Methods, devices, and servers for managing personal data
By storing personal data on a blockchain with user-specific cryptographic data, the method addresses the loss of user control and data portability issues, ensuring data immutability and secure access across environments.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-12-22
- Publication Date
- 2026-03-25
AI Technical Summary
Users lose control over their personal data as it is managed by service providers, making it difficult to identify what is being done with their data, and there is a lack of data portability across different environments.
A method and system that stores users' personal data on a blockchain, associating it with user-specific cryptographic data such as dynamic non-fungible tokens or public keys, enabling data immutability and portability, and allows for secure data management and contract execution in a digital trust environment.
Guarantees user ownership of personal data history, ensures data immutability and portability, and facilitates secure data access and contract execution without disclosing personal information, enhancing user control and privacy.
Smart Images

Figure 2026053532000001_ABST
Abstract
Description
[Technical Field]
[0001] This invention relates to the general field of protecting and managing users' personal data in communication networks.
[0002] In this specification, the "concept of personal data" should be understood in a broad sense, referring to any data that a user wishes to continue to control.
[0003] As non-limiting examples, personal data in the sense of the present invention includes the identity or address of a natural person, data based on banking transactions conducted by a natural person or legal entity, messages exchanged on a communication network, geographical location data of an individual, photographs or videos taken by an individual or received from a third party, or digital contracts. [Background technology]
[0004] With current technology, users' personal data is generally managed by the service provider to which the user subscribes.
[0005] For example, for a user who has both a bank account and a social network account, it is common to provide personal data to the banking organization and also to the operator of the social network.
[0006] Therefore, users lose control over their personal data (Il en resulte que l'utilisateur perd la maitrise de ses donnees personnelles). This is because it is extremely difficult for users to identify what is being done to their data by the service provider. [Overview of the project]
[0007] According to the first aspect, the present invention relates to a method for building a history of a user's personal data, the method being performed by the user's terminal, and comprising: - The process for obtaining the symmetric encryption key associated with the user's profile; - The process for collecting users' personal data; -In the process of collecting the above personal data of the user: (i) the process of encrypting the personal data with the user's symmetric encryption key; and (ii) A step of recording a plurality of blocks containing the above-mentioned encrypted data in a general database, wherein the plurality of blocks are organized based on a blockchain constituting a subgraph of a general graph, the topology of the general graph is defined by a pre-constructed data model, and the root block of the subgraph is associated with encrypted data unique to this user.
[0008] A second aspect of the present invention relates to a management method performed by a computer system for managing the personal data of multiple users, the method comprising managing a comprehensive database in which multiple blocks are recorded, each block comprising the encrypted personal data of one of the above users, the multiple blocks comprising the encrypted personal data of the same user, organized on a blockchain that constitutes a subgraph of the same comprehensive graph, the topology of the comprehensive graph being defined by a pre-built data model, and the root block of the subgraph being associated with the encrypted data unique to this user.
[0009] In one embodiment, the cryptographic data associated with a user is the user's dynamic, non-fungible token.
[0010] In another embodiment, the cryptographic data associated with a user is the public key of that user's digital wallet.
[0011] Thus, generally speaking, the present invention proposes storing a user's personal data history on a blockchain and associating (d'associer) the personal data history with cryptographic data unique to this one user. The cryptographic data is, for example, this user's dynamic non-fungible token or the public key of a digital wallet held by this user. In the sense of the present invention, the user may be a natural person or a legal entity.
[0012] In the following, "digital wallet" means a hardware or software device for securely storing and managing digital files in a broad sense, and digital files such as units of cryptocurrency and / or non-fungible tokens, uniquely associated with a single user. In this regard, a digital wallet has a public key associated with the user. Such a digital wallet enables electronic transactions with other parties, for example, by exchanging units of cryptocurrency.
[0013] Thus, according to the present invention, user-specific cryptographic data, such as a dynamic non-fungible token or the public key of a digital wallet, points to an input node in a graph representing the history of this user's (or user's) personal data, based on a mapping (cartographie) defined by a pre-constructed data model.
[0014] By associating all personal data with a block graph, its probative value (valeur probante) can guarantee the immutability of the data's history. Furthermore, if the cryptographic data is a dynamic, non-fungible token, the present invention guarantees that the user will remain the owner of all their past and future personal data by incorporating the personal data into the blockchain.
[0015] Furthermore, by associating all of a user's personal data with user-specific encrypted data, users can achieve data portability across different environments, significantly simplifying their access to new services.
[0016] In fact, if user information (une connaissance d'un utilisateur) (KYC, "Know Your Customer") is obtained for a first service (e.g., opening a bank account) by verifying this user's documents associated with cryptographic data (dynamic non-fungible tokens, public keys of a digital wallet) in a first environment (e.g., verification of identity, qualifications, eligibility, etc.), and the certificate resulting from this verification is incorporated into the data associated with this cryptographic data, then in a second environment, by obtaining this cryptographic data, it becomes possible to directly assign this user rights for a second service (e.g., vehicle reservation) without having to perform verification of this user's documents again.
[0017] This invention proposes using user-specific cryptographic data as an element to prove the user's identity. If the cryptographic data is a non-fungible token, this data also exhibits the properties of being non-repudiable and non-forgery. The non-fungibility of the token also ensures that this document of ownership (unlike, for example, a digital signature) cannot be copied or used without the user's knowledge.
[0018] In this invention, by using user-specific cryptographic data (non-fungible tokens, public keys of digital wallets), it becomes possible to track the actions of a natural person or legal entity regardless of the environment. For example, if certain cryptographic data, particularly a non-fungible token, is held by a news organization (legal entity), and digital content created by this news organization is recorded in a composite graph associated with this cryptographic data, it becomes very easy to prove, from any environment, that one of the digital contents originates from this news organization.
[0019] In the implementation example, a certificate of ownership, consisting of user-specific cryptographic data, can be explicitly managed using the identifiable identity of the user, whether a natural person or legal entity, or managed completely anonymously. The user can anonymously transmit digital information linked to (relieved by) the cryptographic data (non-fungible tokens, digital wallet public keys, etc.), while a third party can verify that this information is indeed associated with the cryptographic data.
[0020] In one embodiment, the blockchain is a distributed ledger in a peer network, a terminal is a peer in the network configured to locally store at least a portion of the subgraph, and the multiple blocks are stored in the terminal's local database.
[0021] The creation and retrieval of this user's personal data history by the user's device can be performed asynchronously, without a network connection, and can be resynchronized without compromising the functionality or security of the solution.
[0022] In one embodiment, the data model defines how the branches of the subgraph comprise a plurality of blocks having encrypted personal data corresponding to the detected, time-stamped geolocation data of the moving terminal.
[0023] In this embodiment of the present invention, the user's terminal detects movement. When a new movement is detected, a new branch is created in the user's subgraph, and a blockchain containing encrypted, timestamped geolocation data is incorporated into the branch in accordance with the movement (au fur et a mesure du deplacement). The branch stops when it is detected that the terminal's location has not changed for a predetermined period of time.
