A multi-exchange assisted bulk-hosted transaction method and system

By employing a multi-exchange collaborative data bulk custody trading method, and utilizing data encryption and signature sharding technologies, the problems of low trading efficiency and security risks associated with single-exchange transactions are solved, achieving efficient and secure data trading and full custody.

CN121125182BActive Publication Date: 2026-05-12UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
UNIV OF ELECTRONICS SCI & TECH OF CHINA
Filing Date
2025-08-20
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In existing technologies, trading on-exchange data by a single exchange is inefficient and poses security risks, making it difficult to meet the needs of multi-data fusion and protecting data privacy.

Method used

A multi-exchange collaborative data escrow transaction method is adopted. Through data encryption, key sharding, signature sharding and global signature, the data is encrypted and authenticated in batches. The Shamir secret sharing technology is used to generate symmetric keys and public keys to ensure the confidentiality and authenticability of the data, and the data is stored on the cloud server.

Benefits of technology

It improves the computation and communication efficiency of data transactions, avoids single points of failure, ensures data security and privacy, and achieves full data custody.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125182B_ABST
    Figure CN121125182B_ABST
Patent Text Reader

Abstract

The application discloses a multi-exchange-assisted data batch hosting transaction method and system, the method comprising that a data owner encrypts multiple data under the assistance of a multi-exchange and uploads the data to a cloud server for storage. The data owner synthesizes a corresponding global signature for the multiple ciphertexts under the assistance of the multi-exchange and uploads the global signature to the cloud server for storage. A buyer obtains a subset signature of a corresponding data subset based on the global signature and verifies the signature. The buyer decrypts target data ciphertext under the assistance of the multi-exchange to obtain data plaintext. Thus, the method is a multi-exchange-assisted data batch hosting transaction, the data owner can generate an encryption key and a data authentication signature under the assistance of the multi-exchange, the confidentiality of the data to unauthorized entities such as the exchange, the cloud server and the buyer is ensured, and the authenticability of the data to an authorized buyer is ensured. Moreover, the data to be sold by the data owner is batch-encrypted and signed under the assistance of the multi-exchange, and the calculation and communication efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and particularly relates to a multi-exchange-assisted data batch hosting transaction method. BACKGROUND

[0002] In the prior art, exchange-assisted data trading (EADT) is a key mode to release the value of data elements. The current mainstream EADT relies on a single exchange as an intermediary, and the data owner delivers the original data to the exchange, the exchange processes and generates data products, and then hosts them to the cloud server, and the buyer purchases the access right through the exchange.

[0003] However, this method of EADT based on a single exchange has many defects, at least including the following two aspects:

[0004] Firstly, the data owner needs to interact with the exchange on a per-transaction basis, resulting in low efficiency of data batch hosting transactions. With the surge in demand for cross-domain data fusion (such as medical-financial joint modeling), this traditional method has been difficult to meet the needs of multiple data.

[0005] Secondly, there are security risks in the single exchange for EADT. The exchange or the cloud server may steal unauthorized data content to seek benefits, and the data owner or the exchange may also upload unauthenticated illegal data to cause malicious information dissemination. Therefore, although there are strict policies as passive measures to protect interests and privacy, the data owner and the buyer are still worried about the invasion of privacy because the transactions are controlled by the exchange and the cloud server. SUMMARY

[0006] The purpose of the present application is to overcome the shortcomings of the prior art, and to provide a multi-exchange-assisted data batch hosting transaction method and system, which replaces the single exchange transaction method in the prior art with a batch hosting transaction method to avoid various drawbacks of the traditional method.

[0007] The purpose of the present application is achieved by the following technical solutions:

[0008] In a first aspect, this application discloses a method for batch data custody transactions assisted by multiple exchanges, comprising: a data owner sending multiple data sets to various exchanges; the exchanges batch encrypting the multiple data sets and sending back first key fragments; the data owner calculating a first group key based on several first key fragments to encrypt each data set to obtain multiple ciphertexts; the data owner uploading the multiple ciphertexts to a cloud server; the data owner sending the multiple ciphertexts to each of the exchanges; the exchanges calculating corresponding signature fragments based on the multiple ciphertexts and sending the signature fragments back to the data owner; the data owner generating a global signature based on several signature fragments; the data owner uploading the global signature to the cloud server; the buyer downloading the ciphertext of a target data subset and the global signature from the cloud server; the buyer obtaining a subset signature corresponding to the target data subset based on the global signature; the buyer verifying the global signature and the subset signature, and if the verification passes, the transaction is deemed acceptable; otherwise, the agreement is terminated.

