Data cross-domain sharing method and device, medium and equipment

By defining the credential declaration structure and smart contract verification, the identity and permission issues in cross-domain medical data sharing are solved, safe and efficient data resource sharing is achieved, and legal access and privacy protection of medical data is supported.

CN120358048APending Publication Date: 2025-07-22INSPUR ENTERPRISE CLOUD TECHNOLOGY (SHANDONG) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510414675.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

How to achieve reliable sharing of medical data in cross-domain scenarios such as hospitals and research institutions to improve patient visit efficiency, reduce medical expenses and promote the rapid development of medical research.

Method used

Cross-domain data access control is achieved by defining and storing credential declaration structures, generating data holding credentials and usage credentials, and using smart contracts for authentication and permission evaluation.

Benefits of technology

Achieve safe, efficient and convenient data resource sharing in a multi-domain environment to ensure legal access to medical data and privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358048A_ABST
    Figure CN120358048A_ABST
Patent Text Reader

Abstract

The invention provides a data cross-domain sharing method and device, a medium and equipment. The method comprises the steps of defining and storing a corresponding voucher declaration structure when a declaration structure creation request is received; when a resource publishing request initiated by a data publisher is received, a data holding voucher is formed, and the data holding voucher and resources are stored; when a resource authorization request initiated by a data holder is received, generating a data use voucher, and storing the data use voucher; and when a resource access request initiated by the data user of the source domain is received, verifying the identity of the data user, verifying the validity of the data use certificate after the identity verification is passed, and returning the corresponding resource to the data user after the validity verification is passed. It can be seen that when the data user accesses the resources in a cross-domain mode, the identity and authority of the data user need to be identified, the intelligent contract automatically executes the identity verification and authority evaluation process, and safe, efficient and convenient resource sharing can be achieved in the multi-domain environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data sharing, and in particular to a method and device, medium, and equipment for cross-domain data sharing. Background Art

[0002] With the application of various intelligent medical devices in the medical industry, a large amount of diverse medical data has been generated. How to perform reliable medical data sharing in cross-domain scenarios such as between hospitals and between hospitals and research institutions has become an urgent problem to be solved, which can improve the efficiency of patient visits, reduce medical expenses, and is also conducive to promoting the rapid development of medical research. Summary of the Invention

[0003] In view of the above at least one technical problem, embodiments of the present invention provide a method and device, medium, and equipment for cross-domain data sharing.

[0004] According to a first aspect, the cross-domain data sharing method provided by the embodiments of the present invention is executed by a sharing service system, and the method includes:

[0005] When a claim structure creation request is received, define and store a corresponding claim structure;

[0006] When a resource publishing request initiated by a data publisher is received, retrieve the corresponding claim structure, so that the data publisher fills in data resource information in the retrieved claim structure, generate a data holding certificate according to the claim structure filled with data resource information, and store the data holding certificate and the resource corresponding to the data resource information;

[0007] When a resource authorization request initiated by a data holder is received, retrieve the corresponding claim structure, so that the data holder fills in data resource information and data user information for granting authorization in the retrieved claim structure, generate a data usage certificate according to the claim structure filled with data resource information and data user information, and store the data usage certificate;

[0008] When a resource access request initiated by a data user in the source domain is received, verify the identity of the data user, and after the identity verification passes, obtain the data usage certificate of the data user, verify the validity of the data usage certificate, and after the validity verification passes, return the resource corresponding to the data resource information in the data usage certificate in the target domain to the data user.

[0009] In one embodiment, before defining and storing the corresponding claim structure when a claim structure creation request is received, the method further includes:

[0010] When a registration request is received, the entity identity information in the registration request is obtained so that the upper-level administrator can review the entity identity information; after the review is passed, the summary of the entity identity information is calculated, the summary is signed, and a distributed identity identifier corresponding to the entity is generated by calling a smart contract, and the distributed identity identifier is written into the blockchain; wherein, the entities include domain administrators, individual users and devices; the upper-level administrator of the domain administrator is the alliance administrator, and the upper-level administrators of the individual users and the devices are the domain administrators.

[0011] In one embodiment, the claim structure creation request includes: a distributed identity and signature of a domain administrator who initiates the claim structure creation request, and a predefined credential claim structure;

[0012] Correspondingly, upon receiving a claim structure creation request, defining and storing a corresponding credential claim structure includes:

[0013] When receiving the claim structure creation request, extracting the distributed identity and signature of the domain administrator from the claim structure creation request;

[0014] Authenticate the distributed identity and verify the signature by calling a smart contract;

[0015] After the identity authentication and signature verification are passed, the predefined credential declaration structure is written into the blockchain, and a corresponding unique ID is generated for the credential declaration structure.

[0016] In one embodiment, generating a data holding credential according to the credential declaration structure filled in the data resource information, and storing the data holding credential and the resources corresponding to the data resource information, includes:

[0017] Verify the signature of the data publisher by calling the smart contract;

[0018] After passing the verification, the data holding certificate is generated according to the certificate declaration structure filled in the data resource information;

[0019] The data holding certificate and the resources corresponding to the data resource information are stored in the domain registration center, a data release log is generated, and the data release log is recorded in the blockchain.