[0024] In one embodiment, the data model defines how multiple blocks of encrypted personal data corresponding to the digital activity of a device on a given date or to data received from a third party on a given date are linked (est attache) in a user's subgraph to a single block of encrypted personal data corresponding to the geolocation data of the device, timestamped on that date.
[0025] Advantageously, this embodiment makes it possible to permit the date and location of all of the user's digital actions. For example, this embodiment makes it possible to ensure that a photograph taken by the user's device was taken on a certain date while the device was at a certain location.
[0026] In certain embodiments of the present invention, personal geolocation data can be associated with an element that proves the presence of a terminal at a certain location at a given time, the proof element being a signed proof element supplied by a telecommunications carrier which can verify such proof element by, for example, birthage.
[0027] In one embodiment, a method for constructing a user's personal data comprises the step of incorporating a digital contract to which the user is a party into a subgraph of the user, the contract being encrypted with the public key of the user's device, the public key of at least one other party to the contract, and the public key of a digital trust environment, the contract comprising at least the following: - The user's symmetric encryption key encrypted with the public key of the digital trust environment; and -Instructions for the following, which can be executed by the above digital trust environment: (i) Decrypt at least a portion of the user's personal data using a symmetric encryption key; (ii) Verify that the cryptographic data unique to the user associated with the root block of the subgraph belongs to the user; (iii) Analyze the decrypted personal data above (analyser lesdites personnelles dechiffrees); and (iv) Provide the results of the above analysis to at least one party to the contract.
[0028] In this embodiment of the present invention, a method for managing the personal data of multiple users comprises a step for managing a set of instances of a digital trust environment, one of which is configured to perform the following: -Execute an order stipulated in a digital contract to analyze a portion of the personal data of at least one of the above users who is a party to the contract, wherein the contract comprises a symmetric encryption key of the at least one party to the contract, encrypted with the public key of the above instance of the digital trust environment, the symmetric encryption key is capable of being used by the above instance to decrypt the above personal data to be analyzed; - Provide the results of the above analysis to at least one party to the contract.
[0029] In this respect, the present invention proposes that contracts that analyze a user's personal data are concluded in a trusted environment rather than on the terminals of the parties to the contract, so as not to disclose the personal data of the parties to the contract. Conclusion in a trusted environment is also known to those skilled in the art as "confidential computing."
[0030] In a preferred embodiment, the above contracts incorporate delegations of access rights to encrypted personal data for exclusive use by a trusted environment in which such data is analyzed, and this trusted environment is configured to decrypt and analyze all or part of the personal data of the parties to the contract and to transmit the results of the analysis to one or more parties to the contract.
[0031] Embodiments of the present invention advantageously enable the conclusion of contracts between parties in heterogeneous environments. In particular, the present invention enables the portability of user data in the metaverse, including the conclusion of digital contracts that require the analysis of the personal data of the parties to the contract in the metaverse, while protecting said personal data.
[0032] In one embodiment, if user-specific cryptographic data is a dynamic non-fungible token, a method for constructing a history of personal data comprises the steps of generating at least one second dynamic non-fungible token relating to the user, and associating the subgraph of the subgraph with the second dynamic non-fungible token.
[0033] A user who possesses a dynamic, non-fungible token linked to the root of a subgraph containing their personal data history can generate tokens that point to a part of this subgraph, such as a branch of that subgraph.
[0034] This feature allows users to selectively use portions of their history, which is advantageous.
[0035] The present invention also relates to a terminal having a processor configured to perform the following: - The process for obtaining the symmetric encryption key associated with the user's profile; - The process for collecting users' personal data; and -When collecting the above personal data of users: (i) the process of encrypting the personal data with the user's symmetric encryption key; and (ii) A step of recording a plurality of blocks containing the above-mentioned encrypted data in an integrated database, wherein the plurality of blocks are organized based on blockchains that constitute a subgraph of the integrated graph, the topology of the integrated graph is defined by a pre-constructed data model, and the root block of the subgraph is associated with cryptographic data unique to this user (dynamic non-fungible token, public key of digital wallet).
[0036] The present invention also relates to a server for managing the personal data of multiple users, the server comprising a processor configured to manage an integrated database on which multiple blocks are recorded, each block comprising encrypted personal data of a user, and multiple blocks comprising encrypted personal data of the same user, organized on a blockchain that constitutes a subgraph of the same integrated graph, the topology of the integrated graph being defined by a pre-built data model, and the root block of the subgraph being associated with the encrypted data unique to that user.
[0037] The integrated database used in the present invention may be centralized (for example, managed by a server for managing personal data) or distributed.
[0038] The present invention also relates to a computer program on a recording medium that is executable on a computer. This program comprises instructions adapted to perform the method for constructing the history of personal data described above.
[0039] The present invention also relates to a computer program on a recording medium executable by a computer. The program comprises instructions adapted to perform a method for managing a set of personal data of a user as described above.
[0040] Each of these programs may use any programming language and may be in the form of source code, object code, or an intermediate form of code between source code and object code, such as a partially compiled form, or any other desired form.
[0041] The present invention also relates to a computer-readable information medium or recording medium comprising instructions for a first computer program, a second computer program, or a third computer program, as described above.
[0042] The information medium or recording medium may be any entity or device capable of storing a program. For example, the medium may include a ROM such as a CD-ROM or microelectronic circuit ROM, a recording medium such as a hard disk, or a magnetic recording medium such as flash memory.
[0043] On the other hand, the information medium or recording medium may be a transmissible medium such as an electrical signal or an optical signal, and this transmissible medium may be transmitted via an electrical cable or an optical cable, by a wireless link, by a wireless optical link, or by other means.
[0044] In particular, programs based on the present invention can be downloaded from an internet-type network.
[0045] Alternatively, each information medium or recording medium may be an integrated circuit into which a program is incorporated and adapted to perform or be used to perform one of the methods according to the present invention.
[0046] Other features and advantages of the present invention will become apparent from the following description with reference to the accompanying drawings illustrating non-limiting and exemplary embodiments. [Brief explanation of the drawing]
[0047] [Figure 1] Figure 1 shows an instance of a terminal, a server for managing personal data, and a digital trust environment that can be used in a particular embodiment of the present invention. [Figure 2A] Figure 2A shows a comprehensive graph that can be implemented in a specific embodiment of the present invention. [Figure 2B] Figure 2B shows a subgraph of the overall graph in Figure 2A. [Figure 3A] Figure 3A shows the contract proposal prepared by the first party. [Figure 3B] Figure 3B shows the contract that was created after the second party accepted the contract proposal in Figure 3A. [Figure 4]Figure 4 shows the creation of a user account in a specific embodiment of the present invention. [Figure 5] Figure 5 shows the main steps taken to build a history of a user's personal data. [Figure 6] Figure 6 shows the main steps taken by the user's terminal to access this user's personal data. [Figure 7] Figure 7 shows the main steps taken to create a contract. [Figure 8] Figure 8 shows the main steps taken to conclude a contract. [Figure 9] Figure 9 shows the hardware architecture of a terminal based on a specific embodiment of the present invention. [Figure 10] Figure 10 shows the hardware architecture of a server based on a specific embodiment of the present invention. [Modes for carrying out the invention]
[0048] Figure 1 shows User A's terminal T. A , service provider SP's terminal T SP , a server SDP for managing the personal data of multiple users, and multiple instances of a digital trust environment ECN ECN i This refers to a network interconnected by a communication network called NET.
