for implementing a data element circulation method based on blockchain and DID provided by an embodiment of the present invention, including a data supply side, a data use side, a directory chain platform, a DID off-chain parser, and a blockchain network, wherein:

[0064] The data supply side includes the data producer and the DID (Decentralized IDentifier) ​​platform it relies on, local storage and data gateway. The data supply side publishes and approves data through the directory chain platform.

[0065] The user side includes data users and the local storage and data gateways they rely on. The user side checks applications and obtains data through the directory chain platform.

[0066] The DID off-chain resolver is a general open service platform;

[0067] The entire data flow process, including publishing, approval, authorization, and sharing, is recorded in the blockchain ledger to achieve immutability, traceability, and auditability.

[0068] Reference Figure 2 As shown, it is a system schematic diagram of a method for implementing a data element circulation method based on blockchain and DID provided by an embodiment of the present invention, including a data element producer, a data element user, a directory chain platform, a data gateway and a DID off-chain parser, wherein:

[0069] The producer of data elements publishes, approves and authorizes data resources through the directory chain platform. The producer allocates its own distributed identity through the directory chain platform and registers distributed identity for the data resource entity.

[0070] The user of data elements applies for data element authorization and obtains data resource content through the directory chain platform. Users view published data elements through the directory chain platform and submit data resource applications for data of interest.

[0071] The directory chain platform is the core functional platform of the data element circulation platform. It is responsible for the DID registration and on-chain release of data elements, as well as the on-chain trusted flow of data during the circulation process. The directory chain platform records all circulation processes such as the release, application, authorization, and data sharing of data elements in the form of smart contracts in the blockchain ledger to ensure the security and reliability of the entire process of data element circulation.

[0072] The data gateway is responsible for monitoring the on-chain authorized sharing tasks of data resources and executing the transmission of data content.

[0073] The DID off-chain parser is responsible for uniformly parsing DID documents of different DID platforms (blockchain networks).

[0074] Reference Figure 3 As shown, it is a flowchart of a data element circulation method based on blockchain and DID provided in one embodiment of the present invention. In this embodiment, the data element circulation method based on blockchain and DID includes:

[0075] S1. Extract metadata corresponding to a pre-acquired data resource, generate a DID identifier corresponding to the data resource according to a preset DID specification and the metadata data, and convert the data format of the data resource into a preset verification credential data format according to the DID identifier.

[0076] In an embodiment of the present invention, the DID identifier of the data resource can identify specific data information or a certain category of data. For example, for a data resource, only a few rows of data in the data resource need to be extracted, and the data in the few rows are combined into metadata data. The metadata data is a data element that identifies the data resource, and a DID identifier corresponding to the data resource is generated according to the metadata information and the DID specification. DID is a decentralized identity identification standard that can identify an entity. DID does not rely on a central certification agency, can be controlled autonomously by an individual or organization, and bound to a blockchain. For example, the credential DID identifier is did:tdid:cm788g1:0x17420497a50ecc229d6460x9b2118b. The DID identifier is generated by the business according to the segment structure of the DID according to self-defined rules.

[0077] Furthermore, the data element producer allocates its own distributed identity through the directory chain platform and registers a distributed identity for the data resource entity. The identity and the public key are bound to the smart contract of the blockchain. The data element producer holds the private key corresponding to the public key on the chain. The ownership of the DID can be verified through the asymmetric encryption signature verification mechanism. The data resource DID can identify specific data information, and the data content is stored in the file storage in the data format of verifiable credentials (VC).

[0078] In the embodiment of the present invention, the verification credential is a verifiable credential data model released by the W3C working group. The specification provides a mechanism to present such credentials on the Web in a cryptographically secure, privacy-respecting and machine-verifiable manner. The digital signature of the credential can verify the issuer and realize the role of confirming the right, and the data format of the verification credential refers to a standardized format for verifying the structure and content of the credential, including the specific data content and the verification source of the information, and the data format of the verification credential includes a header, a body, a signature, a certification information, a validity period and an authentication method.

[0079] In the embodiment of the present invention, the converting the data format of the data resource into the data format of a preset verification credential according to the DID identifier includes:

[0080] Identify the target data element in the data resource according to the DID identifier;

[0081] Extracting field data corresponding to the target data element according to the data format of the target data element;

[0082] Extracting the credential field data corresponding to the verification credential according to the preset verification credential data format;

[0083] Perform field attribute mapping on the field data and the voucher field data to obtain a field mapping relationship;

[0084] The target data element corresponding to the field data is mapped to the credential field data through the field mapping relationship, and the data format of the data resource is converted into a preset data format of the verification credential according to the mapped field data.