[0009] The beneficial effects of this invention are as follows: The method completes the transaction of the target dataset. During the process, the data is batch-hosted and traded with the assistance of multiple exchanges. The data owner can generate encryption keys and data authentication signatures with the assistance of the exchanges, ensuring the confidentiality of the data to unauthorized entities such as exchanges, cloud servers, and buyers, as well as the authentication of the data to authorized buyers. Furthermore, the data owner's data to be sold is batch-encrypted and signed with the assistance of the exchanges, improving computational and communication efficiency while avoiding the single point of failure of the server. Data storage is outsourced to the cloud server, and the delivery and hosting of data decryption keys are entrusted to multiple exchanges. After the data encryption and signature are generated and uploaded, the data owner does not need to remain online, achieving full custody. Moreover, the exchanges act as lightweight nodes, and all data encryption and signatures to be sold are stored on the cloud server.

[0010] Furthermore, the method also includes the following pre-execution step: generating system common parameters PP based on security parameters.

[0011] Where G1 and G2 are p-order additive cyclic groups formed by points on the elliptic curve, g, These are the generators of G1 and G2, respectively; Z p ={0,1,2,…,p-1} is an integer ring modulo p; e is a bilinear mapping G1×G2→G T H, H1, and H2 are three hash functions, where H: {0, 1} * ×{0,1} * →G1, H0:{0,1} * →G1, H2:{0,1} * →G2;PRG(·):G T →Z pIt is a pseudo-random number generator; n is the number of exchanges, and t is the threshold for Shamir's secret sharing.

[0012] Furthermore, multiple exchanges jointly generate a set of symmetric keys, a set of private keys, and a set of public keys using Shamir secret sharing technology; each exchange holds a symmetric key shard, a private key shard, and a public key shard.

[0013] Furthermore, the data owner sending multiple data sets to various exchanges includes: the data owner selecting a random number and generating a group commitment, a unique commitment vector, and a commitment open vector for the multiple data sets, and then sending a triplet request packet to the exchange. The triplet request packet includes: the group commitment, the data owner's ID information, and an attached instruction identifier.

[0014] Furthermore, the process of exchanges batch encrypting multiple data items and then sending back the first key fragments includes: each exchange verifying the ID information of the data owner; if the verification is successful, calculating the first key fragment for each data item, and then sending the multiple first key fragments back to the data owner.

[0015] Furthermore, the process by which the data owner calculates a first group key based on several first key fragments to encrypt each piece of data into multiple ciphertexts includes: after receiving at least a threshold t first key fragments, the data owner calculates a first group key; based on the first group key, the data owner generates a data key for each piece of data and encrypts the data one by one to obtain multiple ciphertexts.

[0016] Furthermore, the process by which the buyer obtains the subset signature corresponding to the target data subset based on the global signature conversion includes: the buyer downloading the ciphertext of the target subset and the global signature from the cloud server, and deriving the subset signature corresponding to the target data subset from the global signature based on the ciphertext of the target subset and the public key fragment.

[0017] Furthermore, the public key is Each exchange owns and holds symmetric key shards sk i Private key sharding and public key sharding

[0018] Let the non-target subset be

[0019] Define public key shards on non-target subsets as Define public key shards on the target subset as

[0020] The buyer's verification based on the global signature and the subset signature includes:

[0021] Buyer verification and Check if the two equations are true; if they are true, the verification passes; where X is XXX. These are the four components of the i-th signature fragment. Furthermore, the process includes: after successful verification, the buyer sends each ciphertext of the target data subset to various exchanges; after verifying the buyer's identity, each exchange sends the second key fragment back to the buyer; the buyer receives the second key fragments sent back by each exchange, calculates the second group key, and then decrypts to obtain the plaintext data.

