Data sharing method, network-side device, system, electronic device, and storage medium
The described data sharing method uses sandbox environments and metadata-based access control to secure and reliable data sharing, addressing privacy leaks in blockchain technologies by ensuring only authorized users can access and process data.
Patent Information
- Application Number
- JP2024507003
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-09-06
- Filing Date
- 2022-06-14
- Publication Date
- 2025-07-10
- Estimated Expiration
- 2042-06-14
AI Technical Summary
Existing blockchain technologies fail to effectively protect privacy data during data sharing, leading to potential privacy leaks and insecurity in data transactions.
A data sharing method involving the creation of a sandbox on a first network-side device, synchronized with a second network-side device, where metadata is shared, and access requests are managed to ensure only authorized users can access and process data, using encryption and trusted computing to maintain privacy.
Ensures secure and reliable data sharing by preventing unauthorized access and leakage, while maintaining data privacy through sandbox environments and metadata-based access control.
Smart Images

Figure 0007706011000001 
Figure 0007706011000002 
Figure 0007706011000003
Abstract
Description
Cross-reference
[0001] This application is proposed based on a Chinese patent application with the application number "202111040184.0" and the filing date of September 6, 2021, claims the priority of the Chinese patent application, and the entire content of the Chinese patent application is incorporated herein by reference.
Technical Field
[0002] This application relates to the field of data security, and particularly to data sharing methods, network-side devices, systems, electronic devices, and storage media.
Background Art
[0003] Today's society is in an era of rapid information growth. Data, as a new commodity, its sharing has become a new hot spot in today's technology and business. Different from traditional commodities, data has the characteristics of being easily transmitted and copied. Since data may involve the privacy of a large number of individuals and enterprises, higher requirements are imposed on the security, reliability, and traceability of the data sharing process. The conventional data sharing process involves the approval of the center. When data flows through the center, not only are the responsibilities and rights unclear, but there is also the problem of data privacy leakage. As a result, many organizations and institutions are reluctant to share their data with the outside.
[0004] Blockchain is a database technology shared by multiple parties. The core of the technology is the chained storage of block-shaped data and smart contracts. Data can only be read and written, and cannot be modified or deleted. By sharing data through blockchain technology, not only can the reliability and traceability of transactions be ensured, but the transaction efficiency can also be improved.
[0005] However, the inventor of the present application has found that regarding blockchain technology, all data uploaded to the blockchain is publicly available to all users, and if data including privacy information is directly uploaded to the blockchain, a data leakage problem will occur. Currently, most blockchain platforms still cannot effectively protect privacy data, there is a risk of privacy leakage, and the security and reliability of the data sharing process cannot be ensured.
Summary of the Invention
Means for Solving the Problems
[0006] Embodiments of the present application provide a data sharing method, which is applied to a device on the first network side, and includes steps of creating a sandbox for a data provider and synchronizing the information of the sandbox to a device on the second network side, where the sandbox is bound to an original database and the information of the sandbox includes metadata of the original database; receiving a sandbox access request initiated by a data applicant and transferred by the device on the second network side, where the sandbox access request carries metadata of request data; collecting original data queried based on the metadata of the request data in the original database bound to the sandbox; generating response data for the sandbox access request according to the collected original data, and notifying the data applicant that the device on the second network side obtains the response data from the sandbox.
[0007] Embodiments of the present application provide a data sharing method, which is applied to a second network-side device, receives information of a sandbox synchronized by a first network-side device, and provides the information of the sandbox so that a data applicant can query it; transfers a sandbox access request submitted by the data applicant to the first network-side device; and when receiving a response data generation notification from the first network-side device, notifies the data applicant to obtain response data from the sandbox.
[0008] Embodiments of the present application further provide a network-side device, which is configured to create a sandbox for a data provider and synchronize the information of the created sandbox to a second network-side device. The sandbox is bound to an original database, and the information of the sandbox includes a creation module containing metadata of the original database, a reception module configured to receive a sandbox access request initiated by a data applicant and transferred by the second network-side device, where the sandbox access request carries metadata of request data, a collection module configured to collect original data queried based on the metadata of the request data in the original database bound to the sandbox, and a generation module configured to generate response data for the sandbox access request according to the collected original data and notify the data applicant to obtain the response data from the sandbox through the second network-side device.
