Sensitive data exchange and privacy protection method based on distributed identity management
Through distributed identity management and smart contract technology, authorization tokens are generated and data is encrypted and stored. Combined with machine learning and end-to-end encryption, the problems of high trust costs, inflexible authorization and insufficient privacy protection in traditional data exchange systems are solved, and efficient and transparent data sharing and privacy protection are achieved.
Patent Information
- Application Number
- CN202510313210.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-08-12
AI Technical Summary
There are problems in existing data exchange systems with high trust costs, lack of flexible authorization and data usage control, insufficient data privacy protection and poor transparency. Especially in sensitive data exchange, traditional methods are difficult to achieve real-time verification and dynamic control, and there is a risk of data leakage and abuse.
Decentralized identity management and smart contract technology are adopted to create decentralized identity identifiers through blockchain, generate authorization tokens and encrypt and store user data, combine machine learning algorithms to generate a minimized data subset, and use end-to-end encryption technology to ensure data security. Smart contracts record responsibilities and permissions of each link.
Decentralized and flexible authorization control is realized, ensuring the security and transparency of data during transmission and processing, reducing trust costs, and improving the compliance and privacy protection capabilities of data exchange.
Smart Images

Figure CN120474714A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data exchange and privacy protection, and in particular to a sensitive data exchange and privacy protection method based on distributed identity management. Background Art
[0002] With the continuous development of information technology and the rapid increase in data volume, more and more industries and fields rely on the circulation and sharing of data to drive business development. However, in the process of data exchange, especially in scenarios involving sensitive information and personal privacy (such as medical data, financial data, and government service data), due to the trust issues between data owners and users, traditional data sharing models face serious problems such as privacy leakage, data abuse, and compliance risks. Existing technologies generally achieve data sharing through the following methods:
[0003] 1. Centralized Data Management Platform: In traditional centralized platforms, data storage and management are centrally handled by third parties (such as cloud service providers, financial institutions, and governments). These platforms often rely on intermediaries for data authentication, authorization, and transactions. While this provides a certain degree of convenience, it also presents trust issues because all data exchanges rely on a single centralized entity.
[0004] 2. Traditional authorization mechanism: Data access usually relies on authorization letters, contractual agreements, or other manual intervention methods to constrain data usage rights. Although these methods can control data sharing to a certain extent, they cannot verify the validity of authorization in real time, and it is difficult to track the entire process of data use.
[0005] 3. Data encryption: Although existing encryption technologies (such as AES and RSA) provide a certain degree of security during data transmission, traditional encryption methods often lack control over the scope of data usage, and sensitive information may be exposed during the data decryption process, making it impossible to achieve zero leakage.
[0006] The existing technology has the following deficiencies:
[0007] 1. High trust costs and reliance on intermediaries: In existing data exchange systems, data holders and users often rely on third-party intermediaries to ensure data security and legitimacy. This not only increases the trust cost of data exchange but also complicates data processing and compliance reviews. Intermediaries can become single points of failure, and data leaks or management errors can lead to large-scale data privacy breaches.
[0008] 2. Lack of flexible authorization and data usage control mechanisms: Traditional data authorization mechanisms are often based on static agreements (such as contracts and written authorizations) and lack dynamic control and real-time verification capabilities. During data exchange, users cannot flexibly control the specific scope of data sharing and the timeliness of data use, which can easily lead to data abuse or unauthorized access. Existing permission confirmation between data holders and users often relies on manual intervention, which can lead to unclear authorization and unclear responsibilities.
[0009] 3. Inadequate data privacy protection: In traditional encrypted data exchange models, while encryption technology ensures data security during transmission, when the data needs to be decrypted or processed, the data content is exposed to the recipient or processor. This approach cannot effectively address data privacy issues, especially for sensitive data (such as medical records and financial data), where the decryption process itself may introduce data leakage risks.
[0010] 4. Poor transparency in the data exchange process: While traditional data exchange platforms have certain auditing capabilities, they often fail to monitor data flow and usage in real time. This makes it difficult for data holders to effectively audit the entire data exchange process and track whether data is being misused or improperly accessed.