[0049] In the embodiments described herein, the server SDP for managing personal data is configured to provide the following: -Personal data history data service HIST; and - The GES-CONT service for managing digital contracts using all or part of the said personal data.
[0050] As detailed below, the personal data history data service HIST enables users who subscribe to this service to construct and maintain their personal data history from their mobile devices. By associating this history with a dynamic, non-fungible token that is the user's property, proof-of-value is given to this history, and its portability is guaranteed.
[0051] The GES-CONT service for managing contracts enables the conclusion of digital contracts between at least two parties in a digital trust environment (ECN) without disclosing the personal data of those parties. In this regard, and as will be described later, the digital contracts managed by the present invention incorporate a delegation of access rights to the user's personal data, specifically for use in a digital trust environment (ECN).
[0052] In the embodiments described herein, the server SDP for managing personal data also includes a module GES-ECN for managing this digital trust environment ECN.
[0053] This digital trust environment (ECN) constitutes a "Trusted Execution Environment" in which contracts can be entered into between two or more parties (such as users, service providers, or other individuals or legal entities).
[0054] In the embodiments described herein, the GES-ECN module for managing the digital trust environment of the server SDP for managing personal data has a variable number of instance ECNs depending on the number of contracts to be concluded. i ECN j It is configured to be managed dynamically within the network (administrator dynamiquement).
[0055] In the embodiment described herein, the above instance ECN of the digital trust environment i , ECN j is cloned by the module GES-ECN. All of these cloned instances have the same module EXEC-CONT for concluding contracts and a public key KPUB ECN stored in the rewritable non-volatile memory M ECN and an associated private key KPRIV ECN and have the same key pair.
[0056] In the example described herein, the terminal T A is a mobile phone.
[0057] In this example, the user A has downloaded and installed the application APP on his own terminal T A from the server SDP for managing personal data (aupres du serveur SDP). With this application, the user A can access the services provided by the server, particularly the historical data service HIST of personal data and the GES-CONT service for managing digital contracts (acceder).
[0058] The application APP includes a cryptographic module MCY.
[0059] In the embodiment described herein, the application APP also includes a GEN-CONT module for generating contracts. With the GEN-CONT module, the user of the terminal T A can create contracts (de former avec une ou plusieurs autres parties des contrats) with one or more other parties intended to be concluded in the digital trust environment ECN. The above process will be described in detail later with reference to FIG. 7.
[0060] Figure 1 shows terminal T after user A has opened an account via the server SDP for managing personal data and subscribed to the HIST service for the history of their personal data. A This indicates that you need terminal T to open this account. A Steps E40-E45, performed by this process, will be described later with reference to Figure 4. After this account is opened, in this example, terminal T A Rewritable non-volatile memory M A It includes the following: - An identifier LOG / MP (login name, password) that allows user A to access their account via the local application APP; -Private key KPRIV A and public key KPUB A A key pair equipped with; - Symmetric encryption key KS A and -un identifiant unique confidential ID A .
[0061] In the embodiment described herein, terminal T A is terminal T A It includes a module MDD for detecting movement.
[0062] In this example, the MDD module for detecting movement comprises artificial intelligence IA, a GPS geolocation module, and a movement detector MVT, where the movement detector MVT is, for example, a terminal T A It is equipped with an accelerometer and a gyroscope sensor for measuring linear acceleration, attitude, and angular velocity.
[0063] The MDD module for detecting this movement uses User A's timestamped personal geolocation data DP. GEO A It is configured to generate data on the date T i In the real world, terminal T A The location P where this exists i It is equipped with.
[0064] In the embodiment described herein, terminal T A It also includes a camera (CAM) and a payment application (PAY). Photographs taken by the camera (CAM) and transactions performed using the application (PAY) represent the digital actions performed by User A, and User A's personal data (DP) represents User A. DigAct A This shall constitute the following. Other digital operations are also possible, and other digital operations, although not shown in the diagram, include, for example, terminal T A This refers to sending or receiving messages (such as emails or short messages) using messaging applications.
[0065] In the embodiment described herein, terminal T A Personal data (DP) obtained from third parties, such as management services, banks, insurance companies, and commercial organizations. 3rdP A It is configured to manage.
[0066] Generally, User A's personal data is used in DP. A This is how it is written. Data DP A To illustrate in a non-limiting manner, personal geolocation data DP is an example. GEO A , personal data representing digital actions DP DigAct A , and personal data obtained from third parties DP 3rdP A It is equipped with.
[0067] In the embodiment described herein, the server SDP is a centralized integrated database BD C It is equipped with a centralized comprehensive database BD. C This service stores a history of encrypted personal data for all users who have subscribed to the HIST service.
[0068] In the embodiments described herein, encrypted personal data of multiple users is organized based on an n-dimensional blockchain.
[0069] In the embodiments described herein, this n-dimensional blockchain is a general directed acyclic graph (graphe acyclique direct general) G C It takes the form of a composite directed acyclic graph G. C The topology is determined by a pre-built data model, which will be described later with reference to Figures 2A and 2B.
[0070] This blockchain constitutes a distributed ledger that can be updated within a peer network.
[0071] In the embodiment described herein, the user's terminal is a peer in this network. Here, the user has subscribed to the Historical Data Service (HIST) for their personal data. For example, terminal T A It keeps the following locally: - A local database BD containing the user's own encrypted personal data A and - User's own encrypted personal data DP A Comprehensive graph G with history C Subgraph SG A A copy of (of).
[0072] Therefore, terminal T A This can operate without a network connection and asynchronously by exploiting graph ownership.
[0073] Thus, in the embodiment described here, and as will be discussed later with reference to Figure 5, new personal data DP to be recorded is also recorded. A to terminal T A When detected, personal data DPA is terminal T A Encrypted by the MCY encryption module, terminal T A Local database BD A It is saved on terminal T A by terminal T A And locally (local au terminal T A ) Partial graph SG A It is incorporated into and then, when a connection becomes available, the integrated graph G C It can be synchronized with the blockchain (avant d'etre synchronisees, lorsqu'une connexion le permet, avec la chaine de blocs du graphe general G c ).
[0074] Synchronization between multiple peers is handled by the integrated database BD. C This is how it is obtained. When one peer generates or receives a new block, it adds the new block to its own ledger copy and then sends the block to its other peer nodes (a ses node pairs). When those peer nodes receive the block, they verify that the new block is valid. If the block is valid, those peer nodes incorporate the block into their own ledger and then send the block to their other peers.