[0022] Secondly, this application discloses a multi-exchange assisted data bulk custody trading device for implementing the aforementioned multi-exchange assisted data bulk custody trading method, comprising: a first terminal, the first terminal being configured to at least execute: a data owner sending multiple data packets to various exchanges; the data owner calculating a first group key based on several first key fragments to encrypt each data packet to obtain multiple ciphertexts; the data owner uploading the multiple ciphertexts to a cloud server; and the data owner sending the multiple ciphertexts to each of the exchanges; the data owner uploading the global signature to the cloud server; and a buyer terminal, the buyer terminal being configured to at least execute: the buyer purchasing data from the cloud server... The device downloads the ciphertext of a subset of target data and the global signature; the buyer obtains a subset signature corresponding to the subset of target data based on the global signature; the buyer verifies the global signature and the subset signature, and if the verification is successful, the transaction is deemed acceptable; otherwise, the agreement is terminated; an exchange server communicates with the first terminal and the buyer terminal, and is used to at least execute: the exchange performs batch encryption on multiple data and sends back a first key fragment; the exchange calculates the corresponding signature fragment based on the multiple ciphertexts, and sends the signature fragment back to the data owner; a cloud server communicates with at least the first terminal and the buyer terminal. Attached Figure Description

[0023] Figure 1 This is a schematic diagram of a multi-exchange assisted bulk data custody transaction method according to some embodiments of this application;

[0024] Figure 2 This is a schematic diagram illustrating the communication process between various executing entities in a multi-exchange assisted bulk data custody transaction method according to some embodiments of this application. Detailed Implementation

[0025] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0026] This invention provides a method and system for batch data custody and trading with multi-exchange assistance:

[0027] According to an embodiment of this application, a multi-exchange assisted data bulk custody transaction method can be mainly divided into four stages, as described above. Figure 1 The understandings are as follows:

[0028] In the data encryption generation phase, the data owner, with the assistance of multiple exchanges, encrypts multiple data sets and uploads them to a cloud server for storage. In the signature generation phase, the data owner, with the assistance of multiple exchanges, synthesizes a corresponding global signature from the multiple ciphertexts and uploads it to the cloud server for storage. In the verification phase, the buyer obtains a subset signature of the corresponding data subset based on the global signature and verifies the signature. In the decryption phase, the buyer, with the assistance of multiple exchanges, decrypts the target data ciphertext to obtain the plaintext data.

[0029] Next, refer to Figure 2 The following is a detailed description with reference to some embodiments.

[0030] First, in order to achieve secure communication among various exchanges, data owners, and buyers, system parameter initialization and key generation for each party are required, including:

[0031] S10. Generate system common parameters PP based on safety parameters:

[0032]

[0033] Where G1 and G2 are p-order additive cyclic groups formed by points on the elliptic curve, g, These are the generators of G1 and G2, respectively; Z p ={0,1,2,…,p-1} is an integer ring modulo p; e is a bilinear mapping G1×G2→G T H, H1, and H2 are three hash functions, where H: {0, 1} * ×{0,1} * →G1, H0:{0,1} * →G1, H2:{0,1} * →G2;PRG(·):G T →Z p It is a pseudo-random number generator; n is the number of exchanges, and t is the threshold for Shamir's secret sharing.

[0034] Then, each exchange A set of symmetric keys is jointly generated using Shamir's secret sharing technique. A set of private keys and its corresponding set of public keys Each exchange ε i Each has a symmetric key fragment k i Private key sharding and public key sharding Where N represents the total amount of data to be traded by the data owner, i is an intermediate variable representing the i-th exchange, and j is an intermediate variable representing the j-th data.

[0035] After completing the above steps, batch data transactions can be performed. The first stage, namely the aforementioned data encryption generation stage, includes:

[0036] S11. The data owner sends multiple data sets to various exchanges, specifically including:

[0037] The data owner has N data points. To make a group commitment, specifically, the data owner selects a random number. And generate the group commitment γ and the unique commitment vector. and commitment to open vectors Then, a triple request packet (γ, w = H(id, γ), 'GroupKey') is sent to the exchange, where w = H(id, γ) is a mapping function between group commitment and data owner ID information, and it is sent together with the attached instruction identifier 'GroupKey'.