[0011] 5. Weak authentication and authorization control mechanisms: In traditional data exchange processes, authentication and permission control for data use are managed by a single, centralized system. This approach often carries the risk of identity theft or impersonation, and fails to achieve truly decentralized authentication. Furthermore, authorization control relies on manual or static settings, lacking flexible, real-time authorization and revocation mechanisms. Summary of the Invention
[0012] The purpose of the present invention is to address the deficiencies in the prior art and provide a sensitive data exchange and privacy protection method based on distributed identity management.
[0013] To achieve the above objectives, the present invention provides a sensitive data exchange and privacy protection method based on distributed identity management, comprising:
[0014] The user creates a decentralized identity identifier through the blockchain and encrypts the user identity information and authorization data and stores them in a decentralized storage system;
[0015] Users define authorization information through smart contracts on the blockchain, generate authorization tokens, and store them in encrypted form. The authorization information includes the scope of data access and the authorization period.
[0016] The data application party sends a query request to the data holder through a smart contract. After receiving the query request from the data application party, the data holder verifies the authorization token through the smart contract on the blockchain and confirms whether the data application party has the right to access the user's target data based on the rules of the smart contract and the authorization token. If the data application party has the right to access, the authorized data is generated into a minimized data subset based on the query request and authorization information, and the minimized data subset is encrypted and sent to the data application party.
[0017] After receiving the encrypted minimized data subset, the data application party verifies the legitimacy of the data through the smart contract and authorization token. After the verification is passed, the data application party decrypts the received data to obtain the minimized data subset.
[0018] Furthermore, the decentralized identity identifier includes a public-private key pair and a DID document, and the DID document stores user identity information, authentication information, related public keys and service endpoints.
[0019] Furthermore, the authorization token is represented as:
[0020] Token={Data fields,Access Period,Scope,Signature}
[0021] Token is the authorization token, Data fields is the data field, Access Period is the access time range, Scope is the scope of access rights, and Signature indicates the signature using the private key.
[0022] Furthermore, the method of generating a minimized data subset from the authorization data according to the query request and the authorization information is as follows:
[0023] According to the request field F of the data demander Q and user authorization field A U , calculate the actual transmission field F S :
[0024] F S =F Q ∩A U
[0025] Among them, ∩ is the intersection symbol;
[0026] According to the screening conditions of the data demander C Q and user authorization condition C A , calculate the filtering condition C of the actual transmitted data S :
[0027] C S =CQ ∩C U
[0028] Use machine learning algorithms to analyze historical request data, predict the demander's field preferences, and optimize data sharding strategies; and assign weights to fields based on their relevance and historical query frequency;
[0029] The data subset that generates the minimum is:
[0030] D S ={d i ∈D|d i [F S ]Satisfy C S And weight>threshold}
[0031] Among them, D S is the generated minimized data subset, D is the authorized data, D={d1,d2,d3...d n}, where d j Represents each data unit in the data set D, j = 1, 2, ..., n, d i is the data unit in D.
[0032] Furthermore, the minimized data subset is encrypted using an AES-256 or RSA encryption algorithm.
[0033] Furthermore, the data holder also uses a homomorphic encryption algorithm to encrypt the minimized data subset, so that the data application party can perform statistical or computing tasks in the data encryption state.
[0034] Furthermore, the data holder sends the encrypted minimized data subset to the data application party via the TLS1.3 protocol.
[0035] Furthermore, it also includes:
[0036] Smart contracts are used to clearly define the responsibilities and permissions in each link of data exchange. When a liability incident occurs during the data exchange process (such as data leakage, unauthorized access, etc.), the smart contract automatically executes the responsibility allocation and compensation mechanism.
[0037] Furthermore, data requests, authorizations, and transmission operations are uploaded to the blockchain. Through the timestamps and encrypted signatures on the blockchain, data holders, applications, and users can all achieve real-time auditing of data flows and responsibility execution.
