Data processing method and device, electronic equipment and storage medium
By registering decentralized identities (DIDs) for data providers and data directories, and using blockchain to store DID identifiers and verifiable claims (VCs), the problem of centralized malicious activity in multi-party data sharing collaboration is solved, realizing the authenticity of data provider identities and the security of data sharing, and ensuring the credibility of data sharing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2024-11-20
- Publication Date
- 2026-05-22
AI Technical Summary
In existing technologies, multi-party data sharing and collaboration suffers from centralized malicious intent, unreliable data security and identity verification, and cannot guarantee the authenticity of the data provider's identity or the trustworthiness of data sharing.
By registering decentralized identities (DIDs) for data providers and data directories, and using blockchain to store DID identifiers and verifiable claims (VCs), the digital identity construction and attribute endorsement of the data directory are realized, ensuring the authenticity of the data provider's identity and the security of data sharing.
It enables decentralized, trustworthy, and verifiable multi-party data sharing and collaboration, ensuring the authenticity and validity of data provider identities, ensuring that shared data is created by the correct party, and ensuring the security and trustworthiness of data sharing.
Smart Images

Figure CN122072731A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a data processing method, apparatus, device, and storage medium. Background Technology
[0002] Multi-party data sharing and collaboration refers to the exchange, sharing, and use of data among different organizations, departments, or individuals to achieve more efficient data processing and analysis. Data sharing can break down information barriers, allowing data to be widely disseminated and promoting the flow of information. The multiple parties involved in data sharing and collaboration include a data provider and several data users.
[0003] In the proposed solutions, both data providers and users create, apply for, and have their data access approved through a centralized control platform. Traditional centralized solutions rely on a single, centralized institution for services, with intermediate data stored in a centralized database such as MySQL. Therefore, these solutions are prone to malicious centralized manipulation; for example, data may be deleted or tampered with, data security cannot be guaranteed, and the identity of data providers cannot be reliably verified. Summary of the Invention
[0004] This application provides a data processing method, apparatus, device, and storage medium that can help ensure the security and reliability of data sharing.
[0005] In a first aspect, embodiments of this application provide a data processing method, including:
[0006] Obtain the data directory published by the first object, the data directory including the description information of the data source provided by the first object;
[0007] Using the public key of the first object, a decentralized identity DID is registered for the first object, and the first DID identifier of the first object and the corresponding first DID document are saved to the blockchain;
[0008] Register a DID for the data directory, and save the second DID identifier and the corresponding second DID document of the data directory to the blockchain;
[0009] The first verifiable declaration (VC) of the data directory is issued using the private key of the first object, and the first VC is saved to the blockchain; the first VC is used to determine that the data directory was created and owned by the first object.
[0010] Optionally, it also includes obtaining a data usage request from the blockchain, the data usage request being used to request the use of the data corresponding to the first VC provided by the first object; and notifying the first object to conduct data usage approval.
[0011] Optionally, it also includes obtaining the consent notification from the first object, and issuing a second VC using the private key of the first object. The second VC is used by the first object to authorize the second object to use the data corresponding to the first VC; and saving the second VC to the blockchain.
[0012] Optionally, the second VC includes the first DID identifier, the DID identifier of the second object, and the database table field corresponding to the data directory.
[0013] Optionally, the first VC includes some or all of the information of the data directory and the signature information of the first object.
[0014] Optionally, the data directory includes at least one of the following: data source database server address information, login account name and password for the data source database, database name, data table name, and data table fields / types / descriptions.
[0015] Optionally, it also includes using the public key of the first data management platform to register a DID for the first data management platform, and saving the third DID identifier and the corresponding third DID document of the first data management platform to the blockchain; wherein, the first object publishes the data directory by logging into the account on the first data management platform;
[0016] Add the third DID identifier and the private key of the first data management console to the configuration information of the first data management console.
[0017] Secondly, embodiments of this application provide a map data processing apparatus, including:
[0018] A first verifiable claim (VC) is obtained from the blockchain for a data directory, the first VC being used to determine that the data directory was created and owned by a first object; wherein the data directory is published by the first object and includes descriptive information about the data source provided by the first object;
[0019] Obtain the first decentralized identity (DID) document of the first object from the blockchain, and use the public key in the first DID document to verify the signature information of the first VC.
[0020] Optionally, it also includes obtaining a data usage request from a second object, the data usage request being used by the second object to request the use of data corresponding to the first VC provided by the first object; and sending the data usage request to the blockchain.
[0021] Optionally, it also includes obtaining a second VC from the blockchain, the second VC being used by the first object to authorize the second object to use the data corresponding to the first VC; the second object sending the second VC.
[0022] Optionally, the second VC includes the first DID identifier, the DID identifier of the second object, and the database table field corresponding to the data directory.
[0023] Optionally, the first VC includes some or all of the information of the data directory and the signature information of the first object.
[0024] Optionally, the data directory includes at least one of the following: data source database server address information, login account name and password for the data source database, database name, data table name, and data table fields / types / descriptions.
[0025] Optionally, it also includes using the public key of the second data control station to register a DID for the second data control station, and saving the fourth DID identifier and the corresponding fourth DID document of the second data control station to the blockchain; wherein the second data control station subscribes to the data directory VC;
[0026] Add the fourth DID identifier and the private key of the second data management console to the configuration information of the second data management console.
[0027] Optionally, it also includes using the public key of the second object to register a DID for the second object, and saving the fifth DID identifier of the second object and the corresponding fifth DID document to the blockchain;
[0028] Save the fifth DID identifier and the private key of the second object locally.
[0029] Thirdly, embodiments of this application provide a data processing apparatus, including:
[0030] The acquisition unit is used to acquire the data directory published by the first object, wherein the data directory includes description information of the data source provided by the first object;
[0031] The registration unit is used to register a decentralized identity (DID) for the first object using the public key of the first object;
[0032] The on-chain unit is used to save the first DID identifier of the first object and the corresponding first DID document to the blockchain;
[0033] The registration unit is also used to register a DID for the data directory;
[0034] The on-chain unit is also used to save the second DID identifier and the corresponding second DID document of the data directory to the blockchain;
[0035] An issuing unit is configured to issue a first verifiable declaration (VC) of the data directory using the private key of the first object; the first VC is used to determine that the data directory was created and owned by the first object.
[0036] The on-chain unit is also used to save the first VC to the blockchain.
[0037] Fourthly, embodiments of this application provide a data processing apparatus, including:
[0038] An acquisition unit is used to acquire a first verifiable declaration (VC) of a data directory from the blockchain. The first VC is used to determine that the data directory was created and owned by a first object. The data directory is published by the first object and includes descriptive information of a data source provided by the first object.
[0039] The acquisition unit is further configured to acquire the first decentralized identity (DID) document of the first object from the blockchain;
[0040] The verification unit is also used to verify the signature information of the first VC using the public key in the first DID document.
[0041] Fifthly, embodiments of this application provide an electronic device, including:
[0042] A processor and a memory, the memory being used to store a computer program, and the processor being used to invoke and run the computer program stored in the memory to perform the method of the first aspect or the method of the second aspect described above.
[0043] Sixthly, embodiments of this application provide a method for storing a computer program that causes a computer to perform the method described in the first aspect or the method described in the second aspect.
[0044] In a seventh aspect, embodiments of this application provide a computer program product, including computer program code, which, when executed by an electronic device, causes the electronic device to perform the method described in the first aspect or the method described in the second aspect.
