Data acquisition method and device, computer equipment and medium

By using symmetric and asymmetric keys in the data management system to encrypt and decrypt key information, generate tokenized values ​​and associate them with stored data, the problem of waste and leakage of computing resources in hybrid data permission management is solved, and a safer and more efficient data acquisition process is achieved.

CN120180482APending Publication Date: 2025-06-20NETSUNION CLEARING CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311759271.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-20
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In hybrid data permission management, the identification of key information determined by the data management party causes the data generator and the data requester to require additional computing resources, and the risk of leakage is high because the key information is transmitted on the interactive channel.

Method used

By decrypting the decrypted information with the corresponding first symmetric key and asymmetric key of the requesting party identification, the key information plaintext information is determined, and the key information plaintext information is encrypted based on the generator identification, and the tokenized value is obtained. The tokenized value does not need to be transmitted on the interactive channel and is directly stored by the data manager in association with the stored data.

Benefits of technology

It reduces the computing resource consumption of data generators and data requesters, and reduces the risk of leaks in the transmission of key information on the interactive channel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180482A_ABST
    Figure CN120180482A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data management, in particular to a data acquisition method and device, computer equipment and a medium. The data acquisition method comprises the following steps: determining to-be-decrypted information from a received data acquisition request; decrypting the to-be-decrypted information by using a first symmetric key and an asymmetric key corresponding to the requester identifier, and determining key information plaintext information; determining a second symmetric key based on a generator identifier corresponding to the key information plaintext information; encrypting the plaintext information of the key information by using a second symmetric key to obtain a tagged value; and determining the storage data corresponding to the tokenized value as the to-be-sent data under the condition of determining that the requester identifier can access the tokenized value based on the generator identifier, the requester identifier and the tokenized value. Therefore, the requesting party and the generating party do not need to record the marked value, and the marked value cannot be transmitted on the interaction channel, so that the computing resources of the generating party and the requesting party are reduced, and the leakage risk is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the technical field of data management, and particularly to a data acquisition method, apparatus, computer device, and medium. Background Art

[0002] Currently, in hybrid data permission management, generally, the data management party determines the key information identifier of the data (the identifier used to index the corresponding stored data or requested data). In the case where the data management party determines the key information identifier of the data, the data generating party and the data requesting party need to determine the key information identifier corresponding to each service identifier, thus wasting the computing resources of both the data generating party and the data requesting party. In addition, when the stored data is generated by a first data generating party and used by a first data requesting party, it is difficult for the first data requesting party to obtain the generation primary key of the data. Moreover, when transmitting the key information corresponding to the key information identifier on the interaction channel, since the key information is highly confidential data, the risk of leakage is relatively high.

[0003] How to reduce the risk of leakage while reducing the computing resources of the data generating party and the data requesting party is an urgent problem to be solved in the prior art. Summary of the Invention

[0004] To solve the problems in the prior art, embodiments of this specification provide a data acquisition method, apparatus, computer device, and medium, which do not require the requester and the generator to record and save the tokenized value, and the tokenized value will not be transmitted on the interaction channel (the interaction channels between the generator and the data management party and between the requester and the data management party), thereby reducing the computing resources of the generator and the requester and reducing the risk of leakage.

[0005] To solve the above technical problems, the specific technical solutions of this specification are as follows:

[0006] On the one hand, embodiments of this specification provide a data acquisition method, including:

[0007] Determine the information to be decrypted from the received data acquisition request, where the data acquisition request further includes a requester identifier;

[0008] Use the first symmetric key and the asymmetric key corresponding to the requester identifier to decrypt the information to be decrypted, and determine the plaintext information of the key information;

[0009] Based on the generator identifier corresponding to the plaintext information of the key information, determine the second symmetric key;

[0010] Use the second symmetric key to encrypt the plaintext information of the key information to obtain a tokenized value; and

[0011] When it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value, determine the stored data corresponding to the tokenized value as the data to be sent.

[0012] Further, the decrypting the information to be decrypted by using the first symmetric key and the asymmetric key corresponding to the requester identifier to determine the plaintext information of the key information further includes:

[0013] Decrypt the information to be decrypted by using the private key included in the asymmetric key to determine the first decrypted data; and

[0014] Decrypt the first decrypted data by using the first symmetric key to determine the plaintext information of the key information.

[0015] Further, before determining the stored data corresponding to the tokenized value as the data to be sent when it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value, the method further includes,

[0016] Determine the data permission information associated with the producer identifier;

[0017] Based on the data permission information, determine the set of target tokenized values that the requester identifier can access;

[0018] Determine whether there is a target tokenized value in the set of target tokenized values that matches the tokenized value; and

[0019] When it is determined that there is the target tokenized value, determine that the requester identifier can access the tokenized value.

[0020] Further, the data permission information includes a target data source type and a tokenized value to be matched, and the determining the set of target tokenized values that the requester identifier can access based on the data permission information further includes,

[0021] Determine the accessible tokenized values associated with the target data source type;

[0022] Determine the requester identifier from the permitted requester identifiers respectively associated with the accessible tokenized value and the tokenized value to be matched; and

[0023] Based on the candidate tokenized values corresponding to the permitted requester identifier in the accessible tokenized value and the tokenized value to be matched, construct the set of target tokenized values.

[0024] Further, the generation of the data permission information further includes,

[0025] Based on the received data licensing request, determine the producer identifier, the licensee requestor identifier, and the specified key information plaintext information;

[0026] Use the second symmetric key corresponding to the producer identifier to encrypt the specified key information plaintext information to obtain a to-be-matched tokenized value; and

[0027] Add the to-be-matched tokenized value and the licensee requestor identifier to the data licensing information, and associate the data licensing information with the producer identifier.

