Data management method, device, apparatus, and storage medium
By generating data credentials through distributed identifiers and blockchain technology, combined with zero-knowledge proofs, the security and privacy issues of centralized user data management in the traditional Internet are solved, realizing decentralized data management and secure utilization.
Patent Information
- Application Number
- CN202511105829.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-07
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2045-08-07
AI Technical Summary
In the traditional Internet, centralized management of user data leads to a high risk of single point of failure, an increased risk of data leakage, and difficulty in guaranteeing user data privacy and security.
By using distributed identifiers and public-private key pairs, blockchain technology is used to generate and verify data credentials, enabling data holders to manage data autonomously and selectively authorize data access. Combined with zero-knowledge proof technology, data privacy and security are ensured.
It achieves decentralized data management, reduces the risk of privacy leaks caused by data misuse, allows users to control data flow independently, and ensures the security, transparency and efficient use of data.
Smart Images

Figure CN120639316B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to web3.0 technology, decentralized technology, distributed identity technology, and in particular to a data management method, device, equipment and storage medium. BACKGROUND
[0002] In the traditional Internet, centralized services of user data dominate. User data is scattered and stored in various centralized service agencies. With the progress of science and technology and the improvement of data privacy and security awareness, this mode gradually shows its drawbacks.
[0003] In related technologies, data sovereignty is not in the hands of users, and the centralized service data storage and management mode is prone to single point failure. Once the data storage agency has a problem, it may cause a large amount of user data to be lost or leaked, and the protection of data in the process of data storage and transmission is insufficient, so the centralized management of data leads to an increased risk of data leakage. SUMMARY
[0004] The embodiments of the present disclosure provide a data management method, device, equipment and storage medium, which can reduce the risk of privacy leakage caused by data abuse and realize safe, transparent and efficient use of data.
[0005] In one aspect of the embodiments of the present disclosure, a data management method is provided, applied to a first device corresponding to a data holder, and the method comprises:
[0006] In response to a credential obtaining operation, a credential obtaining request is sent to a second device of a data prover, the credential obtaining request carrying a distributed identifier of the data holder and to-be-proved data, the second device being configured to perform data verification on the to-be-proved data based on the distributed identifier, and generate a data credential when the data verification is passed, the data credential carrying a prover signature of the data prover;
[0007] The data credential fed back by the second device is received and stored.
[0008] In response to receiving a data verification request sent by a third device of a verification requester, credential information is generated based on the data credential and sent to the third device, and the third device is configured to determine a data verification result based on the credential information.
[0009] Optionally, in response to receiving a data verification request sent by a third device of a verification requester, credential information is generated based on the data credential and sent to the third device, and the third device is configured to determine a data verification result based on the credential information.
[0010] In response to receiving the data verification request, determining content to be verified corresponding to the data verification request;
[0011] Based on the content to be verified and the data credential, generating the credential information, the credential information including at least one of: information specified in the data credential by the content to be verified, information in the data credential selected by the information selection operation, information generated by zero-knowledge proof technology for representing whether the data credential meets the data verification condition in the content to be verified;
[0012] Sending the credential information to the third device.
[0013] Optionally, based on the content to be verified and the data credential, generating the credential information includes:
[0014] In response to the content to be verified involving at least two data credentials, merging the at least two data credentials to obtain a data expression;
[0015] Based on the content to be verified and the data expression, generating the credential information.
[0016] Optionally, before the method further includes:
[0017] In response to a digital identity creation operation, creating the distributed identifier and generating a public-private key pair, the distributed identifier corresponding to different data holders being different;
[0018] Storing a private key in the public-private key pair, and publishing the distributed identifier and a public key in the public-private key pair to a blockchain;
[0019] The method further includes:
[0020] Using the private key to add a holder signature in the credential acquisition request;
[0021] Sending the credential acquisition request carrying the holder signature to the second device, the second device being configured to, after receiving the credential acquisition operation, query the public key from the blockchain based on the distributed identifier, perform identity verification using the public key and the holder signature, and perform data verification on the data to be proved based on data corresponding to the distributed identifier in the data source after the identity verification passes.
[0022] Optionally, the method further includes:
[0023] adding the holder signature in the credential information by using the private key;
[0024] sending the credential information carrying the holder signature and the prover signature to a third device, the third device being configured to verify the credential information based on the distributed identifier of the data holder and to verify the credential information based on the distributed identifier of the data prover, to obtain the data verification result.
[0025] In another aspect of the embodiments of the present disclosure, a data management method is provided, applied to a second device of a data prover, and the method comprises:
[0026] receiving a credential obtaining request sent by a first device corresponding to a data holder, the credential obtaining request carrying a distributed identifier of the data holder and to-be-proved data;
[0027] verifying the to-be-proved data based on the distributed identifier of the data prover;
[0028] generating a data credential containing a prover signature in response to the data verification passing;
[0029] sending the data credential to the first device, the first device being configured to store the data credential and to send credential information corresponding to the data credential to a third device of a verification requester when receiving a data verification request sent by the third device.
[0030] In another aspect of the embodiments of the present disclosure, a data management method is provided, applied to a third device of a verification requester, and the method comprises:
[0031] sending a data verification request to a first device of a data holder in response to a data verification instruction;
[0032] receiving credential information sent by the first device, the first device being configured to generate the credential information based on a data credential, the data credential being a verifiable credential carrying a prover signature of a data prover, generated by a second device of the data prover based on verification of to-be-proved data by using the distributed identifier of the data prover, and generated in the case of passing data verification;
[0033] determining a data verification result based on the credential information.