[0075] Figure 2A shows the integrated database BD managed by the server SDP for managing personal data. C All users of the historical data service HIST will have their data stored. A , T k Comprehensive graph G representing the organization of encrypted personal data C Here is an example.
[0076] In the example shown here, the combined graph G C This is especially true for the subgraph SG. A Equipped with a subgraph SG A This is the comprehensive database BDC in or local database BD A Encrypted personal data of user A in DP A The following shows the structure. Here, it is assumed that these databases will be synchronized.
[0077] As mentioned above, Comprehensive Graph G C (Therefore, specifically, subgraph SG A The topology is determined by a pre-built data model.
[0078] Figure 2B shows the encrypted personal data DP of user A based on a specific data model. A A subgraph representing the composition SG A This will be explained in more detail.
[0079] In this particular case of the data model, subgraph SG A This is a directed acyclic graph. Subgraph SG A In particular, Route BR A It comprises a series of branches (un ensemble de branches) consisting of multiple blocks interconnected by multiple arcs (arcs).
[0080] In the embodiment described herein, terminal T A The MDD module for detecting movement of a real-world terminal T A It is configured to detect the type of movement, such as movement by car or movement on foot.
[0081] In the exemplary embodiments described herein, based on a pre-built data model, a subgraph of a user's personal data includes, in particular, a branch relating to each of the user's detected movements.
[0082] For example, in Figure 2B: - Each of branches F1 through F3 is a terminal T ATimestamped personal geographical location data DP obtained during movement in the vehicle detected by GEO A comprises a plurality of encrypted blocks; - Each of branches F4 to F5 is timestamped personal geographical location data DP A obtained during walking movement detected by the terminal T GEO A comprises a plurality of encrypted blocks.
[0083] This example is non - limiting, and other types of movement not shown may also be assumed.
[0084] As shown in more detail for branch F5, each branch associated with a movement comprises a series of blocks, and each block B i is an encrypted geographical location P i and a date T i and the encrypted geographical location P i and the date T i indicate that the terminal T A was at the location P i at the time (a l'instant) T i during the movement associated with this branch F5.
[0085] When the module MDD for detecting movement detects that the movement has completed, for example, when it is detected that the position of the terminal T A has not changed over a predetermined time, the branch stops. If a new movement is detected, a new branch is generated.
[0086] The example of Figure 2B shows in more detail three blocks B i-1 、B i 、B i+1 and the three blocks B i-1 、B i 、B i+1 are consecutive times T A of the terminal T i-1 、T i 、Ti+1 Position P i-1 ,P i , P i+1 It is equipped with a blockchain mechanism, with each block B i In addition to the encrypted data of the block itself, the output hash H([B i-1 A Note that this includes ]). Due to the properties of hash functions, any changes to the contents of a block are immediately visible in subsequent blocks.
[0087] In the specific data model described here, the branches associated with the detected movement of a user's device form the main framework of the user's subgraph.
[0088] In the embodiment described herein, the subgraph SG A Also, terminal T A Encrypted personal data of user A obtained during a digital operation performed by DP DigAct A It comprises multiple blocks that include the following:
[0089] In the embodiment described herein, the subgraph SG A Furthermore, encrypted personal data DP of user A obtained from a third party 3rdP A It comprises multiple blocks that include the following features.
[0090] In the embodiments described herein, a block comprising data associated with a digital operation on a certain date or received from a third party on a certain date is a subgraph SG A In this case, the date and the terminal T of that date A It is linked to a block that has a geographical location.
[0091] In this embodiment, as an example, Figure 2B shows the following: - The device is located at P i-1 The time T that existed i-1 Node B, equipped with encrypted PIX photos acquired by camera CAM.k ; - When the terminal is located at position P i+1 at time T i+1 Node B that received the encrypted contract AG from a third party r 。
[0092] This sub - graph is enriched with the user's personal data and evolves dynamically.
[0093] Very advantageously, the personal data DP 3rdP A of user A, in a sub - graph SG A of a blockchain, guarantees the impossibility of tampering with the history of the data and the authenticity of the data when verified by an external trusted third party.
[0094] As is known to those skilled in the art, in order to give probative force to the graph, it is necessary to incorporate, for example, periodically, data generated by an external trusted third party (e.g., another blockchain) into the graph. For example, the terminal can send the hash of the last block of the graph to this trusted third party, and the trusted third party generates information from this hash, and the information signed by the trusted third party is incorporated into the graph.
[0095] In a particular embodiment, the history of the user's personal data is associated with a dynamic non - fungible token by a server SDP for managing the personal data.
[0096] For example, as will be described later with reference to FIG. 4, the output hash of the root block of the sub - graph of the user's historical data can be associated by the server SDP with the encrypted data (e.g., a dynamic non - fungible token or the public key of a digital wallet) assigned to this user by the server.
[0097] Hereinafter, an embodiment of the present invention will be described. In this embodiment, the unique encrypted data of the user is a non - fungible token NFT Aand thus, according to the present invention, a user can associate the history of their personal data with their dynamic non-fungible token NFT A to it.
[0098] In a specific embodiment of the present invention, user A is the owner of a dynamic non-fungible token NFT A and can generate at least one second non-fungible token NFT A 2 and associate a sub-graph of their own sub-graph SG A with this second non-fungible token.
[0099] Here, user A and service provider SP have already subscribed to the GES-CONT service for managing digital contracts, and digital contract AG i intended to be concluded by instance ECN ECN A,SP of digital trust environment ECN is desired to be created without disclosing the personal data of the parties to the contract during the conclusion of the contract.
[0100] The terminal T SP of service provider SP has already downloaded the application GEN-CONT for generating the contract from server SDP, and the application GEN-CONT is compatible with the application APP A downloaded by the terminal T A .
[0101] Assume that the user of terminal SDP has used the application GEN-CONT, opened an account with server SDP for managing personal data, and has already subscribed to the GES-CONT service for managing contracts.
[0102] After opening this account, terminal T SPRewritable non-volatile memory M SP In this example, it includes the following: - An identifier LOG / MP (login name, password) that allows the user to access their account via the local application GEN-CONT; -Private key KPRIV SP and public key KPUB SP A key pair equipped with; - Symmetric encryption key KS SP and -Secret Unique Identifier ID SP .
[0103] In the embodiment described here, the service provider SP uses its application GEN-CONT to create a contract proposal. The contract proposal is then submitted to the AG. ECN* A,SP This is how it is written. In the embodiments described here, the analysis to be performed on the user's data, the frequency of the analysis, the length of the contract, the format of the results, and the rules for distributing the results are clearly stated in the contract proposal.