[0085] In detail, each data element in the data resource has its corresponding DID identifier, which is used to identify specific data information. Since the data format corresponding to the original data resource may be unstructured data, such as a paragraph, it is necessary to convert the unstructured data resource into a standardized data format, that is, the data format of the verification credential, and then identify the target data element that needs to be extracted and converted in the data resource based on the DID identifier. The target data element refers to the data part that needs to be converted into a preset verification credential. For example, a verification credential for personal information may need to verify data elements such as name, date of birth, and ID number.

[0086] Specifically, specific field data is extracted from the data resource according to the data format of the target data element, and each data element has its corresponding data structure. If the target data element is the date of birth, the value of the field (such as 1990-01-01) will be extracted and processed according to the data format (such as ISO date format), and the corresponding field data will be extracted from the preset verification certificate format. For example, if the verification certificate has a field called date of birth, it is necessary to extract the data format requirements of the field so as to perform field mapping. Different data resource formats and verification certificate formats may have different field names and data structures. Therefore, it is necessary to establish a field mapping relationship to determine how the fields in the data resource correspond to the fields in the verification certificate. For example, if the field in the data resource is date of birth, and the field in the verification certificate is dateOfBirth, it is necessary to clarify the mapping relationship. After the mapping relationship is established, the target data element (the field data extracted from the data resource) will be filled into the field of the verification certificate according to the mapping relationship. According to the results of the completed field mapping, the content in the original data resource is organized according to the preset format of the verification certificate, and the final verification certificate (VC) is generated.

[0087] Furthermore, the data element content of the data element producer may contain the identifiers of other DID platforms related to other data content. This identifier is usually saved in the form of a credential declaration in (VC), and the data content is then stored in the file storage by the data element producer in the data format of a verifiable credential (VC).

[0088] S2. Store the data resource in the first local storage corresponding to the data element producer according to the data format of the converted verification certificate, import the data resource into a preset certificate template, generate a product catalog, and store the product catalog in the catalog chain platform.

[0089] In an embodiment of the present invention, the data resource in the data format of the converted verification credential is the (VC) credential corresponding to the data resource, and the (VC) credential generated by the data element producer will be stored in the corresponding local storage, and the data resource corresponding to the data format of the converted verification credential is stored based on the storage address of the local storage, wherein the first local storage refers to the local storage address where the data (VC) credential generated by the data element producer is stored.

[0090] Furthermore, the data elements registered by the data element producers must be published to the directory chain platform for viewing or use by the data element users. The target chain platform is the core functional platform of the data element circulation platform, responsible for the DID registration and on-chain publication of data elements, as well as the on-chain trusted flow of data during the circulation process. The directory chain platform records all circulation processes such as data element publication, application, authorization, and data sharing in the form of smart contracts in the blockchain ledger to ensure the security and reliability of the entire data element circulation process.

[0091] In an embodiment of the present invention, in order to achieve the separation of data model publishing and data content sharing, it is necessary to generate a product catalog. The product catalog is the final data set generated by the verification credential (VC) template, which displays a complete catalog of all relevant information fields. It refers to a set of credential data that conforms to a specific template format and is used to describe a certain type of entity or a collection of attributes.

[0092] In the embodiment of the present invention, the step of importing the data resource into a preset voucher template to generate a product catalog includes:

[0093] Extracting a target data field corresponding to the data resource;

[0094] Mapping the target data field to the voucher subject field in a preset voucher template;

[0095] Generates the product catalog by mapping the target data fields in the document body fields.

[0096] In detail, the target data field refers to a specific information field extracted from the original data resource. These fields usually represent key information in the data, such as the target field id, issuer, etc. The voucher template is the definition of the data field in (VC), and then the target data field extracted from the data resource is filled into the corresponding template field according to the specified format of the template. The voucher body field includes claim, and the fields under it are defined and extended by the business itself, carrying the actual data resource content. signatureValue is the data confirmation signature, which can be used to verify whether the data is generated by the corresponding DID identity through this field and the publicKey in the DID document. Then, the product catalog is composed of only the target data field, and the data content corresponding to the data field is not displayed. The mapped voucher template is output as a complete voucher instance.