[0038] Beneficial Effects: 1. This invention innovatively combines distributed identity management (SSI) and a triple authorization mechanism to provide a decentralized and flexible authorization control solution for multi-party data exchange. Through decentralized identity (DID) and smart contracts, citizens can fully control their own data while authorizing government departments and financial institutions to access their social security data and tax records. This method breaks through the traditional data exchange model that relies on intermediaries and manual operations, and provides a more efficient and transparent data sharing and privacy protection mechanism.
[0039] 2. This invention innovatively combines smart contracts with blockchain technology to automatically implement responsibility sharing and audit traceability during data exchange. By clearly defining the responsibilities of various parties (such as government departments, financial institutions, and citizens) in smart contracts and recording the timestamps and verification information of all data exchange operations on the blockchain, this invention ensures the transparency and traceability of data exchange. This innovation overcomes the limitations of traditional data sharing models, which often involve unclear responsibilities and unmanageable legal risks, and improves the compliance and legal protection of data exchange.
[0040] 3. This invention innovatively introduces privacy computing technology and combines it with end-to-end encryption and data sharding to ensure that data always remains encrypted and protected during transmission and processing. By supporting encrypted computing, data parties can perform necessary calculations and verifications without decrypting the data, while protecting sensitive information. This innovation breaks through the limitation of traditional encryption technology that can only protect the security of data during transmission, and enhances the privacy protection capability in data exchange. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 This is a flow chart of a sensitive data exchange and privacy protection method based on distributed identity management according to an embodiment of the present invention. DETAILED DESCRIPTION
[0042] The present invention will be further illustrated below with reference to the accompanying drawings and specific embodiments. These embodiments are implemented based on the technical solutions of the present invention. It should be understood that these embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention.
[0043] like Figure 1 As shown, an embodiment of the present invention provides a sensitive data exchange and privacy protection method based on distributed identity management, including:
[0044] A user creates a decentralized identity identifier (DID) through a blockchain (such as Ethereum or Hyperledger Indy) and encrypts and stores user identity information and authorization data in a decentralized storage system. Specifically, a DID consists of a public-private key pair and a DID document. The DID document stores user identity information, authentication information, related public keys, service endpoints, etc. The DID document format is defined as:
[0045] DID=did:method:unique-id
[0046] Where method is the DID method and unique-id is the unique identifier.
[0047] Users' personal identity information, authorization data, and other information are stored on decentralized storage systems such as IPFS. Data is encrypted and stored, ensuring only authorized parties can access it. Users can update or revoke authorization at any time, ensuring data remains under their control.
[0048] Users define authorization information through smart contracts on the blockchain, generating authorization tokens and storing them encrypted. Authorization information includes the scope of data access and the authorization time limit. The authorization token includes the data fields to be accessed, the time range, and usage restrictions. Users issue authorization tokens through smart contracts on the blockchain platform, defining which data can be accessed, the scope of access, and the time limit. The authorization token is stored encrypted and can only be decrypted by authorized parties. Authorization token example:
[0049] Token={Data fields,Access Period,Scope,Signature}
[0050] Token is the authorization token, Data fields is the data field, Access Period is the access time range, Scope is the scope of access rights, and Signature indicates the signature using the private key.
[0051] Data application parties (such as insurance companies and lending institutions) send query requests to data holders through smart contracts to ensure that the data they request meets the conditions of user authorization. The data holder returns encrypted data that meets the authorization based on blockchain verification and smart contract execution. Specifically, after receiving the query request from the data application party, the data holder verifies the authorization token through the smart contract on the blockchain, and confirms whether the data application party has the right to access the user's target data based on the rules of the smart contract and the authorization token. If the data application party has the right to access, the authorized data is generated into a minimized data subset based on the query request and authorization information, and the minimized data subset is encrypted and sent to the data application party. The encrypted minimized data subset is preferably sent to the data application party through the TLS1.3 protocol to ensure the security of the data transmission process.
[0052] The above method of generating a minimized data subset from the authorization data based on the query request and authorization information is as follows:
[0053] According to the request field F of the data demander Q and user authorization field A U , calculate the actual transmission field F S :
[0054] F S =F Q ∩A U
[0055] Among them, ∩ is the intersection symbol.
