Data accurate authorization system and method based on distributed digital identity
Through the combined distributed digital identity and verified credential technology of blockchain, data authorization is realized, security and accuracy are solved, and the issues of identity verification and paper authorization management under the centralized identity management system are solved, ensuring the consistency of the willingness of the data subject and privacy protection.
Patent Information
- Application Number
- CN202510847266.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-08-12
AI Technical Summary
The existing data authorization technology relies on a centralized identity management system, and has low automation, making it difficult to achieve consistency verification of the identity and authorization intention of the data subject. The paper authorization letter is inefficient in management efficiency and insufficient privacy protection.
It adopts a distributed digital identity management module, a verified data authorization credential management module and a blockchain system. Through distributed digital identity issuance and verification, combined with verified credential technology, data authorization credentials are generated and parsed, and smart contracts are used to achieve accurate authorization.
It improves the automation and security of data authorization, ensures the consistency of the authorization intention of data subjects, solves the problems of low efficiency and insufficient privacy protection in the management of traditional paper authorization letters, and achieves the efficiency, accuracy and transparency of data authorization.
Smart Images

Figure CN120474823A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data authorization, and more specifically, to a system and method for precise data authorization based on distributed digital identities. Background Art
[0002] Data authorization refers to the process of obtaining and using various types of data in a legal and compliant manner, strictly adhering to the explicit authorization of the data subject (i.e., the owner of the data). Data authorization is the foundation of data sharing, data circulation, and data application, ensuring that data usage complies with laws, regulations, and privacy protection requirements. The core of data authorization is to fully safeguard the wishes of the data subject and ensure that data users use the data legally and within the scope of authorization.
[0003] At present, data authorization mainly relies on traditional centralized identity management systems and authorization mechanisms, which have a low degree of automation, are difficult to meet large-scale data authorization needs, and pose a risk of privacy leakage.
[0004] Chinese invention patent CN113868706A discloses a method for precise authorization of private data in government data sharing. The CA management center issues a personal digital certificate to the applicant, who then authorizes the use of their private data. The applicant then packages the personal data authorization information and the personal digital certificate into a digital pass and sends it to the precise authorization management center. The precise authorization management center verifies with the CA management center based on the parsed information whether the applicant has permission to use the private data. However, the identity system and authorization credentials involved in this authorization scheme rely on a centralized system for issuance and verification, making it difficult to consistently verify the identity and personal wishes of the data subject.
[0005] Chinese invention patent CN115310123A discloses a precise authorization system for a data sharing service system. This system uses a traditional encryption algorithm to encrypt data during transmission. After the authorizer verifies the applicant's information again using electronic certificate information, the application data can be downloaded only after authorization is approved. This multi-dimensional approach protects data security during transmission. However, this authorization scheme primarily relies on manual verification and a centralized precise authorization management center to achieve precise data authorization, resulting in a low level of automation. Furthermore, data authorization is handled by window service personnel, making it difficult to consistently verify the identity and wishes of the data subject.
[0006] Chinese invention patent CN114117389A discloses a method for precise authorization. The data provider connects its private data to the authorization management center according to the access. The data user obtains the directory of data that can be used by subscribing to the data of the authorization management center, and then makes specific preparations for use and interacts with the authorization management party. The authorization management party generates a corresponding precise authorization QR code, which is sent to the authorizer. The authorizer calls the public security facial recognition system in the precise authorization mobile phone application to identify himself and sends the information used by the data user to himself for confirmation. After that, the authorization management center sends the usage information confirmed by himself to the data provider through the API gateway for specific use. However, the authorization code of the above authorization scheme can only be used once, and mainly uses the public security facial recognition system for identity confirmation. The identity information privacy of the data authorizer and user is difficult to protect.
[0007] Based on the above analysis, although existing technologies support the implementation of data authorization to a certain extent, there are still some problems:
[0008] 1) The authorization process is long and the data subject identity verification channels are insufficient. Data subject identity verification usually relies on third-party agencies or manual verification. The limited verification channels make it difficult to verify the consistency between the authorization letter and the data subject's wishes.
[0009] 2) Data subjects are usually required to sign multiple authorizations from different sources and types, which results in a cumbersome process and consumes a lot of time and effort;
[0010] 3) Data authorization documents from different sources have different formats and lack unified standards, making it difficult to efficiently access and manage massive amounts of paper documents;
[0011] 4) Authorization materials are usually separated from the actual business system, making it difficult to control the validity period of data authorization, unable to effectively supervise whether the data user exceeds the limit or uses data beyond the scenario, and difficult to achieve accurate authorization
[0012] Therefore, further research and optimization are still needed to achieve a more efficient, secure and accurate data authorization mechanism. Summary of the Invention
[0013] The purpose of the present invention is to provide a data accurate authorization system and method based on distributed digital identity to solve the problems of complex authorization credential management and insufficient privacy protection in the data authorization process in the existing technology.
[0014] To achieve the above objectives, the present invention provides a data precision authorization system based on distributed digital identity, including a distributed digital identity management module, a verifiable data authorization credential management module, and a blockchain system;
[0015] The distributed digital identity management module is used to issue and verify distributed digital identities for participants in the data authorization process, including some or all of the data providers, data authorizers, and data users;
[0016] The verifiable data authorization credential management module uses distributed digital identity information and verifiable credential technology to generate and verify data authorization credentials, and parses data authorization credentials through smart contracts to achieve accurate authorization of data;
[0017] The blockchain system is used to store distributed digital identity information, data authorization credential information and related operation records.
[0018] In some embodiments, the distributed digital identity management module includes at least an identity issuance submodule, a data signature submodule, and a data verification submodule:
[0019] The identity issuance submodule is used to issue distributed digital identities to participants;
[0020] The data signature submodule uses a private key and a signature algorithm to sign the input data, wherein the input data includes basic information of a distributed digital identity and / or data authorization credential data;
[0021] The data verification submodule is used to perform signature verification on input data, where the input data includes a distributed digital identity and / or data authorization credential data.