[0097] Specifically, the release of data elements requires the import of a voucher (VC) template, which is stored in the blockchain network's smart contract in the form of a product catalog, and a DID is generated to identify the product catalog. The voucher template is the definition of the data field in the (VC). By importing the (VC) template to generate a product catalog, data users can view the data resource model definition to decide whether to apply for the data resource. The actual data content is not carried in the product catalog, but is stored in the local storage of the data producer in the form of (VC), thereby achieving the separation of data model release and data content sharing.

[0098] Furthermore, data users apply for data element authorization and obtain data resource content through the directory chain platform. Users can view published data elements through the directory chain platform and submit data resource applications for data of interest.

[0099] S3. When a data request for a product catalog stored in the catalog chain platform is received from a data element user, data authorization is performed on the data element user according to the data request, and a data sharing task is created according to the authorized data request.

[0100] In an embodiment of the present invention, when a data element user wants to apply for data element authorization and obtain data resource content through a directory chain platform, he needs to make a data acquisition request. Before making the data acquisition request, it is also necessary to evaluate whether there is data of interest to the user in the directory chain platform. Only if there is data, the data element user will make a data acquisition request. If not, the data element user will not make a data acquisition request.

[0101] In the embodiment of the present invention, before receiving the data request from the data element user for the product catalog stored in the catalog chain platform, the method further includes:

[0102] Determining a data resource model according to the product catalog;

[0103] According to the data resource demand of the data element user, query whether there is a target data resource corresponding to the data resource demand in the data resource model;

[0104] When the target data resource exists in the data resource model, the data request is generated.

[0105] In detail, the data resource model is a way to organize, structure and classify data stored in the directory chain platform. It is a data structure that describes different types of data and their relationships. It can help users (usually data demanders) understand and locate the required data resources. For example, in a product catalog, there may be different types of data resources (such as product information, inventory quantity, price, description, etc.). These resources will be mapped to the data resource model and organized through pre-defined data model structures and fields. Then, based on the data resource requirements of the data element users, the data resource model is queried to see if there is required data. The data resource requirements refer to the specific data resources required by the data demander (user). When making a data request, the user usually explicitly requires certain specific data, such as "the current inventory quantity of a product" or "the price of a specific product."

[0106] Specifically, after receiving the data demand, the system will query the data resource model to determine whether the data model contains resources that match the request. If there is a matching target data resource (i.e., the requested data) in the data resource model, a data request corresponding to the data element user will be generated. The data request includes the specific data items requested, the data source or target requested, or the conditions requested, so as to obtain the corresponding data from the directory chain platform based on the data request.

[0107] Furthermore, the directory chain platform can register a DID identifier for the user's identity, and carry the identity identifier when applying for data authorization for verification by the data producer. Only after the data producer has passed the verification will the data element user be approved and authorized.

[0108] In the embodiment of the present invention, the step of performing data authorization on the data element user according to the data request includes:

[0109] Encrypt the data request using the private key of the data element user, and send the encrypted data request to the directory chain platform;

[0110] Utilize the directory chain platform to parse the public key of the data element user in the identity DID identifier corresponding to the data element user;

[0111] Using the public key to verify the encrypted data request in the target chain platform to obtain a verification result;

[0112] When the verification result is verification failure, the data authorization of the data element user is rejected. When the verification result is verification success, the data element user is approved and authorized.

[0113] In detail, in a decentralized identity management system, each DID is usually controlled by a public key and a private key pair. The public key is used to identify the identity, and the private key is used for signing and encryption operations. The data element user has its corresponding identity DID identifier, and then encrypts the identity DID identifier through the private key corresponding to the data element user. That is, the data demander encrypts its DID identifier with its own private key to form an encrypted data block. The encrypted identifier can prevent others from forging requests and ensure that the request comes from a legitimate data demander.

[0114] Specifically, the data producer uses the public key of the data demander to decrypt the encrypted DID and verify it. The data producer will verify through the public key whether the encrypted DID is indeed encrypted by the private key of the requester to ensure the authenticity of the requester's identity, that is, the data producer has a public key corresponding to the data demander's DID, which can be used to decrypt the DID. When the decrypted DID matches and verifies correctly, the data producer can confirm that the identity of the data requester is legitimate. If the verification fails, it means that the request may be forged or unauthorized. If during the verification process, the data producer finds that the encrypted identity DID does not match the expected one, or cannot match the original DID after decryption, the verification will fail, and the data producer will reject the data request and will not allow the data user to access the data; if the verification passes, the data producer confirms the identity of the data demander, and the identity meets the requirements for accessing the data, and the data authorization approval will be carried out.