[0020] In one embodiment, generating a data usage credential based on a credential declaration structure filled with data resource information and data user information, and storing the data usage credential includes:

[0021] By calling the smart contract, the signature and data holding certificate of the data holder are verified;

[0022] After passing the verification, a data usage certificate is generated according to the voucher declaration structure for filling in data resource information and user information.

[0023] The data usage certificate is stored in a public registry or a domain registry, a resource authorization log is generated, the resource authorization log is stored in the blockchain, and the ID of the data usage certificate is returned to the data user.

[0024] In one embodiment, when receiving a resource access request initiated by a data user in the source domain, the identity of the data user is verified, and after the identity verification passes, the data usage certificate of the data user is obtained, and the validity of the data usage certificate is verified. After the validity verification passes, the corresponding resource in the target domain of the data resource information in the data usage certificate is returned to the data user, including:

[0025] When receiving a resource access request initiated by a data user in the source domain for a resource in the target domain, the ID of the data usage certificate, the signature of the data user, and the distributed identity identifier of the data user are extracted from the resource access request.

[0026] The signature of the data user is verified by calling a smart contract.

[0027] If it is determined that the signature is valid after verification, the validity of the distributed identity identifier is verified by the public key of the administrator in the source domain.

[0028] If it is determined that the distributed identity identifier is valid after verification, the corresponding data usage certificate is queried in the registry of the target domain according to the ID of the data usage certificate, and the validity of the data usage certificate is verified by using the public key of the data holder.

[0029] If it is determined that the voucher information is valid after verification, the corresponding resource in the target domain is returned to the data user according to the data resource information recorded in the data usage certificate, a resource access log is generated, and the resource access log is recorded in the blockchain.

[0030] In one embodiment, the method further includes:

[0031] The data holding certificate, the data usage certificate, and the resources are stored in a cloud storage manner or a distributed storage manner.

[0032] According to a second aspect, the data cross-domain sharing device provided by an embodiment of the present invention is deployed on a shared service system, and the device includes:

[0033] A structure definition module, configured to define and store a corresponding credential claim structure when receiving a claim structure creation request;

[0034] A resource publishing module, configured to retrieve a corresponding credential claim structure when receiving a resource publishing request initiated by a data publisher, so that the data publisher fills in data resource information in the retrieved credential claim structure, generates a data holding credential according to the credential claim structure filled with the data resource information, and stores the data holding credential and the resource corresponding to the data resource information;

[0035] A resource authorization module, configured to retrieve a corresponding credential claim structure when receiving a resource authorization request initiated by a data holder, so that the data holder fills in data resource information and data user information for which authorization is given in the retrieved credential claim structure, generates a data usage credential according to the credential claim structure filled with the data resource information and the data user information, and stores the data usage credential;

[0036] A resource access module, configured to verify the identity of the data user when receiving a resource access request initiated by a data user in a source domain, and after the identity verification is passed, obtain the data usage credential of the data user, verify the validity of the data usage credential, and return the resource corresponding to the data resource information in the data usage credential in the target domain to the data user after the validity verification is passed.

[0037] In one embodiment, before the structure definition module defines and stores a corresponding credential claim structure when receiving a claim structure creation request, it is further configured to: when receiving a registration request, obtain the entity identity information in the registration request, so that the upper-layer administrator reviews the entity identity information; after the review is passed, calculate the digest of the entity identity information, sign the digest, generate a distributed identity identifier corresponding to the entity by calling a smart contract, and write the distributed identity identifier into the blockchain; wherein, the entity includes a domain administrator, an individual user, and a device; the upper-layer administrator of the domain administrator is a consortium administrator, and the upper-layer administrator of the individual user and the device is a domain administrator.

[0038] In one embodiment, the claim structure creation request includes: the distributed identity identifier and signature of the domain administrator who initiates the claim structure creation request, and a predefined credential claim structure;

[0039] Correspondingly, the structure definition module is specifically configured to: when receiving a claim structure creation request, extract the distributed identity identifier and signature of the domain administrator from the claim structure creation request; authenticate the distributed identity identifier and verify the signature by invoking a smart contract; after the authentication and signature verification are passed, write the predefined credential claim structure into the blockchain and generate a corresponding unique ID for the credential claim structure.

[0040] In one embodiment, the resource publishing module is specifically configured to: verify the signature of the data publisher by invoking a smart contract; after passing the verification, generate the data holding credential according to the credential claim structure filled with data resource information; store the data holding credential and the resource corresponding to the data resource information in the domain registration center, generate a data publishing log, and record the data publishing log in the blockchain.

[0041] In one embodiment, the resource authorization module is specifically configured to: verify the signature of the data holder and the data holding credential by invoking a smart contract; after passing the verification, generate a data usage credential according to the credential claim structure filled with data resource information and user information; store the data usage credential in the public registration center or the domain registration center, generate a resource authorization log, store the resource authorization log in the blockchain, and return the ID of the data usage credential to the data user.

[0042] In one embodiment, the resource access module is specifically configured to: when receiving a resource access request from a data user in the source domain to the target domain, extract the ID of the data usage credential, the signature of the data user, and the distributed identity identifier of the data user from the resource access request; verify the signature of the data user by invoking a smart contract; if it is determined that the signature is valid after verification, verify the validity of the distributed identity identifier with the public key of the administrator of the source domain; if it is determined that the distributed identity identifier is valid after verification, query the corresponding data usage credential in the registration center of the target domain according to the ID of the data usage credential, and verify the validity of the data usage credential with the public key of the data holder; if it is determined that the credential information is valid after verification, return the corresponding resource in the target domain to the data user according to the data resource information recorded in the data usage credential, generate a resource access log, and record the resource access log in the blockchain.