[0022] In some embodiments, the distributed digital identity management module further includes a real-name identity management submodule:
[0023] The real-name identity management submodule is used to authenticate the real-name identity of the participants and map and verify the real-name identity with the distributed digital identity.
[0024] In some embodiments, the distributed digital identity data includes at least an identity identifier and a DID document;
[0025] The identity identifier is used to uniquely identify the distributed digital identity;
[0026] The DID document is used to describe identity information and includes at least the DID's identity identifier and public key information.
[0027] In some embodiments, the data signature submodule performs batch signing on the input data.
[0028] In some embodiments, the data verification submodule uses the identity identifier to retrieve the corresponding DID document in the blockchain system to obtain the public key information of the distributed digital identity data, and uses the public key to perform signature verification on the input data.
[0029] In some embodiments, the verifiable data authorization credential management module includes a data authorization credential generation submodule and a data authorization credential verification submodule:
[0030] The data authorization credential generation submodule is used to generate a data authorization credential using distributed digital identity information in combination with verifiable credential technology;
[0031] The data authorization certificate verification submodule is used to verify the data authorization certificate and parse the data authorization certificate through the smart contract to achieve accurate authorization of the data.
[0032] In some embodiments, the DID document includes at least the following fields:
[0033] The id field is an identifier that uniquely identifies the DID document;
[0034] The version field is used to specify the version number of the DID document;
[0035] The controller field is used to specify one or more DID controllers;
[0036] The proof field contains the signature information of the DID document and is used to verify the DID document.
[0037] In some embodiments, the data authorization certificate includes at least the following fields:
[0038] The id field is the unique identifier of the data authorization credential;
[0039] The issuer field is the issuer of the data authorization certificate;
[0040] The issuanceDate field is the authorization date of the data authorization certificate;
[0041] The expirationDate field is the authorization expiration date of the data authorization certificate;
[0042] The credentialSubject field is the authorization data item;
[0043] The proof field contains the signature information of the data authorization certificate.
[0044] To achieve the above objectives, the present invention provides a method for accurate data authorization based on distributed digital identity, comprising the following steps:
[0045] Data authorization steps: Based on the data authorization request initiated by the data authorizer, the distributed digital identity of the data authorizer is issued and uploaded to the chain. The distributed digital identity information is combined with the verifiable certificate technology to generate the data authorization certificate and upload it to the chain;
[0046] Data usage request step: Initiate a data usage request based on the data user's data usage requirements;
[0047] Data provision steps: In response to the data user's data usage request, obtain the data authorization certificate related to the data authorizer, verify the data authorization certificate based on the data authorizer's distributed digital identity information, and parse the data authorization certificate through the smart contract to achieve accurate data authorization from the data provider to the data user.
[0048] In some embodiments, the data user request step further includes: after the data user initiates the data user request, issuing a distributed digital identity of the data user and uploading it to the blockchain;
[0049] The data providing step also includes: authenticating the real-name identity of the participants, mapping and verifying the real-name identity with the distributed digital identity, and the participants at least include data users and / or data authorizers.
[0050] In some embodiments, the data authorization step further includes: signing a DID document of the distributed digital identity of the data authorizer and signing basic information of the data authorization credential of the data authorizer;
[0051] The data providing step also includes: verifying the DID document signature of the distributed digital identity of the data authorizer and verifying the signature of the data authorization certificate of the data authorizer.
[0052] In some embodiments, the data authorization step further includes:
[0053] Batch signing is performed on input data, where the input data includes basic information of a distributed digital identity and / or data authorization credential data.
[0054] In some embodiments, the distributed digital identity data includes at least an identity identifier and a DID document;
[0055] The identity identifier is used to uniquely identify the distributed digital identity;
[0056] The DID document is used to describe identity information and includes at least the DID's identity identifier and public key information.
[0057] In some embodiments, the DID document includes at least the following fields:
[0058] The id field is an identifier that uniquely identifies the DID document;
[0059] The version field is used to specify the version number of the DID document;
[0060] The controller field is used to specify one or more DID controllers;
[0061] The proof field contains the signature information of the DID document and is used to verify the DID document.
[0062] In some embodiments, the data authorization certificate includes at least the following fields:
[0063] The id field is the unique identifier of the data authorization credential;
[0064] The issuer field is the issuer of the data authorization certificate;
[0065] The issuanceDate field is the authorization date of the data authorization certificate;
[0066] The expirationDate field is the authorization expiration date of the data authorization certificate;
[0067] The credentialSubject field is the authorization data item;
[0068] The proof field contains the signature information of the data authorization certificate.
[0069] In order to achieve the above-mentioned objectives, the present invention provides a computer-readable storage medium on which a computer program executable by a processor is stored. When the computer program is executed by the processor, a method for accurate data authorization based on distributed digital identity is implemented.
[0070] The present invention proposes a method and system for precise data authorization based on distributed digital identity. By combining distributed digital identity (DID) and verifiable credentials (VC), as well as the transparency and immutability of blockchain, it ensures the security, accuracy and efficiency of the data authorization process. It not only improves the authorization efficiency, but also effectively solves the problems in the management of traditional paper authorization documents, while protecting the privacy of the participants and the accuracy of the authorization intention. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] The above and other features, properties and advantages of the present invention will become more apparent from the following description taken in conjunction with the accompanying drawings and embodiments, in which like reference numerals denote like features throughout, wherein:
[0072] Figure 1A block diagram of a distributed digital identity-based data authorization system according to an embodiment of the present invention is disclosed;
[0073] Figure 2 A step diagram of a method for accurate data authorization based on distributed digital identity according to an embodiment of the present invention is disclosed;
[0074] Figure 3 A workflow diagram of a distributed digital identity-based data precision authorization system according to an embodiment of the present invention is disclosed.