[0115] Furthermore, after data approval and authorization, a data sharing task will be created to enable data resources to be shared and circulated between data element producers and data element users.

[0116] S4. After the data element user obtains authorization, a data sharing task is created according to the data request, and the data sharing task is uploaded to the directory chain platform.

[0117] In an embodiment of the present invention, first, the producer needs to authorize data sharing. Authorization usually means that the access rights to the data are formally confirmed. After authorization, the user can legally request and use the producer's data. Between the producer and the user, the user will make a data request based on actual needs (for example, data of a certain period, data in a specific format, etc.), and after the data element user obtains authorization, both the data element user and the data element producer can create a data sharing task. The producer will actively create a data sharing task based on the user's data request and the existing authorization results. That is, once the data authorization is successful, the data element production will actively create a data sharing task based on the data request, that is, create a data sharing task based on the details such as the type of data required, the time range of the data, the format requirements, and the usage objectives specified in the data request.

[0118] Furthermore, when the producer creates a data sharing task, the data authorization result will be sent to the user. After obtaining the approval authorization of the data producer, the data element user obtains the specific content of the data resource by creating and triggering the data sharing task, and then creates a data sharing task according to the data demand. The data demand refers to the data element user's own demand for data. For example, the user may need sales data within a certain period of time, behavior data of a certain type of user, etc. The data sharing task includes task ID, data source, data target, data sharing content, sharing method, and access rights. For example, the task ID is task_1, the data source is data producer A, the data target is data requester B, the shared data content is sales data from January to June 2024, the access right is read-only, the sharing method is API interface access, and the authorization period is from xx / xx / 2024 to xx / xx / 2024.

[0119] In an embodiment of the present invention, after the sharing task is created, the data sharing task needs to be put on the chain. Putting the data sharing task on the chain means using blockchain technology to record the execution process and related information of the data sharing task into the blockchain, which can ensure the transparency, security, traceability and compliance of the data sharing task throughout its life cycle, reduce disputes, and ensure the non-tamperability and encryption protection of task data through blockchain technology, thereby increasing the security of data sharing. In addition, on the directory chain platform, the status, historical records, related metadata, etc. of all shared tasks can be tracked and managed, ensuring the transparency and controllability of the data sharing process.

[0120] Furthermore, according to the created data sharing task, the data requested by the data element user needs to be transmitted through the data gateway, and the data content is carried in the credential statement of the VC and transmitted through the data gateway.

[0121] S5. Trigger the data transmission conditions according to the data sharing task in the directory chain platform, send the data resources stored in the first local storage to the data element user through the preset data gateway and the data transmission conditions, and store the data resources sent to the data element user in the second local storage corresponding to the data element user.

[0122] In an embodiment of the present invention, as long as a data sharing task is created, the data transmission condition will be triggered, and the data transmission condition refers to monitoring the data sharing task, that is, monitoring the on-chain authorized sharing task of the data resource through the data gateway and executing the transmission of the data content. The data gateway only relies on the transmission task event on the blockchain network to trigger the execution of data transmission, and at the same time uses the DID public key to verify the signatures of the data producer and user on the chain.

[0123] Furthermore, since the data content is stored in files in the form of VC, such as COS storage, it is necessary to send the content to the data gateway of the data user through the data gateway of the data producer, and the data gateway of the user stores the received data in the local file storage.

[0124] In the embodiment of the present invention, the sending of the data resources stored in the first local storage to the data element user through the preset data gateway and the data transmission condition includes:

[0125] Read the data resources stored in the first local storage through the data gateway corresponding to the data element producer;

[0126] Encrypt the read data resources in the data gateway corresponding to the data element producer;

[0127] Execute data transmission according to the data transmission conditions, and when executing data transmission, send the encrypted data resource to the data gateway corresponding to the data element user;

[0128] The data resources sent to the data gateway are verified using the private key of the data element user. Once the verification is successful, the data resources sent to the data gateway are written to the second local storage.