[0045] On the one hand, this application embodiment registers a DID for the first object using the public key of the first object, registers a DID for the data directory published by the first object, and saves the DID identifier and DID document corresponding to the first object and the data directory to the blockchain. This enables the construction of digital identities for the first object and the data directory based on the blockchain DID, and the use of the first object's private key to issue a VC for the data directory to realize the attribute endorsement of the first object's DID as the DID of the data directory. This achieves decentralized, trustworthy, and verifiable multi-party data sharing and collaboration, and identifies the user identity of the data provider and confirms the rights to the shared data, ensuring the authenticity and validity of the data provider's identity and the security and trustworthiness of data sharing.
[0046] On the other hand, the embodiments of this application obtain the first VC of the data directory published by the first object from the blockchain, as well as the first DID document of the first object, and use the public key in the first DID document to verify the signature information of the first VC. This enables the confirmation of ownership of shared data provided by the data provider during the multi-party data sharing collaboration process, ensuring that the shared data is created by the correct data provider and ensuring the security and trustworthiness of data sharing. Attached Figure Description
[0047] Figure 1 This is a schematic diagram of the blockchain involved in an embodiment of this application;
[0048] Figure 2A This is a schematic diagram illustrating an application scenario of an embodiment of this application;
[0049] Figure 2B This is another schematic diagram illustrating an application scenario of an embodiment of this application;
[0050] Figure 3 A schematic diagram illustrating a data processing method provided in an embodiment of this application;
[0051] Figure 4 A schematic diagram illustrating another data processing method provided in an embodiment of this application;
[0052] Figure 5 This is a schematic diagram illustrating the process of system initialization for the data management console provided in an embodiment of this application;
[0053] Figure 6 This is a schematic diagram of the process for creating a user object provided in an embodiment of this application;
[0054] Figure 7 This is a schematic diagram illustrating the process of a data provider publishing data, as provided in the embodiments of this application.
[0055] Figure 8 This is a flowchart illustrating the process of a data user applying for data, as provided in the embodiments of this application.
[0056] Figure 9 This is a flowchart illustrating the data provider's approval process for the embodiments of this application.
[0057] Figure 10 This is a schematic block diagram of a data processing apparatus according to an embodiment of this application;
[0058] Figure 11 This is a schematic block diagram of another data processing apparatus according to an embodiment of this application;
[0059] Figure 12 This is a schematic block diagram of the electronic device provided in the embodiments of this application. Detailed Implementation
[0060] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0061] It should be understood that in the embodiments of this application, "B corresponding to A" means that B is associated with A. In one implementation, B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.
[0062] In the description of this application, unless otherwise stated, "at least one" means one or more, and "multiple" means two or more. Additionally, "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.
[0063] It should also be understood that the descriptions of "first", "second", etc. appearing in the embodiments of this application are only for illustration and to distinguish the objects being described, and there is no order to them. They do not indicate any special limitation on the number of devices in the embodiments of this application, and cannot constitute any limitation on the embodiments of this application.
[0064] It should also be understood that specific features, structures, or characteristics relating to embodiments in the specification are included in at least one embodiment of this application. Furthermore, these specific features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0065] Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion, such that a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such processes, methods, products, or devices.
[0066] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.
[0067] First, the relevant terms involved in the embodiments of this application will be described.
[0068] 1. Data Provider: The party that owns and provides data, whose data can only be obtained by approved data users.
[0069] 2. Data users: Participants who wish to use the data provided by the data provider will apply to the data provider for the data they need, and can only obtain the data after approval.
[0070] 3. Decentralized Identity (DID): Compared to traditional identity systems based on Public Key Infrastructure (PKI), DID digital identity systems built on blockchain have advantages such as ensuring data authenticity and trustworthiness, protecting user privacy and security, and strong portability. Its advantages include:
[0071] Decentralization: Based on blockchain, it avoids identity data being controlled by a single centralized authority;
[0072] Self-controlled identity: Based on Distributed Public Key Infrastructure (DPKI), each user's identity is not controlled by a trusted third party, but by its owner, and individuals can manage their own identities autonomously;
[0073] Trusted data exchange: Identity-related data is anchored on the blockchain, and the authentication process does not depend on the application providing the identity.
[0074] 4. DID Identifier: A specific formatted string used to represent the digital identity of an entity, which can be a person, machine, thing, etc. The format of the DID identifier is: did:example:123456789abcdefghijk, where didi is the scheme, example is the DID method, and 123456789abcdefghijk is the DID method specific string.
[0075] 5. DID Document: Each DID identifier corresponds to a DID document, which contains the DID identifier, public key, server endpoint, authorization information, timestamp, etc., with the public key information being the most important. Generally, the DID identifier is used as the key, and the DID document is used as the value, stored in the blockchain. Leveraging the blockchain's immutability and shared data access characteristics, trusted data can be quickly accessed and retrieved during subsequent identity verification.
[0076] 6. Verifiable Claim (VC): A VC is a descriptive claim issued by one DID to endorse certain attributes of another DID, and is accompanied by its own digital signature to prove the authenticity of these attributes, similar to a digital certificate.
[0077] 7. A blockchain consists of a series of blocks that are sequentially generated in chronological order. Once a new block is added to the blockchain, it will not be removed. The blocks record the data submitted by the nodes in the blockchain system.
[0078] Figure 1 This is an optional diagram of a block structure. Each block includes the hash value of the transactions stored in that block (the hash value of this block) and the hash value of the previous block. Blocks are linked together through their hash values to form a blockchain. Additionally, blocks may include information such as a timestamp when the block was generated. Essentially, a blockchain is a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains relevant information used to verify the validity of the information (anti-counterfeiting) and to generate the next block.
[0079] Figure 2A An optional schematic diagram of an application scenario of this application embodiment is shown.
[0080] like Figure 2A As shown, this application scenario involves terminal 102 and server 104. Terminal 102 can communicate with server 104 via a communication network. Server 104 can be a backend server for terminal 102.
[0081] For example, terminal 102 can refer to a type of device that has rich human-computer interaction methods, internet access capabilities, typically runs various operating systems, and has strong processing capabilities. Terminal 102 can be a smartphone, tablet computer, laptop computer, desktop computer, smart voice interaction device, wearable device, smart home appliance, in-vehicle device, aircraft, etc., but is not limited to these. Optionally, terminal 102 can install applications, which include, but are not limited to, web applications, mini-programs, native applications (apps), or applications with other technology stack forms.
[0082] Server 104 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. A server can also become a node in a blockchain.
[0083] There may be one or more servers. When there are multiple servers, at least two servers are used to provide different services, and / or at least two servers are used to provide the same service, such as providing the same service in a load-balanced manner. This application does not limit this.
[0084] The terminal and the server can be connected directly or indirectly via wired or wireless communication, and this application does not limit this. This application does not limit the number of servers or terminals. The solution provided in this application can be implemented independently by the terminal, independently by the server, or jointly by the terminal and the server, and this application does not limit this.
[0085] Optionally, this application scenario may also include a data storage system. The data storage system can store the data required by server 104. The data storage system can be configured independently, integrated into server 104, or deployed in the cloud or on other servers; there are no limitations.