[0034] In another aspect of the embodiments of the present disclosure, a data management apparatus is provided, applied to a first device corresponding to a data holder, and the apparatus comprises:
[0035] The first sending module is configured to, in response to a credential obtaining operation, send a credential obtaining request to a second device of the data prover, the credential obtaining request carrying a distributed identifier of the data holder and to-be-proved data, the second device being configured to perform data verification on the to-be-proved data based on the distributed identifier, and generate a data credential when the data verification is passed, the data credential carrying a prover signature of the data prover;
[0036] The first receiving module is configured to receive the data credential fed back by the second device and store the data credential.
[0037] The first generating module is configured to, in response to receiving a data verification request sent by a third device of the verification requester, generate credential information based on the data credential and send the credential information to the third device, the third device being configured to determine a data verification result based on the credential information.
[0038] In another aspect of the embodiments of the present disclosure, a data management system is provided, comprising a first device corresponding to a data holder, a second device corresponding to a data prover, and a third device corresponding to a verification requester.
[0039] The first device is configured to, in response to a credential obtaining operation, send a credential obtaining request to the second device, the credential obtaining request carrying a distributed identifier of the data holder and to-be-proved data; receive a data credential fed back by the second device and store the data credential; and in response to receiving a data verification request sent by the third device, generate credential information based on the data credential and send the credential information to the third device.
[0040] The second device is configured to receive the credential obtaining request sent by the first device; perform data verification on the to-be-proved data based on a distributed identifier of the data prover; in response to the data verification being passed, generate the data credential containing a prover signature; and send the data credential to the first device.
[0041] The third device is configured to, in response to a data verification instruction, send a data verification request to the first device; receive the credential information sent by the first device; and determine a data verification result based on the credential information.
[0042] In another aspect of the embodiments of the present disclosure, an electronic device is provided, comprising:
[0043] The memory is configured to store a computer program.
[0044] The processor is configured to execute the computer program stored in the memory, and when the computer program is executed, the method in the above aspect is implemented.
[0045] In another aspect of the embodiments of the present disclosure, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the method in the above aspect.
[0046] In another aspect of the embodiments of the present disclosure, a computer program product is provided, and the computer program product includes computer program instructions. The computer program instructions are executed by a processor to implement the method in the above aspect.
[0047] According to the embodiments of the present disclosure, the data holder verifies the data through the data proof provider, obtains the data credential carrying the signature of the proof provider and stores the data credential, and when receiving the data verification request of the verification requestor, sends the credential information generated based on the data credential to the verification requestor. The verification requestor can verify the authenticity of the user data based on the credential information. By combining the distributed identifier and the verifiable data credential, a decentralized data circulation management method is realized, in which the user can independently manage the personal data. The data management authority is transferred from the Internet service institution to the user. The user can freely choose whether to authorize the third party to access the data according to the specific needs, so as to more effectively protect the user data privacy, enable the user to maintain the data management rights and interests, and avoid the problems of data forced sharing and data abuse existing in the traditional centralized mode, reduce the privacy leakage risk caused by data abuse, and realize the safe, transparent and efficient use of data.
[0048] The technical solutions of the present disclosure will be described in further detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0049] The accompanying drawings, which form a part of the specification, illustrate embodiments of the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0050] The present disclosure can be understood more clearly with reference to the following detailed description in conjunction with the accompanying drawings, in which:
[0051] Figure 1 a flowchart of an embodiment of the data management method of the present disclosure;
[0052] Figure 2 a flowchart of an embodiment of the data management method of the present disclosure;
[0053] Figure 3 a flowchart of an embodiment of the data management method of the present disclosure;
[0054] Figure 4 a flowchart of another embodiment of the data management method of the present disclosure;
[0055] Figure 5 a flowchart of another embodiment of the data management method of the present disclosure;
[0056] Figure 6 Structure diagram of one embodiment of the data management device of the present disclosure;
[0057] Figure 7 Structure diagram of another embodiment of the data management device of the present disclosure;
[0058] Figure 8 Structure diagram of another embodiment of the data management device of the present disclosure;
[0059] Figure 9 Structure diagram of one embodiment of the data management system of the present disclosure;
[0060] Figure 10 Structure diagram of one application embodiment of the electronic device of the present disclosure. DETAILED DESCRIPTION
[0061] Various exemplary embodiments of the present disclosure will now be described in detail below with reference to the accompanying drawings. Note that the relative arrangement, numerical expressions, and numerical values of components and steps set forth in these embodiments are not limiting to the scope of the present disclosure unless otherwise specifically stated.
[0062] Those skilled in the art can understand that the terms "first", "second", and the like in the embodiments of the present disclosure are only used to distinguish different steps, devices, or modules, and do not represent any specific technical meaning, nor do they represent a necessary logical sequence between them.
[0063] It should also be understood that in the embodiments of the present disclosure, "multiple" can mean two or more, and "at least one" can mean one, two, or more.
[0064] It should also be understood that for any component, data, or structure mentioned in the embodiments of the present disclosure, unless specifically limited or the context gives a contrary implication, it can be understood as one or more in general.
[0065] In addition, the term "and / or" in the present disclosure is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B can mean that there are three cases of A alone, A and B together, and B alone. In addition, the character " / " in the present disclosure generally represents an "or" relationship between the front and rear associated objects.
[0066] It should also be understood that the description of various embodiments of the present disclosure focuses on the differences between various embodiments, and the same or similar parts can be referred to each other, and for the sake of brevity, will not be repeated one by one.
[0067] At the same time, it should be understood that in order to facilitate description, the size of each part shown in the drawings is not drawn in accordance with the actual proportional relationship.
[0068] The following description of at least one exemplary embodiment is merely exemplary in nature and is in no way intended to limit the disclosure or its application or uses.