[0129] In detail, before data transmission, in order to ensure the confidentiality and security of data transmission, the sender can use the public key of the receiver to perform an asymmetric encryption algorithm to encrypt the data, so that only the receiver with the corresponding private key can decrypt the data, that is, use the public key of the data element user to encrypt the data resources stored in the first local storage. Through public key encryption, it is ensured that even if the data is intercepted during the data transmission process, the data content is still encrypted and cannot be read by unauthorized third parties. After the data is encrypted, the data element producer reads the encrypted data resources through the data gateway, where the data gateway is required to be deployed in a data center close to the file storage to ensure that the data file content can be read and written efficiently. The data producer and user are not limited to using the same data gateway, and can also use the data gateway of their respective data centers.

[0130] Specifically, after the data is encrypted and accessed through the data gateway, the actual data transmission needs to be performed according to the agreed data transmission conditions. After the data is transmitted to the data gateway of the data element user, the receiving data gateway will use the private key of the data element user to verify the data, that is, check the legitimacy of the encrypted data to ensure that the data has not been tampered with during the transmission process. Once the data verification is passed, the data will be written to the second local storage, where the second local storage refers to the local storage address where the data (VC) credential received by the data element user is stored.

[0131] Furthermore, if the data content involves other DID identifiers, the user of the data elements can quickly parse the DID document through the DID off-chain parser to obtain the attribute information of the relevant data.

[0132] S6. Parse the DID identifier corresponding to the data resource in the second local storage, parse the DID document corresponding to the data resource in the second local storage in the data element producer according to the parsed DID identifier, and circulate the parsed DID document to the data element user.

[0133] In the embodiment of the present invention, when the data content involves other DID identifiers, it is necessary to resolve the corresponding DID identifier through the DID off-chain resolver, and then resolve the corresponding DID document according to the DID identifier. The DID off-chain resolver is responsible for uniformly resolving DID documents of different DID platforms (blockchain networks). DID documents of different platforms may be stored on different blockchain networks. For example, the VC content of the data producer involves the DID identifier of the relevant data, which may be registered on other blockchain networks. The DID resolver can provide a unified DID document parsing interface to the outside world without the requester having to connect to different DID platforms or blockchain networks separately. The implementation of the off-chain DID resolver follows the W3C Decentralized IdentifierResolution (DID Resolution) specification.

[0134] In an embodiment of the present invention, the DID document corresponding to the data resource in the second local storage in the data element producer is parsed according to the parsed DID identifier, including:

[0135] Identify the target DID document corresponding to the DID in the second local storage according to the parsed DID;

[0136] Receive a document parsing request corresponding to the target DID document using a preset DID off-chain parser;

[0137] The document attribute information corresponding to the target DID document is parsed according to the document parsing request.

[0138] In detail, each DID identifier corresponds to a DID document, which contains detailed identity and data resource attributes and public key information. The content and resolution request of the DID document can be processed by an off-chain resolver. Although the basic information of the DID document (such as public key, service endpoint, etc.) is usually stored on a decentralized network (such as a blockchain), the detailed content and attributes of the document may be stored in an off-chain system. The off-chain resolver is a tool responsible for parsing these off-chain storages. It can issue a resolution request to the target DID document and obtain and parse data from the relevant storage according to the resolution request. When the DID off-chain resolver receives a document resolution request, it will search for the target DID document and extract the required attributes based on the content of the request; for example, if the request is for public key information, the resolver will extract the public key field from the DID document; if the request is for service endpoint information, the service address defined in the DID document will be returned.

[0139] Specifically, the producers and users of data elements can quickly parse the other party's identity DID and the DID document identified by the DID in the data content through the DID off-chain parser. The signature verification can be performed through the DID public key information to verify the other party's identity and the VC publisher's signature, completing the data content confirmation process. The DID document mainly contains the DID identification character field id, the public key field publickey required for identity authentication, and the identity attribute fields defined by the business itself, such as billDidDetail. The fields can be expanded according to business needs.

[0140] Furthermore, the parsed DID document is transmitted to the data element user, thereby realizing the circulation of data elements between the data element user and the data element producer.