[0056] According to the screening conditions of the data demander C Q and user authorization condition C A , calculate the filtering condition C of the actual transmitted data S :
[0057] C S =C Q ∩C U
[0058] Machine learning algorithms are used to analyze historical request data, predict the requester's field preferences, and optimize data sharding strategies. Fields are weighted based on their relevance and historical query frequency, prioritizing high-weighted fields for subsequent transmission. These machine learning algorithms include cluster analysis and regression analysis.
[0059] The data subset that generates the minimum is:
[0060] D S ={d i ∈D|d i [F S ]Satisfy C S And weight>threshold}
[0061] Among them, D S is the generated minimized data subset, D is the authorized data, D={d1,d2,d3...d n}, where d j Represents each data unit in the data set D, j = 1, 2, ..., n, d i is the data unit in D.
[0062] Preferably, the minimized data subset is encrypted using an AES-256 or RSA encryption algorithm. Taking the AES-256 encryption algorithm as an example, it is specifically expressed as follows:
[0063] D E =E K (D S )
[0064] Among them, D E is the encrypted minimized data subset, E K (.) is the AES-256 encryption function.
[0065] After receiving the encrypted minimized data subset, the data application party verifies the legitimacy of the data through smart contracts and authorization tokens. After the verification is passed, the data it receives is decrypted to obtain the minimized data subset.
[0066] Data holders also prefer to use homomorphic encryption algorithms to encrypt a minimized subset of data, allowing data users to perform statistical or computational tasks while the data is encrypted. For example, calculating the total amount of reimbursement. Homomorphic encryption ensures that data is processed in an encrypted state, reducing the risk of data leakage.
[0067] Smart contracts can also be used to clearly define the responsibilities and permissions in each link of data exchange. When a liability incident occurs during the data exchange process (such as data leakage, unauthorized access, etc.), the smart contract automatically executes the responsibility allocation and compensation mechanism. Smart contract example:
[0068] Contract
[0069] ={DataOwner,ApplicationRequester,Responsibilities,Signatures}
[0070] Among them, Contract represents the smart contract, DataOwner represents the data holder, DataOwner represents the data user, and Responsibilities represents the responsibilities and permissions in each link of data exchange.
[0071] Data requests, authorizations, and transmission operations can also be uploaded to the blockchain. Through the timestamps and encrypted signatures on the blockchain, data holders, applications, and users can audit data flows and responsibility execution in real time.
[0072] Specific examples:
[0073] 1. Background
[0074] In many countries and regions, governments are required to regularly collect and update citizens' social security information and tax records. This data is fundamental to public services, welfare distribution, and tax administration. However, traditional methods of data exchange and sharing often face risks of privacy breaches and data misuse, especially since citizens' personal social security data and tax records are highly sensitive.
[0075] At the same time, financial institutions (such as banks and credit institutions) also need to access some of citizens' tax records and social security information for loan approvals, credit assessments, and other operations. To ensure the security and privacy of this sensitive data while meeting the needs of governments, financial institutions, and citizens, a data exchange method based on distributed identity management (SSI) and a triple authorization mechanism provides an innovative and compliant solution.
[0076] 2. Solution
[0077] 1. Distributed Identity Management (SSI)
[0078] Goal: To empower citizens with control over their social security data and tax records through a decentralized identity management system (e.g., blockchain-based DIDs), ensuring data privacy and security.
[0079] step:
[0080] 1) Citizens create a decentralized identity (DID): Citizens create a decentralized identifier (DID) on a blockchain platform (such as Ethereum or Hyperledger Indy). This identifier uniquely identifies the citizen and is tied to their personal information (such as name, address, social security number, tax ID number, etc.). The DID document stores the user's identity information and public key, ensuring data encryption and unforgeability.
[0081] 2) Identity Information Storage and Management: Citizens' social security information and tax records are stored on decentralized storage platforms (such as IPFS). Data is encrypted to ensure only authorized parties have access. Citizens can review and update their authorization information at any time and decide which government departments or financial institutions can access which data.