[0075] The meanings of the reference numerals in the figures are as follows:
[0076] 100 distributed digital identity management module;
[0077] 101 identity issuance submodule;
[0078] 102 data signature submodule;
[0079] 103 data verification submodule;
[0080] 104 real-name identity management submodule;
[0081] 200 Verifiable data authorization credential management module;
[0082] 201 data authorization certificate generation submodule;
[0083] 202 data authorization credential verification submodule;
[0084] 300 blockchain system. DETAILED DESCRIPTION
[0085] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the invention and are not intended to limit the invention.
[0086] The present invention proposes an implementation scheme, device system and storage medium for precise data authorization based on distributed digital identity, which adopts a distributed digital identity (DID) based on blockchain and realizes precise data authorization through verifiable credentials (VC).
[0087] Distributed digital identity (DID) is a new type of identity authentication mechanism that uses decentralized technologies (such as blockchain) for management, providing enhanced security and privacy. Each DID identity is stored in a DID document on the blockchain, which can be retrieved from the blockchain using the DID identifier. The DID document is structured data that describes the identity information and includes the DID's unique identifier, public key information, and more.
[0088] A Verifiable Credential (VC) is a blockchain-based authentication credential designed to ensure data is tamper-proof during the authorization process and can be verified by all parties. A VC is a DID identity that endorses another DID's data request and other information. The issuer adds their DID's digital signature to the VC, ensuring the verifiability and immutability of the VC content.
[0089] Figure 1 The principle block diagram of the data accurate authorization system based on distributed digital identity according to an embodiment of the present invention is disclosed. Figure 1 As shown, the present invention proposes a data precision authorization system based on distributed digital identity, including a distributed digital identity management module 100, a verifiable data authorization credential management module 200, and a blockchain system 300:
[0090] The distributed digital identity management module 100 is used to issue and verify distributed digital identities for participants in the data authorization process, including some or all of the data providers, data authorizers, and data users.
[0091] The verifiable data authorization credential management module 200 uses distributed digital identity information and verifiable credential technology to generate and verify data authorization credentials, and parses data authorization credentials through smart contracts to achieve accurate authorization of data;
[0092] The blockchain system 300 is used to store distributed digital identity information, data authorization credential information and related operation records.
[0093] Furthermore, the distributed digital identity management module 100 includes an identity issuance submodule 101 , a data signature submodule 102 , a data verification submodule 103 , and a real-name identity management submodule 104 .
[0094] The identity issuance submodule 101 is used to issue a distributed digital identity (DID) to a participant.
[0095] The participants include data authorizers (data subjects), data providers, and data users. Data authorizers (data subjects) are the entities that own the data and exercise authorization authority, confirming their authorization intention through their DID identities. Data providers are the entities that store or manage data and are responsible for providing designated data after verifying authorization credentials. Data users are the requestors who obtain data usage rights and must use the data within the scope of authorization.
[0096] Participants can be individuals or legal entities. Any participant with data authorization needs can use this system. While protecting user identity privacy, it solves the problem of consistency between identity verification and data authorization intentions, and uses blockchain technology and smart contract technology to accurately authorize data.
[0097] DID identity data consists of two main data: identity identifier and DID document:
[0098] The identity identifier is used to uniquely identify the DID;
[0099] The DID document is a data file in JSON format that describes identity information. The document content includes the unique identity identifier of the DID identity, public key information, etc.
[0100] In this embodiment, the DID identity identifier and the corresponding DID document are both stored on the blockchain system 300.
[0101] The DID document includes but is not limited to the following main fields:
[0102] id field, used to uniquely identify the DID document;
[0103] The version field is used to specify the version number of the DID document;
[0104] The controller field specifies one or more DID controllers who can modify this DID document after being authorized.
[0105] The proof field contains the signature information of the DID document and is used to verify the DID document. It specifically describes the signature information of the DID issuer.
[0106] In the proof field of a DID document, a signature is generated by the identity authority (such as a CA or government agency) using its private key. This signature does not belong to the three data authorization parties (data subject, user, and data provider), but rather is an endorsement of the legitimacy of the participant's identity by a trusted third party.
[0107] For example, the data structure and content of a DID document are as follows:
[0108]
[0109]
[0110] The context field defines the JSON-LD (Linked Data) context used by the DID document. In this example, it points to the standard DID context (https: / / www.w3.org / ns / did / v1) and the system-specific context (https: / / www.unitrust.com.cn / individual / data_delegation / v1). Context is key to ensuring consistent interpretation of data structures.
[0111] The id field represents the unique identifier of the DID document. In this example, did:unitrust:51uYnBT3KXnbHowvEn5ksG23quaJ is the DID identifier, which identifies the identity to which this document belongs. did:unitrust is the DID method used by this system, while the following portion is the DID identifier, which uniquely identifies that identity.
[0112] The controller field specifies one or more DID controllers (typically the owner or manager of the identity). In this example, the controller of the DID document is
[0113] did:unitrust:51uYnBT3KXnbHowvEn5ksG23quaJand
[0114] did:unitrust:5LiUUEscVL5Lr3FNyEVw6mssCxVZ, these controllers are authorized to modify or manage DID documents.
[0115] The assertionMethod field lists the method used to verify the DID's identity assertion. In this example, did:unitrust:51uYnBT3KXnbHowvEn5ksG23quaJ#key-1 is the key associated with the DID, which ensures the DID's identity is verified and signed. The assertionMethod typically refers to the public key in the certificate chain used to assert the identity.
[0116] The created field records the creation time of the DID document. 2024-09-25T21:40:59Z indicates the creation time of the document in UTC time.
[0117] The updated field records the last update time of the DID document. Similar to the created field, it indicates the last update time of the document.
[0118] The deactivated field indicates whether the DID identity has been deactivated. A false value indicates that the DID identity is activated. If this field is true, it indicates that the DID identity has been deactivated or disabled and can no longer be used for authentication.
[0119] The versionId field specifies the version number of the DID document. In this example, versionId:1 indicates that this is the first version of the DID document. If the document is modified, the version number will be incremented.
[0120] The keyValidity field contains the key's validity information, including the key's validity period and permissions. In this example, key-1 is valid until 2124-09-25, and the permissions field is empty, meaning that the key has no specific permissions or restrictions attached.