[0104] Contract Proposal AG ECN* A, SP An example is shown in Figure 3A. This proposal includes the following: - Digital Trust Environment ECN Instance ECN i A literal description interpretable by DLII, and / or its instance ECN. i This is executable by and A's personal data DP A Code to perform the analysis; - Personal data DP that the digital trust environment ECN should be the subject of the above analysis (sur lesquelles l'environnement de confiance numerique ECN doit porter cette analyzes) A AThe description DDP, where the description DDP is, for example, the category of personal data (data with geographical timestamps, photographs, messages, etc.) and the associated time range (personal data detected between this day and that day, etc.); - Contract start date DD, contract end date DF, and contract period PER (la date de debut DD, la date de fin DF et une periodicite PER d'execution du contrat); - A format (FORM) that the digital trust environment should use to return the analysis results to different parties A and SP; - An instance (ECN) of the digital trust environment configured to conclude contracts. i Common public key KPUB ECN The encryption key KS of the party SP, which was encrypted. SP and - Service provider's private key KPRIV SP The signing SIG of this contract proposal SP .
[0105] Public Key KPUB ECN Encryption key KS SP [KS SP ECN It is written as ].
[0106] Terminal T A When this encrypted contract proposal is obtained, the service provider SP's public key KPUB is also obtained. SP Signed by SIG SP We will verify this.
[0107] Terminal T A If User A accepts the contract proposal, User A will be granted an instance ECN in the digital trust environment. i Common public key KPUB ECNThe encryption key KS, which is encrypted with A Insert your private key KPRIV into this completed proposal. A By signing, you can create your own signature SIG A Insert this into the contract proposal and contract AG ECN A, SP Create (il y insere sa cle de chiffrement KS A chiffree avec la cle publique KPUB ECN commune aux instances ECN, de l'environnement de confiance numerique, signe cette proposition completee avec sa cle privee KPRIV A , et insere sa signature SIG A dans la proposition de contrat pour former le contrat AG ECN A; SP ). Public key KPUB ECN Encryption key KS A [KS A ECN It is written as ].
[0108] Contract AG was created in this manner. ECN A, SP This is shown in Figure 3B. Contract AG ECN A, SP This includes the delegation of authority over encrypted personal data of Party A and SP, and the instance of the Digital Trust Environment ECN in which the data is analyzed. i It incorporates features for exclusive use by [company name].
[0109] In the embodiment described herein, Contract AG ECN A, SP This is the public key KPUB of Party A and SP of the contract. A KPUB SPand all instances of the digital trust environment ECN i Common public key KPUB ECN It will be signed by [company name].
[0110] Parties A and SP, and any instance ECN of the Digital Trust Environment ECN i Each of them can decrypt the contract by using their own private key (sa seule cle privee).
[0111] The process of concluding a contract using an instance of a digital trust environment will be explained with reference to Figure 8.
[0112] Figure 4 shows the main steps performed in a particular embodiment of the present invention to create a user account and assign a dynamic non-fungible token to the user. For illustrative purposes, User A's terminal T A From there, an account for user A is created, and user A's non-fungible token (NFT) is managed by the server SDP for personal data management. A Let's consider creating it.
[0113] The present invention is directly applicable to other embodiments in which the user-specific cryptographic data is not a dynamic non-fungible token, particularly when the cryptographic data consists of the public key of a digital wallet.
[0114] In process E40, terminal T A User A creates their account using the History Data Service (HIST) for personal data provided by the Server SDP. In the embodiment described herein, for this purpose, User A accesses their terminal T from the Server SDP for managing personal data. A By using a pre-downloaded local application APP, the following is obtained on terminal T A Memory M A Record in: - Identifier LOG / MP (login name, password) for accessing User A's account via the local application APP; - Secret key KPRIV A and public key KPUB A to form a key pair; - Symmetric encryption key KS A ; and - Secret unique identifier ID A .
[0115] These elements (identifier, key pair, symmetric encryption key, unique identifier) are preferably generated by the terminal T A e.g., by a local application APP
[0116] These are preferably stored in the memory M A of the terminal T A .
[0117] <00976>In step E42, the terminal T A incorporates its secret unique identifier ID A into the root block BR A of its data structure SG A and encrypts the root block BR A with its symmetric encryption key KS A . Denote this encrypted data block as H[BR A A . The output hash H([BR A A ) of the root block is calculated by applying the hash function H to the encrypted data block [BR A A .
[0118] In step E43, the root block BR A is also associated with the descriptor DESC A of this block encrypted with the symmetric encryption key KS A of the terminal T RA . Denote this encrypted descriptor as [DESC RA A .
[0119] The descriptor DESC A of the root block BRRA For example, this is the string "root block". This descriptor allows the symmetric encryption key KS A Any person who possesses the root block BR of user A's data structure A It becomes possible to find (retrouve).
[0120] The selection of descriptors may be arbitrary. However, in a preferred embodiment of the present invention, the selection of descriptors is determined in a pre-constructed data model. This model includes, for example, arrangements regarding the descriptors to be used.
[0121] In the embodiments described herein, the root block does not have a hash that concatenates itself to one or more previous data blocks.
[0122] In step E44, the encrypted root block [BR A A ] but terminal T A Local database BD A to, the encrypted descriptor [DESC RA A It is saved in the state associated with ]. Encrypted root block [BR A ] and its associated encrypted descriptor [DESC RA A These are sent to the server SDP when a network connection is available. They are then sent to the comprehensive database BD. C Recorded and encrypted root block [BR A ] is a comprehensive graph G C It can be synchronized with that.
[0123] In process E45, terminal T A That is the graph SG A Route block BR A Output hash H([BR A A ]) is sent to the SDP server for managing personal data.
[0124] In step E46, the server SDP for managing personal data uses dynamic non-fungible tokens (NFTs). A Create a root block and grant ownership to user A (dont il accorde la propriete a l'utilisateur A), and output hash H([BR A A ]) this dynamic non-fungible token NFT A To associate with.
[0125] User A's symmetric encryption key KS A Unless you have the output hash H([BR A A ]) cannot be found in other encrypted blocks, therefore the output hash H([BR A A Please note that it is not possible to associate ]) with user A's data.
[0126] Figure 5 shows the user's personal data DP. A For example, this shows the main steps taken to build a history of user A's personal data.
[0127] In the embodiments described herein, the data may be of any type. The data may be, for example, declarative data, or data that includes a proof element such as a digital signature or an embedded secure link.
[0128] As mentioned above, personal data DP A is terminal T A During detected movement, for example, during movement actions (walking, riding a motorcycle, running, driving a car, etc.), terminal T is acquired. A Personal data with geographical location timestamps DP GEO A This may also be the case. Such data could be, for example, from a moving terminal T. A consecutive time T i-1 , T i , T i+1 GPS location P i-1 , P i , Pi+1 It is equipped with.
[0129] As mentioned above, personal data DP A This includes, for example, taking photos or videos, exchanging messages, and using a terminal. A Interactions using applications, etc., on terminal T A Personal data DP corresponding to digital operations performed DigAct A That's fine.
[0130] As mentioned above, personal data DP A This includes personal data obtained from third parties such as management services, banks, insurance companies, and commercial organizations. 3rdP A That's fine.
[0131] In the embodiment described here, the personal data DP of user A A is terminal T A As soon as it is detected, it is automatically incorporated into the user's history. In a modified version, at least some of the data is incorporated into the user's device only with the user's explicit permission.