[0082] 3) Authorization management: Citizens define the scope and time limit of authorization through smart contracts. For example, they can authorize banks or credit institutions to access their tax records when applying for a loan, but not allow other data (such as social security account balances, etc.) to be accessed.
[0083] 2. Triple authorization mechanism
[0084] Objective: To ensure that the responsibilities and authorities of the government, financial institutions, and citizens are clearly defined during the data exchange process, and to enhance the compliance and transparency of data exchange.
[0085] step:
[0086] 1) User Authorization: Citizens authorize access to the distributed identity management platform, specifying the information they allow the government and financial institutions to access. For example, they may authorize a bank to view their tax records and social security information (such as social security contributions), but not other private information (such as home address). This authorization information is encrypted and stored, generating an authorization token that includes the fields to be accessed, the time limit, and the scope of the permission.
[0087] Example authorization token:
[0088] Token = {Data fields = {Tax records, Social Security information}, Scope = {Access is limited to data from the past 12 months}, Signature}
[0089] 2) Confirmation by the data holder (government agency): Upon receiving a request from a financial institution, a government agency (such as the tax bureau or social security bureau) first queries the citizen's authorization information through the blockchain to confirm whether the citizen has authorized the data to be provided. The government agency verifies the legitimacy of the data based on the smart contract and generates a confirmation certificate, demonstrating that the data exchange process complies with user authorization and legal requirements.
[0090] Example of confirmation certificate:
[0091] Proof=Hash(Authorization Token)
[0092] After the confirmation certificate is verified through cryptographic signature, the government department returns it to the bank to confirm that the data exchange is legal and in compliance with authorization.
[0093] 3) Data Requests from Financial Institutions: Banks or credit institutions initiate data requests to ensure they only access citizens' tax and social security data within their authorized scope. Data requests are executed through smart contracts, ensuring they adhere to the scope and timeframe authorized by the user.
[0094] Request={Tax Records,Social Security Contributions,Period=Last12months}
[0095] 3. Data encryption and privacy protection
[0096] Goal: To ensure privacy and security during data exchange and prevent sensitive data from being stolen or misused during transmission.
[0097] step:
[0098] 1) Data Sharding and Encryption: Government agencies dynamically segment citizens' tax and social security data, generating minimal data sets based on the needs of financial institutions and user authorization (for example, only providing tax records for the past 12 months). Each data segment is encrypted using the AES-256 encryption algorithm or RSA encryption to ensure data security during transmission.
[0099] 2) Data transmission: Use TLS1.3 or higher-level encryption protocols to ensure the security of data transmission and prevent it from being intercepted or tampered with.
[0100] 3) Data decryption and verification: After receiving the encrypted data, the financial institution uses the private key to decrypt the data fragments and verify the legitimacy of the data through smart contracts to ensure that the data exchange complies with the authorized scope.
[0101] 4) Smart contracts and responsibility sharing
[0102] Goal: Ensure clear accountability and compliance during data exchange through smart contracts and responsibility-sharing agreements.
[0103] step:
[0104] 1) Smart Contracts Define Responsibilities: Smart contracts clarify the responsibilities of data holders (government agencies) and data users (financial institutions) during data exchange. For example, government agencies are responsible for data storage and authorization verification, while financial institutions are responsible for the legal use of data and privacy protection. The contract defines the proportion of responsibilities for each party, ensuring that liability is automatically allocated in the event of data misuse or leakage.
[0105] 2) Responsibility allocation and automated execution: When a liability event (such as a data leak) occurs during data exchange, the smart contract will automatically execute the responsibility allocation. For example, if a bank fails to use data within the scope of authorization, the bank will be held legally responsible.
[0106] Smart contract liability examples:
[0107] Contract={Data Owner=Government,Data User=Bank,Responsibilities,Signature}
[0108] The contract records the allocation of responsibilities for each link to ensure that all responsibilities are traceable and enforceable.