[0069] Techniques, methods, and apparatus known to those of ordinary skill in the relevant art can not be discussed in detail herein, but should be considered part of the specification.
[0070] It is to be noted that like reference numerals and letters refer to like items in the drawings, and as such, further discussion of the same will not be repeated.
[0071] In the traditional Internet mode, the root of the user data flow problem is that the data sovereignty is not in the hands of the user, and the data protection is insufficient in the storage and transmission process. In recent years, with the continuous development of technologies such as distributed ledger, the user data privacy and security will be effectively protected by means such as encryption algorithm and distributed storage. Under the promotion of Web3.0, the present disclosure is committed to building a decentralized data flow solution that can be independently managed by users, gradually transferring the data leading right from the Internet service institutions to the users, so as to more effectively protect the user data privacy, enable the users to better maintain their data rights and interests, and realize the safe, transparent and efficient use of data.
[0072] Figure 1 A flowchart of a data management method provided for an exemplary embodiment of the present disclosure. The data management method of the present embodiment can be implemented by a first device corresponding to a data holder. The data holder is the owner of the data, such as a graduate with a degree certificate, a house buyer with a house property certificate, etc.
[0073] As shown in Figure 1 , the method comprises the following steps:
[0074] Step 101, in response to a credential acquisition operation, a credential acquisition request is sent to a second device of a data prover.
[0075] The credential acquisition request carries a distributed identifier of the data holder and the data to be proved. The second device is used to verify the data to be proved based on the distributed identifier, and generate a data credential when the data verification is passed. The data credential carries a prover signature of the data prover. The prover signature can be generated based on the distributed identifier of the data prover, and is used to represent that the corresponding data credential is a credential issued by the data prover.
[0076] In a possible implementation, in response to the credential obtaining operation, a distributed identifier input by the credential obtaining operation and to-be-proved data are determined to generate a credential obtaining request. Illustratively, the distributed identifier can be a decentralized identifier (also referred to as a distributed identifier, DID), which is unique and different for different data holders. The to-be-proved data is data used by the data holder to obtain a data credential to prove identity authenticity or information authenticity, for example, when a user needs to obtain an electronic diploma, the to-be-proved data can include name, school name, student ID, and the like.
[0077] Optionally, the second device of the data proving party receives the distributed identifier of the data proving party and the to-be-proved data in the credential obtaining request. Specifically, first, it is verified based on the distributed identifier whether the first device is a device of the data holder of the to-be-proved data, and then it is verified based on a data source (for example, a database of a cooperative institution or a self-owned system of the data proving party) whether the to-be-proved data is correct. If both the identity verification and the data verification pass, a data credential is issued to the data holder, which is a kind of verifiable credential (VC), for example, an electronic diploma, an electronic ID card, and the like.
[0078] In step 102, the data credential fed back by the second device is received and stored.
[0079] In a possible implementation, the first device stores the received data credential, so that the user can autonomously manage data and selectively authorize data.
[0080] Optionally, the first device can store the data credential in a local or private cloud storage.
[0081] In step 103, in response to receiving a data verification request sent by a third device of a verification request party, credential information is generated based on the data credential and sent to the third device.
[0082] The third device is configured to determine a data verification result based on the credential information.
[0083] The verification request party usually needs the data holder to meet certain conditions before providing services or resources for the data holder, and therefore needs to perform data verification. For example, an enterprise needs to confirm the graduation school of an interviewee, and a bank needs to confirm the identity certificate of a customer before providing services for the customer. The third device of the verification request party sends a data verification request to the first device based on business needs, and the data verification request is used to indicate to-be-verified content.
[0084] The first device can selectively authorize the third device to access information based on the to-be-verified content after receiving the data verification request sent by the third device. Illustratively, the first device can directly send a complete data credential to the third device and authorize the third device to read all contents of the data credential, or send the complete data credential to the third device but encrypt part of the information and only authorize the third device to read the part of information to be verified. For example, the verification requester needs to verify the graduation certificate of XX school, and the first device can selectively authorize the third device to read the information such as the name, school name, and graduation year, and hide other information such as the student ID and major.
[0085] The credential information carries the proof party signature in the data credential, and the third device can verify the authenticity of the credential information based on the proof party signature to obtain a data verification result. If the data verification result indicates that the credential information is from the credential issued by the data proof party and is the personal data of the data holder, the verification requester provides a corresponding service to the data holder, for example, allowing the first device to access the webpage of the verification requester.
[0086] According to the embodiments of the present disclosure, the data holder verifies the data through the data proof party, obtains the data credential carrying the proof party signature and stores the data credential, and sends the credential information generated based on the data credential to the verification requester when receiving the data verification request of the verification requester. The verification requester can verify the authenticity of the user data based on the credential information. By combining the distributed identifier and the verifiable data credential, a decentralized data circulation management method in which the user can independently manage personal data is implemented. The data management authority is transferred from the Internet service institution to the user. The user can freely choose whether to authorize the third party to access the data according to specific needs, thereby more effectively protecting the user data privacy, enabling the user to maintain the data management rights and interests, avoiding the problems of data forced sharing and data abuse existing in the traditional centralized mode, reducing the risk of privacy leakage caused by data abuse, and realizing safe, transparent, and efficient use of data.
[0087] In a possible implementation, when the third device accesses the data credential, the first device can selectively authorize the third device to access the information in the data credential, such as Figure 2 As shown in FIG. 10, the step 103 can include the following steps.
[0088] Step 201: In response to receiving the data verification request, determining the to-be-verified content corresponding to the data verification request.
[0089] The to-be-verified content includes a target data credential to be verified and target information in the target data credential. For example, the to-be-verified content of an enterprise for an interviewee includes a bachelor's degree certificate as the target data credential and the student's name and whether the student is a graduate as the target information.