[0121] The proof field includes the following subfields:
[0122] type: Indicates the signature type. In this example, SM3WithSM2 is used, which is a Chinese standard digital signature algorithm that combines the SM3 hash algorithm and the SM2 public key algorithm.
[0123] created: indicates the creation time of the signature. 2024-09-25T21:40:59Z is the timestamp of the signature.
[0124] verificationMethod: Specifies the public key verification method used to verify the signature. In this example, did:unitrust:5LiUUEscVL5Lr3FNyEVw6mssCxVZ#key-1 is used to verify the signature.
[0125] proofPurpose: Indicates the purpose of the signature, and assertionMethod indicates that the signature is used to verify the legitimacy of the identity claim.
[0126] ProofValue: This is the signature value, which is generated using the private key to ensure the authenticity and immutability of the document. The signature value is encrypted and requires public key verification to ensure that the data has not been tampered with.
[0127] This DID document contains identity information, version control, public key information, and the signature information of the DID issuer to ensure the authenticity, integrity, and immutability of the DID identity.
[0128] Furthermore, the data signature submodule 102 is used to use a signature algorithm to sign the input data using the private key of the DID.
[0129] Specifically, the DID's private key is held by the owner of the DID identity, ensuring the consistency between the identity of the data signature and its signing intention.
[0130] When data needs to be signed, the data signature submodule 102 is called, and the data signature submodule 102 uses a signature algorithm to add a signature value to the data. This signature value represents the signature DID's confirmation of the data, ensuring the authenticity and integrity of the data.
[0131] In this embodiment, the data input into the data signature submodule 102 includes basic information of a distributed digital identity and / or data authorization credential data.
[0132] The data signature submodule 102 supports batch data signature function, which effectively solves the problem that the data subject needs to sign multiple authorization letters from different sources and different types when handling business.
[0133] The specific implementation method of batch data signing is completed through the following methods:
[0134] Once the data subject passes DID identity verification and confirms their willingness to sign multiple authorization certificates, the digital signature submodule 102 retrieves these authorization certificates and digitally signs each one using the data subject's private key. Each authorization certificate is assigned a unique signature value. During the verification phase, the data user uses the data subject's public key to verify each authorization certificate and its corresponding signature, ensuring the integrity and authenticity of each authorization certificate.
[0135] Through this function, the data signature submodule 102 only needs to perform one signing operation to complete the signing confirmation of all relevant authorization certificates; then, based on the signing intention of the data subject, a unique signature will be generated for each authorization certificate.
[0136] In this embodiment, the signing process uses signature algorithms (such as SM2, RSA, and ECDSA) to ensure data integrity and immutability during transmission and storage. SM2 is an elliptic curve public key algorithm in my country's commercial cryptography standards, RSA is a classic asymmetric encryption algorithm based on the large integer factorization problem, and ECDSA is an international standard algorithm based on elliptic curve digital signatures. All three effectively guarantee data security.
[0137] The data verification submodule 103 is used to perform signature verification on input data, where the input data includes a distributed digital identity and / or data authorization credential data.
[0138] Specifically, the input data of the data verification submodule 103 is data signed using the private key of the DID.
[0139] During the verification process, the data verification submodule 103 retrieves the DID document corresponding to the DID through the blockchain system 300 and obtains the DID's public key. The public key is then used with the corresponding cryptographic algorithm (such as SM2, RSA, and ECDSA) to verify the signature of the input data.
[0140] If the signature verification succeeds, it means that the signature was indeed generated by the identity subject corresponding to the DID, confirming the integrity of the data and the consistency of the signing intention. If the verification fails, it means that the signature is invalid and the data may have been tampered with or the source is unknown.
[0141] It should be noted that the data verification submodule 103 is a fundamental capability module within the system, responsible for completing DID-based signature verification and data integrity checks. At a higher level in the business logic, the data authorization verification submodule 202 invokes the basic verification functions of module 103 and further verifies the status and lifecycle of the data authorization credential (e.g., whether it is valid, expired, or revoked) through blockchain smart contracts, thereby ensuring the credential's validity and credibility at the business level.
[0142] The real-name identity management submodule 104 is used to authenticate the real-name identity of the participants in the data authorization process, and map and verify the real-name identity with the distributed digital identity.
[0143] Specifically, the real-name identity management submodule 104 is used when the data provider needs to match the real-name identity and DID identity of the data subject and the data user, ensuring that the real-name identity and DID identity can be accurately associated and confirmed in scenarios where real-name authentication is required.
[0144] During the data authorization process, after the participant completes the real-name authentication, the identity issuance submodule 101 will automatically generate a unique DID for the participant by calling the smart contract on the blockchain system 300.
[0145] The real-name identity management submodule 104 is applicable when the data owner is a real-name identity. However, if the data owner is a DID, the real-name identity management submodule 104 will not be called. In this case, the real-name identity of the participant will be hidden, thereby protecting their identity privacy and ensuring that the privacy of the data subject is fully protected.
[0146] The verifiable data authorization credential (VC) management module 200 is used for generating and verifying data authorization credentials.
[0147] Furthermore, the verifiable data authorization credential management module 200 includes a data authorization credential generation submodule 201 and a data authorization credential verification submodule 202:
[0148] The data authorization certificate generation submodule 201 is used to generate a data authorization certificate using distributed digital identity information in combination with verifiable certificate technology;
[0149] The data authorization certificate verification submodule 202 is used to verify the data authorization certificate and parse the data authorization certificate through a smart contract to achieve accurate authorization of the data.
[0150] The data authorization certificate generation submodule 201 generates basic information of the data authorization certificate in a standard format according to the authorization intention of the data subject;
[0151] The basic information of the data authorization certificate includes the identity of the data subject, the identity of the user, the authorization period, whether the authorization is valid for one time, the authorized data items, etc.