[0038] S12. The exchange performs batch encryption on multiple data sets and then sends back the first key fragment, specifically including:

[0039] Each exchange verifies the data owner's ID information, i.e., verifies w = H(id, γ). If the verification is successful, each exchange i calculates its own group key shard for each piece of data. Then each data exchange shards the group key (gk) it has calculated. i (N in total) are returned to the data owner.

[0040] S13. The data owner calculates a first group key based on several first key fragments to encrypt each piece of data, resulting in multiple ciphertexts, specifically including:

[0041] The data owner receives at least threshold t first key fragments Then, the first group key gk is calculated using Lagrange interpolation. Where λ i These are the Lagrange interpolation coefficients, based on the first group key gk, the data owner assigns each data m... j Generate data key mk j =e(gk,H1(q) j The ciphertext is obtained by encrypting each piece of data.

[0042] At this point, the method has completed its first stage: generating ciphertext through the collaborative efforts of multiple exchanges, and then sending the ciphertext to the cloud server and each exchange, including:

[0043] S101A, The data owner will transfer the multiple encrypted messages Uploaded to the cloud server.

[0044] S101B, The data owner will transfer the multiple encrypted messages Send to multiple of the aforementioned exchanges

[0045] It should be understood that the aforementioned S101A and S101B can be performed simultaneously or sequentially.

[0046] Next, the method enters the second stage, which is the signature generation stage, and specifically includes the following steps:

[0047] S21. The exchange calculates the corresponding signature fragments based on the multiple ciphertexts, and sends the signature fragments back to the data owner, specifically including:

[0048] Various exchanges ε i Share a random number σ0∈G2, and then calculate the corresponding i-th signature fragment: After the calculation is complete, the signature fragment is returned to the data owner, where These are the identity elements of G1 and G1, respectively. These are the four components of the i-th signature segment.

[0049] S22. The data owner generates a global signature based on several signature fragments, specifically including:

[0050] The data owner receives at least the threshold t signed fragments. Calculate the global signature using Lagrange interpolation:

[0051]

[0052] Where, λ i These are the Lagrange interpolation coefficients.

[0053] At this point, the second stage of the method execution is complete, that is, the process of generating the global signature is completed, and then the following can be executed: S201, the data owner uploads the global signature σ to the cloud server.

[0054] Next, the method proceeds to the third stage, the verification stage, where the buyer verifies the global signature. This stage includes the following steps:

[0055] S31. The buyer downloads a subset of the target data from the cloud server. The ciphertext c = {c j |j∈J} and the global signature. The target data subset described here is the portion of the data that the buyer actually wants to purchase. It can be understood as a portion of the data that the buyer chooses to purchase from all the data hosted on the cloud server by the data owner.

[0056] S32. The buyer obtains the subset signature corresponding to the target data subset based on the global signature conversion, specifically including:

[0057] Let the non-target subset be The subset signature is:

[0058]

[0059] Here, public key sharding on non-target subsets is defined as follows:

[0060] S11. The buyer verifies the global signature and the subset signature. If the verification passes, the transaction is deemed acceptable; otherwise, the agreement is terminated. This specifically includes:

[0061] Buyer verification and Check if the two equations are true; if they are true, the verification is successful.

[0062] Here, the public key shards on the target subset are defined as follows:

[0063] At this point, the third stage is complete. After verification, the fourth stage, decryption, is required. This involves the buyer decrypting the ciphertext of the target data subset to obtain the plaintext, including:

[0064] S41. After successful verification, the buyer will send each ciphertext of the target data subset to the respective exchanges, specifically including:

[0065] Buyer orders target data subset Each ciphertext c in j =(id,γ,q) j ,x j ), and the quadruple (id, γ, q) j ,'MessageKey') is sent to various exchanges In the quadruple, 'MessageKey' is the instruction identifier.

[0066] S42. After each exchange verifies the buyer's identity, it sends the second key fragment back to the buyer, specifically including:

[0067] Each exchange calculates w = H(id||γ) and fragments the second key. Returned to the buyer.