[0043] In one embodiment, the device further includes:

[0044] A data storage module, configured to store the data holding credential, the data usage credential, and the resources in a cloud storage manner or a distributed storage manner.

[0045] According to a third aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method provided by the first aspect.

[0046] According to a fourth aspect, a computing device provided by an embodiment of the present invention includes a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method provided by the first aspect is implemented.

[0047] The data cross-domain sharing method, apparatus, medium, and device provided by the embodiments of the present invention are as follows. First, the data sharing system defines and stores a corresponding credential claim structure. When the data sharing system receives a resource publishing request initiated by a data publisher, it retrieves the corresponding credential claim structure. Then, the data publisher fills in data resource information in the retrieved credential claim structure. Next, the data sharing system generates a data holding credential based on the credential claim structure filled with data resource information, and stores the data holding credential and the resource corresponding to the data resource information. When the data sharing system receives a resource authorization request initiated by a data holder, it retrieves the corresponding credential claim structure. Then, the data holder fills in data resource information and data user information for which authorization is given in the retrieved credential claim structure. The data sharing system generates a data usage credential based on the credential claim structure filled with data resource information and data user information, and stores the data usage credential. When the data sharing system receives a resource access request initiated by a data user in the source domain, it verifies the identity of the data user. After the identity verification passes, it obtains the data usage credential of the data user and verifies the validity of the data usage credential. After the validity verification passes, it returns the resource corresponding to the data resource information in the data usage credential in the target domain to the data user. It can be seen that when a data user accesses a resource across domains, it is necessary to authenticate its identity and permissions. The smart contract automatically executes the identity verification and permission evaluation processes, thus effectively solving the key problems related to data access control in a cross-domain environment and improving the convenience of data sharing. The entire process is based on distributed identity identifiers and verifiable credentials, realizing cross-domain authentication of user identities and cross-domain circulation of data resources, breaking information silos, and enabling secure, efficient, and convenient sharing of data resources in a multi-domain environment, providing strong support for the sharing and protection of medical data. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 It is a schematic flowchart of the data cross-domain sharing method in an embodiment of the present invention;

[0049] Figure 2 It is an architecture diagram of the data sharing system in an embodiment of the present invention;

[0050] Figure 3 This is an example diagram of the data cross - domain sharing method in an embodiment of the present invention;

[0051] Figure 4 This is a structural block diagram of the data cross - domain sharing device in an embodiment of the present invention. Detailed implementation manners

[0052] In a first aspect, an embodiment of the present invention provides a data cross - domain sharing method, which is executed by a sharing service system. Refer to Figure 1 , the method includes the following steps S110 to S150:

[0053] S110. When receiving a claim structure creation request, define and store the corresponding credential claim structure;

[0054] Before executing S110, an entity may be created first. An entity refers to a domain administrator, an individual user, a device, etc. The domain administrator is created by the alliance administrator, and the identity information of individual users and devices within each domain is created and managed by the administrators of each domain.

[0055] Therefore, in one embodiment, before the step of defining and storing the corresponding credential claim structure when receiving a claim structure creation request in S110, the method may further include:

[0056] When receiving a registration request, obtain the entity identity information in the registration request to enable the upper - layer administrator to review the entity identity information; after the review is passed, calculate the digest of the entity identity information, sign the digest, generate a distributed identity identifier corresponding to the entity by calling a smart contract, and write the distributed identity identifier into the blockchain; wherein, the entity includes a domain administrator, an individual user, and a device; the upper - layer administrator of the domain administrator is the alliance administrator, and the upper - layer administrator of the individual user and the device is the domain administrator.

[0057] That is to say, the entity submits a registration request to the sharing service system. The registration request contains the identity information of the entity. The upper - layer administrator corresponding to the entity reviews and evaluates the identity of the entity. After the review and evaluation are passed, calculate the digest of the entity, sign the digest to obtain the signature of the entity, then call the smart contract DID, i.e., the distributed identity identifier, and write the DID into the blockchain.

[0058] In S110, different types of credential declaration structures can be defined according to different business requirements in each domain. The credential declaration structure can also be called a data structure of a credential declaration type, abbreviated as a CPT data structure. Moreover, the definition of the credential declaration structure is initiated based on a declaration structure creation request by a domain administrator. Therefore, the declaration structure creation request may include: the distributed identity and signature of the domain administrator who initiated the declaration structure creation request, and the predefined credential declaration structure. It can be seen that the credential declaration structure is predefined by the domain administrator. After submitting the declaration structure creation request, the data sharing system stores it according to the credential declaration structure predefined by the domain administrator, thereby obtaining the defined credential declaration structure.

[0059] To this end, in one embodiment, upon receiving a claim structure creation request, defining and storing a corresponding credential claim structure may include the following steps S111 to S113:

[0060] S111. When receiving a claim structure creation request, extracting a distributed identity and signature of a domain administrator from the claim structure creation request;

[0061] S112, authenticating the distributed identity and verifying the signature by calling a smart contract;

[0062] S113. After the identity authentication and signature verification are passed, the predefined credential declaration structure is written into the blockchain, and a corresponding unique ID is generated for the credential declaration structure.