[0141] Furthermore, if Figure 4As shown in the figure, it is an interactive sequence diagram of the circulation of data elements. First, on the supply side, that is, the data element production direction DID platform registers the data DID, and stores the VC corresponding to the new data resource in the local storage, and then publishes the data element product catalog through the directory chain platform, and puts the product catalog on the chain. On the user side, that is, the data element user direction directory chain platform requests to view the data element catalog. If there is data to be obtained, the supply side is notified to review the data element. When the data element is authorized successfully, the directory chain platform notifies the user side that it has been authorized, and the user side creates and executes the data sharing task, and the data gateway listens to the chain. Once a data sharing task event is monitored, the data gateway obtains the VC file from the local storage and sends it from the local data gateway to the peer gateway. The data gateway on the user side will receive the VC file and store it in the local storage corresponding to the user side, parse the VC file, and use the data. If the VC file has other DID identifiers, the DID parser will parse the DID of the data content and parse the DID document to the DID platform on the supply side. The supply side will query the DID document in the blockchain network and return the queried DID document to the user side for the user side to use the data.

[0142] The embodiment of the present invention uses DID and VC to make unified data modeling for data element resources, which is compatible with various types of data, and the data resources have interoperability, so as to realize the unified circulation of different data elements; the whole process of data element release, application, authorization, and shared circulation is recorded in the blockchain account book, and based on the centralized and tamper-proof characteristics of the blockchain, the trust, auditability, and traceability of data circulation and sharing are realized; the trusted confirmation of the data element circulation process is separated from the shared transmission of data resources, so as to realize the trustworthiness of the sharing process while ensuring the efficiency, confidentiality, and security of data transmission; the data resource content supports the DID identification description of different platforms, and the DID document parsing of various types of data resources is unified through the off-chain DID parser, and the interconnection and interoperability in the closed-loop data element circulation system process. Therefore, the data element circulation method, device, equipment, and medium based on blockchain and DID proposed by the present invention can solve the problem of low security when circulating data elements.

[0143] like Figure 5 The figure shows a functional module diagram of a data element circulation device based on blockchain and DID provided by one embodiment of the present invention.

[0144] The data element circulation device 100 based on blockchain and DID of the present invention can be installed in an electronic device. According to the functions implemented, the data element circulation device 100 based on blockchain and DID can include a data format conversion module 101, a product catalog generation module 102, a data authorization module 103, a data sharing task creation module 104, a data resource transmission module 105 and a document parsing module 106. The module of the present invention can also be called a unit, which refers to a series of computer program segments that can be executed by an electronic device processor and can complete fixed functions, which are stored in the memory of the electronic device.

[0145] In this embodiment, the functions of each module / unit are as follows:

[0146] The data format conversion module 101 is used to extract the metadata data corresponding to the pre-acquired data resource, generate a DID identifier corresponding to the data resource according to a preset DID specification and the metadata data, and convert the data format of the data resource into a preset data format of the verification credential according to the DID identifier;

[0147] The product catalog generation module 102 is used to store the data resource in the first local storage corresponding to the data element producer according to the converted verification credential data format, import the data resource into a preset credential template, generate a product catalog, and store the product catalog in the catalog chain platform;

[0148] The data authorization module 103 is used to, when receiving a data request from a data element user for a product catalog stored in the catalog chain platform, authorize the data element user according to the data request;

[0149] The data sharing task creation module 104 is used to create a data sharing task according to the data request after the data element user obtains authorization, and upload the data sharing task to the directory chain platform;

[0150] The data resource transmission module 105 is used to trigger the data transmission condition according to the data sharing task in the target chain platform, send the data resources stored in the first local storage to the data element user through the preset data gateway and the data transmission condition, and store the data resources sent to the data element user in the second local storage corresponding to the data element user;

[0151] The document parsing module 106 is used to parse the DID identifier corresponding to the data resource in the second local storage, parse the DID document corresponding to the data resource in the second local storage of the data element producer according to the parsed DID identifier, and circulate the parsed DID document to the data element user.

[0152] In detail, each module described in the data element circulation device 100 based on blockchain and DID in the embodiment of the present invention is used in the same manner as described above. Figure 3 The data element circulation method based on blockchain and DID described in the article uses the same technical means and can produce the same technical effects, so I will not go into details here.

[0153] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 6 As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external client via a network connection. When the computer program is executed by the processor, it implements the functions or steps of a user information storage control method service side.

[0154] In one embodiment, a computer device is provided. The computer device may be a client, and its internal structure diagram may be as follows: Figure 7 As shown. The computer device includes a processor, a memory, a network interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external server through a network connection. When the computer program is executed by the processor, it realizes the functions or steps of the client side of a user information storage control method.