[0086] It should be understood that Figure 2A This is merely an illustrative example and does not specifically limit the application scenarios of the embodiments in this application. For example, Figure 2A An example of a terminal and a server is shown, but in practice, other numbers of terminals and servers may be included, and this application does not limit this.
[0087] The system involved in the embodiments of the present invention can also be a data sharing system formed by connecting a client and multiple nodes (any form of computing device in the network, such as a server or user terminal) through network communication.
[0088] A data sharing system refers to a system used for data sharing between nodes. This system can include multiple nodes, which can refer to various clients within the system. Each node, in its normal operation, receives input information and maintains the shared data within the system based on this information. To ensure interoperability within the data sharing system, information connections exist between each node, allowing for information transmission. For example, when any node in the system receives input information, other nodes retrieve this input information according to a consensus algorithm and store it as part of the shared data, ensuring data consistency across all nodes.
[0089] Each node in the data-sharing system stores the same blockchain. When generating blocks in the blockchain, the node receiving the input information verifies it. After verification, it stores the input information in a memory pool and updates its hash tree used to record the input information. Then, it updates the timestamp to the time the input information was received and tries different random numbers, performing feature value calculations multiple times to ensure the calculated feature values meet specific conditions. When a random number that meets the conditions is obtained, the corresponding information is stored, generating a block header and block body, thus obtaining the current block. Subsequently, the node sending the newly generated block to other nodes in its data-sharing system verifies the new block and adds it to its stored blockchain after verification, thereby achieving data on-chain processing.
[0090] Figure 2B A schematic diagram illustrating an application scenario of this application is shown. For example... Figure 2BAs shown, Organization 1, Organization 2, Organization 3, and Organization 4 can each update the data of their corresponding chain nodes in the blockchain through their respective data management consoles. These chain nodes can share data, thereby achieving multi-party data sharing and collaboration among Organization 1, Organization 2, Organization 3, and Organization 4. The data management consoles can use a MySQL database for data storage. For example, Organization 1 and Organization 4 may include data users, and Organization 3 may include a data provider.
[0091] In some possible implementations, administrator 1 of organization 1 can create a proxy gateway on data management console 1. Data management console 1 then registers a gateway chain identity certificate with chain node 1, enabling it to send shared data to chain node 1 using the data proxy gateway. For example, organizations 1, 3, and 4 can use data proxy gateway 1 for data transmission. Optionally, data proxy gateway 1 can send shared data to chain node 1, chain node 3, or chain node 4 via Remote Procedure Call (RPC). Optionally, the data proxy gateway can also download data through the data management console. For example, data users in organization 1 can save downloaded data to organization 1's database through the data proxy gateway, and data users in organization 4 can save downloaded data to organization 4's database through the data proxy gateway. Additionally, data providers in organization 3 can upload data from their database to data proxy gateway 1.
[0092] The technical solutions of the embodiments of this application will be described in detail below through some examples. The following embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0093] Figure 3 This is a flowchart illustrating a data processing method 300 provided in an embodiment of this application. The executing entity in this embodiment is a device with data processing capabilities. This device can be, for example, each node 201 in the data sharing system 200 shown in Figure 2, and is not limited thereto. It should be understood that... Figure 3 The steps or operations of the data processing method are illustrated, but these steps or operations are merely examples, and other operations can be performed in this application. Figure 3 Variations of various operations within it.
[0094] like Figure 3 As shown, the method 300 may include steps S310 to S340.
[0095] S310, Obtain the data directory published by the first object, which includes description information of the data source provided by the first object.
[0096] S320: Using the public key of the first object, register a decentralized identity (DID) for the first object, and save the first DID identifier and the corresponding first DID document of the first object to the blockchain.
[0097] S330, register a DID for the data directory, and save the second DID identifier and the corresponding second DID document of the data directory to the blockchain.
[0098] S340, using the private key of the first object, issue a first verifiable claim (VC) for the data directory. The first VC is used to determine that the data directory was created and owned by the first object, and the first VC is saved to the blockchain.
[0099] This application embodiment registers a DID for the first object using the public key of the first object, registers a DID for the data directory published by the first object, and saves the DID identifier and DID document corresponding to the first object and the data directory to the blockchain. This enables the construction of digital identities for the first object and the data directory based on blockchain-based DIDs, and the issuance of VCs for the data directory using the private key of the first object to achieve attribute endorsement of the first object's DID as the DID of the data directory. This realizes decentralized, trustworthy, and verifiable multi-party data sharing and collaboration, and identifies the user identity of the data provider and confirms the rights to the shared data, ensuring the authenticity and validity of the data provider's identity and the security and trustworthiness of data sharing.
[0100] In some embodiments, the first device may deploy a first data management console, which performs each of the steps S210 to S240 described above. For example, the data management console may be a trusted data exchange platform built on blockchain technology, capable of combining the on-chain and off-chain capabilities of blockchain to achieve trusted data sharing and privacy protection. On-chain, the data management console stores data catalogs and data authorization information, ensuring data traceability and security; off-chain, by constructing secure and reliable data transmission channels and a secure multi-party computation platform, it enables the circulation of data content and data value without centralized aggregation.
[0101] Optionally, the first object is the data provider object, that is, the participant that owns and provides the data, whose data can only be obtained by the user after approval. Specifically, the first object publishes the data catalog by logging into its account on the first data management console.
[0102] In some implementation methods, the first user can log in to the first data management console using a username and password. Optionally, when the administrator creates a user account for the first user on the first data management console, the first user can enter basic information such as username, email address, and mobile phone number. Optionally, the first user can modify this basic information after logging into the data management console.
[0103] In some implementations, the first entity, the data provider, publishes its data resources through a data catalog, enabling other entities (data users) to share and use them. Because the data catalog includes descriptive information about the data source provided by the first entity, rather than the data source itself, it helps protect data privacy and security.
[0104] In some embodiments, the data directory includes at least one of the following: data source database server address information, login account name and password of the data source database, database name, data table name, and data table fields / types / descriptions.
[0105] For example, the data source database server address information can be the data source database server Internet Protocol (IP) address.
[0106] Optionally, embodiments of this application may encrypt the data directory. For example, sensitive information in the data directory, such as the database IP address, login username, and password, may be encrypted.
[0107] In some embodiments, in step S320, the first data management console can create a public-private key pair for the first object locally, and register a DID for the first object using the DID service and the first object's public key, obtaining the first DID identifier and the corresponding first DID document for the first object. The first DID identifier represents the digital identity of the first object, and the first DID document includes the first DID identifier, the first object's public key, and other information, including but not limited to server endpoints, authorization information, and timestamps. Then, the first DID identifier and the corresponding first DID document are saved to the blockchain.
[0108] In some implementations, the first DID identifier can be used as the key, and the first DID document can be stored in the blockchain as the value. Due to the immutability and shared data access characteristics of the blockchain, trusted data, such as the public key of the first object, can be quickly accessed and obtained during subsequent identity verification.
[0109] Optionally, the first data control console can store the first DID identifier and the private key of the first object locally, such as in a local database. Optionally, in this embodiment of the application, the private key of the first object is stored in encrypted form to prevent data leakage.
[0110] Therefore, by registering a DID for the first object, the embodiments of this application can ensure the authenticity and validity of the data provider's identity.
[0111] In some embodiments, in step S330, the first data management console registers a DID for the data directory using the DID service, obtaining a second DID identifier and a corresponding second DID document for the data directory. The second DID identifier represents the digital identity of the data directory, and the second DID document includes the second DID identifier, a public key, and other information, including but not limited to server endpoints, authorization information, and timestamps. The public key is generated by the first data management console. Then, the second DID identifier and the corresponding second DID document are saved to the blockchain.