[0028] Furthermore, the storage process of the stored data further includes,

[0029] Determine the producer identifier from the received data storage request, and the data storage request further includes the stored data;

[0030] Based on the stored data, determine the key information plaintext information corresponding to the key information identifier;

[0031] Use the second symmetric key corresponding to the producer identifier to encrypt the key information plaintext information to obtain the tokenized value; and

[0032] Associate and store the stored data with the tokenized value and the producer identifier.

[0033] Furthermore, the step of determining the key information plaintext information corresponding to the key information identifier based on the stored data further includes,

[0034] Determine the key information identifier according to the service identifier of the stored data; and

[0035] Determine the key information plaintext information corresponding to the key information identifier from the stored data.

[0036] Furthermore, the generation process of the to-be-decrypted information further includes,

[0037] Determine the key information plaintext information of the stored information requested to be accessed;

[0038] Use the first symmetric key to encrypt the key information plaintext information to determine candidate encrypted data; and

[0039] Use the public key included in the asymmetric key to encrypt the candidate encrypted data to obtain the to-be-decrypted information.

[0040] On the other hand, an embodiment of this specification also provides a data acquisition system, including a data producer, a data manager, and a data requestor,

[0041] The data generating party is used to send the stored data to the data managing party;

[0042] The data requesting party is used to, when requesting the stored data, encrypt the plaintext information of the key information corresponding to the stored data by using a first symmetric key and an asymmetric key pair to obtain the information to be decrypted; and send a data acquisition request including the information to be decrypted to the data managing party; and

[0043] The data managing party is used to receive the stored data; perform an encryption process on the plaintext information of the key information included in the stored data to obtain a tokenized value and associate and store the stored data with the tokenized value and the generating party identifier; be used to receive the data request sent by the data requesting party for the stored data; determine the information to be decrypted from the received data acquisition request, and the data acquisition request further includes a requester identifier; use the first symmetric key and the asymmetric key corresponding to the requester identifier to decrypt the information to be decrypted to determine the plaintext information of the key information; determine a second symmetric key based on the generating party identifier corresponding to the plaintext information of the key information; use the second symmetric key to encrypt the plaintext information of the key information to obtain a tokenized value; when it is determined that the requester identifier can access the tokenized value based on the generating party identifier, the requester identifier, and the tokenized value, determine the stored data corresponding to the tokenized value as the data to be sent; and send the data to be sent to the data requesting party.

[0044] On the other hand, an embodiment of the present specification further provides a data acquisition device, including,

[0045] A first determination unit, configured to determine the information to be decrypted from the received data acquisition request, where the data acquisition request further includes a requester identifier;

[0046] A decryption unit, configured to decrypt the information to be decrypted by using the first symmetric key and the asymmetric key corresponding to the requester identifier to determine the plaintext information of the key information;

[0047] A second determination unit, configured to determine a second symmetric key based on the generating party identifier corresponding to the plaintext information of the key information;

[0048] A first encryption unit, configured to encrypt the plaintext information of the key information by using the second symmetric key to obtain a tokenized value; and

[0049] A third determination unit, configured to determine the stored data corresponding to the tokenized value as the data to be sent when it is determined that the requester identifier can access the tokenized value based on the generating party identifier, the requester identifier, and the tokenized value.

[0050] Further, the device further includes

[0051] a fourth determination unit, configured to determine data permission information associated with the producer identifier;

[0052] a fifth determination unit, configured to determine a set of target tokenized values that the requester identifier can access based on the data permission information;

[0053] a judgment unit, configured to judge whether there is a target tokenized value in the set of target tokenized values that matches the tokenized value; and

[0054] a sixth determination unit, configured to determine that the requester identifier can access the tokenized value when it is determined that there is the target tokenized value.

[0055] Further, the device further includes

[0056] a seventh determination unit, configured to determine the producer identifier, the licensed requester identifier, and the specified key information plaintext information based on a received data permission request;

[0057] a second encryption unit, configured to encrypt the specified key information plaintext information by using the second symmetric key corresponding to the producer identifier to obtain a to-be-matched tokenized value; and

[0058] a permission adding unit, configured to add the to-be-matched tokenized value and the licensed requester identifier to the data permission information, and associate the data permission information with the producer identifier.

[0059] Further, the device further includes

[0060] an eighth determination unit, configured to determine the producer identifier from a received data storage request, and the data storage request further includes the stored data;

[0061] a ninth determination unit, configured to determine the key information plaintext information corresponding to the key information identifier based on the stored data;

[0062] a third encryption unit, configured to encrypt the key information plaintext information by using the second symmetric key corresponding to the producer identifier to obtain the tokenized value; and

[0063] an associated storage unit, configured to associate and store the stored data with the tokenized value and the producer identifier.

[0064] Further, the device further includes

[0065] a tenth determination unit, configured to determine the key information plaintext information of the stored information requested to be accessed;

[0066] A fourth encryption unit, configured to encrypt the plaintext information of the key information by using the first symmetric key to determine candidate encrypted data; and

[0067] A fifth encryption unit, configured to encrypt the candidate encrypted data by using the public key included in the asymmetric key to obtain the information to be decrypted.

[0068] On the other hand, an embodiment of this specification further provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above method is implemented.

[0069] On the other hand, an embodiment of this specification further provides a computer-readable storage medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the above method is implemented.

[0070] On the other hand, an embodiment of this specification further provides a computer program product, including a computer program / instructions. The method implemented when the computer program / instructions are executed by a processor.