[0090] In step 202, the credential information is generated based on the to-be-verified content and the data credential.
[0091] The credential information includes at least one of the following: information specified in the to-be-verified content in the data credential, information selected in the data credential by the information selection operation, and information generated by the zero-knowledge proof technology and used to represent whether the data credential meets the data verification condition in the to-be-verified content.
[0092] Optionally, the first device can directly send the target data credential to the third device as the credential information, and authorize the third device to read all the content of the target data credential.
[0093] Optionally, in order to protect user privacy and data security, the first device can selectively provide part of the information in the target data credential to the third device. For example, the data credential is identified according to the to-be-verified content, and the information related to the to-be-verified content is determined as the credential information; or the target data credential is displayed through an information selection interface, and the authorized information is selected from the target data credential by the user through an information selection operation; or the first device generates the credential information by using the zero-knowledge proof technology, and the first device judges whether the target data credential meets the data verification condition represented by the to-be-verified content based on the to-be-verified content and the target data credential. For example, the to-be-verified content is whether student A is a graduate of B college, and the first device generates the credential information representing whether the data holder meets the condition by using the zero-knowledge proof technology, without providing the specific data of the data holder to the third device.
[0094] In step 203, the credential information is sent to the third device.
[0095] Optionally, the data required to be verified by the verification requestor can involve multiple data credentials, for example, the financial institution needs to verify the user's ID card and property certificate. The above step 202 can specifically include the following steps:
[0096] In step 202a, in response to the to-be-verified content involving at least two data credentials, the at least two data credentials are combined to obtain a data expression.
[0097] In step 202b, the credential information is generated based on the to-be-verified content and the data expression.
[0098] The data presentation is a verifiable presentation (VP), and the data presentation is obtained by combining a plurality of data credentials. Further, after the data presentation is generated, the data presentation can be directly sent to the third device, or selectively disclose part of the information in the data presentation to the third device. Moreover, the data presentation carries the proof party signature of each data credential involved, so as to verify the authenticity of the data presentation by the third device.
[0099] Based on the embodiments of the present disclosure, the data holder can selectively authorize part of the credential information to the verification request party, or show the data verification result and authenticity to the verification request party by zero-knowledge proof technology and hide the specific data, only disclose the necessary information in the process of data access by the verification request party, prevent the overexposure of user sensitive information, which not only improves the security of data management and data sharing, but also reduces the risk of data leakage, especially for data scenarios involving personal privacy and business secrets such as the financial field and the medical field, provides a safe and decentralized data management and circulation mechanism.
[0100] In a possible implementation, the data holder first creates a distributed identifier before verifying the data by the data proof party. The data management method provided by the embodiments of the present disclosure further includes the following steps:
[0101] Step one, in response to a digital identity creation operation, a distributed identifier is created and a public-private key pair is generated, and the distributed identifiers corresponding to different data holders are different.
[0102] Step two, store the private key in the public-private key pair, and publish the distributed identifier and the public key in the public-private key pair to the blockchain.
[0103] Optionally, in response to a digital identity creation operation, the first device creates a unique distributed identifier, which corresponds to a public-private key pair (including a public key and a private key), for ensuring the authenticity and tamper resistance of the user identity. The private key is stored in the first device, and the public key and the distributed identifier can be published to the blockchain through a smart contract, and the blockchain network verifies and records the distributed identifier, ensuring that the relationship between the distributed identifier and the public key is tamper-proof. Other devices can query the corresponding public key on the blockchain based on the distributed identifier sent by the first device, and decrypt the holder signature carried by the distributed identifier using the corresponding public key, to verify whether the data sending end is the first device of the data holder corresponding to the distributed identifier. The holder signature can be generated by the first device using the private key to encrypt the distributed identifier of the data holder, to represent that the corresponding distributed identifier is the distributed identifier of the data holder.
[0104] Optionally, the first device generates a distributed identifier document after creating the distributed identifier and publishes the distributed identifier document to the blockchain, where the distributed identifier document includes information such as the distributed identifier, the public key, and the service endpoint (service address).
[0105] In a possible implementation, the first device can add a digital signature to the transmitted data by using a private key, so that the receiving end can perform identity verification. The step 101 can specifically include the following steps.
[0106] In step 101a, a holder signature is added to the credential acquisition request by using a private key.
[0107] In step 101b, the credential acquisition request carrying the holder signature is sent to the second device.
[0108] The second device is configured to, after receiving the credential acquisition request, query the public key from the blockchain based on the distributed identifier, perform identity verification by using the public key and the holder signature, and perform data verification on the to-be-verified data based on the data corresponding to the distributed identifier in the data source, if the public key is successfully used to unlock the holder signature, it can be confirmed that the device sending the credential acquisition request is the first device of the data holder of the distributed identifier, and the identity verification is passed.
[0109] According to the embodiments of the present disclosure, a public-private key pair is created when a distributed identifier is created, the distributed identifier is associated with the public key and published to the blockchain, and the private key is stored locally. When transmitting data or a request, the private key is used to add a holder signature, which can realize audit tracking and compliance guarantee of data management and circulation, and ensure the security of the data.
[0110] Figure 3 A flowchart of a data management method provided by an embodiment of the present disclosure is shown. The data management method of the present embodiment can be implemented by a second device corresponding to a data verifier. The data verifier is a trusted third party, such as a school, a bank, or the like, which can provide data credentials for a data holder.
[0111] As shown in Figure 3 , the method includes the following steps:
[0112] In step 301, a credential acquisition request sent by a first device corresponding to a data holder is received.
[0113] The credential acquisition request carries a distributed identifier of the data holder and to-be-verified data.