[0112] In some implementations, the second DID identifier can be used as the key, and the second DID document can be stored in the blockchain as the value. Due to the immutability and shared data access characteristics of the blockchain, subsequent identity verification can quickly access and obtain trusted data, such as data directory information.
[0113] Optionally, the first data control console can store the second DID identifier locally, such as in a local database.
[0114] In some embodiments, the public key of the first data control station can be used to register a DID for the first data control station, and the third DID identifier and the corresponding third DID document of the first data control station can be saved to the blockchain.
[0115] For example, the first data management console can create a public-private key pair locally and register a DID for itself using the DID service and its public key, thus obtaining a third DID identifier and a corresponding third DID document. The third DID identifier represents the digital identity of the first data management console, and the third DID document includes the third DID identifier, the first data management console's public key, and other information, including but not limited to server endpoints, authorization information, and timestamps. Then, the third DID identifier and the corresponding third DID document are saved to the blockchain.
[0116] In some implementations, the third-party DID identifier can be used as the key, and the third-party DID document can be stored in the blockchain as the value. Due to the immutability and shared data access characteristics of the blockchain, trusted data, such as the public key of the primary data control platform, can be quickly accessed and obtained during subsequent identity verification.
[0117] In some embodiments, the DID service can be used to register the third DID identifier of the first data control console as an authoritative body, so that the first data control console can register DIDs for each object under the body.
[0118] Optionally, the first data management console adds the third DID identifier and the private key of the first data management console to the configuration information of the first data management console.
[0119] In some implementations, the first data management console can be started after the third DID identifier and the private key of the first data management console are added to the configuration information of the first data management console.
[0120] Therefore, by registering a DID on the first data management console, this embodiment of the application can ensure the authenticity and reliability of the data management console's identity, which in turn helps to ensure the authenticity and validity of the identity of the data provider logged on the data management console.
[0121] In some embodiments, when saving the first DID identifier and the corresponding first DID document of the first object to the blockchain, it is possible to check whether the request initiator, i.e., the first data control platform, is an authoritative institution, i.e., based on the third DID identifier of the first data control platform. If so, the first DID identifier and the first DID document can be successfully uploaded to the blockchain. If not, the first DID identifier and the first DID document cannot be uploaded to the blockchain.
[0122] In some embodiments, the first VC includes some or all of the information of the data directory and the signature information of the first object.
[0123] For example, the first data control console can use the private key of the hosted data provider, i.e., the first object, to issue the first VC of the data directory. The proof portion of the first VC includes data target information, which can be partial or complete information about the data target. For example, it may include some or all of the following: the IP address of the data source database server, the login username and password of the data source database, the database name, the data table name, and the data table fields / types / descriptions. The proof portion of the first VC is the signature information of the data provider, i.e., the first object. Therefore, the first VC proves that the data target was indeed created and owned by the data provider, i.e., the first object. In other words, the first VC is the signature endorsement of the data provider, i.e., the first object, for the data directory DID.
[0124] In summary, based on steps S310 to S340 above, the first entity, namely the data provider, can publish the data. Further details can be found in the following sections. Figure 3 The second data control console can execute the following steps S350 and S360 to obtain the VC of the published data.
[0125] S350, the second data control console obtains the first VC of the data directory from the blockchain. The first VC is used to determine that the data directory was created and owned by the first object; wherein, the data directory is published by the first object and includes descriptive information of the data source provided by the first object.
[0126] S360 retrieves the first DID document of the first object from the blockchain and uses the public key in the first DID document to verify the signature information of the first VC.
[0127] Therefore, by obtaining the first VC of the data directory published by the first object and the first DID document of the first object from the blockchain, and verifying the signature information of the first VC using the public key in the first DID document, this application can realize the confirmation of ownership of the shared data provided by the data provider in the process of multi-party data sharing collaboration, ensuring that the shared data is created by the correct data provider, and ensuring the security and trustworthiness of data sharing.
[0128] In some embodiments, the second device may deploy a second data control console, which performs each step of S350 and S360 described above. Optionally, the second data control console may be a different data control console from the first data control console, or it may be the same data control console, without limitation.
[0129] In some implementations, the second data management console can subscribe to the VCs of all published data directories on the blockchain. Thus, when a VC for a data directory is added to the blockchain, the blockchain can send the updated VC to the second data management console. For example, after step S340 is executed and the first VC is saved to the blockchain, the second data management console can retrieve the first VC from the blockchain.
[0130] In some implementations, when the signature information of the first VC is verified using the public key in the first DID document, if the verification passes, it means that the data directory was created by the correct data provider; if the verification fails, it means that the data directory was not created by the correct data provider, and the first VC is ignored.
[0131] Optionally, once the verification passes, the first VC can be written to the local database, making it convenient for the data user, i.e., the second object, to see which data providers provided which data.
[0132] In some embodiments, the public key of the second data management console can be used to register a DID for the second data management console, and the fourth DID identifier and corresponding fourth DID document of the second data management console can be saved to the blockchain. Optionally, the fourth DID identifier and the private key of the second data management console can also be added to the configuration information of the second data management console. By registering a DID for the second data management console, the authenticity and trustworthiness of the data management console's identity can be ensured, which in turn helps to ensure the authenticity and validity of the identity of the data user logged on to the data management console.
[0133] Specifically, the process of registering a DID for the second data management console is similar to that of registering a DID for the first data management console, as described above.
[0134] In some embodiments, the public key of the second object can be used to register a DID for the second object, and the fifth DID identifier of the second object and the corresponding fifth DID document can be saved to the blockchain. Optionally, the fifth DID identifier and the private key of the second object can also be saved locally. By registering a DID for the second object, the authenticity and validity of the data user's identity can be ensured.
[0135] Specifically, the process of registering a DID for the second object is similar to the process of registering a DID for the first object, as described above.
[0136] Optionally, the second object is the data user object, that is, the participant who wants to use the data provided by the data provider. Specifically, the second object logs into its account on the second data management console and applies to use the data; the data can only be obtained after approval.
[0137] In some embodiments, the second object can log in to the second data management console using a username and password. Optionally, when the administrator creates a user account for the second object on the second data management console, the second object can enter basic information such as a username, email address, and mobile phone number. Optionally, the second object can modify this basic information after logging into the data management console.
[0138] Afterwards, the data user, i.e., the second party, can request to use the data. Optional, see [link to relevant documentation]. Figure 4 The second object can obtain shared data through the following steps S410 to S440.
[0139] S410, the second data control console obtains the data usage request of the second object, which is used by the second object to request the use of the data corresponding to the first VC provided by the first object; and sends the data usage request to the blockchain.
[0140] For example, after a data user, i.e., a second object, finds data of interest, it can create a data usage request, i.e., send a data usage request to a second data management platform, requesting the use of data from a specific data catalog provided by a specific data provider, such as the data corresponding to the first VC provided by the first object mentioned above. Optionally, the data usage request can also be used to request the use of data from a specific database table or a specific data field within a specific data catalog. Afterwards, the data usage request is saved to the blockchain.
[0141] S420, the first data control console obtains data usage requests from the blockchain; and notifies the first object to approve data usage.