[0152] The data subject identity is the identity information of the data authorizer;
[0153] The user identity is the identity information of the data user;
[0154] The authorization period is the start and end time of the authorization;
[0155] Whether the authorization is valid for one time, used to indicate whether the authorization is limited to one time use;
[0156] The authorized data items are specific authorized data items, which may involve personal information or information items.
[0157] The data authorization certificate generation submodule 201 signs the basic information of the data authorization certificate by calling the data signature submodule 102 of the distributed digital identity management module 100, ensures the legitimacy of the certificate content and the confirmation of the data subject, and generates a data authorization certificate based on a verifiable certificate (VC).
[0158] The present invention generates a standardized data authorization certificate based on a verifiable certificate (VC) through the data authorization certificate generation submodule 201, thereby solving the problem that traditional paper authorization documents are difficult to access.
[0159] The data authorization credential data will be stored on the blockchain system 300, and relevant participants can access and verify these data authorization credentials through the blockchain system 300.
[0160] Next, the data authorization credentials are explained.
[0161] In this embodiment, the data authorization certificate includes but is not limited to the following main fields.
[0162] The id field is the unique identifier of the data authorization certificate, which ensures the uniqueness of the certificate on the blockchain and facilitates identification and access;
[0163] The issuer field is the issuer of the data authorization certificate, which is a DID (distributed digital identity) in this case, representing the authorized party of the data authorization certificate;
[0164] The issuanceDate field is the authorization date of the data authorization certificate, that is, the specific time when the certificate was issued;
[0165] The expirationDate field is the authorization expiration date of the data authorization certificate. The certificate will no longer be valid after this date and is used to control the validity period of the certificate.
[0166] The credentialSubject field is the authorization data item;
[0167] The proof field contains the signature information of the verifiable data authorization certificate and is used to verify the verifiable data authorization certificate.
[0168] In the proof field of the VC document, the signature is generated by the data authorizer (such as the car owner) using his or her own private key to confirm the authenticity and consistency of the authorized content.
[0169] The following is an example of VC data structure and content:
[0170]
[0171]
[0172] The @context field defines the JSON-LD (JSON for Linked Data) context, indicating the structure and understanding rules of the current data.
[0173] The type field defines the type of credential. In this example, it includes VerifiableCredential and IndividualDataDelegation. These two types specify that the credential is verifiable and is used for authorization of personal data.
[0174] The credentialSubject field contains the subject information of the authorization credential, specifically describing the data authorization matters involved in the credential, and includes the following subfields:
[0175] id: the DID identifier of the data subject, indicating the authorized object involved in the data authorization certificate;
[0176] requester: The identity of the data user requesting data;
[0177] requestScene: indicates the scenario of the data request, which may be a specific application scenario or purpose (represented here as yyy);
[0178] ifOnce: Indicates whether the authorization is valid only once. True means that the credential is valid only for one authorization.
[0179] requestDataItem: Indicates the data authorization item, which can contain multiple data items. Here, the authorization includes data items such as ID card, vehicle information, insurance, and education.
[0180] The proof field contains the following subfields:
[0181] type: specifies the signature type. In this example, Ed25519Signature2020 is used, which is a signature method using the Ed25519 algorithm.
[0182] Created: indicates the creation time of the signature, ensuring the timestamp of the signature, here is 2024-06-08T13:24:33Z;
[0183] verificationMethod: Specifies the verification method required to verify the signature. This is a reference to a DID method that indicates how to verify the signature. The specific verification method is did:unitrust:ks1fn89MsLc#key-2, which refers to the key used in the issuer's DID.
[0184] proofPurpose: Indicates the purpose of the signature, which is indicated as assertionMethod here, that is, to prove the authenticity of the content of the certificate.
[0185] proofValue: Contains the actual signature value, which is a signature generated using the issuer's private key to ensure the validity and non-tampering of the certificate.
[0186] In this example, the "issuer" refers specifically to the data subject among the participating parties, that is, the party that owns the data. The data subject identifies itself through its DID and signs the data authorization certificate using the key bound to the DID, thereby authorizing the use of its data.
[0187] The data authorization credential verification submodule 202 is used to verify the generated data authorization credential based on the verifiable credential (VC).
[0188] Specifically, the data authorization certificate verification submodule 202 verifies the signature of the data subject in the data authorization certificate by calling the data verification submodule 103 in the distributed digital identity management module 100. If the verification is successful, it means that the data authorization certificate is consistent with the authorization intention of the data subject and the certificate content is authentic and valid.
[0189] After successful verification, the data provider will parse the basic information in the data authorization certificate through the smart contract of the data authorization certificate verification sub-module 202. The basic information includes data authorization items, user identity, data authorization period, number of data authorizations, etc., to ensure accurate authorization of the data and provide the corresponding authorization data to the user.
[0190] Smart contracts consist of contract code, state variables, functions, events, storage mechanisms, and access controls. These components work together to implement automated, decentralized data authorization, signature verification, and identity authentication. Deployed on a blockchain, smart contracts leverage the blockchain's transparency and immutability to ensure the security, compliance, and efficiency of the data authorization process.
[0191] Furthermore, smart contracts are essentially computer programs and protocols that digitally transmit, verify, or enforce multi-party agreements. Their core content is computer code. This code is deployed and run on a blockchain platform. When pre-set terms and conditions are met, it automatically executes the corresponding actions. This execution process is tamper-proof and requires no human intervention, resulting in high trustworthiness and automated performance.
[0192] In addition, all relevant data usage records will be automatically synchronized to the blockchain system 300 for supervision, ensuring that the use of data authorization complies with regulations and is traceable, thereby achieving accurate authorization and transparent monitoring of data usage.
[0193] As the infrastructure of the system, the blockchain system 300 is mainly responsible for storing, verifying and managing distributed digital identity information, data authorization credential information and all related operation records.
[0194] The blockchain system 300 is responsible for blockchain storage, specifically including:
[0195] Store DID identity data (identifiers, DID documents, etc.).
[0196] Store data authorization credentials to ensure the verifiability and non-tamperability of the credentials.