[0114] In a possible implementation, the first device determines, in response to the credential obtaining operation, a distributed identifier input by the credential obtaining operation and data to be proved, to generate a credential obtaining request. The second device of the data prover receives the distributed identifier of the data prover and the data to be proved in the credential obtaining request.
[0115] At step 302, the data to be proved is verified based on the distributed identifier of the data prover.
[0116] In a possible implementation, the first device is first verified based on the distributed identifier to be the device of the data holder of the data to be proved, and then the data to be proved is verified to be correct based on a data source (for example, a database of a self-owned system of the data prover or a cooperative organization, etc.). Specifically, the distributed identifier sent by the first device carries a digital signature generated by using a private key corresponding to the distributed identifier. After receiving the credential obtaining operation, the second device queries the corresponding public key from the block chain based on the distributed identifier, and verifies the identity by using the public key and the holder signature. If the public key queried can successfully unlock the holder signature, it can be confirmed that the device sending the credential obtaining request is the first device of the data holder of the distributed identifier, the identity verification is passed, and then the data verification is performed, for example, the data holder is queried from the database based on the name, student ID, and other data in the data to be proved to determine whether the data holder is a graduate of the school.
[0117] At step 303, in response to the data verification passing, a data credential containing a prover signature is generated.
[0118] If the identity verification and the data verification both pass, the data credential is issued to the data holder, for example, an electronic degree certificate, an electronic identity card, etc., and the prover signature of the data prover is added to the data credential.
[0119] Optionally, the data prover also has a unique distributed identifier, and the prover signature can be generated by using the private key corresponding to the distributed identifier of the data prover, so that after the request party obtains the credential information, the authenticity of the credential information can be verified by querying the public key corresponding to the distributed identifier of the data prover, to determine whether the data credential corresponding to the credential information is the credential issued by the data prover.
[0120] At step 304, the data credential is sent to the first device.
[0121] The first device is configured to store the data credential, and send the credential information corresponding to the data credential to the third device of the verification request party when receiving the data verification request sent by the third device. The process of receiving and storing the data credential and generating the credential information can be referred to the above Figures 1-2 The corresponding embodiments are not described herein again.
[0122] Figure 4 A flowchart of the data management method provided by the embodiments of the present disclosure is shown. The data management method of the embodiments of the present disclosure can be implemented by a third device corresponding to a verification requestor. The verification requestor verifies the identity of a user to provide corresponding services or resources, for example, an enterprise needs to confirm the graduate school of an interviewee, a bank needs to confirm the identity of a customer before providing services to the customer, etc.
[0123] As shown in Figure 4 The method comprises the following steps:
[0124] Step 401, in response to a data verification instruction, a data verification request is sent to a first device of a data holder.
[0125] In a possible implementation, the data verification instruction can be triggered by a user of the data holder, or can be triggered by the first device upon receiving an operation of the data holder. For example, when the data holder logs in to a certain website, the website needs to verify the identity information of the user, and the first device sends a login request to the third device upon receiving the login operation, triggering the third device to generate a data verification instruction.
[0126] Step 402, receiving the credential information sent by the first device.
[0127] The first device is configured to generate credential information based on data credentials. The data credentials are verifiable credentials generated by a second device of a data prover based on data verification of to-be-verified data by a distributed identifier of the data prover, and carrying a prover signature of the data prover in the case where the data verification is passed. The process of generating and sending the credential information by the first device can refer to the above Figures 1-2 Corresponding embodiments are not described here again.
[0128] Step 403, determining a data verification result based on the credential information.
[0129] In a possible implementation, the credential information carries a prover signature and also carries a holder signature of the data holder. The third device can obtain a corresponding public key from the blockchain based on an identity code of the data holder, and query a corresponding public key from the blockchain based on an identity code of the data prover (which can be obtained from the data prover or from the credential information), and decode the holder signature by using the public key of the data holder to verify whether the credential information is the credential information of the data holder, and verify whether the data credentials corresponding to the credential information are the credentials issued by the data prover by using the public key of the data prover.
[0130] In combination with the above various embodiments, Figure 5 A flowchart of data management and circulation is shown. As Figure 5As shown, first, the first device of the data holder creates a distributed identifier, the private key corresponding to the distributed identifier is stored in the first device, and a distributed identifier document containing information such as the distributed identifier, the public key, and the service endpoint is published to the blockchain; the first device of the data holder submits the data to be proved to the second device of the data prover, and applies for a data credential; the second device of the data prover issues a data credential after identity verification and data verification, and the data credential can contain the distributed identifier of the data holder, issuance information, and validity period; the first device of the data holder encrypts and stores the data credential in the local or private cloud storage; the third device of the verification request party sends a request to the first device of the data holder for identity data verification; the first device of the data holder shows the third device of the verification request party the credential information generated based on the data credential; the third device of the verification request party verifies the authenticity of the credential information, and provides corresponding services or resources to the data holder after verification.
[0131] Figure 6 A structural block diagram of a data management apparatus provided by one exemplary embodiment of the present disclosure is shown. The data management apparatus is applied to a first device corresponding to a data holder, and the data management apparatus comprises:
[0132] The first sending module 601 is configured to send a credential acquisition request to the second device of the data prover in response to a credential acquisition operation, the credential acquisition request carrying a distributed identifier of the data holder and data to be proved, the second device being configured to perform data verification on the data to be proved based on the distributed identifier, and generate a data credential when the data verification is passed, the data credential carrying a prover signature of the data prover.
[0133] The first receiving module 602 is configured to receive the data credential fed back by the second device and store the data credential.
[0134] The first generating module 603 is configured to generate credential information based on the data credential and send the credential information to the third device in response to receiving a data verification request sent by the third device of the verification request party, the third device being configured to determine a data verification result based on the credential information.