[0071] Using the embodiment of this specification, after receiving a data acquisition request sent by a requester, the information to be decrypted is determined from the data acquisition request, and the information to be decrypted is decrypted twice by using a first symmetric key and an asymmetric key corresponding to the requester identifier included in the data acquisition request to determine the plaintext information of the key information; based on the producer identifier corresponding to the plaintext information of the key information, a second symmetric key is determined; the plaintext information of the key information is encrypted by using the second symmetric key to obtain a tokenized value; and when it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value, the stored data corresponding to the tokenized value is determined as the data to be sent. Thus, the tokenized value is used as the key information retained in the current system. This tokenized value does not need to be recorded and saved by the requester and the producer, and only the plaintext information of the key information (such as part of the data in the data to be sent) needs to be retained, thereby reducing the computing resources of the producer and the requester. In addition, since the tokenized value is not transmitted on the interaction channel, the risk of information leakage is reduced. Description of the Drawings

[0072] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0073] Figure 1The figure shows a schematic diagram of an implementation system of a data acquisition method according to an embodiment of this specification;

[0074] Figure 2 The figure shows a flowchart of a data acquisition method according to an embodiment of this specification;

[0075] Figure 3 The figure shows a flowchart of a method for determining clear text information of key information according to an embodiment of this specification;

[0076] Figure 4A The figure shows a flowchart of a method for verifying tokenized values according to an embodiment of this specification;

[0077] Figure 4B The figure shows a flowchart of a method for determining a set of target tokenized values according to an embodiment of this specification;

[0078] Figure 4C The figure shows a flowchart of a method for determining data permission information according to an embodiment of this specification;

[0079] Figure 5A The figure shows a schematic diagram of the principle of a method for storing data according to an embodiment of this specification;

[0080] Figure 5B The figure shows a flowchart of a method for determining clear text information of key information according to another embodiment of this specification;

[0081] Figure 6 The figure shows a flowchart of a method for determining information to be decrypted according to an embodiment of this specification;

[0082] Figure 7A The figure shows a schematic diagram of the structure of a data acquisition device according to an embodiment of this specification;

[0083] Figure 7B The figure shows a schematic diagram of the structure of a data acquisition device according to another embodiment of this specification;

[0084] Figure 7C The figure shows a schematic diagram of the structure of a data acquisition device according to another embodiment of this specification;

[0085] Figure 7D The figure shows a schematic diagram of the structure of a data acquisition device according to another embodiment of this specification;

[0086] Figure 7E The figure shows a schematic diagram of the structure of a data acquisition device according to another embodiment of this specification;

[0087] Figure 8 The figure shows a schematic diagram of the structure of a computer device according to an embodiment of this specification.

[0088]

Explanation of Reference Numerals

[0089] 101. Data producer

[0090] 102. Data manager

[0091] 103. Data requester

[0092] 710. First determination unit

[0093] 720. Decryption unit

[0094] 730. Second determination unit

[0095] 740. First encryption unit

[0096] 750. Third determination unit

[0097] 7410. Fourth determination unit

[0098] 7420. Fifth determination unit

[0099] 7430. Judgment unit

[0100] 7440. Sixth determination unit

[0101] 760. Seventh determination unit

[0102] 770. Second encryption unit

[0103] 780. Permission addition unit

[0104] 790. Eighth determination unit

[0105] 7110. Ninth determination unit

[0106] 7120. Third encryption unit

[0107] 7130. Associated storage unit

[0108] 711. Tenth determination unit

[0109] 712. Fourth encryption unit

[0110] 713. Fifth encryption unit

[0111] 802. Computer device

[0112] 804. Processing device

[0113] 806. Storage resource

[0114] 808. Driving mechanism

[0115] 810. Input / output module

[0116] 812. Input device;

[0117] 814. Output device;

[0118] 816. Presentation device;

[0119] 818. Graphical user interface;

[0120] 820. Network interface;

[0121] 822. Communication link;

[0122] 824. Communication bus. Detailed implementation manners

[0123] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.

[0124] It should be noted that the terms "first", "second", etc. in the description and claims of this specification and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this specification described here can be implemented in an order different from those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.

[0125] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.

[0126] Figure 1The following is a schematic diagram of an implementation system for a data acquisition method according to an embodiment of this specification, which may include: a data generation party 101, a data management party 102, and a data request party 103. The data generation party 101 communicates with the data management party 102, and the data management party 102 communicates with the data request party 103 via a network. The network may include a Local Area Network (LAN), a Wide Area Network (WAN), the Internet, or a combination thereof, and is connected to a website, a user device (such as a computing device), and a backend system. When the data generation party 101 wants to store stored data, the data generation party 101 sends the stored data to the data management party 102. It should be noted that the data generation party 101 may also obtain a key information identifier corresponding to the stored data from the data management party 102 by means of a request, and then use a second symmetric key to encrypt the key information plaintext information corresponding to the key information identifier included in the stored data to obtain a tokenized value, and send the tokenized value and the stored data to the data management party 102.

[0127] After receiving the stored data, the data management party 102 encrypts the key information plaintext information included in the stored data to obtain a tokenized value, and associates and stores the tokenized value with the stored data. For example, when the data management party 102 receives the tokenized value and the stored data, it associates and stores the tokenized value with the stored data. Encrypting the key information plaintext information included in the stored data to obtain a tokenized value and associating and storing the tokenized value with the stored data may specifically be: determining a generator identifier from the received data storage request, and the data storage request further includes stored data; based on the stored data, determining the key information plaintext information corresponding to the key information identifier; using a second symmetric key corresponding to the generator identifier to encrypt the key information plaintext information to obtain a tokenized value; and associating and storing the stored data with the tokenized value.

[0128] When the data request party 103 wants to obtain the above-mentioned stored data, it encrypts the key information plaintext information corresponding to the stored data using a first symmetric key and an asymmetric key to obtain information to be decrypted; and sends a data acquisition request including the information to be decrypted to the data management party 102.

[0129] After receiving the data acquisition request, the data management party 102 determines the information to be decrypted from the received data acquisition request, and the data acquisition request further includes a requester identifier; uses the first symmetric key and the asymmetric key corresponding to the requester identifier to decrypt the information to be decrypted to determine the plaintext information of the key information; determines the second symmetric key based on the producer identifier corresponding to the plaintext information of the key information; uses the second symmetric key to encrypt the plaintext information of the key information to obtain a tokenized value; determines the stored data corresponding to the tokenized value as the data to be sent when it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value; and sends the data to be sent to the data requester 103.