[0132] In process E50, terminal T A However, personal data DP that should be incorporated into User A's personal data history i A It shall detect [this].
[0133] In process E52, personal data DP i A , graph SG A Block B i It is incorporated into the graph. The position of this block in the graph is determined by a pre-built data model.
[0134] As described above with reference to Figure 2, this Block B i It includes the following: - Route Block BR A Excluding graph SG A Block B ini Multiple blocks B on the upstream side k Each output hash H k and - Personal Data DP i A .
[0135] Terminal T A The symmetric encryption key KS A Block B i Encrypt this data block. This encrypted data block is then stored in [B i A This is written as ]. Block B i Output hash H([B i A ]) is an encrypted data block [B i A It is calculated by applying it to [].
[0136] In process E54, encrypted block B i This is the descriptor DESC of this block. i It is associated with the descriptor DESC. i This is selected, for example, based on the arrangement of a pre-built data model. This descriptor DESC i Also, terminal T A The symmetric encryption key KS A It is encrypted. This encrypted descriptor is [DESC i A It is written as ].
[0137] for example: - Terminal T on June 4, 2021 A Acquired while traveling in a car, terminal T A Personal data with geographical location timestamps DP GEO A Data block B i Descriptor DESC associated with i This could be the string "2021 / 06 / 04||by car"; -Terminal T on 27 / 07 / 2021 A Personal data DP corresponding to digital operations DigActA Data block B i Descriptor DESC associated with i This could be the string "2021 / 07 / 27||photo" or "2021 / 07 / 27||email"; -On 08 / 04 / 2022, terminal T A Personal data obtained from a third party DP 3rdP A Data block B i Descriptor DESC associated with i This could be the string "2022 / 04 / 08||Bank".
[0138] In step E56, the encrypted data block [B i A ] is an encrypted descriptor [DESC i A In the state associated with ], terminal T A Local database BD A It is stored in the encrypted descriptor [DESC i A [B] Encrypted data block associated with ] i A ] is when a network connection is available, the comprehensive graph G C It can be synchronized with that.
[0139] Graph SG representing the history of user A's personal data A The entire thing is terminal T A Please note that permanent storage is not required. Terminal T A Local database BD A The periodic updating of the collections of multiple blocks in terminal T can be determined, for example, by the data model and the current state of the graph. A The strategy for maintaining partial history may be based on feature selection (construction of data and undeniable history necessary for the function to function) and performance (delay in accessing blocks in the local database versus delay in online access).
[0140] Terminal T A Personal Data Disclosure by A The history can be built and referenced asynchronously, without a network connection (hors reseau), and can be resynchronized without degrading the functionality or security of the solution.
[0141] Figure 6 shows the main steps for accessing a user's personal data performed by the user's terminal. As an example, terminal T of user A. A The user's personal data DP performed by A The process for reference is described in detail.
[0142] Symmetric key KS A Encrypted blocks [B i A ] is indeed the same symmetric encryption key KS A The descriptor of the block encrypted by [DESC i A Please remember that it is associated with ].
[0143] Conversely, data block B i Access to the associated descriptor DESC i It is done by [the specified method].
[0144] User A, descriptor DESC i It is assumed that you wish to refer to the block associated with it. The descriptor consists of, for example, the string "2021 / 06 / 04||by car".
[0145] In step E60, the user selects a descriptor based on the pre-built data model configuration.
[0146] In process E62, this descriptor DESC i is the user's symmetric key KS A Encrypted with, encrypted descriptor [DESC i A ] is generated.
[0147] In step E64, the encrypted descriptor [DESC i A [B] Corresponding encrypted block i A ] is identified.
[0148] In step E66, the encrypted block [B] identified in the previous step (E64) i A ] but terminal T A The symmetric key KS A Decrypted by, decrypted block B i This is generated.
[0149] In step E68, according to the user's needs, decoded block B i The contents of this document may be presented to User A. Personal Data DP A Graph SG A , graph SG A It can be reconstructed by using the hierarchical structure (parent-child links) between the blocks (peut etre reconstitue en utilisant la hierarchie (liens pere-fils) entre les blocs du graphe SG A This hierarchical structure can be derived (deduated) from the hashes contained in the data blocks.
[0150] Partial graph SG A The structure is Personal Data DP A Before decryption, or to the advantage of personal data DP A Please note that this may appear after the decoding process.
[0151] Graph SG A The integrity (L'integrite) of terminal T A This can be verified.
[0152] Figure 7 shows the main steps taken to create a contract between at least two parties. As an example, User A and A's personal data DP.A Agreement AG intended to be concluded in a digital trust environment ECN between a service provider SP wishing to perform the analysis ECN A, SP Let's consider creating it.
[0153] In the embodiments described herein, in general step E700, the server SDP for managing personal data is a set of instances ECN of the digital trust environment. i ECN j , instance ECN i ECN j They are both copies, and manage them. (gere un ensemble d'instances ECN i , ECN j (of the numerical contract environment clones between them). As mentioned above, all of these instances use the same EXEC-CONT module for concluding the contract and the public key KPUB. ECN and private key KPRIV ECN It comprises an identical pair having and . In the embodiments described herein, the instance is a composite graph G C It is generated or destroyed depending on the number of contracts recorded.
[0154] In step E70, Party SP submits the contract proposal AG between Party SP and Party A. ECN* A, SP Prepare it.
[0155] This contract proposal AG ECN* A, SP As shown in Figure 3A, it comprises the following: - Digital Trust Environment ECN Instance ECN i A literal description that can be interpreted by and / or the instance ECN i Personal data DP of A performed by A Code to perform the analysis; - Digital Trust Environment ECN Instance ECNi A literal description DLII that can be interpreted by, and / or the instance ECN. i This is executable by and A's personal data DP A Code to perform the analysis; - Personal data A that should be the subject of the above analysis by the Digital Trust Environment ECN A The description DDP, where the description is, for example, the category of personal data (data with geographical timestamps, photographs, messages, etc.) and the associated time range (personal data detected between this day and that day, etc.); - Contract start date DD, contract end date DF, and contract term PER; - The format (FORM) that the digital trust environment should use when returning analysis results to separate parties A and SP; - An instance of a digital trust environment configured to enter into contracts (ECN) i Common public key KPUB ECN The encryption key KS of the party SP, which was encrypted. SP .
[0156] In step E71, the party SP uses their private key KPRIV SP Contract proposal AG ECN* A, SP Sign this document. This signature will be sent to SIG. SP This is how it is written.
[0157] In process E72, party SP submitted the contract proposal AG. ECN* A, SP and signatory SIG SP Send this to party A.
[0158] Party A submits contract proposal to AG ECN* A, SP If accepted, in process E73, terminal T A This is the private key KPRIV of A. A Contract proposal AG ECN* A, SP Sign this document. This signature will be sent to SIG. A This is how it is written.