[0135] Optionally, in a possible implementation, the first generating module 603 is further configured to:
[0136] In response to receiving the data verification request, determine the content to be verified corresponding to the data verification request.
[0137] Based on the to-be-verified content and the data credential, credential information is generated, the credential information including at least one of: information specified in the data credential by the to-be-verified content, information in the data credential selected by the information selection operation, information generated by a zero-knowledge proof technology and used to represent whether the data credential meets the data verification condition in the to-be-verified content;
[0138] The credential information is sent to a third device.
[0139] Optionally, in a possible implementation, the first generation module 603 is further used for:
[0140] In response to the to-be-verified content involving at least two data credentials, the at least two data credentials are combined to obtain a data expression;
[0141] Based on the to-be-verified content and the data expression, the credential information is generated.
[0142] Optionally, in a possible implementation, the data management apparatus provided by the embodiment of the present disclosure further includes:
[0143] An identifier creation module is configured to create a distributed identifier and generate a public-private key pair in response to a digital identity creation operation, the distributed identifiers corresponding to different data holders being different;
[0144] A publishing module is configured to store the private key in the public-private key pair, and publish the distributed identifier and the public key in the public-private key pair to a blockchain;
[0145] The first sending module 601 is further used for:
[0146] The private key is used to add a holder signature in the credential acquisition request;
[0147] The credential acquisition request carrying the holder signature is sent to a second device, the second device being configured to, after receiving a credential acquisition operation, query the public key from the blockchain based on the distributed identifier, perform identity verification based on the public key and the holder signature, and perform data verification on the to-be-proved data based on the data corresponding to the distributed identifier in the data source after the identity verification passes.
[0148] Optionally, in a possible implementation, the first generation module 603 is further used for:
[0149] The private key is used to add a holder signature in the credential information;
[0150] The credential information carrying the holder signature and the prover signature is sent to a third device, the third device being configured to perform identity verification on the credential information based on the distributed identifier of the data holder and perform authenticity verification on the credential information based on the distributed identifier of the data prover, to obtain a data verification result.
[0151] Figure 7 A structural block diagram of a data management apparatus provided by one example embodiment of the present disclosure is shown. The data management apparatus is applied to a second device corresponding to a data prover, and the data management apparatus comprises:
[0152] A second receiving module 701 is configured to receive a credential acquisition request sent by a first device corresponding to a data holder, and the credential acquisition request carries a distributed identifier of the data holder and to-be-proved data.
[0153] A data verification module 702 is configured to perform data verification on the to-be-proved data based on the distributed identifier of the data prover received by the second receiving module 701.
[0154] A second generating module 703 is configured to generate a data credential containing a prover signature in response to a determination that the data verification is passed by the data verification module 702.
[0155] A second sending module 704 is configured to send the data credential generated by the second generating module 703 to the first device, and the first device is configured to store the data credential, and send credential information corresponding to the data credential to a third device corresponding to a verification requestor in response to a data verification request sent by the third device.
[0156] Figure 8 A structural block diagram of a data management apparatus provided by one example embodiment of the present disclosure is shown. The data management apparatus is applied to a third device corresponding to a verification requestor, and the data management apparatus comprises:
[0157] A third sending module 801 is configured to send a data verification request to the first device corresponding to the data holder in response to a data verification instruction.
[0158] A third receiving module 802 is configured to receive credential information sent by the first device, and the first device is configured to generate the credential information based on a data credential, wherein the data credential is a verifiable credential carrying a prover signature of a data prover, and the data credential is generated by a second device corresponding to the data prover based on data verification on to-be-proved data based on a distributed identifier of the data prover, and the data verification is passed.
[0159] A determining module 803 is configured to determine a data verification result based on the credential information.
[0160] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same, similar or corresponding parts of various embodiments can be mutually referred to. Since the method, device, system and equipment embodiments are basically corresponding, the relevant parts of the description can be mutually referred to. The method, device, system and equipment of the embodiments of the disclosure are also mutually corresponding in the specific implementation manner and beneficial technical effects. The relevant contents can be mutually referred to, and will not be repeated.
[0161] In addition, as Figure 9 indicated, the embodiments of the disclosure also provide a data management system, which comprises: a first device 901 corresponding to a data holder, a second device 902 corresponding to a data prover, and a third device 903 corresponding to a verification requester;
[0162] The first device is configured to: in response to a credential obtaining operation, send a credential obtaining request to the second device, wherein the credential obtaining request carries a distributed identifier of the data holder and to-be-proved data; receive a data credential fed back by the second device and store the data credential; and in response to receiving a data verification request sent by the third device, generate credential information based on the data credential and send the credential information to the third device;
[0163] The second device is configured to: receive the credential obtaining request sent by the first device; perform data verification on the to-be-proved data based on a distributed identifier of the data prover; in response to the data verification passing, generate a data credential containing a signature of the prover; and send the data credential to the first device;
[0164] The third device is configured to: in response to a data verification instruction, send a data verification request to the first device; receive the credential information sent by the first device; and determine a data verification result based on the credential information.
[0165] Optionally, in a possible implementation, the data management system further comprises a DID registration system 904. The first device 901 can create a distributed identifier and generate a public-private key pair based on a digital identity creation operation, and associate and publish the distributed identifier and the public key in the public-private key pair to the DID registration system 904, so as to perform identity verification by the data prover and the verification requester.
[0166] In addition, the embodiments of the disclosure also provide an electronic device, which comprises:
[0167] A memory is configured to store a computer program;
[0168] A processor is configured to execute the computer program stored in the memory, and when the computer program is executed, the data management method of any one of the embodiments of the disclosure is implemented.