[0130] Optionally, the data management party 102 may be a node of a cloud computing system (not shown in the figure), or each data management party 102 may be a separate cloud computing system, including multiple computers interconnected by a network and operating as a distributed processing system.

[0131] In an alternative embodiment, the data producer 101 and the data requester 103 may include electronic devices such as, but not limited to, smartphones, acquisition devices, desktop computers, tablets, laptops, smart speakers, digital assistants, augmented reality (AR) / virtual reality (VR) devices, smart wearable devices, and other types of electronic devices. Optionally, the operating systems running on the electronic devices may include, but are not limited to, Android, IOS, Linux, Windows, etc.

[0132] In addition, it should be noted that Figure 1 What is shown is only an application environment provided in this specification. In actual applications, there may also be multiple data producers 101, multiple data management parties 102, and multiple data requesters 103, which are not limited in this specification.

[0133] As Figure 2 Shown is a flowchart of a data acquisition method according to an embodiment of this specification. The data acquisition process is described in this figure, but based on routine or non-creative labor, there may be more or fewer operation steps. The order of the steps listed in the embodiment is only one way among the execution orders of numerous steps and does not represent the only execution order. When the actual system or device product executes, it may execute in the order of the method shown in the embodiment or the figure, or execute in parallel. Specifically, as Figure 2 shown, the method may include:

[0134] S210, determine the information to be decrypted from the received data acquisition request, and the data acquisition request further includes a requester identifier;

[0135] S220, decrypt the information to be decrypted by using the first symmetric key and the asymmetric key corresponding to the requester identifier, and determine the plaintext information of the key information;

[0136] S230, determine the second symmetric key based on the producer identifier corresponding to the plaintext information of the key information;

[0137] S240, encrypt the plaintext information of the key information by using the second symmetric key to obtain a tokenized value;

[0138] S250, when it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value, determine the stored data corresponding to the tokenized value as the data to be sent.

[0139] Using the embodiments of this specification, after receiving a data acquisition request sent by a requester, determine the information to be decrypted from the data acquisition request, and decrypt the information to be decrypted twice by using the first symmetric key and the asymmetric key corresponding to the requester identifier included in the data acquisition request to determine the plaintext information of the key information; determine the second symmetric key based on the producer identifier corresponding to the plaintext information of the key information; encrypt the plaintext information of the key information by using the second symmetric key to obtain a tokenized value; and when it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value, determine the stored data corresponding to the tokenized value as the data to be sent. Thus, the tokenized value is used as the key information retained in the current system. This tokenized value does not need to be recorded and saved by the requester and the producer, and only the plaintext information of the key information (such as part of the data in the data to be sent) needs to be retained, thereby reducing the computing resources of the producer and the requester. In addition, since the tokenized value is not transmitted on the interaction channel, the risk of information leakage is reduced.

[0140] According to an embodiment of this specification, if a data requester wants to obtain the stored data generated by a data producer, it needs to send the information to be decrypted corresponding to the stored data to the data management party. The data acquisition request includes the information to be decrypted and the requester identifier. The information to be decrypted is the encrypted information obtained by encrypting the plaintext information of the key information corresponding to the stored data. The requester identifier is the unique identifying information characterizing the requester. After receiving the data acquisition request, the data management party determines the information to be decrypted and the requester identifier from the data acquisition request.

[0141] Steps 210 - 250 are operations performed by the data management party. Specifically, a symmetric key and an asymmetric key are pre-configured for each user terminal (data requester and data generator), and the symmetric key and asymmetric key configured for each user terminal may or may not be the same. This specification does not limit this. It should be noted that the data management party holds the private key of the asymmetric key and sends the public key of the asymmetric key to the user terminal. Both the data management party and the user terminal hold the symmetric key. It should be noted that the symmetric key and the asymmetric key can be any existing symmetric key and asymmetric key, and this specification does not limit this. Similarly, the specific encryption and decryption methods of the key are similar to the existing encryption and decryption methods, and this specification will not elaborate on this.

[0142] Determine the symmetric key corresponding to the requester identifier as the first symmetric key, and determine the asymmetric key corresponding to the requester identifier. Use the first symmetric key and the asymmetric key to decrypt the information to be decrypted to obtain the plaintext information of the key information. The plaintext information of the key information can be, for example, user identifiers and transaction identifiers, etc. Specifically, using the first symmetric key and the asymmetric key to decrypt the information to be decrypted can be using the first symmetric key and the private key of the asymmetric key to decrypt the information to be decrypted to obtain the plaintext information of the key information. Specifically, the decryption steps can be: first, decrypt the information to be decrypted with the first symmetric key to obtain candidate decryption information; then decrypt the candidate decryption information with the private key of the asymmetric key to obtain the plaintext information of the key information.

[0143] When storing data, the plaintext information of the key information of the stored data can be associated with the generator identifier of the generator of the stored data, or the stored data can be associated with the plaintext information of the key information and the generator identifier separately. In the case where the plaintext information of the key information is associated with the generator identifier, use the plaintext information of the key information to determine the corresponding generator identifier; in the case where the stored data is associated with the plaintext information of the key information and the generator identifier separately, use the plaintext information of the key information to determine the stored data, and then use the stored data to determine the corresponding generator identifier. Based on the determined generator identifier, determine the symmetric key associated with it as the second symmetric key.

[0144] Encrypt the plaintext information of the key information with the second symmetric key to obtain a tokenized value. In advance, the data generator can perform access configuration for the stored data. For example, configure which data requesters can query and download this stored data. Specifically, corresponding conditions, accessible time, accessible times, and accessible data volume and other information can be configured during the configuration.