[0068] S43. The buyer receives the second key fragments sent back from each exchange, calculates the second group key, and then decrypts it to obtain the plaintext data, specifically including:

[0069] For each ciphertext c j The data owner receives at least a threshold t data key fragments. Calculate the data key using Lagrange interpolation:

[0070] Where λ i These are the Lagrange interpolation coefficients; the data owner decrypts c line by line. j Obtain the target data in plaintext

[0071] Therefore, this method facilitates the trading of the target dataset through batch data custody transactions assisted by multiple exchanges. Data owners can generate encryption keys and data authentication signatures with the assistance of these exchanges, ensuring the confidentiality of the data to unauthorized entities such as exchanges, cloud servers, and buyers, as well as the authentication of the data to authorized buyers. Furthermore, the batch encryption and signing of the data to be sold by the data owner, with the assistance of the exchanges, improves computational and communication efficiency while avoiding single points of failure on the server. Data storage is outsourced to cloud servers, and the delivery of data decryption keys is entrusted to multiple exchanges. After the data encryption and signature are generated and uploaded, the data owner does not need to remain online, achieving full custody. Moreover, the exchanges act as lightweight nodes, with all data encryption and signatures for sale stored on the cloud server.

[0072] According to an embodiment of this application, a multi-exchange assisted data bulk custody trading device can be combined with... Figure 2 It is understood that the apparatus is used in the multi-exchange assisted bulk data custody trading method described in any of the foregoing embodiments, including:

[0073] A first terminal, the first terminal being used to perform at least the following actions: a data owner sending multiple data packets to various exchanges; the data owner calculating a first group key based on several first key fragments to encrypt each data packet to obtain multiple ciphertexts; the data owner uploading the multiple ciphertexts to a cloud server; and the data owner sending the multiple ciphertexts to each of the exchanges; and the data owner uploading the global signature to the cloud server.

[0074] The buyer terminal is used to perform at least the following actions: the buyer downloads the ciphertext of a target data subset and the global signature from the cloud server; the buyer converts the global signature to obtain a subset signature corresponding to the target data subset; the buyer verifies the global signature and the subset signature, and if the verification is successful, the transaction is deemed acceptable; otherwise, the agreement is terminated.

[0075] An exchange server communicates with the first terminal and the buyer terminal, and is used to at least perform the following: the exchange performs batch encryption on multiple data and sends back a first key fragment; the exchange calculates the corresponding signature fragment based on the multiple ciphertexts, and the exchange sends the signature fragment back to the data owner;

[0076] A cloud server, which communicates with at least the first terminal and the buyer's terminal.

[0077] The above description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the concept described herein through the above teachings or related technologies or knowledge. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.

Claims

1. A method for batch data custody and trading with multi-exchange assistance, characterized in that, include: The data owner sent multiple data sets to various exchanges in bulk; The exchange encrypts multiple data items in batches and then sends them back as fragments of the first key. The data owner calculates a first group key based on several first key fragments to encrypt each piece of data, resulting in multiple ciphertexts; The data owner uploads the multiple encrypted messages to the cloud server; The data owner sends the multiple encrypted messages to each of the respective exchanges; The exchange calculates the corresponding signature fragments based on the multiple ciphertexts, and sends the signature fragments back to the data owner; the data owner generates a global signature based on the signature fragments. The data owner uploads the global signature to the cloud server; The buyer downloads the encrypted subset of the target data and the global signature from the cloud server; the buyer derives the subset signature corresponding to the target data subset based on the global signature; the buyer verifies the global signature and the subset signature, and if the verification is successful, the transaction is deemed acceptable; otherwise, the agreement is terminated.

2. The multi-exchange assisted data bulk custody transaction method according to claim 1, characterized in that, The method also includes the following to be executed first: Generate system common parameters PP based on safety parameters: Where G1 and G2 are p-order additive cyclic groups formed by points on the elliptic curve, g, These are the generators of G1 and G2, respectively; Z p ={0,1,2,…,p-1} is an integer ring modulo p; e is a bilinear mapping G1×G2→G T H, H1, and H2 are three hash functions, where H: {0, 1} * ×{0,1} * →G1, H0:{0,1} * →G1, H2:{0,1} * →G2;PRG(·):G T →Z p It is a pseudo-random number generator; n is the number of exchanges, and t is the threshold for Shamir's secret sharing.