[0063] Among them, the credential declaration structure is used to define the structure of the verifiable credential, which is the data holding credential and the data use credential. You can use JSON Schema to define the credential declaration structure. For example, the credential declaration structure has attributes such as "name", "gender", and "address". After filling in the corresponding specific information for these attributes, you can get the claim part of the verifiable credential. The claim part refers to the part of the verifiable credential that carries specific key information. For example, a claim part "claims":{"Name":"Jack","Gender":"Male","Address":"xxx, Haidian District, Beijing"}.

[0064] In other words, the credential declaration structure is predefined by the domain administrator and then submitted to the data sharing system. Different business requirements in each domain predefine different types of credential declaration structures, which must be filled in according to the attributes required in the credential declaration structure to form the declaration part of the verifiable credential.

[0065] It can be seen that the process of defining and storing the corresponding credential claim structure in the data sharing system is generally as follows: The domain administrator submits a claim structure creation request to the data sharing system, which includes the DID of the domain administrator, the predefined credential claim structure, and a signature. The smart contract verifies the domain administrator. After passing the verification, the predefined credential claim structure is written into the blockchain, and a unique ID is generated for it.

[0066] S120. When receiving a resource publishing request initiated by a data publisher, retrieve the corresponding credential claim structure, so that the data publisher fills in data resource information in the retrieved credential claim structure, generate a data holding credential according to the credential claim structure filled with data resource information, and store the data holding credential and the resource corresponding to the data resource information.

[0067] It can be seen that S120 is the process of resource publishing.

[0068] In one embodiment, the step of generating a data holding credential according to the credential claim structure filled with data resource information and storing the data holding credential and the resource corresponding to the data resource information in S120 specifically includes the following steps S121 to S123:

[0069] S121. Verify the signature of the data publisher by calling the smart contract.

[0070] S122. After passing the verification, generate the data holding credential according to the credential claim structure filled with data resource information.

[0071] S123. Store the data holding credential and the resource corresponding to the data resource information in the domain registration center, generate a data publishing log, and record the data publishing log in the blockchain.

[0072] It can be understood that the data publisher issues a data holding credential to the data holder to achieve the publishing of data resources. Different types of data resources correspond to different types of credential claim structures. For example, the types of credential claim structures corresponding to patient information, diagnostic data, and medical images are different, that is, the attributes included in the credential claim structure are different.

[0073] Based on the above S121~S123, the general process of S120 can specifically include: the data publisher initiates a resource publishing request to the data sharing system, and then the data sharing system retrieves the corresponding credential declaration structure. After the data publisher fills in the information on the credential declaration structure, it obtains the declaration part in the data holding credential, signs the declaration part with the data publisher's private key, and then submits the resource and the declaration part to the data sharing system. The data sharing system will call the smart contract to verify the signature of the data publisher, generate a data holding credential after verification, and store it in the registration center within the domain together with the resource, and generate a resource publishing log record in the blockchain.

[0074] S130, when receiving a resource authorization request initiated by a data holder, retrieving a corresponding credential declaration structure, so that the data holder fills in data resource information and authorized data user information in the retrieved credential declaration structure, generating a data use credential based on the credential declaration structure filled with data resource information and data user information, and storing the data use credential;

[0075] It can be seen that S130 is actually the process in which the data holder grants resource access rights to the data user.

[0076] In one embodiment, the step of generating a data usage credential according to the credential declaration structure filled with data resource information and data user information, and storing the data usage credential in S130 includes S131 to S133:

[0077] S131. Verify the signature and data holding certificate of the data holder by calling the smart contract;

[0078] S132, after verification, generate a data usage certificate according to the certificate declaration structure filled with data resource information and user information;

[0079] S133: Store the data usage credential in a public registration center or a domain registration center, generate a resource authorization log, store the resource authorization log in a blockchain, and return the ID of the data usage credential to the data user.

[0080] It can be seen that the data holder issues a data usage certificate to the data user to achieve the authorization of data resources. The detailed process specifically includes: the data holder sends a resource authorization request to the data sharing system, and then the data sharing system retrieves the corresponding certificate statement structure. Thus, the data holder fills in the data resource information and the information of the authorized data user in the certificate statement structure to form the statement part in the data usage certificate, and submits it to the data sharing system. The data sharing system verifies the signature of the data holder and the data holding certificate through a smart contract. After the verification passes, it generates a data usage certificate according to the statement part in the data usage certificate, stores it in the public registration center or the domain registration center, and at the same time generates a resource authorization log and records it in the blockchain. Then it returns the ID of the data usage certificate to the data user, and the certificate information and the data resource can be queried through this ID.

[0081] S140. When receiving a resource access request initiated by a data user in the source domain, verify the identity of the data user. After the identity verification passes, obtain the data usage certificate of the data user, and verify the validity of the data usage certificate. After the validity verification passes, return the corresponding resource of the data resource information in the data usage certificate in the target domain to the data user.

[0082] It can be seen that S140 is actually the resource access process of the data user.