[0145] Determine whether the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value. In the case where it is determined that the current requester identifier can access the tokenized value, determine the stored data associated therewith based on the tokenized value, and use the stored data as the data to be sent. For example, after determining the data to be sent, the data to be sent can also be sent to the data requester.

[0146] Figure 3 The figure shows a flowchart of a method for determining plaintext information of key information according to an embodiment of the present specification. A process for determining plaintext information of key information is described in this figure, but based on routine or non-creative labor, it may include more or fewer operation steps. Specifically, as Figure 3 shown, the method may include:

[0147] S321, decrypt the information to be decrypted using the private key included in the asymmetric key to determine the first decrypted data;

[0148] S322, decrypt the first decrypted data using the first symmetric key to determine the plaintext information of the key information.

[0149] According to another embodiment of the present specification, the asymmetric key may be, for example, a key generated based on encryption algorithms such as the RSA algorithm, the elliptic curve cryptography algorithm (ECC), and the digital signature algorithm (DSA). The symmetric key may be, for example, a key generated based on encryption algorithms such as the data encryption standard (DES), the international data encryption algorithm (IDEA), and the advanced encryption standard (AES).

[0150] Perform the first decryption on the information to be decrypted using the private key included in the asymmetric key to obtain the first decrypted data; then perform the second decryption on the first decrypted data using the first symmetric key to obtain the plaintext information of the key information. Specifically, the decryption process is similar to the existing decryption process, and the present specification will not elaborate on this. Since asymmetric encryption is more secure than symmetric encryption, the encrypted information obtained by first using symmetric encryption and then using asymmetric encryption is more secure than the encrypted information obtained by first using asymmetric encryption and then using symmetric encryption.

[0151] Figure 4A The figure shows a flowchart of a method for verifying a tokenized value according to an embodiment of the present specification. A process for verifying a tokenized value is described in this figure, but based on routine or non-creative labor, it may include more or fewer operation steps. Specifically, as Figure 4A shown, the method may include:

[0152] S4401, determine the data permission information associated with the producer identifier;

[0153] S4402. Based on the data permission information, determine the set of target tokenized values that the requester identifier can access;

[0154] S4403. Determine whether there is a target tokenized value in the set of target tokenized values that matches the tokenized value;

[0155] S4404. When it is determined that there is a target tokenized value, determine that the requester identifier can access the tokenized value;

[0156] S4405. When it is determined that there is no target tokenized value, determine that the requester identifier cannot access the tokenized value.

[0157] According to another embodiment of this specification, before determining the stored data corresponding to the tokenized value as the data to be sent when it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value, the above steps 4401 - 4405 are executed by the data management party.

[0158] The data permission information can, for example, include the stored data representing the permission of the data producer and the permission information of the corresponding data requester. Based on the producer identifier, determine the associated data permission information.

[0159] In the data permission information, determine the associated requester identifier that is consistent with the current requester identifier; use the permitted tokenized value associated with the associated requester identifier (i.e., the tokenized value that the data producer permits the data requester to access) as the target tokenized value, and use the set composed of the determined multiple target tokenized values as the target tokenized set. Determine whether there is a target tokenized value in the target tokenized set that matches the tokenized value. If there is such a target tokenized value, determine that the requester identifier can access the tokenized value. If there is no such target tokenized value, determine that the requester identifier cannot access the tokenized value.

[0160] Specifically, determining whether there is a target tokenized value in the target tokenized set that matches the tokenized value can be to calculate the similarity between each permitted tokenized value in the target tokenized set and the tokenized value; and determine the permitted tokenized value corresponding to the similarity that is greater than or equal to the preset threshold as the target tokenized value. Thus, it is determined that there is a target tokenized value in the target tokenized set that matches the tokenized value. Otherwise, it is determined that there is no target tokenized value that matches the tokenized value. The preset threshold can, for example, be 1, that is, the above matching process is a consistency matching process.

[0161] Figure 4BThe figure below is a flowchart of a method for determining a set of target tokenized values according to an embodiment of this specification. A process for determining a set of target tokenized values is described in this figure, but it may include more or fewer operation steps based on routine or non-creative labor. Specifically, as Figure 4B shown, the method may include:

[0162] S4021, determine accessible tokenized values associated with the target data source type;

[0163] S4022, determine the requester identifier from the licensed requester identifiers respectively associated with the accessible tokenized values and the tokenized values to be matched;

[0164] S4023, construct a set of target tokenized values based on the candidate tokenized values corresponding to the licensed requester identifier in the accessible tokenized values and the tokenized values to be matched.

[0165] According to another embodiment of this specification, the data licensing information may, for example, include the target data source type and the tokenized values to be matched.

[0166] The data source type is, for example, the type of channel interface used by the data producer when rewriting and storing data. For example, one or more data interfaces connected to the data management party are configured for each user terminal, and each data interface corresponds to a data source type.

[0167] When configuring the data licensing information, the data producer may configure the licensed requester identifier for each piece of stored data, or may configure the licensed requester identifier for each data source type.

[0168] In the case where it is determined that the data licensing information includes the target data source type, determine the tokenized values of all stored data written from the target data source corresponding to the target data source type as the accessible tokenized values. Then, the tokenized values to be matched included in the data licensing information and the accessible tokenized values constitute all the tokenized values licensed by the data producer.

[0169] Since each tokenized value is configured with a corresponding licensed requester identifier, the licensed requester identifiers and the requester identifier corresponding to the tokenized values to be matched and the accessible tokenized values are respectively subjected to consistency matching, and the tokenized values to be matched and the accessible tokenized values corresponding to the requester identifier are respectively determined as candidate tokenized values, and the candidate tokenized values are summarized to obtain the set of target tokenized values, so as to be matched with the tokenized values generated based on the information to be decrypted to determine whether the requester identifier can access the tokenized value.