[0197] The blockchain system 300 executes operations such as issuance of distributed digital identities and data verification through smart contracts.
[0198] Smart contracts ensure the automation and decentralization of the data issuance and verification process, avoiding human intervention.
[0199] The transparency of blockchain provides real-time supervision of data usage. All authorized operations and data call records are recorded in the blockchain, ensuring the legal use of data. If data usage exceeds the authorized scope, it can be tracked and corrected in a timely manner.
[0200] The present invention provides a data precision authorization system based on distributed digital identity, which uses blockchain technology to ensure the high security and transparency of identity authentication and data authorization. Through the collaborative work of modules such as distributed digital identity management, authorization credential generation and verification, the authorization intention and identity consistency of the data subject are effectively guaranteed, while ensuring the accuracy, legality and traceability of data use.
[0201] In order to solve the problems of the prior art, the present invention also proposes a method for accurate data authorization of a distributed digital identity.
[0202] Figure 2 The following discloses a step diagram of a method for accurate data authorization based on distributed digital identity according to an embodiment of the present invention. Figure 2 As shown, the distributed digital identity data accurate authorization method proposed in the present invention includes the following steps:
[0203] S1 data authorization step: based on the data authorization request initiated by the data authorizer, the distributed digital identity of the data authorizer is issued and uploaded to the chain. The distributed digital identity information is combined with the verifiable certificate technology to generate the data authorization certificate and upload it to the chain;
[0204] S2: data usage request step, based on the data usage requirements of the data user, initiates a data usage request;
[0205] The S3 data provision step responds to the data user's data usage request, obtains the data authorization certificate related to the data authorizer, verifies the data authorization certificate based on the data authorizer's distributed digital identity information, and parses the data authorization certificate through the smart contract to achieve accurate data authorization from the data provider to the data user.
[0206] Furthermore, in scenarios involving real-name authentication, the user data request step also includes:
[0207] After the data user initiates a data usage request, the data user's DID identity is issued and uploaded to the blockchain system;
[0208] The data provision step also includes:
[0209] The real-name identity of the participants is authenticated, and the real-name identity is mapped and verified with the distributed digital identity. The participants include at least the data user and / or the data authorizer.
[0210] For example, real-name identity authentication can be performed on data users to further ensure that the data users are consistent with their authorized identities.
[0211] The data accurate authorization method based on distributed digital identity proposed in this invention can be used Figure 1 The data precision authorization system based on distributed digital identity is shown to be implemented. Of course, other suitable systems can also be used, and the present invention is not limited to this.
[0212] Below Figure 1 The data precise authorization method based on distributed digital identity proposed in the present invention is described by taking the distributed digital identity-based data precise authorization system as an example.
[0213] Figure 3 The following discloses a workflow diagram of a data accurate authorization system based on distributed digital identity according to an embodiment of the present invention. Figure 3 As shown, the workflow of the data precision authorization system based on distributed digital identity is as follows:
[0214] In the S1 data authorization step, the data authorizer initiates a data authorization request, issues the data authorizer's DID identity and uploads it to the chain, and generates a verifiable data authorization certificate based on the DID identity and uploads it to the chain.
[0215] More specifically, the data authorizer generates a DID identity through the identity issuance submodule 101, and the identity information is uploaded to the blockchain system 300;
[0216] The data authorization certificate generation submodule 201 generates basic information of the data authorization certificate and uploads it to the blockchain system 300;
[0217] The blockchain system 300 obtains the DID identity of the data authorizer and sends it to the data signature submodule 102 for signing;
[0218] The data signature submodule 102 uses the private key of the data authorizer to sign the data authorization certificate, and uploads the data authorization certificate containing the signature information to the blockchain system 300.
[0219] In the step S2 of data usage request, the data user initiates a data usage request to the data provider based on the data usage requirements. The data usage request includes the usage scenario, data type and authorization information.
[0220] More specifically, the data user generates a data user DID identity through the distributed digital identity issuance submodule 101 and uploads its identity information to the blockchain system 300.
[0221] In the S3 data provision step, the data provider obtains the data authorization certificate related to the data authorizer based on the data user request, verifies the signature of the data authorization certificate based on the DID identity information of the data authorizer, parses the basic information of the data authorization certificate, and provides accurate data authorization to the data user.
[0222] More specifically, the data provider obtains the data authorization credential through the blockchain system 300 and verifies the validity of the credential through the data authorization credential verification submodule;
[0223] The data provider parses the data authorization certificate based on the smart contract, obtains basic information such as data authorization items, user identity, authorization validity period, etc., and decides whether to provide data based on the verification results.
[0224] Furthermore, in the real-name identity authentication scenario, the real-name identity management submodule 104 verifies the mapping relationship between the data user's DID identity and the real-name identity to ensure that the data user is an authenticated legal entity.
[0225] Data usage records and authorization processes are automatically synchronized to the blockchain system 300 for full-process supervision to ensure the legitimacy and transparency of authorized data use.
[0226] It should be noted that in the present invention, the technical solutions of the data precision authorization method based on distributed digital identity and the authorization system complement each other. For the implementation details not described in detail in the method (such as DID document structure, etc.), the relevant descriptions in the aforementioned system embodiment can be directly quoted; similarly, business scenario applications not expanded in the system embodiment can also be implemented by referring to the specific steps of the method embodiment.
[0227] When the implementation process file of the data precision authorization method based on distributed digital identity is a computer program, it can also be stored in a readable storage medium of a computer or mobile device as a product. For example, a computer-readable storage medium may include, but is not limited to, magnetic storage devices (e.g., hard disks, floppy disks, magnetic strips), optical disks (e.g., compact disks (CDs), digital versatile disks (DVDs)), smart cards, and flash memory devices (e.g., electrically erasable programmable read-only memories (EPROMs), cards, sticks, key drives). In addition, the various storage media described herein can represent one or more devices and / or other machine-readable media for storing information. The term "machine-readable medium" may include, but is not limited to, wireless channels and various other media (and / or storage media) that can store, contain, and / or carry code and / or instructions and / or data.