[0009] Embodiments of the present application further provide a network-side device, including a receiving module configured to receive information of a sandbox synchronized by a first network-side device and provide the information of the sandbox so that a data applicant can inquire, a transfer module configured to transfer a sandbox access request submitted by the data applicant to the first network-side device, and a notification module configured to, when receiving a response data generation notification of the first network-side device, notify the data applicant of obtaining response data from the sandbox.
[0010] Embodiments of the present application further provide a data sharing system, including a first network-side device and a second network-side device capable of implementing the above data sharing method.
[0011] Embodiments of the present application further provide an electronic device, including at least one processor and a memory communicatively connected to the at least one processor, where at least one executable instruction for the at least one processor is stored in the memory, and when the instruction is executed by the at least one processor, the at least one processor can execute the above data sharing method.
[0012] Embodiments of the present application further provide a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above data sharing method is realized.
[0013] For one or more embodiments, they are exemplarily described with reference to the figures of the corresponding drawings. These exemplary descriptions do not limit the embodiments. Elements having the same reference numerals in the drawings represent similar elements. Unless otherwise specified, the figures in the drawings do not constitute a scale limitation.
Brief Description of the Drawings
[0014]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Embodiments for Carrying out the Invention
[0015] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will describe each embodiment of the present application in detail with reference to the drawings. However, those skilled in the art can understand that in each embodiment of the present application, many technical details are proposed for the reader to better understand the present application. However, even without these technical details and various changes or modifications based on the following embodiments, the technical solutions claimed in the present application can be realized.
[0016] One embodiment of the present application relates to a data sharing method, which is applied to a device on the first network side. The specific process is shown in FIG. 1. In this embodiment, the device on the first network side creates a sandbox for the data provider, synchronizes the information of the created sandbox to the device on the second network side, the sandbox is bound to the original database, the information of the sandbox includes the metadata of the original database, receives a sandbox access request initiated by the data applicant and transferred by the device on the second network side, the sandbox access request carries the metadata of the requested data, collects the original data queried based on the metadata of the requested data in the original database bound to the sandbox, and generates response data according to the queried original data so that the data applicant can obtain it through the device on the second network side.
[0017] This embodiment aims to provide a data sharing method that protects the privacy information of data and ensures the security of the data sharing process.
[0018] The following specifically describes the implementation details of the data sharing method in this embodiment. The following content is only the implementation details for facilitating the understanding of this means and is not essential for the implementation of this means. As shown in FIG. 1, the specific process includes at least the following steps 101 to 105, but is not limited thereto.
[0019] Step 101: Create a sandbox for the data provider. In this embodiment, the data provider provides and shares data. In this step, the device on the first network side creates a sandbox for the data provider, and the sandbox serves as a safe and reliable environment for the data provider to store and process data.
[0020] The process by which the first network-side device creates a sandbox for the data provider is shown in Figure 2. Specifically, in this embodiment, the first network-side device designs the service type of the sandbox according to the needs of the data provider. When creating the sandbox, the data provider binds the original database to the sandbox and sets the address, account, and password for accessing the original database. The data provider may further set the masking rules of the sandbox. Specifically, partial masking or complete masking may be selected.
[0021] In one example, the first network-side device determines the service type provided by the sandbox according to the sandbox creation request of the data provider. The service type includes shared exchange and trusted computing. The sandbox is created according to the selected service type. In addition, the capacity and retention period of the sandbox may be further set. In addition to storing data as a safe and reliable environment, the sandbox that provides a shared exchange service can provide data that has been processed such as masking and encryption so that the data applicant can obtain it. The sandbox of trusted computing can provide the calculation result of the data of the data provider so that the data applicant can obtain it.