[0159] In process E74, terminal T A This is the contract proposal AG ECN* A, SP This signature SIG A and instances ECN with different digital trust environments i Common public key KPUB ECN Your own public key encrypted with KPUB A Insert the public key KPUB. ECN Encrypted public key KPUB A [KPUB A ECN It is written as ].
[0160] Contract proposal AG, initiated by party SP and accepted by party A. ECN* A, SP This is a contract AG created between party A and SP. ECN A, SP They may be qualified as such.
[0161] In process E75, two signature SIGs SP SIG A Contract AG ECN A, SP This is the public key KPUB of party A and SP. A KPUB SP and instances ECN with different digital trust environments i Common public key KPUB ECN The contract is encrypted asymmetrically. The contract encrypted in this way is then [AG ECN A, SP It is written as ].
[0162] In process E76, Contract AG ECN A, SP However, descriptor DESC ECN A, SP It is associated with the descriptor AG. ECN A, SP For example, the string is "Contract between A and SP". This descriptor DESC ECN A, SP This is the public key KPUB of party A and SP. A KPUB SPand instances ECN with different digital trust environments i Common public key KPUB ECN The descriptor encrypted in this way is [DESC ECN A, SP It is written as ].
[0163] Therefore, parties A and SP and any instance ECN of the digital trust environment ECN i Each of them possesses a private key KPRIV that only they have. A KPRIV SP KPRIV ECN The contract can be decrypted by using [this method].
[0164] In process E78, the encrypted contract [AG ECN A, SP ] and its encrypted descriptor [DESC ECN A, SP ] is User A's graph SG A and Comprehensive Graph G C It will be incorporated into it.
[0165] Encrypted contract [AG ECN A, SP ] is a comprehensive graph G C It is indistinguishable in this respect.
[0166] In the embodiment described here, the composite graph G C Encrypted contract in [AG] ECN A, SP ] is available, and this agreement is for the GraphSG on this server SP The server SP is notified that it has been incorporated (E79).
[0167] Figure 8 shows the main steps performed for concluding a contract based on a specific embodiment of the present invention. As an example, an instance ECN is created between User A and Service Provider SP in a digital trust environment. i Contract AG, which is intended to be concluded by ECN A, SP We will consider concluding an agreement.
[0168] As mentioned above, the encrypted contract is used by User A, SP's graph SG. A SG SP , ...and Comprehensive Graph G C It will be recorded.
[0169] In one embodiment of the present invention, users can access their graph SG A SG SP Or Comprehensive Graph G C The existence of the contract is verified. For this purpose, and as described above with reference to Figure 6, users use a descriptor to identify the contract on the blockchain. The descriptor consists of, for example, the string "contract".
[0170] In the modified example, the instance ECN of the digital trust environment i However, Comprehensive Graph G C The above verification will be performed.
[0171] Process E80 is executed repeatedly, for example, at regular intervals. In process E80, terminal T A Based on the contract descriptors, its graph SG A Or Comprehensive Graph G C Search for encrypted contracts [AG] located at [location].
[0172] Terminal T A is an encrypted contract [AG ECN A, SP When ] is identified, in step E81, the encrypted contract [AG ECN A, SP ] your private key KPRIV A Then decrypt it.
[0173] In process E82, terminal T A The system determines whether a contract is scheduled to be concluded based on the contract start date (DD), contract end date (DF), and contract term (PER). If applicable, terminal T A In process E83, one instance of the digital trust environment is an ECN.i We will notify them of this.
[0174] In step E84, one instance of the digital trust environment is an ECN. i is an encrypted contract [AG ECN A, SP ] obtain your private key KPRIV ECN Then decrypt it.
[0175] As described above with reference to Figure 3B, the encrypted contract AG ECN A, SP This is an instance ECN. i KPUB public key ECN The symmetric encryption keys KS of each of the multiple parties, encrypted with A , KS SP (each [KS A ECN ]……KS SP ECN It is equipped with (which is written as ].
[0176] In process E85, instance ECN i is their private key KPRIV ECN The encrypted encryption key is decrypted, and each of the multiple parties' encryption keys KS A , KS SP Obtain it.
[0177] The contract is for an instance ECN in a digital trust environment. i It is concluded based on the terms of the contract.
[0178] In process E86, instance ECN i Based on the Descriptive DDP, it determines which of the parties' personal data should be included in the analysis, and performs the analysis by interpreting the interpretable literal description DLII or by executing the code included in the contract. During this analysis, the necessary personal data of the parties is used in the instance ECN. i It is then decrypted using the symmetric encryption key of the parties involved.
[0179] By following the parent-child links (liens de parente) determined by the blockchain hash for the subgraphs of the parties involved, the instance ECN can be identified. i This involves encrypted data specific to the user, such as a subgraph SG. A Route block BR A Dynamic non-fungible tokens (NFTs) associated with A , that it belongs to user A (for example, user A's public key KPUB in the database) A It is possible to verify that it is associated with the party, to reconstruct the entire history of this party's personal data, and to perform analysis of the personal data covered by the Descriptive DDP.
[0180] In process E87, instance ECN i This involves formatting the RES (Resource Instance) based on the FORM (Format) specified in the contract. i This result is that party A and SP's public key KPUB A KPUB SP The data is encrypted using [RES]. The result of this encryption is denoted as [RES].
[0181] In step E88, the result RES is descriptor DESC RES It is associated with the descriptor DESC. RES For example, the string "Result of the conclusion of the contract between A and SP". This descriptor DESC RES This is the public key KPUB of party A and SP. A , KPU SP It is encrypted in this way. The descriptor encrypted in this way is [DESC RES It is written as ].
[0182] In step E89, the encrypted result [RES] and its encrypted descriptor [DESC RES ] is a comprehensive graph G C Incorporated into the partial graph SG of the parties to the contract. A SG SP It is synchronized and a notification is sent to the participant's device.
[0183] As described above with reference to Figure 4, terminal T A When user A creates their account using the Historical Data Service (HIST) for personal data provided by the Server SDP, the Server SDP manages the personal data, including encrypted data (e.g., Dynamic Non-Fungible Tokens (NFTs)). A Alternatively, create a public key for a digital wallet, grant ownership of it to user A, and associate the history of encrypted personal data with this encrypted data.
[0184] Figure 9 shows the hardware architecture of a terminal according to the present invention. The terminal comprises, in particular, a processor 10, a read-only memory 11 (of the "ROM" type), a rewritable non-volatile memory 12 (of the "EEPROM" or "Flash NAND" type), a rewritable volatile memory 13 (of the "RAM" type), and a communication interface 14.
[0185] The read-only memory 11 constitutes a recording medium according to an exemplary embodiment of the present invention, is readable by the processor 10, and stores a first computer program P1 according to an exemplary embodiment of the present invention. In a modified example, the first computer program P1 is stored in a rewritable non-volatile memory 12.
[0186] The first computer program P1 enables the terminal to perform a method for constructing a history of personal data based on the present invention.