[0109] The above description is merely a preferred embodiment of the present invention. It should be noted that any other aspects not specifically described are considered prior art or common knowledge to those skilled in the art. Improvements and modifications may be made without departing from the principles of the present invention, and such improvements and modifications are also within the scope of protection of the present invention.
Claims
1. A sensitive data exchange and privacy protection method based on distributed identity management, characterized in that: include: The user creates a decentralized identity identifier through the blockchain and encrypts the user identity information and authorization data and stores them in a decentralized storage system; Users define authorization information through smart contracts on the blockchain, generate authorization tokens, and store them in encrypted form. The authorization information includes the scope of data access and the authorization period. The data application party sends a query request to the data holder through a smart contract. After receiving the query request from the data application party, the data holder verifies the authorization token through the smart contract on the blockchain and confirms whether the data application party has the right to access the user's target data based on the rules of the smart contract and the authorization token. If the data application party has the right to access, the authorized data is generated into a minimized data subset based on the query request and authorization information, and the minimized data subset is encrypted and sent to the data application party. After receiving the encrypted minimized data subset, the data application party verifies the legitimacy of the data through the smart contract and authorization token. After the verification is passed, the data application party decrypts the received data to obtain the minimized data subset.
2. A sensitive data exchange and privacy protection method based on distributed identity management according to claim 1, characterized in that: The decentralized identity identifier includes a public-private key pair and a DID document, and the DID document stores user identity information, authentication information, related public keys and service endpoints.
3. The sensitive data exchange and privacy protection method based on distributed identity management according to claim 1 is characterized in that: The authorization token is represented as: Token={Data fields,Access Period,Scope,Signature} Token is the authorization token, Data fields is the data field, Access Period is the access time range, Scope is the scope of access rights, and Signature indicates the signature using the private key.
4. The sensitive data exchange and privacy protection method based on distributed identity management according to claim 1 is characterized in that: The method of generating a minimized data subset from the authorization data according to the query request and the authorization information is as follows: According to the request field F of the data demander Q and user authorization field A U , calculate the actual transmission field F S : F S =F Q ∩A U Among them, ∩ is the intersection symbol; According to the screening conditions of the data demander C Q and user authorization condition C A , calculate the filtering condition C of the actual transmitted data S : C S =C Q ∩C U Use machine learning algorithms to analyze historical request data, predict the demander's field preferences, and optimize data sharding strategies; and assign weights to fields based on their relevance and historical query frequency; The data subset that generates the minimum is: D S ={d i ∈D|d i [F S ]Satisfy C S And weight>threshold} Among them, D S is the generated minimized data subset, D is the authorized data, D={d1,d2,d3...d n }, where d j Represents each data unit in the data set D, j = 1, 2, ..., n, d i is the data unit in D.
5. The sensitive data exchange and privacy protection method based on distributed identity management according to claim 1 is characterized in that: The minimized data subset is encrypted using an AES-256 or RSA encryption algorithm.
6. The sensitive data exchange and privacy protection method based on distributed identity management according to claim 1 is characterized in that: The data holder also uses a homomorphic encryption algorithm to encrypt the minimized data subset so that the data application party can perform statistical or computing tasks in the data encrypted state.
7. The sensitive data exchange and privacy protection method based on distributed identity management according to claim 1 is characterized in that: The data holder sends the encrypted minimized data subset to the data application party via the TLS 1.3 protocol.
8. The sensitive data exchange and privacy protection method based on distributed identity management according to claim 1 is characterized in that: Also includes: Smart contracts are used to clearly define the responsibilities and permissions in each link of data exchange. When a liability incident occurs during the data exchange process (such as data leakage, unauthorized access, etc.), the smart contract automatically executes the responsibility allocation and compensation mechanism.
9. The sensitive data exchange and privacy protection method based on distributed identity management according to claim 1, characterized in that: Data requests, authorizations, and transmission operations are all uploaded to the blockchain. Through the timestamps and encrypted signatures on the blockchain, data holders, applications, and users can all audit data flows and enforce responsibilities in real time.