[0142] S430, the first data control console obtains the consent notification from the first object, and issues a second VC using the private key of the first object. The second VC is used by the first object to authorize the second object to use the data corresponding to the first VC; and the second VC is saved to the blockchain.
[0143] Specifically, approval of data usage requests can be achieved through steps S420 and S430.
[0144] In some implementations, the first data control console can subscribe to data target usage requests from the blockchain. If it is found that the data provider of the data usage request belongs to the current user of the first data control console, such as the first object, then the subsequent step S430 will be processed; otherwise, the data usage request will be discarded.
[0145] For example, in step S430, if the data usage request is for data of the first VC provided by the first object, the first data control console can notify the data provider, i.e., the first object, to approve it via event notification. In one implementation, the data provider, i.e., the first object, can see in the event center that the data user is a second object requesting data of the first VC provided by the first object. The first object can then express its agreement or refusal.
[0146] If the first object agrees to the second object's use of the data in the first VC, it can send a consent notification to the second data control console. In response to this consent notification, the second data control console issues a second VC using the first object's private key. This second VC is a data authorization VC, which can be used by the first object to authorize the second object to use the data corresponding to the first VC. Afterwards, the second VC is saved to the blockchain.
[0147] Optionally, the second VC may include the first DID identifier, the second object's DID identifier, and the corresponding database table fields of the data directory. This allows the second object to be authorized to use the corresponding database table fields of the first VC provided by the first object.
[0148] Optionally, the second view controller (VC) may not include the database table fields of the data target object. In this case, the second object can be authorized by default to use any database table fields provided by the first object in the first VC.
[0149] S440, the second data control console obtains the second VC from the blockchain; and sends the second VC to the second object.
[0150] Specifically, the second data control platform obtains the second VC from the blockchain and sends the second VC to the data user, i.e., the second object. Thus, the second object can hold the second VC and use the data corresponding to the first VC published by the data provider, i.e., the first object.
[0151] Therefore, in this embodiment of the application, after determining that the data sharing of the data provider is secure and trustworthy, the data usage application of the second object can be put on the blockchain and the approval of the data usage application can be triggered. Then, after the first object is approved, a second VC is issued to authorize the second object to use the data corresponding to the first VC, thereby ensuring that the data user can only obtain the data after the data provider's approval, thus ensuring the security and trustworthiness of data sharing.
[0152] The following, in conjunction with the appendix Figures 5 to 9 The overall flow of the data processing method provided in the embodiments of this application is described. Figures 5 to 9 The process consists of the following steps: system initialization, user object creation, data publishing, data application, and data approval.
[0153] It should be understood that Figures 5 to 9 The steps or operations of the data processing method are illustrated, but these steps or operations are merely examples. Other operations or variations of the operations shown in the figures may also be performed in the embodiments of this application. Furthermore, the steps in the figures may be performed in a different order than those presented in the figures, and it is not necessary to perform all the operations shown in the figures.
[0154] It should be understood that, Figures 5 to 9 In this context, administrators operate the data management console front-end (client or webpage), and the corresponding front-end responds by obtaining the corresponding input information. Similarly, data providers operate the data management console front-end (client or webpage), and the corresponding front-end responds by obtaining the corresponding input information. Data users operate the data management console front-end (client or webpage), and the corresponding front-end responds by obtaining the corresponding input information. The data management console can refer to its back-end. The back-end can provide various data management services. Blockchain resources, or blockchain resources, can include DID services and the blockchain itself.
[0155] Figure 5 A flowchart illustrating the system initialization process for the data control console is shown. For example... Figure 5 As shown, the system initialization process includes the following steps S501 to S512.
[0156] S501, the administrator creates a public / private key pair for the control console locally.
[0157] S502, the administrator uploads the public key to the DID service to register the DID.
[0158] S503, the DID service puts the DID identifier and DID document on the blockchain.
[0159] S504, the blockchain returns a response to the DID service.
[0160] S505, the DID service returns the DID identifier to the administrator.
[0161] Specifically, administrators can create a public-private key pair for the first data control console locally and offline to identify its identity. Administrators can then upload the public key of the first data control console to the DID service to register a DID for the console, obtaining a DID identifier. This DID identifier corresponds to a DID document. The DID document can contain the DID identifier, public key, server endpoint, authorization information, timestamp, etc. The most important information is the public key. For example, the DID identifier could be: did:tdid:c44:0x41537d38bb8d67025f960018f024d2b6435ea5a6. By uploading the DID identifier and DID document to the blockchain, the DID document will be publicly recorded on the blockchain.
[0162] S506, the administrator uses the DID service to set the DID of the management console as the authoritative organization.
[0163] S507, the DID service will put the DID of the control console onto the blockchain for authoritative institutions.
[0164] S508, the blockchain returns a response to the DID service.
[0165] S509, the DID service returns a response to the administrator.
[0166] Specifically, the administrator registers the DID of the first data management console as an authoritative institution on the DID service. The authoritative institution's DID can create DIDs for users under the institution, such as data providers.
[0167] S510: The administrator configures the control console DID and private key in the control console configuration file.
[0168] S511, First Data Control Console Started.
[0169] S512, the first data control console returns a response to the administrator.
[0170] It should be understood that Figure 5 The initialization of the data provider's control console (the first data control console) will be used as an example. The initialization process for the data user's control console (the second data control console) is similar and can be found by referring to [the example]. Figure 5 The relevant description in the document.
[0171] Therefore, this application embodiment can achieve system initialization of the data management console by registering the DID of the data management console, uploading the DID identifier and DID document to the blockchain, and registering the management console DID as an authoritative institution.
[0172] Figure 6 A schematic diagram illustrating the process of creating a user object is shown. Figure 6 As shown, the user object creation process includes the following steps S601 to S609.
[0173] S601, the administrator creates a user account.
[0174] Specifically, administrators can create platform user objects, which can be trusted participants in collaborative data sharing, such as data providers and data users, without limitation. For example, administrators can create regular users who fill in basic information such as username, email address, and mobile phone number. Optionally, this information can be modified after the user object logs in.
[0175] S602, the first data control console locally creates user public and private key pairs.
[0176] S603, the first data control console uploads the public key to the DID service to register the DID.
[0177] S604, the DID service puts the DID identifier and DID document on the blockchain.
[0178] S605, blockchain verification of authoritative institutions.
[0179] S606, the blockchain returns a response to the DID service.
[0180] S607, the DID service returns the DID identifier to the first data management console.
[0181] Specifically, the first data management platform creates a public-private key pair locally for the data provider to identify the data provider. The platform can then upload the data provider's public key to the DID service to register a DID for the data provider, obtaining a DID identifier. This DID identifier also corresponds to a DID document. Similarly, the data provider's DID and its DID document are also recorded on the blockchain.
[0182] Optionally, when the data provider's DID and its document are uploaded to the blockchain, the blockchain can check whether the request initiator (i.e., the first data control authority) is an authoritative body. If not, the blockchain will report an error. If so, the data provider's DID and its document can be successfully uploaded to the blockchain, and the DID identifier will be returned.
[0183] S608, the first data control console stores the DID and private key in the database.
[0184] S609, the first data control console returns a response to the administrator.
[0185] Specifically, the first data control console stores the data provider's DID identifier and private key in a local database. Optionally, the data provider's private key can be stored encrypted to ensure data security.