[0170] Figure 4CThe flowchart of a method for determining data permission information according to an embodiment of this specification is shown. A process for determining data permission information is described in this figure, but it may include more or fewer operation steps based on routine or non-creative labor. Specifically, as Figure 4C shown, the method may include:

[0171] S4011, based on the received data permission request, determine the producer identifier, the licensee requestor identifier, and the specified key information plaintext information;

[0172] S4012, use the second symmetric key corresponding to the producer identifier to encrypt the specified key information plaintext information to obtain the to-be-matched tokenized value;

[0173] S4013, add the to-be-matched tokenized value and the licensee requestor identifier to the data permission information, and associate the data permission information with the producer identifier.

[0174] According to another embodiment of this specification, when a data producer needs to grant permission for a stored data, it sends a data permission request including the producer identifier, the licensee requestor identifier, and the specified key information plaintext information corresponding to the stored data to the data management party.

[0175] After receiving the data permission request, the data management party determines the producer identifier, the licensee requestor identifier, and the specified key information plaintext information based on the data permission request. Based on the producer identifier, it determines the associated second symmetric key. It uses the second symmetric key to encrypt the specified key information plaintext data to obtain the to-be-matched tokenized value. Then it adds the to-be-matched tokenized value and the licensee requestor identifier to the data permission information, and associates the data permission information with the producer identifier. It should be noted that the data permission information may also include information such as the conditions for data access, the accessible time, the number of accessible times, and the amount of accessible data, which are not limited in this specification.

[0176] Figure 5A The schematic diagram of a method for storing data according to an embodiment of this specification is shown. A process for storing data is described in this figure, but it may include more or fewer operation steps based on routine or non-creative labor. Specifically, as Figure 5A shown, the method may include:

[0177] S5010, determine the producer identifier from the received data storage request, and the data storage request further includes the stored data;

[0178] S5020, based on the stored data, determine the key information plaintext information corresponding to the key information identifier;

[0179] S5030, encrypt the plaintext information of the key information using the second symmetric key corresponding to the producer identifier to obtain a tokenized value;

[0180] S5040, associate and store the stored data with the tokenized value and the producer identifier.

[0181] According to another embodiment of this specification, when the data producer needs to store the stored data, the producer identifier and the stored data are sent as a data storage request to the data management party.

[0182] After receiving the data storage request, the data management party performs the above operations 5010 - 5040. Specifically, determine the producer identifier and the stored data from the data storage request. Based on the stored data, determine the corresponding key information identifier. This key information identifier can, for example, represent the unique identifying information of the key information plaintext information. Specifically, the key information identifier can, for example, be a user identifier (ID), and the key information plaintext information is the specific user identifier (specific data or information) corresponding to the user. Based on this key information identifier, determine the corresponding key information plaintext information from the stored data.

[0183] Based on the producer identifier, determine the corresponding second symmetric key; use this second symmetric key to encrypt the key information plaintext information to obtain a tokenized value. Furthermore, store the tokenized value and the stored data in association, and store the stored data and the producer identifier in association.

[0184] Figure 5B The following shows a flowchart of a method for determining key information plaintext information according to another embodiment of this specification. In this figure, a process for determining key information plaintext information is described, but based on routine or non - creative labor, it may include more or fewer operation steps. Specifically, as Figure 5B shown, the method may include:

[0185] S5201, determine the key information identifier according to the service identifier of the stored data;

[0186] S5202, determine the key information plaintext information corresponding to the key information identifier from the stored data.

[0187] According to another embodiment of this specification, each stored data has a corresponding service identifier, and this service identifier can, for example, be the unique identifying information of the service that generates the stored data. Pre - configure the pre - stored key information identifier corresponding to each service identifier.

[0188] Based on the stored data, determine the corresponding business information; and then, based on this business information, determine the corresponding key information identifier. Determining the corresponding business information based on the stored data can be, for example, determined by any method that can currently determine the identifier of the business that generated the data based on the data, such as a neural network algorithm, etc., which will not be elaborated in this specification.

[0189] After determining the key information identifier, from the stored data, determine the information corresponding to the key information identifier, and use this information as the key information plaintext. Specifically, the key information identifier can be matched with the identifier corresponding to each piece of data in the stored data for consistency, determine the target identifier that is consistently matched with the key information identifier, and use the data corresponding to the target identifier as the key information plaintext.

[0190] Figure 6 The flowchart of a method for determining information to be decrypted according to an embodiment of this specification is shown. A process for determining information to be decrypted is described in this figure, but based on routine or non-creative labor, it may include more or fewer operation steps. Specifically, such as Figure 6 As shown, the method may include:

[0191] S6011, determine the key information plaintext of the stored information requested to be accessed;

[0192] S6012, encrypt the key information plaintext using the first symmetric key to determine the candidate encrypted data;

[0193] S6013, encrypt the candidate encrypted data using the public key included in the asymmetric key to obtain the information to be decrypted.

[0194] According to another embodiment of this specification, after the data requester sends a data acquisition request, the process of generating the information to be decrypted is as shown in steps 6011 - 6013.

[0195] Specifically, determine the key information plaintext of the stored information that needs to be accessed. The data requester pre-determines the key information identifier corresponding to each stored information, and based on this key information identifier, the corresponding key information plaintext can be determined. Use the first symmetric key stored by the data requester to perform the first encryption on this key information plaintext to obtain the candidate encrypted data; and then use the public key included in the asymmetric key stored by the data requester to perform the second encryption on the candidate encrypted data to obtain the information to be decrypted. Then, send the information to be decrypted and the requester identifier as a data acquisition request to the data management party.