[0083] In one embodiment, when receiving a resource access request initiated by a data user in the source domain in S140, verifying the identity of the data user, obtaining the data usage certificate of the data user after the identity verification passes, verifying the validity of the data usage certificate, and after the validity verification passes, returning the corresponding resource of the data resource information in the data usage certificate in the target domain to the data user can specifically include S141 - S145:

[0084] S141. When receiving a resource access request initiated by a data user in the source domain for a resource in the target domain, extract the ID of the data usage certificate, the signature of the data user, and the distributed identity identifier of the data user from the resource access request.

[0085] S142. Verify the signature of the data user by calling a smart contract.

[0086] S143. If it is determined that the signature is valid after verification, verify the validity of the distributed identity identifier through the public key of the administrator in the source domain.

[0087] S144. If it is determined through verification that the distributed identity identifier is valid, query the corresponding data usage certificate in the registration center of the target domain according to the ID of the data usage certificate, and verify the validity of the data usage certificate using the public key of the data holder;

[0088] S145. If it is determined through verification that the voucher information is valid, return the corresponding resources in the target domain to the data user according to the data resource information recorded in the data usage certificate, generate a resource access log, and record the resource access log in the blockchain.

[0089] It can be seen that when a data user accesses resources across domains, it is necessary to first verify the legality of the data user's identity and then verify the data user's access rights to the resources. For example, the source domain is a1, the target domain is b1, and the data user in the source domain a1 is A1. The data user A1 initiates a resource access request to the target domain b1. The resource access request includes a DID, a data usage certificate ID, and a signature. The data sharing system first verifies the validity of the signature through a smart contract, then uses the public key of the domain administrator in the source domain to verify the validity of the DID. After verifying the validity, it retrieves the detailed information of the data usage certificate in the registration center of the target domain b1 according to the ID of the data usage certificate, and uses the public key of the data holder to verify the validity of this certificate. After all the above verifications pass, the corresponding resources are returned to the data user A1, and a resource access log is generated and recorded in the blockchain.

[0090] In one embodiment, the method further includes:

[0091] Store the data holding certificate, the data usage certificate, and the resources in a cloud storage manner or a distributed storage manner.

[0092] The architecture of the data sharing system is divided into four layers: the data layer, the blockchain layer, the service layer, and the user layer:

[0093] (1) Data layer: Stores information related to data sharing and access control, which is divided into three categories: blockchain data, verifiable credentials, and shared resources. 1) Blockchain data includes distributed identity identifier (DID) information, credential claim structures, and logs, all of which are recorded on the blockchain. 2) Verifiable credentials include data holding credentials and data usage credentials. Data holding credentials represent the ownership of data by the data holder, who can autonomously authorize and revoke the access of other users to the data. Data holding credentials are issued by the data publisher to the data holder. The validity of data holding credentials can be verified using the public key of the data publisher, who is generally a hospital, doctor, or various devices. Data usage credentials are proof that the data user has been granted the right to use the data, and the validity of the credentials can be verified using the public key of the data holder. Data usage credentials are stored in a public registry or a domain registry, and are generally stored in the domain registry. 3) Shared resources generally include patients' medical treatment data, examination data of medical devices, etc. The storage scheme for verifiable credentials and resources is cloud storage or distributed storage. For example, distributed storage is carried out through IPFS, which is the InterPlanetary File System, a network transmission protocol designed to create persistent and distributed storage and sharing of files.

[0094] (2) Blockchain layer: Provides blockchain services for the data sharing system and builds a bridge for interaction between components at all levels. Among them, the distributed ledger is used to maintain the data storage content of the blockchain; block propagation between nodes is achieved based on the P2P network; smart contracts are responsible for handling the logic related to user management, credential issuance, and data access control within the system, such as generating DIDs, issuing data holding credentials, managing data resources, and verifying users' data access permissions. These operations are all triggered by the service layer to automatically execute the smart contracts. Both DIDs and verifiable credentials are recorded on the blockchain, thus providing reliable identity authentication and permission granting services for users.

[0095] (3) Service layer: Provides data sharing-related services to users through methods such as Web pages or client apps, and the business requirements of different user types are also different. For example, the alliance administrator is responsible for the overall management and maintenance of the system, mainly including the deployment and maintenance of blockchain nodes and smart contracts, and the management of domain administrators; the business requirements of domain administrators include generating DIDs for users within their domain, publishing credential claim structures, and auditing data authorization and access logs; the business requirements of data publishers mainly include uploading data resources and issuing data holding credentials; the business requirements of data holders mainly include viewing the data resources they hold and authorizing the use of data resources; the business requirements of data users mainly include viewing data usage credentials and accessing data resources.

[0096] (4) User layer: Composed of different types of entities, such as consortium administrators, domain administrators, individual users, and various devices. According to the different requirements of each domain, individual users and various devices can be either data publishers or data consumers, and the data holders are generally individual users. Automated management of access control is achieved through smart contracts and supervised by consortium administrators and domain administrators. Each domain participates in the consortium as a blockchain node, and multiple domains together form a consortium system.