[0155] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the following steps when executing the computer program:

[0156] Extracting metadata corresponding to the pre-acquired data resource, generating a DID identifier corresponding to the data resource according to a preset DID specification and the metadata, and converting the data format of the data resource into a preset data format of the verification credential according to the DID identifier;

[0157] Store the data resource in the first local storage corresponding to the data element producer according to the converted verification credential data format, import the data resource into a preset credential template, generate a product catalog, and store the product catalog in the catalog chain platform;

[0158] When receiving a data request from a data element user for a product catalog stored in the catalog chain platform, performing data authorization on the data element user according to the data request;

[0159] After the data element user obtains authorization, a data sharing task is created according to the data request, and the data sharing task is uploaded to the directory chain platform;

[0160] According to the data sharing task in the target chain platform, the data resources stored in the first local storage are sent to the data element user through the preset data gateway and the data transmission conditions, and the data resources sent to the data element user are stored in the second local storage corresponding to the data element user;

[0161] Parse the DID identifier corresponding to the data resource in the second local storage, parse the DID document corresponding to the data resource in the second local storage of the data element producer according to the parsed DID identifier, and circulate the parsed DID document to the data element user.

[0162] In one embodiment, a computer readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:

[0163] Extracting metadata corresponding to the pre-acquired data resource, generating a DID identifier corresponding to the data resource according to a preset DID specification and the metadata, and converting the data format of the data resource into a preset data format of the verification credential according to the DID identifier;

[0164] Store the data resource in the first local storage corresponding to the data element producer according to the converted verification credential data format, import the data resource into a preset credential template, generate a product catalog, and store the product catalog in the catalog chain platform;

[0165] When receiving a data request from a data element user for a product catalog stored in the catalog chain platform, performing data authorization on the data element user according to the data request;

[0166] After the data element user obtains authorization, a data sharing task is created according to the data request, and the data sharing task is uploaded to the directory chain platform;

[0167] According to the data sharing task in the target chain platform, the data resources stored in the first local storage are sent to the data element user through the preset data gateway and the data transmission conditions, and the data resources sent to the data element user are stored in the second local storage corresponding to the data element user;

[0168] Parse the DID identifier corresponding to the data resource in the second local storage, parse the DID document corresponding to the data resource in the second local storage of the data element producer according to the parsed DID identifier, and circulate the parsed DID document to the data element user.

[0169] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or computer device can refer to the relevant descriptions on the server side and the client side in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.

[0170] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0171] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation.

[0172] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0173] In addition, each functional module in each embodiment of the present invention may be integrated into one processing unit, each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional modules.

[0174] It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0175] Therefore, no matter from which point of view, the embodiments should be regarded as illustrative and non-restrictive, and the scope of the present invention is not limited only according to the above description, and it is intended that all changes within the meaning and scope of equivalent elements within the scope of protection are included in the present invention.

[0176] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Among them, artificial intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.

[0177] In addition, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices stated in the system can also be implemented by one unit or device through software or hardware. The words first, second, etc. are used to indicate names, and do not indicate any particular order.

[0178] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention.

Claims

1. A data element circulation method based on blockchain and DID, characterized in that: The method comprises: Extracting metadata corresponding to the pre-acquired data resource, generating a DID identifier corresponding to the data resource according to a preset DID specification and the metadata, and converting the data format of the data resource into a preset data format of the verification credential according to the DID identifier; The data resource is stored in the first local storage corresponding to the data element producer according to the converted verification credential data format, the data resource is imported into a preset credential template, a product catalog is generated, and the product catalog is stored in the catalog chain platform; When receiving a data request from a data element user for a product catalog stored in the catalog chain platform, performing data authorization on the data element user according to the data request; After the data element user obtains authorization, a data sharing task is created according to the data request, and the data sharing task is uploaded to the directory chain platform; According to the data sharing task in the target chain platform, the data resources stored in the first local storage are sent to the data element user through the preset data gateway and the data transmission conditions, and the data resources sent to the data element user are stored in the second local storage corresponding to the data element user; Parse the DID identifier corresponding to the data resource in the second local storage, parse the DID document corresponding to the data resource in the second local storage of the data element producer according to the parsed DID identifier, and circulate the parsed DID document to the data element user.