[0196] Figure 7A The structural schematic diagram of a data acquisition device according to an embodiment of this specification is shown. As Figure 7A shown, it includes

[0197] The first determination unit 710 is configured to determine the information to be decrypted from the received data acquisition request, and the data acquisition request further includes a requester identifier;

[0198] The decryption unit 720 is configured to decrypt the information to be decrypted by using the first symmetric key and the asymmetric key corresponding to the requester identifier, and determine the plaintext information of the key information;

[0199] The second determination unit 730 is configured to determine the second symmetric key based on the producer identifier corresponding to the plaintext information of the key information;

[0200] The first encryption unit 740 is configured to encrypt the plaintext information of the key information by using the second symmetric key to obtain a tokenized value; and

[0201] The third determination unit 750 is configured to determine the stored data corresponding to the tokenized value as the data to be sent when it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value.

[0202] Since the principle of the above device for solving problems is similar to that of the above method, the implementation of the above device can refer to the implementation of the above method, and the repeated parts will not be described again.

[0203] Figure 7B The following shows a schematic structural diagram of a data acquisition device according to another embodiment of the present specification. As Figure 7B shown, it includes

[0204] The fourth determination unit 7410 is configured to determine the data permission information associated with the producer identifier;

[0205] The fifth determination unit 7420 is configured to determine the set of target tokenized values that the requester identifier can access based on the data permission information;

[0206] The judgment unit 7430 is configured to judge whether there is a target tokenized value in the set of target tokenized values that matches the tokenized value; and

[0207] The sixth determination unit 7440 is configured to determine that the requester identifier can access the tokenized value when it is determined that there is a target tokenized value.

[0208] Since the principle of the above device for solving problems is similar to that of the above method, the implementation of the above device can refer to the implementation of the above method, and the repeated parts will not be described again.

[0209] Figure 7C The following shows a schematic structural diagram of a data acquisition device according to another embodiment of the present specification. As Figure 7C shown, it includes

[0210] A seventh determination unit 760, configured to determine a producer identifier, a licensee requestor identifier, and specified plaintext information of key information based on a received data license request;

[0211] A second encryption unit 770, configured to encrypt the specified plaintext information of key information by using a second symmetric key corresponding to the producer identifier to obtain a to-be-matched tokenized value; and

[0212] A license addition unit 780, configured to add the to-be-matched tokenized value and a target requestor identifier to data license information, and associate the data license information with the producer identifier.

[0213] Since the principle of the above device for solving problems is similar to that of the above method, the implementation of the above device can refer to the implementation of the above method, and the repeated parts will not be described again.

[0214] Figure 7D The following shows a schematic structural diagram of a data acquisition device according to another embodiment of this specification. As Figure 7D shown, it includes

[0215] An eighth determination unit 790, configured to determine a producer identifier from a received data storage request, where the data storage request further includes stored data;

[0216] A ninth determination unit 7110, configured to determine plaintext information of key information corresponding to a key information identifier based on the stored data;

[0217] A third encryption unit 7120, configured to encrypt the plaintext information of key information by using a second symmetric key corresponding to the producer identifier to obtain a tokenized value; and

[0218] An associated storage unit 7130, configured to store the stored data in an associated manner with the tokenized value and the producer identifier.

[0219] Since the principle of the above device for solving problems is similar to that of the above method, the implementation of the above device can refer to the implementation of the above method, and the repeated parts will not be described again.

[0220] Figure 7E The following shows a schematic structural diagram of a data acquisition device according to another embodiment of this specification. As Figure 7E shown, it includes

[0221] A tenth determination unit 711, configured to determine plaintext information of key information of stored information requested to be accessed;

[0222] A fourth encryption unit 712, configured to encrypt the plaintext information of key information by using a first symmetric key to determine candidate encrypted data; and

[0223] A fifth encryption unit 713 is configured to encrypt candidate encrypted data by using a public key included in an asymmetric key to obtain information to be decrypted.

[0224] Since the principle of the above device for solving the problem is similar to that of the above method, the implementation of the above device can refer to the implementation of the above method, and the repeated parts will not be described again.

[0225] As Figure 8 shown in the structural schematic diagram of a computer device according to an embodiment of the present specification, the device in the present specification may be the computer device in this embodiment, and execute the method in the present specification. The computer device 802 may include one or more processing devices 804, such as one or more central processing units (CPUs), and each processing unit may implement one or more hardware threads. The computer device 802 may further include any storage resource 806 for storing any type of information such as code, settings, data, etc. Non-limiting, for example, the storage resource 806 may include any one or more combinations of the following: any type of RAM, any type of ROM, flash memory devices, hard disks, optical discs, etc. More generally, any storage resource may use any technology to store information. Further, any storage resource may provide volatile or non-volatile retention of information. Further, any storage resource may represent a fixed or removable component of the computer device 702. In one case, when the processing device 804 executes the associated instructions stored in any storage resource or combination of storage resources, the computer device 802 may perform any operation of the associated instructions. The computer device 802 further includes one or more drive mechanisms 808 for interacting with any storage resource, such as a hard disk drive mechanism, an optical disc drive mechanism, etc.

[0226] The computer device 802 may further include an input / output module 810 (I / O) for receiving various inputs (via the input device 812) and for providing various outputs (via the output device 814). A specific output mechanism may include a presentation device 816 and an associated graphical user interface (GUI) 818. In other embodiments, the input / output module 810 (I / O), the input device 812, and the output device 814 may not be included, and it is only a computer device in the network. The computer device 802 may further include one or more network interfaces 820 for exchanging data with other devices via one or more communication links 822. One or more communication buses 824 couple the components described above together.

[0227] The communication link 822 can be implemented in any manner, for example, through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication link 822 can include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc. governed by any protocol or combination of protocols.

[0228] The embodiments of this specification also provide a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above method is implemented.

[0229] The embodiments of this specification also provide a computer program product including a computer program, and when the computer program is executed by a processor, the above method is implemented.

[0230] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0231] This specification is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of this specification. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0232] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0233] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the steps for realizing the functions specified in one process or a plurality of processes and / or blocks Figure 1 one process or a plurality of processes and / or blocks Figure 1 steps for realizing the functions specified in one block or a plurality of blocks.