[0097] See Figure 2 , Figure 2 The figure shows the overall architecture diagram of cross-domain data sharing based on blockchain proposed by the present invention. The blockchain data in the data layer is the on-chain part, and the verifiable credentials and shared resources are the off-chain part. The storage solution for off-chain data is cloud storage or distributed storage. The verifiable credentials and shared resources are stored together in the public registration center or domain registration center; the number of nodes in the P2P network of the blockchain layer corresponds to the total number of domains in the data sharing system; in the service layer, the underlying chain management module includes functions of blockchain node management and smart contract management, the user management module includes functions of domain administrator management and ordinary user management, the verifiable credential management module includes functions of credential issuance, viewing, and revocation, and the log record module records data publication logs, data authorization logs, and data access logs.

[0098] Figure 3 It is the overall process of cross-domain data sharing. The participating parties come from two domains, namely Domain A and Domain B, to enable data consumers in Domain B to access data in Domain A. First, the consortium administrator performs system initialization operations, including deploying contracts and creating domain administrators, etc. Then, the domain administrator creates various types of users within the domain, that is, generates DIDs for the entities. The domain administrator creates a credential statement structure and stores it in the public / domain registration center. After the data publisher issues a data holding credential to the data holder, the credential and resources are stored in the public / domain registration center. The data holder authorizes the data consumer to access the data resources by issuing a data usage credential. During cross-domain access, the data sharing system verifies the identity and access rights of the data consumer to ensure legal access. The entire process is realized through smart contracts for automated management, ensuring the security and compliance of the data, and at the same time improving the efficiency and convenience of data access.

[0099] It is understandable that medical data is highly sensitive and private and can only be accessed after the patient authorizes a specific organization or individual to ensure the legality of data access and protect the patient's privacy. Data sharing among different institutions involves cross-domain information interaction, permission management, and access control, and faces problems such as data heterogeneity, forgery and tampering of identities or permissions, and leakage of data resources. Deeply integrating blockchain technology with distributed digital identities can have absolute advantages in privacy protection, permission management, and data security. Therefore, the method provided in the embodiments of the present invention is applicable to the application scenario of medical data sharing.

[0100] The embodiments of the present invention propose a blockchain-based cross-domain data sharing solution. Each institution participating in data sharing joins the blockchain network as a domain node to form a consortium blockchain, which serves as the basis for data sharing and access control. The distributed identity identifier DID is the identity of the user in the data sharing system and is responsible for the management of the user's life cycle. When a data user accesses resources across domains, the data user presents their DID and data usage credentials to authenticate their identity and permissions, and the smart contract automatically executes the identity verification and permission evaluation process, thus effectively solving the key problems related to data access control in a cross-domain environment and improving the convenience of data sharing.

[0101] The embodiments of the present invention are implemented based on a blockchain network, effectively combining blockchain technology and data resource sharing management. To ensure the privacy, security, convenience of medical data sharing management, and the traceability of authorization and access, cross-domain authentication of user identities and cross-domain circulation of data resources are realized based on distributed identity identifiers and verifiable credentials, breaking the information silos. Users have full control over the data they hold, and data resources are authorized by issuing data usage credentials. The authorization and access process forms a detailed log, which is convenient for auditing and responsibility attribution. Secure, efficient, and convenient data resource sharing can be realized in a multi-domain environment, providing strong support for the sharing and protection of medical data.

[0102] The decentralized architecture based on blockchain has high security, eliminates the risk of single-point failures, and improves the anti-attack ability of the data sharing system; cross-domain circulation based on verifiable credentials realizes cross-domain sharing and access of data resources; users have full control over their own identity information and permission credentials, avoiding the risk of privacy leakage; the smart contract automatically executes the relevant processes of data authorization and access according to the predetermined logic, improving the usability and working efficiency of the data sharing system; the data authorization and access process records complete and detailed log information, which is convenient for auditing and responsibility attribution. In summary, the system realizes secure, efficient, and convenient access control in a multi-domain environment, providing strong support for the sharing and protection of data resources.

[0103] Second aspect, an embodiment of the present invention provides a data cross - domain sharing device, which is deployed on a sharing service system. Refer to Figure 4 , the device 100 includes:

[0104] A structure definition module 110, configured to define and store a corresponding credential statement structure when receiving a statement structure creation request;

[0105] A resource publishing module 120, configured to retrieve a corresponding credential statement structure when receiving a resource publishing request initiated by a data publisher, so that the data publisher fills in data resource information in the retrieved credential statement structure, generates a data holding credential according to the credential statement structure filled with data resource information, and stores the data holding credential and the resource corresponding to the data resource information;

[0106] A resource authorization module 130, configured to retrieve a corresponding credential statement structure when receiving a resource authorization request initiated by a data holder, so that the data holder fills in data resource information and data user information for granting authorization in the retrieved credential statement structure, generates a data usage credential according to the credential statement structure filled with data resource information and data user information, and stores the data usage credential;

[0107] A resource access module 140, configured to verify the identity of the data user when receiving a resource access request initiated by a data user in the source domain, and after the identity verification passes, obtain the data usage credential of the data user, verify the validity of the data usage credential, and return the corresponding resource of the data resource information in the data usage credential in the target domain to the data user after the validity verification passes.

[0108] In one embodiment, before the structure definition module defines and stores a corresponding credential statement structure when receiving a statement structure creation request, it is further configured to: when receiving a registration request, obtain the entity identity information in the registration request to enable the upper - layer administrator to review the entity identity information; after the review passes, calculate a digest of the entity identity information, sign the digest, generate a distributed identity identifier corresponding to the entity by invoking a smart contract, and write the distributed identity identifier into the blockchain; where the entity includes a domain administrator, an individual user, and a device; the upper - layer administrator of the domain administrator is a consortium administrator, and the upper - layer administrator of the individual user and the device is the domain administrator.