2. The data element circulation method based on blockchain and DID as claimed in claim 1, characterized in that: The converting the data format of the data resource into a preset data format of the verification credential according to the DID identifier includes: Identify the target data element in the data resource according to the DID identifier; Extracting field data corresponding to the target data element according to the data format of the target data element; Extracting the credential field data corresponding to the verification credential according to the preset verification credential data format; Perform field attribute mapping on the field data and the voucher field data to obtain a field mapping relationship; The target data element corresponding to the field data is mapped to the credential field data through the field mapping relationship, and the data format of the data resource is converted into a preset data format of the verification credential according to the mapped field data.

3. The data element circulation method based on blockchain and DID as claimed in claim 1, characterized in that: The step of importing the data resource into a preset voucher template to generate a product catalogue includes: Extracting a target data field corresponding to the data resource; Mapping the target data field to the voucher subject field in a preset voucher template; Generates the product catalog by mapping the target data fields in the document body fields.

4. The data element circulation method based on blockchain and DID as claimed in claim 1, characterized in that: Before receiving a data request from a data element user for a product catalog stored in the catalog chain platform, the method further includes: Determining a data resource model according to the product catalog; According to the data resource demand of the data element user, query whether there is a target data resource corresponding to the data resource demand in the data resource model; When the target data resource exists in the data resource model, the data request is generated.

5. The data element circulation method based on blockchain and DID as claimed in claim 4, characterized in that: The step of authorizing the data element user according to the data request includes: Encrypt the data request using the private key of the data element user, and send the encrypted data request to the directory chain platform; Utilize the directory chain platform to parse the public key of the data element user in the identity DID identifier corresponding to the data element user; Using the public key to verify the encrypted data request in the target chain platform to obtain a verification result; When the verification result is verification failure, the data authorization of the data element user is rejected. When the verification result is verification success, the data element user is approved and authorized.

6. The data element circulation method based on blockchain and DID as claimed in claim 1, characterized in that: The sending of the data resource stored in the first local storage to the data element user through the preset data gateway and the data transmission condition includes: Read the data resources stored in the first local storage through the data gateway corresponding to the data element producer; Encrypt the read data resources in the data gateway corresponding to the data element producer; Execute data transmission according to the data transmission conditions, and when executing data transmission, send the encrypted data resource to the data gateway corresponding to the data element user; The data resources sent to the data gateway are verified using the private key of the data element user. Once the verification is successful, the data resources sent to the data gateway are written to the second local storage.

7. The data element circulation method based on blockchain and DID as claimed in claim 1, characterized in that: The step of parsing the DID document corresponding to the data resource in the second local storage in the data element producer according to the parsed DID identifier includes: Identify the target DID document corresponding to the DID in the second local storage according to the parsed DID; Receive a document parsing request corresponding to the target DID document using a preset DID off-chain parser; The document attribute information corresponding to the target DID document is parsed according to the document parsing request.

8. A data element circulation device based on blockchain and DID, characterized in that: The device comprises: A data format conversion module, used to extract metadata data corresponding to a pre-acquired data resource, generate a DID identifier corresponding to the data resource according to a preset DID specification and the metadata data, and convert the data format of the data resource into a preset data format of a verification credential according to the DID identifier; A product catalog generation module, used to store the data resource in the first local storage corresponding to the data element producer according to the converted verification credential data format, import the data resource into a preset credential template, generate a product catalog, and store the product catalog in the catalog chain platform; A data authorization module, for, upon receiving a data request from a data element user for a product catalog stored in the catalog chain platform, performing data authorization on the data element user according to the data request; A data sharing task creation module, used to create a data sharing task according to the data request after the data element user obtains authorization, and upload the data sharing task to the directory chain platform; A data resource transmission module, which is used to trigger the data transmission condition according to the data sharing task in the target chain platform, send the data resources stored in the first local storage to the data element user through the preset data gateway and the data transmission condition, and store the data resources sent to the data element user in the second local storage corresponding to the data element user; The document parsing module is used to parse the DID identifier corresponding to the data resource in the second local storage, parse the DID document corresponding to the data resource in the second local storage of the data element producer according to the parsed DID identifier, and circulate the parsed DID document to the data element user.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the data element circulation method based on blockchain and DID as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, the data element circulation method based on blockchain and DID is implemented as described in any one of claims 1 to 7.