[0234] In the above specific embodiments, the objectives, technical solutions and beneficial effects of this specification have been further described in detail. It should be understood that the above are only specific embodiments of this specification and are not used to limit the protection scope of this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this specification shall be included in the protection scope of this specification.

Claims

1. A data acquisition method, characterized in that, Including: Determine the information to be decrypted from the received data acquisition request, where the data acquisition request further includes a requester identifier; Use a first symmetric key and an asymmetric key corresponding to the requester identifier to decrypt the information to be decrypted, and determine the plaintext information of the key information; Based on the producer identifier corresponding to the plaintext information of the key information, determine a second symmetric key; Use the second symmetric key to encrypt the plaintext information of the key information to obtain a tokenized value; And When it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value, determine the stored data corresponding to the tokenized value as the data to be sent.

2. The method according to claim 1, characterized in that, The using a first symmetric key and an asymmetric key corresponding to the requester identifier to decrypt the information to be decrypted and determine the plaintext information of the key information includes: Use the private key included in the asymmetric key to decrypt the information to be decrypted to determine a first decrypted data; and Use the first symmetric key to decrypt the first decrypted data to determine the plaintext information of the key information.

3. The method according to claim 1, characterized in that, Before determining the stored data corresponding to the tokenized value as the data to be sent when it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value, it further includes: Determine the data permission information associated with the producer identifier; Based on the data permission information, determine a set of target tokenized values that the requester identifier can access; Determine whether there is a target tokenized value in the set of target tokenized values that matches the tokenized value; and When it is determined that there is the target tokenized value, determine that the requester identifier can access the tokenized value.

4. The method according to claim 3, characterized in that, The data permission information includes a target data source type and a tokenized value to be matched. The determining a set of target tokenized values that the requester identifier can access based on the data permission information includes: Determine the accessible tokenized values associated with the target data source type; Determine the requester identifier from the permitted requester identifiers respectively associated with the accessible tokenized value and the tokenized value to be matched; and Based on the candidate tokenized values corresponding to the permitted requester identifier in the accessible tokenized value and the tokenized value to be matched, construct the set of target tokenized values.

5. The method according to claim 3, characterized in that, The generation of the data permission information includes: Based on the received data permission request, determine the producer identifier, the permitted requester identifier, and the specified plaintext information of the key information; Use the second symmetric key corresponding to the producer identifier to encrypt the specified plaintext information of the key information to obtain a tokenized value to be matched; and Add the tokenized value to be matched and the permitted requester identifier to the data permission information, and associate the data permission information with the producer identifier.

6. The method according to claim 1, characterized in that, The storage process of the stored data includes: Determine the producer identifier from the received data storage request, where the data storage request further includes the stored data; Determine the plaintext information of the key information corresponding to the key information identifier based on the stored data; Encrypt the plaintext information of the key information using the second symmetric key corresponding to the producer identifier to obtain the tokenized value; and Associate and store the stored data with the tokenized value and the producer identifier.

7. The method according to claim 6, characterized in that, The determining the plaintext information of the key information corresponding to the key information identifier based on the stored data includes: Determine the key information identifier according to the service identifier of the stored data; and Determine the plaintext information of the key information corresponding to the key information identifier from the stored data.

8. The method according to claim 1, characterized in that, The generation process of the information to be decrypted includes: Determine the plaintext information of the key information of the stored information requested to be accessed; Encrypt the plaintext information of the key information using the first symmetric key to determine candidate encrypted data; and Encrypt the candidate encrypted data using the public key included in the asymmetric key to obtain the information to be decrypted.

9. A data acquisition system, characterized in that, Including a data producer, a data manager, and a data requester, The data producer is used to send the stored data to the data manager; The data requester is used to, when requesting the stored data, encrypt the plaintext information of the key information corresponding to the stored data using the first symmetric key and the asymmetric key to obtain the information to be decrypted; and send a data acquisition request including the information to be decrypted to the data manager; And The data manager is used to receive the stored data; perform encryption processing on the plaintext information of the key information included in the stored data to obtain a tokenized value and associate and store the stored data with the tokenized value and the producer identifier; Used to receive the data request sent by the data requester for the stored data; determine the information to be decrypted from the received data acquisition request, and the data acquisition request further includes a requester identifier; use the first symmetric key and the asymmetric key corresponding to the requester identifier to decrypt the information to be decrypted to determine the plaintext information of the key information; determine the second symmetric key based on the producer identifier corresponding to the plaintext information of the key information; Encrypt the plaintext information of the key information using the second symmetric key to obtain a tokenized value; when it is determined that the requester identifier can access the tokenized value based on the producer identifier, the requester identifier, and the tokenized value, determine the stored data corresponding to the tokenized value as the data to be sent; And send the data to be sent to the data requester.

10. A data acquisition device, characterized in that, Including: A first determination unit, configured to determine the information to be decrypted from the received data acquisition request, and the data acquisition request further includes a requester identifier; A decryption unit, configured to decrypt the information to be decrypted using the first symmetric key and the asymmetric key corresponding to the requester identifier to determine the plaintext information of the key information; A second determination unit, configured to determine the second symmetric key based on the producer identifier corresponding to the plaintext information of the key information; A first encryption unit, configured to encrypt the plaintext information of the key information using the second symmetric key to obtain a tokenized value; And A third determination unit, configured to determine the stored data corresponding to the tokenized value as the data to be sent when it is determined, based on the producer identifier, the requester identifier, and the tokenized value, that the requester identifier can access the tokenized value.

11. A computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the method according to any one of claims 1-8 above is implemented.

12. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is run by a processor, the method according to any one of claims 1-8 above is executed.

13. A computer program product, including a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, the method according to any one of claims 1-8 is implemented.