[0109] In one embodiment, the statement structure creation request includes: the distributed identity identifier and signature of the domain administrator who initiates the statement structure creation request, and a predefined credential statement structure;

[0110] Correspondingly, the structure definition module is specifically configured to: when receiving a claim structure creation request, extract the distributed identity identifier and signature of the domain administrator from the claim structure creation request; authenticate the distributed identity identifier and verify the signature by calling a smart contract; after the authentication and signature verification are passed, write the predefined credential claim structure into the blockchain and generate a corresponding unique ID for the credential claim structure.

[0111] In one embodiment, the resource publishing module is specifically configured to: verify the signature of the data publisher by calling a smart contract; after passing the verification, generate the data holding credential according to the credential claim structure filled with data resource information; store the data holding credential and the resource corresponding to the data resource information in the domain registration center, generate a data publishing log, and record the data publishing log in the blockchain.

[0112] In one embodiment, the resource authorization module is specifically configured to: verify the signature of the data holder and the data holding credential by calling a smart contract; after passing the verification, generate a data usage credential according to the credential claim structure filled with data resource information and user information; store the data usage credential in the public registration center or the domain registration center, generate a resource authorization log, store the resource authorization log in the blockchain, and return the ID of the data usage credential to the data user.

[0113] In one embodiment, the resource access module is specifically configured to: when receiving a resource access request from a data user in the source domain to a resource in the target domain, extract the ID of the data usage credential, the signature of the data user, and the distributed identity identifier of the data user from the resource access request; verify the signature of the data user by calling a smart contract; if it is determined that the signature is valid after verification, verify the validity of the distributed identity identifier by the public key of the administrator in the source domain; if it is determined that the distributed identity identifier is valid after verification, query the corresponding data usage credential in the registration center of the target domain according to the ID of the data usage credential, and verify the validity of the data usage credential by the public key of the data holder; if it is determined that the credential information is valid after verification, return the corresponding resource in the target domain to the data user according to the data resource information recorded in the data usage credential, generate a resource access log, and record the resource access log in the blockchain.

[0114] In one embodiment, the device further includes:

[0115] A data storage module, configured to store the data holding credential, the data usage credential, and the resources in a cloud storage manner or a distributed storage manner.

[0116] It is understandable that for the explanations, specific implementation manners, beneficial effects, examples, etc. of the relevant content in the device provided in the embodiments of the present invention, reference may be made to the corresponding parts in the method provided in the first aspect, and details are not described herein again.

[0117] In a third aspect, an embodiment of the present invention provides a computer-readable medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the processor is caused to execute the method provided in the first aspect.

[0118] Specifically, a system or device equipped with a storage medium may be provided, on which software program code for implementing the functions of any one of the above embodiments is stored, and the computer (or CPU or MPU) of the system or device is caused to read and execute the program code stored in the storage medium.

[0119] In this case, the program code read from the storage medium itself can implement the functions of any one of the above embodiments. Therefore, the program code and the storage medium storing the program code constitute a part of the present invention.

[0120] Embodiments of the storage medium for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the program code may be downloaded from a server computer via a communication network.

[0121] In addition, it should be clear that not only can the actual operations be completed in part or in whole by executing the program code read by the computer, but also by means of instructions based on the program code, the operating system operating on the computer, etc., so as to implement the functions of any one of the above embodiments.

[0122] In addition, it can be understood that the program code read from the storage medium is written into the memory provided in the expansion board inserted into the computer or into the memory provided in the expansion module connected to the computer, and then based on the instructions of the program code, the CPU, etc. installed on the expansion board or the expansion module are caused to execute part and all of the actual operations, so as to implement the functions of any one of the above embodiments.

[0123] It is understandable that for the explanations, specific implementation manners, beneficial effects, examples, etc. of the relevant content in the computer-readable medium provided in the embodiments of the present invention, reference may be made to the corresponding parts in the method provided in the first aspect, and details are not described herein again.

[0124] Fourthly, an embodiment of this specification provides a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method in any one of the embodiments in the specification is implemented.

[0125] It can be understood that for the explanations, specific implementation manners, beneficial effects, examples, etc. of the relevant content in the computing device provided in the embodiments of the present invention, reference can be made to the corresponding parts in the method provided in the first aspect, and details are not described herein again.

[0126] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0127] Those skilled in the art should be able to realize that in the above one or more examples, the functions described in the present invention can be implemented by hardware, software, add-ons, or any combination thereof. When implemented by software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0128] The specific implementation manners described above further elaborate on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are only the specific implementation manners of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solution of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for cross - domain data sharing, characterized in that, Executed by a shared service system, the method includes: When receiving a claim structure creation request, defining and storing a corresponding credential claim structure; When receiving a resource publication request initiated by a data publisher, retrieving the corresponding credential claim structure, enabling the data publisher to fill in data resource information in the retrieved credential claim structure, generating a data holding credential based on the credential claim structure filled with data resource information, and storing the data holding credential and the resource corresponding to the data resource information; When receiving a resource authorization request initiated by a data holder, retrieving the corresponding credential claim structure, enabling the data holder to fill in data resource information and data user information for granting authorization in the retrieved credential claim structure, generating a data usage credential based on the credential claim structure filled with data resource information and data user information, and storing the data usage credential; When receiving a resource access request initiated by a data user in the source domain, verifying the identity of the data user, and after the identity verification passes, obtaining the data usage credential of the data user, verifying the validity of the data usage credential, and after the validity verification passes, returning the corresponding resource of the data resource information in the data usage credential in the target domain to the data user.