[0228] Next, an example of the present invention will be introduced, namely a data precision authorization system based on distributed digital identity, which is applied to a car maintenance service platform.
[0229] In this example, a car owner authorizes registration on a car maintenance service platform to register the vehicle information under his name.
[0230] First, after the car owner completes real-name identity authentication, they will obtain a unique DID identity through the system's distributed digital identity management module. This identity identifier and related DID documents will be uploaded to the blockchain system for evidence storage, ensuring the authenticity and immutability of the car owner's identity.
[0231] The car owner then calls the system's verifiable data authorization credential management module 200 to confirm the data items requiring authorization, such as the user of the ID card, vehicle registration certificate, driver's license, usage scenario, data authorization period, and number of authorizations. Based on this information, the basic information of the data authorization credential is generated and signed using the car owner's DID private key to complete the authorization confirmation. Finally, a verifiable data authorization credential (VC) is generated and uploaded to the blockchain to ensure the authenticity and immutability of the credential.
[0232] Next, the car maintenance service platform initiates a data usage request through a smart contract.
[0233] The data provider obtains the car owner's data authorization VC through the blockchain system and calls the system's verifiable data authorization certificate management module 200 to perform signature verification. Through signature verification, the system ensures that the data subject's signature is consistent with the authorization intention and verifies the validity of the data authorization certificate.
[0234] After verification, the smart contract automatically parses the information in the data authorization certificate to confirm the validity period and number of valid authorizations. Within the authorization period and number of authorized times, the data provider will provide the specified data content to the car maintenance service platform to achieve accurate authorization.
[0235] In addition, all data authorization operations and usage records will be synchronized to the blockchain system 300, providing transparent supervision and audit traceability for data authorization, ensuring compliance and transparency in the data usage process.
[0236] The present invention proposes a method and system for precise data authorization based on distributed digital identity. By combining distributed digital identity (DID) and verifiable credentials (VC), as well as the transparency and immutability of blockchain, it ensures the security, accuracy and efficiency of the data authorization process. It not only improves the authorization efficiency, but also effectively solves the problems in the management of traditional paper authorization documents, while protecting the privacy of the participants and the accuracy of the authorization intention.
[0237] The present invention proposes a method and system for accurate data authorization based on distributed digital identity, which has the following beneficial effects:
[0238] 1) Through blockchain-based distributed digital identity (DID) technology, real-name DID identities are issued to data authorization participants, solving the problem of user real-name information leakage and ensuring that identity information cannot be tampered with or forged. Combined with cryptographic signature verification algorithms, it abandons reliance on third-party identity verification mechanisms and achieves consistency verification between the data subject's identity and authorization intention, ensuring the authenticity and credibility of the authorization process, and solving the problem of consistency verification between the data subject's identity and data authorization intention;
[0239] 2) The use of Verifiable Credentials (VC) technology has achieved standardized templates for data authorization credentials. The data subject only needs to sign once to generate all relevant authorization credentials, avoiding the tedious operation of signing multiple authorization documents from different sources and types in the traditional process, significantly improving authorization efficiency and user experience;
[0240] 3) By unifying the authorization certificate format and sharing the certificate on the chain, the standardization and traceability of the authorization certificate are achieved. Relevant participants can efficiently access the authorization certificate through the blockchain, solving the problem of difficult access and management of paper authorization documents, and improving the management efficiency of data authorization;
[0241] 4) Through blockchain and smart contract technology, precise control is exercised over data usage scenarios, scope, and authorization time, ensuring that data users use data legally within the authorized scope. Furthermore, data access records are stored on-chain, enabling full process oversight and effectively preventing users from using data across scenarios and beyond their scope, ensuring the accuracy and compliance of data authorization.
[0242] Although the above methods are illustrated and described as a series of acts for simplicity of explanation, it is to be understood and appreciated that these methods are not limited by the order of the acts, as some acts may occur in a different order and / or concurrently with other acts from those illustrated and described herein or not illustrated and described herein but understandable to those skilled in the art according to one or more embodiments.
[0243] As used in this application and the claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" are not intended to refer to the singular but may include the plural. Generally speaking, the terms "comprises" and "include" only indicate the inclusion of the steps and elements specifically identified, and these steps and elements do not constitute an exclusive list. A method or apparatus may also include other steps or elements.
[0244] Those skilled in the art will appreciate that information, signals, and data may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips cited throughout the foregoing description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0245] Those skilled in the art will further appreciate that the various illustrative logic blocks, modules, circuits, and algorithmic steps described in conjunction with the embodiments disclosed herein can be implemented as electronic hardware, computer software, or a combination of the two. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps are generally described above in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system. A skilled person may implement the described functionality in different ways for each specific application, but such implementation decisions should not be interpreted as resulting in a departure from the scope of the present invention.
[0246] The various illustrative logic modules and circuits described in conjunction with the embodiments disclosed herein may be implemented or executed using a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.
[0247] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. The software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read and write information from / to the storage medium. In an alternative, the storage medium may be integrated into the processor. The processor and storage medium may reside in an ASIC. The ASIC may reside in a user terminal. In an alternative, the processor and storage medium may reside in a user terminal as discrete components.
[0248] The above embodiments are provided to persons familiar with the art for implementing or using the present invention. Personnel familiar with the art may make various modifications or changes to the above embodiments without departing from the inventive concept of the present invention. Therefore, the scope of protection of the present invention is not limited to the above embodiments, but should be the maximum scope of the innovative features mentioned in the claims.
Claims
1. A data precision authorization system based on distributed digital identity, characterized by: Including distributed digital identity management module, verifiable data authorization credential management module and blockchain system; The distributed digital identity management module is used to issue and verify distributed digital identities for participants in the data authorization process, including some or all of the data providers, data authorizers, and data users; The verifiable data authorization credential management module uses distributed digital identity information and verifiable credential technology to generate and verify data authorization credentials, and parses data authorization credentials through smart contracts to achieve accurate authorization of data; The blockchain system is used to store distributed digital identity information, data authorization credential information and related operation records.