[0186] It should be understood that Figure 6 The process of creating a user account for a data provider using the first data management console as an example illustrates the user object creation process. The process of creating a user account for a data user using the second data management console is similar and can be found in the following example. Figure 6 The relevant description in the document.
[0187] Therefore, by registering DIDs for participants in trusted sharing collaboration and uploading their DID identifiers and DID documents to the blockchain, this application embodiment can achieve the creation of accounts for participants in trusted sharing collaboration.
[0188] Figure 7 This diagram illustrates the process by which a data provider publishes data. For example... Figure 7 As shown, the data publishing process includes the following steps S701 to S713.
[0189] S701, the data provider logs in to the platform using a username and password.
[0190] S702, the first data control console returns a response to the data provider.
[0191] Specifically, the data provider logs into the first data management console using a username and password. Optionally, the data provider can modify... Figure 6 The initial configuration information during creation.
[0192] S703, Data provider publishes data catalog.
[0193] S704, First Data Control Console creates data catalog.
[0194] For example, the first data control console can input the database configuration information of the data provider.
[0195] S705, the first data control console encrypts sensitive data.
[0196] For example, the database IP address, login username, and password can be encrypted.
[0197] S706, the first data control console uses the DID service to register DIDs for the data directory.
[0198] S707, the DID service puts the DID identifier and DID document on the blockchain.
[0199] S708, the blockchain returns a response to the DID service.
[0200] S709, the DID service returns the DID identifier to the first data management console.
[0201] Specifically, after logging into the First Data Management Console, data providers can publish data directories. The data directory contains descriptive information about the data source, including but not limited to the data source database server IP address, login username and password, database name, table name, table fields, types, and descriptions. The First Data Management Console will register a DID for the data directory, and the DID and its corresponding document will also be stored on the blockchain.
[0202] S710, the first data control console issues data catalog VC.
[0203] Specifically, the first data control console uses the data provider's private key to issue a data directory VC. The proof portion of the data directory VC contains data directory configuration information, while the proof portion contains the data provider's signature information. The data directory VC is an example of the first VC in the above embodiment.
[0204] S711, the first data management console puts the data catalog VC on the blockchain.
[0205] S712, the blockchain returns a response to the first data control console.
[0206] S713, the first data control console returns a response to the data provider.
[0207] Specifically, the first data control console uses the private key of the hosted data provider to issue a Data Target Verification (VC). The verification portion of this VC can include some or all of the information from the data directory, such as the IP address of the data source database server, the login username and password for the data source database, the database name, table names, table fields, types, and descriptions. The proof portion of the VC contains the data provider's signature information. Therefore, this data directory VC can prove that the data directory was indeed created and owned by the data provider.
[0208] Therefore, this application embodiment proves that the data directory was indeed created and owned by the data provider by registering the DID of the data directory published by the data provider and putting its DID identifier and DID document on the blockchain, and by publishing the data directory VC for the data directory. This enables the user identification and data ownership confirmation of the data provider, realizes the authenticity and validity of the data provider's identity, and ensures the security and trustworthiness of data sharing.
[0209] Figure 8 This diagram illustrates the process by which a data user requests data. Figure 8 As shown, the data application process includes the following steps S801 to S811.
[0210] S801, the second data management console subscribes to the published data catalog VC from the blockchain.
[0211] For example, the second data control console can subscribe to all published data catalogs (VCs) from the blockchain.
[0212] S802, the blockchain sends the data catalog VC to the second data control console.
[0213] For example, the blockchain can send all data catalogs (VCs) to a second data control console.
[0214] S803, the second data control console requests the DID document from the data provider from the DID service.
[0215] S804, the DID service returns a response to the second data control console. This response includes the DID document from the data provider.
[0216] S805, the second data control console verifies the signature of the target data VC.
[0217] Specifically, the second data control console can use the public key in the data provider's DID document to verify the signature of the data directory VC.
[0218] S806, the second data control console writes to the local database.
[0219] Specifically, if the verification passes, the second data management console will write the data directory VC to the local database so that data users can see which data providers provided which data.
[0220] If the validation fails, the data directory VC will be ignored and will not be recorded in the local database.
[0221] Steps S803 to S805 can be used to verify whether the data directory VC is published by the correct data provider.
[0222] Specifically, the second data control platform can obtain the DID document of the provider of the data directory VC from the blockchain, and verify the signature of the data directory VC using the public key in the DID document to confirm that the data directory was indeed created by the specified data provider. Furthermore, the second data control platform stores the correct and valid data directory VC in a local database, making it easier for data users to obtain the data they are interested in from the second data control platform.
[0223] S807, the data user creates a data usage application on the second data management console.
[0224] S808, the second data control console specifies the data to be retrieved from the data directory VC.
[0225] Specifically, the second data control console can specify which data directory in VC it wants to retrieve.
[0226] S809, the second data management platform will upload the data catalog usage application to the blockchain.
[0227] S810, the blockchain returns a response to the second data control console.
[0228] S811, the second data control console returns a response to the data user.
[0229] Specifically, after finding data of interest, a data user can create a data usage request on the second data control platform, specifying which data provider, data directory (VC), and data fields they wish to obtain. This data usage request is stored on the blockchain and triggers a contract event. This data usage request is an example of a data usage request in the above embodiments.
[0230] Therefore, in this embodiment of the application, by obtaining the public key of the data provider based on the DID document of the data provider, and then verifying the signature of the data directory VC based on the public key, it is possible to determine the authenticity and validity of the data provider's identity and the security and trustworthiness of data sharing, and then the data user can apply for the use of the data directory.
[0231] Figure 9 This diagram illustrates the data provider's approval process. Figure 9 As shown, the data application process includes the following steps S901 to S910.
[0232] S901, Subscription to on-chain data directory usage application.
[0233] S902, if the data provider is not the current control console user, then discard it.
[0234] S903: If the data provider is the current control console user, the data will be entered into the local database.
[0235] Steps S901 to S903 enable the detection of data usage application events on the blockchain. Specifically, the first data control console can subscribe to data catalog usage applications from the chain. If it finds that the data provider of the data catalog application belongs to a user of the current data control console, further processing is performed. Otherwise, the application is discarded.
[0236] S904, the first data control console notifies the data provider.
[0237] For example, the first data control console can notify the data provider of pending events.
[0238] S905, Data provider approves usage application.
[0239] S906, Agree / Reject.
[0240] Specifically, if the data provider requesting the data target is a user of the current data management console, the data provider will be notified via event notification for approval. For example, the data provider can see in the event center who the data user is, which database table and which fields from which data directory are being requested, etc. The data provider can then express their approval or rejection.
[0241] S907, if agreed, then create a data license using VC.
[0242] For example, the first data management console can create a data authorization VC and issue the data catalog DID and the data user's DID information to the VC. For example, the data authorization VC may include information such as the data catalog DID, data request table fields, and the data user's DID.
[0243] If the data provider refuses, the data catalog application fails and can be marked as failed directly on the blockchain.
[0244] S908, the first data management platform will authorize the use of VC to put data on the blockchain.
[0245] S909, the blockchain returns a response to the first data control console.
[0246] Approval events can be processed through steps S904 to S909.
[0247] S910, the first data control console returns a response to the data provider.
[0248] Subsequent data users can hold this VC to use the data corresponding to the data provider's data directory.