[0169] Figure 10 FIG. 1 illustrates a structure of an electronic device according to an embodiment of the present disclosure. Figure 10 The electronic device can be one of the first device and the second device, or both of them, or a standalone device independent of them, which can communicate with the first device and the second device to receive the collected input signals therefrom.
[0170] As shown in FIG. 1, the electronic device includes one or more processors and a memory. Figure 10
[0171] The processor can be a central processing unit (CPU) or other form of processing unit having data processing and / or instruction execution capabilities, and can control other components in the electronic device to perform desired functions.
[0172] The memory can include one or more computer program products, which can include various forms of computer readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory, for example, can include random access memory (RAM), cache, and / or the like. The non-volatile memory, for example, can include read only memory (ROM), hard disk, flash memory, and / or the like. One or more computer program instructions can be stored on the computer readable storage media, and the processor can execute the program instructions to implement the data management method of various embodiments of the present disclosure described above and / or other desired functions.
[0173] In one example, the electronic device can further include input and output devices, which are interconnected through a bus system and / or other forms of connection mechanism (not shown).
[0174] The input device, for example, can include a keyboard, a mouse, and / or the like.
[0175] The output device can output various information, including the determined distance information, direction information, and / or the like, to the outside. The output device can include, for example, a display, a speaker, a printer, a communication network and a remote output device connected thereto, and / or the like.
[0176] Of course, for simplicity, Figure 10 In FIG. 1, only some of the components related to the present disclosure among the components in the electronic device are illustrated, and components such as a bus, an input / output interface, and / or the like are omitted. In addition to this, the electronic device can include any other appropriate components according to a specific application.
[0177] In addition to the method and the device described above, embodiments of the present disclosure can also be a computer program product, which includes computer program instructions, which, when executed by a processor, cause the processor to perform the steps of the data management method according to various embodiments of the present disclosure described in the above parts of the specification.
[0178] The computer program product can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, C++, etc., and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server.
[0179] In addition, embodiments of the present disclosure can also be a computer readable storage medium, which stores computer program instructions, which, when executed by a processor, cause the processor to perform the steps of the data management method according to various embodiments of the present disclosure described in the above parts of the specification.
[0180] The computer readable storage medium can take the form of one or more combinations of any type of readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can include, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0181] Those of ordinary skill in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction-related hardware. The aforementioned program can be stored in a computer readable storage medium, and the program, when executed, performs steps including the above-mentioned method embodiments. The aforementioned storage medium includes ROM, RAM, magnetic or optical disc, and various media that can store program codes.
[0182] The above describes the basic principles of the present disclosure in conjunction with specific embodiments, but it should be noted that the advantages, benefits, effects and the like mentioned in the present disclosure are merely examples and are not limiting, and these advantages, benefits, effects and the like cannot be considered as necessary for each embodiment of the present disclosure. In addition, the above specific details are merely for the purpose of example and understanding, and are not limiting, and the above details do not limit the present disclosure to be necessarily implemented with the above specific details.
[0183] Each embodiment in the specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between each embodiment can be mutually referred to. For system embodiments, since they basically correspond to method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.
[0184] The block diagrams of the devices, apparatuses, equipment, systems involved in the present disclosure are merely exemplary examples and are not intended to require or imply the connection, arrangement, configuration shown in the block diagram. As those skilled in the art will recognize, these devices, apparatuses, equipment, systems can be connected, arranged, configured in any manner. Words such as "include", "contain", "have" and the like are open-ended words, which mean "including but not limited to", and can be used interchangeably. The words "or" and "and" used herein mean the word "and / or", and can be used interchangeably unless the context clearly indicates otherwise. The word "such as" used herein means the phrase "such as but not limited to", and can be used interchangeably.
[0185] The methods and devices of the present disclosure can be implemented in many ways. For example, the methods and devices of the present disclosure can be implemented by software, hardware, firmware, or any combination of software, hardware, firmware. The above order of steps for the method is merely for illustration, and the steps of the method of the present disclosure are not limited to the above specifically described order, unless otherwise specifically described. In addition, in some embodiments, the present disclosure can also be implemented as programs recorded in recording media, which include machine-readable instructions for implementing the method according to the present disclosure. Therefore, the present disclosure also covers the recording media storing the programs for executing the method according to the present disclosure.
[0186] It should also be noted that in the devices, equipment and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions of the present disclosure.
[0187] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein can be applied to other aspects without departing from the scope of the disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0188] The above description has been presented for the purpose of illustration and description. Furthermore, this description is not intended to limit the embodiments of the disclosure to the forms disclosed herein. Although several example aspects and embodiments have been discussed above, those of ordinary skill in the art will appreciate a variety of modifications, alternatives, permutations, additions, and sub-combinations of the described aspects and features.
Claims
1. A data management method, characterized in that, The method, applied to a first device corresponding to a data holder, includes: In response to the credential acquisition operation, a credential acquisition request is sent to the second device of the data proof party. The credential acquisition request carries the distributed identifier of the data holder and the data to be proven. The distributed identifier is associated with the public key of the data holder and stored in the blockchain. The private key of the data holder is stored in the first device. The second device is used to perform data verification on the data to be proven based on the distributed identifier. When the data verification is successful, a data credential is generated. The data credential carries the proof party signature of the data proof party. Receive the data credentials fed back by the second device and store the data credentials; In response to receiving a data verification request from a third device of the verification requesting party, the system generates credential information based on the data credentials and sends the credential information to the third device, which then determines the data verification result based on the credential information. The step of responding to a data verification request sent by a third device from a verification requester, generating credential information based on the data credential, and sending the credential information to the third device includes: In response to receiving the data verification request, determine the content to be verified corresponding to the data verification request; Based on the content to be verified and the data certificate, the certificate information is generated. The certificate information includes at least one of the following: information specified in the content to be verified in the data certificate, information in the data certificate selected by the information selection operation, and information generated by zero-knowledge proof technology to characterize whether the data certificate meets the data verification conditions in the content to be verified. Send the credential information to the third device.