2. The data accurate authorization system based on distributed digital identity according to claim 1 is characterized in that: The distributed digital identity management module includes at least an identity issuance submodule, a data signature submodule, and a data verification submodule: The identity issuance submodule is used to issue distributed digital identities to participants; The data signature submodule uses a private key and a signature algorithm to sign the input data, wherein the input data includes basic information of a distributed digital identity and / or data authorization credential data; The data verification submodule is used to perform signature verification on input data, where the input data includes a distributed digital identity and / or data authorization credential data.
3. The data accurate authorization system based on distributed digital identity according to claim 2 is characterized in that: The distributed digital identity management module also includes a real-name identity management submodule: The real-name identity management submodule is used to authenticate the real-name identity of the participants and map and verify the real-name identity with the distributed digital identity.
4. The data accurate authorization system based on distributed digital identity according to claim 2 is characterized in that: The distributed digital identity data includes at least an identity identifier and a DID document; The identity identifier is used to uniquely identify the distributed digital identity; The DID document is used to describe identity information and includes at least the DID's identity identifier and public key information.
5. The data accurate authorization system based on distributed digital identity according to claim 2 is characterized in that: The data signature submodule performs batch signature on input data.
6. The data accurate authorization system based on distributed digital identity according to claim 4 is characterized in that: The data verification submodule uses the identity identifier to retrieve the corresponding DID document in the blockchain system to obtain the public key information of the distributed digital identity data, and uses the public key to sign and verify the input data.
7. The data accurate authorization system based on distributed digital identity according to claim 1 is characterized in that: The verifiable data authorization credential management module includes a data authorization credential generation submodule and a data authorization credential verification submodule: The data authorization credential generation submodule is used to generate a data authorization credential using distributed digital identity information in combination with verifiable credential technology; The data authorization certificate verification submodule is used to verify the data authorization certificate and parse the data authorization certificate through smart contracts to achieve accurate authorization of the data.
8. The data accurate authorization system based on distributed digital identity according to claim 4 is characterized in that: The DID document includes at least the following fields: The id field is an identifier that uniquely identifies the DID document; The version field is used to specify the version number of the DID document; The controller field is used to specify one or more DID controllers; The proof field contains the signature information of the DID document and is used to verify the DID document.
9. The data accurate authorization system based on distributed digital identity according to claim 7 is characterized in that: The data authorization certificate includes at least the following fields: The id field is the unique identifier of the data authorization credential; The issuer field is the issuer of the data authorization certificate; The issuanceDate field is the authorization date of the data authorization certificate; The expirationDate field is the authorization expiration date of the data authorization certificate; The credentialSubject field is the authorization data item; The proof field contains the signature information of the data authorization certificate.
10. A method for accurate data authorization based on distributed digital identity, characterized in that: The following steps are involved: Data authorization steps: Based on the data authorization request initiated by the data authorizer, the distributed digital identity of the data authorizer is issued and uploaded to the chain. The distributed digital identity information is combined with the verifiable certificate technology to generate the data authorization certificate and upload it to the chain; Data usage request step: Initiate a data usage request based on the data user's data usage requirements; Data provision steps: In response to the data user's data usage request, obtain the data authorization certificate related to the data authorizer, verify the data authorization certificate based on the data authorizer's distributed digital identity information, and parse the data authorization certificate through the smart contract to achieve accurate data authorization from the data provider to the data user.
11. The method for accurate data authorization based on distributed digital identity according to claim 10, characterized in that: The data request step further includes: after the data user initiates the data request, issuing the distributed digital identity of the data user and uploading it to the chain; The data providing step also includes: authenticating the real-name identity of the participants, mapping and verifying the real-name identity with the distributed digital identity, and the participants at least include the data user and / or the data authorizer.
12. The method for accurate data authorization based on distributed digital identity according to claim 10, characterized in that: The data authorization step further includes: signing the DID document of the distributed digital identity of the data authorizer and signing the basic information of the data authorization certificate of the data authorizer; The data providing step also includes: verifying the DID document signature of the distributed digital identity of the data authorizer and verifying the signature of the data authorization certificate of the data authorizer.
13. The method for accurate data authorization based on distributed digital identity according to claim 10, characterized in that: The data authorization step further includes: Batch signing is performed on input data, where the input data includes basic information of a distributed digital identity and / or data authorization credential data.
14. The method for accurate data authorization based on distributed digital identity according to claim 10, characterized in that: The distributed digital identity data includes at least an identity identifier and a DID document; The identity identifier is used to uniquely identify the distributed digital identity; The DID document is used to describe identity information and includes at least the DID's identity identifier and public key information.
15. The method for accurate data authorization based on distributed digital identity according to claim 14, characterized in that: The DID document includes at least the following fields: The id field is an identifier that uniquely identifies the DID document; The version field is used to specify the version number of the DID document; The controller field is used to specify one or more DID controllers; The proof field contains the signature information of the DID document and is used to verify the DID document.
16. The method for accurate data authorization based on distributed digital identity according to claim 10, characterized in that: The data authorization certificate includes at least the following fields: The id field is the unique identifier of the data authorization credential; The issuer field is the issuer of the data authorization certificate; The issuanceDate field is the authorization date of the data authorization certificate; The expirationDate field is the authorization expiration date of the data authorization certificate; The credentialSubject field is the authorization data item; The proof field contains the signature information of the data authorization certificate.
17. A computer-readable storage medium having stored thereon a computer program executable by a processor, characterized in that: When the computer program is executed by a processor, the method for accurate data authorization based on distributed digital identity as described in any one of claims 10 to 16 is implemented.
Citation Information
Patent Citations
Precise authorization method for privacy data in government affair data sharing
CN113868706A
Accurate authorization method
CN114117389A
Data sharing accurate authorization method
CN115310123A
Cited By
Distributed data use control method and system based on DID and verifiable certificate
CN121690700A