[0249] Therefore, this application embodiment puts the data usage application of the second object on the blockchain and triggers the data provider to approve the data usage application. After the approval is passed, an authorization VC for authorizing the data user to use the data catalog VC is issued, thereby ensuring that the data user can only obtain the data after the data provider's approval, thus ensuring the security and trustworthiness of data sharing.
[0250] In summary, the embodiments of this application can utilize blockchain-based DID to construct a digital identity system, providing DID identities for trusted data providers and users, enabling user identification and data ownership verification during multi-party collaboration, ensuring the authenticity and validity of the participants' identities, and ensuring the security and trustworthiness of data sharing.
[0251] The specific embodiments of this application have been described in detail above with reference to the accompanying drawings. However, this application is not limited to the specific details of the above embodiments. Within the scope of the technical concept of this application, various simple modifications can be made to the technical solutions of this application, and these simple modifications all fall within the protection scope of this application. For example, the various specific technical features described in the above embodiments can be combined in any suitable manner without contradiction. To avoid unnecessary repetition, this application will not describe the various possible combinations separately. Furthermore, various different embodiments of this application can also be arbitrarily combined, as long as they do not violate the spirit of this application, they should also be considered as the content disclosed in this application.
[0252] It should also be understood that, in the various method embodiments of this application, the sequence numbers of the above processes do not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. It should be understood that these sequence numbers can be interchanged where appropriate so that the embodiments of this application described can be implemented in a sequence other than those illustrated or described.
[0253] The method embodiments of this application have been described in detail above. The following description, in conjunction with... Figures 8 to 10 The following describes in detail the device embodiments of this application.
[0254] Figure 10 This is a schematic block diagram of the data processing apparatus 10 according to an embodiment of this application. Figure 10 As shown, the device 10 may include: an acquisition unit 11, a registration unit 12, an on-chain unit 13, and an issuance unit 14.
[0255] The acquisition unit 11 is used to acquire the data directory published by the first object, the data directory including the description information of the data source provided by the first object;
[0256] Registration unit 12 is used to register a decentralized identity (DID) for the first object using the public key of the first object;
[0257] On-chain unit 13 is used to save the first DID identifier of the first object and the corresponding first DID document to the blockchain;
[0258] The registration unit 12 is also used to register a DID for the data directory;
[0259] The on-chain unit 13 is also used to save the second DID identifier and the corresponding second DID document of the data directory to the blockchain;
[0260] Issuance unit 14 is used to issue a first verifiable declaration (VC) of the data directory using the private key of the first object; the first VC is used to determine that the data directory was created and owned by the first object;
[0261] The on-chain unit 13 is also used to save the first VC to the blockchain.
[0262] Optionally, the acquisition unit 11 is also used for:
[0263] A data usage request is obtained from the blockchain, the data usage request being used to request the use of the data corresponding to the first VC provided by the first object;
[0264] The data processing device 10 also includes a notification unit for notifying the first object to undergo data usage approval.
[0265] Optionally, the acquisition unit 11 is also used for:
[0266] Obtain the consent notification from the first object and issue a second VC using the private key of the first object. The second VC is used by the first object to authorize the second object to use the data corresponding to the first VC.
[0267] On-chain unit 13 is also used to save the second VC to the blockchain.
[0268] Optionally, the second VC includes the first DID identifier, the DID identifier of the second object, and the database table field corresponding to the data directory.
[0269] Optionally, the first VC includes some or all of the information of the data directory and the signature information of the first object.
[0270] Optionally, the data directory includes at least one of the following: data source database server address information, login account name and password for the data source database, database name, data table name, and data table fields / types / descriptions.
[0271] Optionally, registration unit 12 is also used for:
[0272] Using the public key of the first data control platform, a DID is registered for the first data control platform, and the third DID identifier and the corresponding third DID document of the first data control platform are saved to the blockchain; wherein, the first object publishes the data directory by logging into the account on the first data control platform;
[0273] The data processing device 10 also includes a storage unit for adding the third DID identifier and the private key of the first data control console to the configuration information of the first data control console.
[0274] It should be understood that the device embodiments and method embodiments can correspond to each other, and similar descriptions can be referred to the method embodiments. To avoid repetition, further details will not be provided here. Specifically, Figure 10 The device shown can perform Figure 3 The method executed by the first data control console in the illustrated embodiment, and the aforementioned and other operations and / or functions of each module in the device are respectively for implementing the corresponding process in the above method, will not be described in detail here for the sake of brevity.
[0275] Figure 11 This is a schematic block diagram of the data processing apparatus 20 according to an embodiment of this application. Figure 11 As shown, the device 20 may include an acquisition unit 21 and a verification unit 22.
[0276] The acquisition unit 21 is used to acquire a first verifiable declaration (VC) of a data directory from the blockchain. The first VC is used to determine that the data directory was created and owned by a first object. The data directory is published by the first object and includes descriptive information of the data source provided by the first object.
[0277] The acquisition unit 21 is further configured to acquire the first decentralized identity (DID) document of the first object from the blockchain;
[0278] The verification unit 22 is also used to verify the signature information of the first VC using the public key in the first DID document.
[0279] Optionally, the acquisition unit 21 is also used for:
[0280] Obtain a data usage request from a second object, wherein the data usage request is used by the second object to request the use of the data corresponding to the first VC provided by the first object;
[0281] Device 20 also includes an on-chain unit for sending the data usage request to the blockchain.
[0282] Optionally, the acquisition unit 22 is also used for:
[0283] A second VC is obtained from the blockchain, and the second VC is used by the first object to authorize the second object to use the data corresponding to the first VC;
[0284] Send the second VC to the second object.
[0285] Optionally, the device 20 also includes a registration unit for:
[0286] Using the public key of the second data control station, a DID is registered for the second data control station, and the fourth DID identifier and the corresponding fourth DID document of the second data control station are saved to the blockchain; wherein, the second data control station subscribes to the data directory VC;
[0287] The device 20 also includes a storage unit for adding the fourth DID identifier and the private key of the second data control console to the configuration information of the second data control console.
[0288] Optionally, the registration unit is also used to register a DID for the second object using the public key of the second object, and save the fifth DID identifier of the second object and the corresponding fifth DID document to the blockchain;
[0289] The storage unit is also used to save the fifth DID identifier and the private key of the second object to the local storage.
[0290] It should be understood that the device embodiments and method embodiments can correspond to each other, and similar descriptions can be referred to the method embodiments. To avoid repetition, further details will not be provided here. Specifically, Figure 10 The device shown can perform Figure 3 The method executed by the second data control console in the illustrated embodiment, and the aforementioned and other operations and / or functions of each module in the device are respectively for implementing the corresponding process in the above method, will not be described in detail here for the sake of brevity.
[0291] The apparatus and system of this application embodiments have been described above from the perspective of functional modules in conjunction with the accompanying drawings. It should be understood that these functional modules can be implemented in hardware, in software instructions, or in a combination of hardware and software modules. Specifically, the steps of the method embodiments in this application can be completed by integrated logic circuits in the processor's hardware and / or by software instructions. The steps of the methods disclosed in this application embodiments can be directly embodied as being executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. Optionally, the software module can reside in a mature storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps in the above method embodiments.
[0292] Figure 12 This is a schematic block diagram of the electronic device 30 provided in the embodiments of this application.
[0293] like Figure 12 As shown, the electronic device 30 may include:
[0294] The system includes a memory 31 and a processor 32. The memory 31 stores computer programs and transfers the program code to the processor 32. In other words, the processor 32 can retrieve and run the computer programs from the memory 31 to implement the methods described in the embodiments of this application.