2. The method according to claim 1, characterized in that, Based on the content to be verified and the data credentials, the credential information is generated, including: In response to the fact that the content to be verified involves at least two data credentials, the at least two data credentials are merged to obtain a data representation; Based on the content to be verified and the data representation, the credential information is generated.
3. The method according to claim 1 or 2, characterized in that, Before sending a credential acquisition request to the second device of the data proof party in response to the credential acquisition operation, the method further includes: In response to the digital identity creation operation, the distributed identifier is created and a public-private key pair is generated, with different distributed identifiers corresponding to different data holders; Store the private key in the public-private key pair, and associate the distributed identifier with the public key in the public-private key pair and publish it to the blockchain; Sending a credential acquisition request to the second device of the data proof party includes: Use the private key to add the holder's signature to the credential acquisition request; The second device sends a credential retrieval request carrying the holder's signature to the second device. After receiving the credential retrieval operation, the second device queries the public key from the blockchain based on the distributed identifier, performs identity verification using the public key and the holder's signature, and performs data verification on the data to be proved based on the data corresponding to the distributed identifier in the data source after the identity verification is passed.
4. The method according to claim 3, characterized in that, The step of generating credential information based on the data credential and sending the credential information to the third device includes: The holder's signature is added to the credential information using the private key; The third device sends the credential information carrying the signature of the holder and the signature of the certifier to the third device. The third device is used to authenticate the credential information based on the distributed identifier of the data holder and to verify the authenticity of the credential information based on the distributed identifier of the data certifier, thereby obtaining the data verification result.
5. A data management method, characterized in that, The method, applied to a second device of the data proof party, includes: The system receives a credential acquisition request sent by a first device corresponding to the data holder. The credential acquisition request is sent by the first device to the second device in response to the credential acquisition operation. The credential acquisition request carries the distributed identifier of the data holder and the data to be proved. The distributed identifier is associated with the public key of the data holder and stored in the blockchain. The private key of the data holder is stored in the first device. The data to be proved is verified based on the distributed identifier of the data prover; Upon successful data verification, a data credential containing the signature of the certifying party is generated. The data credentials are sent to the first device, which stores the data credentials. Upon receiving a data verification request from a third device of the verification requesting party, the first device generates credential information based on the data credentials and sends the credential information to the third device. The third device determines the data verification result based on the credential information. The first device is further configured to: in response to receiving the data verification request, determine the content to be verified corresponding to the data verification request; generate the credential information based on the content to be verified and the data credential, the credential information including at least one of the following: information specified in the content to be verified in the data credential, information in the data credential selected by the information selection operation, information generated by zero-knowledge proof technology to characterize whether the data credential meets the data verification conditions in the content to be verified; and send the credential information to the third device.
6. A data management method, characterized in that, The method, applied to a third device for verifying the requester, includes: In response to a data verification command, a data verification request is sent to the first device of the data holder; The system receives credential information sent by the first device. The credential information is generated by the first device based on a data credential and sent to the third device. The data credential is a verifiable credential carrying the signature of the data certifier. It is generated by the second device of the data certifier after receiving a credential acquisition request sent by the first device in response to the credential acquisition operation. The data credential is based on the distributed identifier of the data certifier and verifies the data to be proved. The distributed identifier is associated with the public key of the data holder and stored in the blockchain. The private key of the data holder is stored in the first device. The data verification result is determined based on the voucher information; The first device is further configured to: in response to receiving the data verification request, determine the content to be verified corresponding to the data verification request; generate the credential information based on the content to be verified and the data credential, the credential information including at least one of the following: information specified in the content to be verified in the data credential, information in the data credential selected by the information selection operation, information generated by zero-knowledge proof technology to characterize whether the data credential meets the data verification conditions in the content to be verified; and send the credential information to the third device.
7. A data management device, characterized in that, A first device applied to a data holder, the device comprising: The first sending module is configured to, in response to a credential acquisition operation, send a credential acquisition request to the second device of the data proof party. The credential acquisition request carries the distributed identifier of the data holder and the data to be proven. The distributed identifier is associated with the public key of the data holder and stored in the blockchain. The private key of the data holder is stored in the first device. The second device is configured to perform data verification on the data to be proven based on the distributed identifier. When the data verification is successful, a data credential is generated. The data credential carries the proof party signature of the data proof party. The first receiving module is used to receive the data credentials fed back by the second device and store the data credentials. A first generation module is configured to, in response to receiving a data verification request sent by a third device from a verification requesting party, generate credential information based on the data credential and send the credential information to the third device, wherein the third device is configured to determine a data verification result based on the credential information; the first generation module is further configured to: in response to receiving the data verification request, determine the content to be verified corresponding to the data verification request; generate the credential information based on the content to be verified and the data credential, wherein the credential information includes at least one of the following: information specified in the content to be verified in the data credential, information in the data credential selected by an information selection operation, information generated by zero-knowledge proof technology to characterize whether the data credential meets the data verification conditions in the content to be verified; and send the credential information to the third device.
8. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing a computer program stored in the memory, wherein when the computer program is executed, it implements the method of any one of claims 1-4, or the method of claim 5, or the method of claim 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 1-4, or the method described in claim 5, or the method described in claim 6.
Citation Information
Patent Citations
Verifiable certificate-based distributed zero-knowledge identity authentication method and system
CN118694541A
KR1025695820000B1