2. The method according to claim 1, characterized in that Before defining and storing the corresponding credential claim structure when receiving a claim structure creation request, the method further includes: When receiving a registration request, obtaining the entity identity information in the registration request, enabling the upper-layer administrator to review the entity identity information; after the review passes, calculating the digest of the entity identity information, signing the digest, generating a distributed identity identifier corresponding to the entity by calling a smart contract, and writing the distributed identity identifier into the blockchain; where the entity includes a domain administrator, an individual user, and a device; the upper-layer administrator of the domain administrator is the consortium administrator, and the upper-layer administrator of the individual user and the device is the domain administrator.

3. The method according to claim 2, wherein The claim structure creation request includes: the distributed identity identifier and signature of the domain administrator initiating the claim structure creation request, and a predefined credential claim structure; Correspondingly, defining and storing the corresponding credential claim structure when receiving a claim structure creation request includes: When receiving a claim structure creation request, extracting the distributed identity identifier and signature of the domain administrator from the claim structure creation request; Authenticating the distributed identity identifier and verifying the signature by calling a smart contract; After the identity authentication passes and the signature verification passes, writing the predefined credential claim structure into the blockchain and generating a corresponding unique ID for the credential claim structure.

4. The method according to claim 2, characterized in that, Generating a data holding credential based on the credential claim structure filled with data resource information and storing the data holding credential and the resource corresponding to the data resource information includes: Verifying the signature of the data publisher by calling a smart contract; After passing the verification, generating the data holding credential based on the credential claim structure filled with data resource information; Store the resource corresponding to the data holding voucher and the data resource information in the domain registration center, generate a data publication log, and record the data publication log in the blockchain.

5. The method according to claim 2, wherein The generation of a data usage voucher according to the voucher declaration structure filled with data resource information and data user information and the storage of the data usage voucher include: Verify the signature of the data holder and the data holding voucher by invoking a smart contract; After passing the verification, generate a data usage voucher according to the voucher declaration structure filled with data resource information and user information; Store the data usage voucher in the public registration center or the domain registration center, generate a resource authorization log, store the resource authorization log in the blockchain, and return the ID of the data usage voucher to the data user.

6. The method according to claim 2, characterized in that, When receiving a resource access request initiated by a data user in the source domain, verify the identity of the data user, and after passing the identity verification, obtain the data usage voucher of the data user and verify the validity of the data usage voucher. After passing the validity verification, return the corresponding resource in the target domain of the data resource information in the data usage voucher to the data user, including: When receiving a resource access request initiated by a data user in the source domain to the target domain, extract the ID of the data usage voucher, the signature of the data user, and the distributed identity identifier of the data user from the resource access request; Verify the signature of the data user by invoking a smart contract; If it is determined that the signature is valid after verification, verify the validity of the distributed identity identifier by the public key of the administrator of the source domain; If it is determined that the distributed identity identifier is valid after verification, query the corresponding data usage voucher in the registration center of the target domain according to the ID of the data usage voucher, and verify the validity of the data usage voucher by the public key of the data holder; If it is determined that the voucher information is valid after verification, return the corresponding resource in the target domain to the data user according to the data resource information recorded in the data usage voucher, generate a resource access log, and record the resource access log in the blockchain.

7. The method according to claim 1, wherein It also includes: Store the data holding voucher, the data usage voucher, and the resource in a cloud storage manner or a distributed storage manner.

8. A data cross-domain sharing device, characterized in that, The device is deployed on a shared service system, and the device includes: A structure definition module for defining and storing a corresponding voucher declaration structure when receiving a declaration structure creation request; A resource publication module for retrieving a corresponding voucher declaration structure when receiving a resource publication request initiated by a data publisher, so that the data publisher fills in data resource information in the retrieved voucher declaration structure, generates a data holding voucher according to the voucher declaration structure filled with data resource information, and stores the data holding voucher and the resource corresponding to the data resource information; A resource authorization module, which is used to retrieve the corresponding credential statement structure when receiving a resource authorization request initiated by a data holder, so that the data holder fills in data resource information and data user information given authorization in the retrieved credential statement structure, generates a data usage credential according to the credential statement structure filled with data resource information and data user information, and stores the data usage credential; A resource access module, which is used to verify the identity of the data user when receiving a resource access request initiated by the data user in the source domain, and after the identity authentication is passed, obtain the data usage credential of the data user, verify the validity of the data usage credential, and return the corresponding resource of the data resource information in the data usage credential in the target domain to the data user after the validity verification is passed.

9. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the computer program is executed on a computer, the computer is made to execute the method according to any one of claims 1 to 7.

10. A computing device, characterized in that, It includes a memory and a processor, an executable code is stored in the memory, and when the processor executes the executable code, the method according to any one of claims 1 to 7 is implemented.