[0295] For example, the processor 32 can be used to execute the above-described method embodiments according to instructions in the computer program. For example, the processor can execute a data processing method, including:
[0296] Obtain the data directory published by the first object, the data directory including the description information of the data source provided by the first object;
[0297] Using the public key of the first object, a decentralized identity DID is registered for the first object, and the first DID identifier of the first object and the corresponding first DID document are saved to the blockchain;
[0298] Register a DID for the data directory, and save the second DID identifier and the corresponding second DID document of the data directory to the blockchain;
[0299] The first verifiable declaration (VC) of the data directory is issued using the private key of the first object, and the first VC is saved to the blockchain; the first VC is used to determine that the data directory was created and owned by the first object.
[0300] For example, a processor can execute a data processing method, including:
[0301] A first verifiable claim (VC) is obtained from the blockchain for a data directory, the first VC being used to determine that the data directory was created and owned by a first object; wherein the data directory is published by the first object and includes descriptive information about the data source provided by the first object;
[0302] Obtain the first decentralized identity (DID) document of the first object from the blockchain, and use the public key in the first DID document to verify the signature information of the first VC.
[0303] In some embodiments of this application, the processor 32 may include, but is not limited to:
[0304] General-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0305] In some embodiments of this application, the memory 31 includes, but is not limited to:
[0306] Volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).
[0307] In some embodiments of this application, the computer program may be divided into one or more modules, which are stored in the memory 31 and executed by the processor 32 to perform the method provided in this application. The one or more modules may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the electronic device.
[0308] like Figure 12 As shown, the electronic device 30 may further include:
[0309] Transceiver 33, which can be connected to processor 32 or memory 31.
[0310] The processor 32 can control the transceiver 33 to communicate with other devices; specifically, it can send information or data to other devices or receive information or data sent by other devices. The transceiver 33 may include a transmitter and a receiver. The transceiver 33 may further include antennas, and the number of antennas may be one or more.
[0311] It should be understood that the various components in the electronic device are connected through a bus system, which includes a data bus, a power bus, a control bus, and a status signal bus.
[0312] According to one aspect of this application, a computer storage medium is provided that stores a computer program thereon, which, when executed by a computer, enables the computer to perform the methods of the above-described method embodiments. Alternatively, embodiments of this application also provide a computer program product containing instructions that, when executed by a computer, cause the computer to perform the methods of the above-described method embodiments.
[0313] According to another aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method described in the above-described method embodiments.
[0314] In other words, when implemented using software, it can be implemented wholly or partially in the form of a computer program product. This computer program product includes one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., digital video disc (DVD)), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0315] It is understood that specific embodiments of this application may involve user information and other related data. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions.
[0316] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0317] In the several embodiments provided in this application, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or modules may be electrical, mechanical, or other forms.
[0318] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. For example, the functional modules in the various embodiments of this application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.
[0319] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A data processing method, characterized in that, include: Obtain the data directory published by the first object, the data directory including the description information of the data source provided by the first object; Using the public key of the first object, register a decentralized identity DID for the first object, and save the first DID identifier of the first object and the corresponding first DID document to the blockchain; Register a DID for the data directory, and save the second DID identifier and the corresponding second DID document of the data directory to the blockchain; A first verifiable declaration (VC) for the data directory is issued using the private key of the first object, and the first VC is saved to the blockchain; The first VC is used to determine that the data directory was created and owned by the first object.
2. The method according to claim 1, characterized in that, Also includes: A data usage request is obtained from the blockchain, the data usage request being used to request the use of the data corresponding to the first VC provided by the first object; The first object is notified to undergo data usage approval.
3. The method according to claim 2, characterized in that, Also includes: Obtain the consent notification from the first object and issue a second VC using the private key of the first object. The second VC is used by the first object to authorize the second object to use the data corresponding to the first VC. Save the second VC to the blockchain.
4. The method according to claim 3, characterized in that, The second VC includes the first DID identifier, the second object's DID identifier, and the database table field corresponding to the data directory.
5. The method according to any one of claims 1-4, characterized in that, The first VC includes some or all of the information of the data directory and the signature information of the first object.
6. The method according to any one of claims 1-4, characterized in that, Also includes: Using the public key of the first data control platform, a DID is registered for the first data control platform, and the third DID identifier and the corresponding third DID document of the first data control platform are saved to the blockchain; wherein, the first object publishes the data directory by logging into the account on the first data control platform; Add the third DID identifier and the private key of the first data management console to the configuration information of the first data management console.
7. A data processing method, characterized in that, include: A first verifiable claim (VC) is obtained from the blockchain for a data directory, the first VC being used to determine that the data directory was created and owned by a first object; wherein the data directory is published by the first object and includes descriptive information about the data source provided by the first object; Obtain the first decentralized identity (DID) document of the first object from the blockchain, and use the public key in the first DID document to verify the signature information of the first VC.
8. The method according to claim 7, characterized in that, Also includes: Obtain a data usage request from a second object, wherein the data usage request is used by the second object to request the use of the data corresponding to the first VC provided by the first object; Send the data usage request to the blockchain.
9. The method according to claim 8, characterized in that, Also includes: A second VC is obtained from the blockchain, and the second VC is used by the first object to authorize the second object to use the data corresponding to the first VC; Send the second VC to the second object.
10. The method according to any one of claims 7-9, characterized in that, Also includes: Using the public key of the second data control station, a DID is registered for the second data control station, and the fourth DID identifier and the corresponding fourth DID document of the second data control station are saved to the blockchain; wherein, the second data control station subscribes to the data directory VC; Add the fourth DID identifier and the private key of the second data management console to the configuration information of the second data management console.
11. A data processing apparatus, characterized in that, include: The acquisition unit is used to acquire the data directory published by the first object, wherein the data directory includes description information of the data source provided by the first object; The registration unit is used to register a decentralized identity (DID) for the first object using the public key of the first object; The on-chain unit is used to save the first DID identifier of the first object and the corresponding first DID document to the blockchain; The registration unit is also used to register a DID for the data directory; The on-chain unit is also used to save the second DID identifier and the corresponding second DID document of the data directory to the blockchain; The issuing unit is configured to issue a first verifiable declaration (VC) of the data directory using the private key of the first object. The first VC is used to determine that the data directory was created and owned by the first object; The on-chain unit is also used to save the first VC to the blockchain.
12. A data processing apparatus, characterized in that, include: An acquisition unit is used to acquire a first verifiable declaration (VC) of a data directory from the blockchain. The first VC is used to determine that the data directory was created and owned by a first object. The data directory is published by the first object and includes descriptive information of a data source provided by the first object. The acquisition unit is further configured to acquire the first decentralized identity (DID) document of the first object from the blockchain; The verification unit is also used to verify the signature information of the first VC using the public key in the first DID document.
13. An electronic device, characterized in that, include: A processor and a memory, the memory being used to store a computer program, the processor being used to invoke and run the computer program stored in the memory to perform the method according to any one of claims 1-10.
14. A computer storage medium, characterized in that, Used to store a computer program that causes a computer to perform the method as described in any one of claims 1-10.
15. A computer program product, characterized in that, It includes computer program code that, when executed by an electronic device, causes the electronic device to perform the method of any one of claims 1-10.