[0187] Figure 10 shows the hardware architecture of a server for managing personal data according to the present invention. The server comprises, in particular, a processor 20, read-only memory 21 (of the "ROM" type), rewritable non-volatile memory 22 (of the "EEPROM" or "Flash NAND" type), rewritable volatile memory 23 (of the "RAM" type), and a communication interface 24.
[0188] The read-only memory 21 constitutes a recording medium according to an exemplary embodiment of the present invention, is readable by the processor 20, and stores a second computer program P2 according to an exemplary embodiment of the present invention. In a modified example, the second computer program P2 is stored in a rewritable non-volatile memory 12.
[0189] The second computer program P2 enables a server for managing personal data to perform a method for managing the personal data of multiple users based on the present invention.
Claims
1. User (A)'s personal data (DP A A method for constructing a history of the user (A)'s terminal (T A ) is executed by, - The symmetric encryption key (KS) associated with the profile of the user (A) A Step (E40) to obtain ); - The user's personal data (DP A (E50) A process for collecting ) - The personal data (DP) of the user (A) A ) in the process of collecting: (i) The user's symmetric encryption key (KS A (E52) A step for encrypting the personal data in the same manner as above; and (ii) A step (E56) of recording, in a comprehensive database (BD C ), a plurality of blocks (B iA ) each containing the encrypted data ([B i ), wherein the plurality of blocks (B i ) are arranged based on a blockchain constituting a sub-graph (SG C ) of a comprehensive graph (G A ), the topology of the comprehensive graph is defined by a pre-constructed data model, and the root block (BR A ) of the sub-graph (SG A ) is associated with a dynamic non-fungible token (NFT A ) of this user (A). (E56) A method that includes [a certain feature].
2. The aforementioned blockchain is a distributed ledger in a peer network, and the terminal (T A ) is the aforementioned subgraph (SG A The peer of the network is configured to locally store at least a portion of the plurality of blocks (B i ) is the aforementioned terminal (T A ) local database (BD A A method for constructing a history of personal data as described in claim 1, which is stored in ()
3. According to the data model, the subgraph (SG A The branch of the terminal (T A The detected moving terminal (T A Multiple blocks (B) having encrypted personal data corresponding to timestamped geolocation data of ) i A method for constructing a history of personal data as described in claim 1 or 2, wherein the method for constructing the history of personal data is specified.
4. The data model comprises multiple blocks (B) having encrypted personal data corresponding to the digital operation of the terminal on a given date or data received from a third party on a given date. k , B r ) is the aforementioned subgraph (SG A ) in the terminal (T A One block (B) having encrypted personal data corresponding to geolocation data of ) i A method for constructing a history of personal data as described in claim 3, which specifies how the data is linked to the data.
5. The above method is the subgraph (SG A ) to the digital contract ([AG) in which the aforementioned user (A) is a party ECN A, SP The contract includes a process (E78) for incorporating the terminal (T A ) public key (KPUB A ), the public key of at least one other party to the agreement (KPUB SP ), and the public key of the digital trust environment (KPUB ECN The agreement is encrypted by ) and is at least: - Public key of the aforementioned digital trust environment (KPUB ECN The symmetric encryption key of the user (A) encrypted with [KS A ]); and - Executable by the aforementioned digital trust environment: (i) The personal data (DP) of the user A ) at least a portion of the symmetric encryption key (KS A ) for decryption; (ii) The aforementioned partial graph (SG A ) the aforementioned root block (BR A The dynamic non-fungible token (NFT) associated with ) A (iii) for verifying that the person belongs to user (A); for analyzing the decrypted personal data; and (iv) To provide the results of the analysis to at least one party to the contract, A method for constructing a history of personal data according to any one of claims 1 to 4, comprising commands (DLII, CODE).
6. At least one second dynamic non-fungible token (NFT) relating to the user A 2 The process for generating the second dynamic non-fungible token (NFT) A 2 ) in the subgraph (SG) of the subgraph (DGA) A 2 A method for constructing a history of personal data according to any one of claims 1 to 5, comprising the steps of associating )
7. A management method performed by a server (SDP) for managing the personal data of multiple users, the method comprising multiple blocks (B i ) is recorded in the comprehensive database (BD C It is equipped to manage each block (B i ) comprises the encrypted personal data of one user, and the plurality of blocks (B i ) contains the same user's encrypted personal data and the same comprehensive graph (G C ) subgraph (SG A ) is organized based on the blockchain that constitutes the comprehensive graph (G C The topology of the subgraph (SG) is defined by a pre-built data model, and the subgraph (SG) A ) Route block (BR A ) is this user (A)'s dynamic non-fungible token (NFT) A A management method associated with ).
8. The method comprises a step (E700) for managing a series of instances of a digital trust environment, one of which is: - Digital contract (AG ECN A, SP The orders (DLII, CODE) specified in the said contract and the said personal data (DP) of at least one user who is a party to the said contract A The contract executes an instruction to analyze a portion of the public key (KPUB) of the instance of the digital trust environment, where the contract executes an instruction to analyze a portion of the public key (KPUB) of the instance of the digital trust environment. ECN The symmetric encryption key of at least one party to the said contract, encrypted with [KS A ]) and the symmetric encryption key ([KS A ]) can be used by the aforementioned instance to decrypt the aforementioned personal data to be analyzed; - Provide the results of the analysis to at least one party to the agreement. The management method according to claim 7, configured as described above.
9. - Symmetric encryption key (KS) associated with user (A)'s profile A The process for obtaining ) - The user's personal data (DP A The process for collecting ) and - The personal data (DP) of the user (A) A ) in the process of collecting: (i) The user's symmetric encryption key (KS A (E52) A step for encrypting the personal data in the same manner as above; and (ii) General Database (BD C ) contains the encrypted data ([B iA Multiple blocks (B) comprising ]) i A step (E56) to record the plurality of blocks (B i ) is a comprehensive graph (G C ) subgraph (SG A ) is organized based on the blockchain that constitutes the comprehensive graph (G C The topology of the subgraph (SG) is defined by a pre-built data model, and the subgraph (SG) A ) Route block (BR A ) is this user (A)'s dynamic non-fungible token (NFT) A Process (E56) associated with ) A terminal (T) equipped with a processor configured to run A ).
10. A server (SDP) for managing personal data of a plurality of users, the server comprising a processor configured to manage a comprehensive database (BD i ) in which a plurality of blocks (B C ) are recorded, each block (B i ) comprising the encrypted personal data of one of the users, the plurality of blocks (B i ) comprising the encrypted personal data of the same user, and being organized based on a blockchain constituting a sub-graph (SG C ) of the same comprehensive graph (G A ), the topology of the comprehensive graph (G C ) being defined by a pre-constructed data model, and the root block (BR A ) of the sub-graph (SG A ) being associated with a dynamic non-fungible token (NFT A ) of this user (A), server (SDP).
11. A computer program (P1) comprising instructions for performing a method for constructing a history of personal data as described in any one of claims 1 to 6, when executed by a computer.
12. A computer program (P2) that, when executed by a computer, comprises instructions for performing the method for managing the personal data of multiple users as described in claim 7 or 8.