3. The multi-exchange assisted data bulk custody transaction method according to claim 1 or 2, characterized in that, Multiple exchanges jointly generate a set of symmetric keys, a set of private keys, and a set of public keys using Shamir secret sharing technology; each exchange holds a symmetric key shard, a private key shard, and a public key shard.

4. The multi-exchange assisted data bulk custody transaction method according to claim 1, characterized in that, The data owner sent multiple data sets to various exchanges, including: The data owner selects a random number and generates a group commitment, a unique commitment vector, and a commitment open vector for multiple data sets. Then, the data owner sends a triplet request packet to the exchange. The triplet request packet includes the group commitment, the data owner's ID information, and an accompanying instruction identifier.

5. The multi-exchange assisted data batch custody transaction method according to claim 4, characterized in that, After the exchange performs batch encryption on multiple data sets, it sends back the first key fragment, which includes: Each exchange verifies the ID information of the data owner. If the verification is successful, it calculates the first key fragment of each data and then sends multiple first key fragments back to the data owner.

6. The multi-exchange assisted data bulk custody transaction method according to claim 1, characterized in that, The data owner calculates a first group key based on several first key fragments to encrypt each piece of data, resulting in multiple ciphertexts including: After receiving at least t first key fragments, the data owner calculates the first group key. Based on the first group key, the data owner generates a data key for each data and encrypts the data one by one to obtain multiple ciphertexts.

7. The multi-exchange assisted data batch custody transaction method according to claim 2, characterized in that, The subset signature obtained by the buyer based on the global signature transformation for the target data subset includes: The buyer downloads the ciphertext and global signature of the target subset from the cloud server, and derives the subset signature corresponding to the target data subset from the global signature based on the ciphertext and public key fragments of the target subset.

8. The multi-exchange assisted data bulk custody transaction method according to claim 7, characterized in that, The public key is Each exchange owns and holds symmetric key shards sk i Private key sharding and public key sharding Let the non-target subset be Define public key shards on non-target subsets as Define public key shards on the target subset as The buyer's verification based on the global signature and the subset signature includes: Buyer verification and Check if the two equations are true; if they are true, the verification passes. Wherein, It is the master key. These are the four components of the i-th signature segment.

9. The multi-exchange assisted data bulk custody transaction method according to claim 1, characterized in that, Also includes: After successful verification, the buyer will send each encrypted subset of the target data to the respective exchanges; After each exchange verifies the buyer's identity, it sends the second key fragment back to the buyer. The buyer receives the second key fragment sent back by each exchange, calculates the second group key, and then decrypts it to obtain the plaintext data.

10. A multi-exchange assisted data bulk custody trading device, characterized in that, The method for implementing the multi-exchange assisted bulk data custody trading method according to any one of claims 1-9 includes: A first terminal, the first terminal being used to perform at least the following actions: a data owner sending multiple data packets to various exchanges; the data owner calculating a first group key based on several first key fragments to encrypt each data packet to obtain multiple ciphertexts; the data owner uploading the multiple ciphertexts to a cloud server; and the data owner sending the multiple ciphertexts to each of the exchanges; and the data owner uploading the global signature to the cloud server. The buyer terminal is used to perform at least the following actions: the buyer downloads the ciphertext of a target data subset and the global signature from the cloud server; the buyer converts the global signature to obtain a subset signature corresponding to the target data subset; the buyer verifies the global signature and the subset signature, and if the verification is successful, the transaction is deemed acceptable; otherwise, the agreement is terminated. An exchange server communicates with the first terminal and the buyer terminal, and is used to at least perform the following: the exchange performs batch encryption on multiple data and sends back a first key fragment; the exchange calculates the corresponding signature fragment based on the multiple ciphertexts, and the exchange sends the signature fragment back to the data owner; A cloud server, which communicates with at least the first terminal and the buyer's terminal.