[0022] In one example, after the settings of the sandbox are completed, the user clicks OK to complete the release of the sandbox. The first network-side device applies for an independent storage area for the created sandbox, mounts it to the path of the intermediate directory named after the sandbox, and is used to store the shared data.
[0023] Step 102, synchronize the information of the sandbox to the second network-side device. In this step, the information of the sandbox is synchronized to the second network-side device, and the second network-side device provides it to the data applicant so that the data applicant can query the information of the sandbox.
[0024] In one example, after the first network-side device synchronizes the created sandbox with the second network-side device, it uploads the sandbox release and synchronization process to the blockchain for evidence preservation. The information uploaded to the blockchain includes the identifier of the sandbox, the identifier of the data provider, and the metadata of the original database, etc. By uploading the sandbox release process to the blockchain, the traceability of the sandbox release process is ensured.
[0025] The blockchain according to this embodiment may be a commonly seen blockchain such as Hyperledger Fabric. In this embodiment, the on-chain and evidence preservation processes rely on smart contracts.
[0026] Step 103: Receive the sandbox access request initiated by the data applicant and transferred by the second network-side device. When the data applicant sends a sandbox access request to the second network-side device, the second network-side device transfers the sandbox access request to the first network-side device. In this step, the first network-side device receives the sandbox access request initiated by the data applicant and transferred by the second network-side device, and the metadata of the request data is carried in the sandbox access request.
[0027] Specifically, the data applicant queries the sandbox information provided by the data provider on the second network device, which contains the metadata of the data provided by the data provider, and further sends a sandbox access request. The sandbox access request is transferred by the second network device to the first network device. The first network device receives the sandbox access request transferred by the second network device, and the sandbox access request carries the metadata of the data requested by the data applicant.
[0028] In one example, after receiving the sandbox access request initiated by the data applicant and transferred by the second network device, the first network device generates an approval document in response to the sandbox access request initiated by the data applicant, and notifies the data provider to approve the sandbox access request. By notifying the data provider to approve, it can be ensured that only the data applicant who has obtained the permission of the data provider can query the shared data, and the leakage of private data to all users can be avoided.
[0029] Step 104: In the original database bound to the sandbox, collect the queried original data.
[0030] Specifically, after receiving the sandbox access request initiated by the data applicant and transferred by the second network device, in this step, the first network device queries the original data in the original database bound to the sandbox according to the metadata of the request data carried in the sandbox access request, and collects the original data queried based on the metadata of the request data.
[0031] Step 105: Generate response data and notify the data applicant to obtain it from the sandbox by the second network device.
[0032] Specifically, the first network-side device generates response data for the sandbox access request according to the original data collected in the previous step, stores the generated response data in the sandbox, sends a response data generation notification to the second network-side device, and further notifies the data applicant that the second network-side device obtains the response data from the sandbox.
[0033] In one example, when the data applicant requests access to a shared exchange type sandbox, that is, when the service type provided by the sandbox is shared exchange, the first network-side device performs masking processing on the collected original data according to the masking rules of the sandbox set by the data provider, and further performs encryption processing on the data after the masking processing using the public key of the data applicant, thereby completing the generation of the response data. The process by which the data applicant requests access to a shared exchange type sandbox and finally obtains the response data is shown in Figure 3.
[0034] In another example, the data applicant requests access to a trusted computing sandbox, that is, the service type provided by the sandbox is trusted computing. Correspondingly, the sandbox access request initiated by the data applicant is to obtain the calculation results of some or all of the data provided by the data provider. In this case, the first network-side device performs an encryption process on the collected original data, pushes the encrypted data into the trusted computing environment for trusted computing, and further performs an encryption process on the calculation results using the public key of the data applicant, thereby completing the generation of the response data (calculation results). The process by which the data applicant requests access to the trusted computing sandbox and finally obtains the response data (calculation results) is shown in FIG. 4. Since all the encryption processes of the generated response data use the public key of the data applicant and the request data can only be decrypted by the data applicant with the private key and finally obtained, it is ensured that only the data applicant who has obtained the permission of the data provider can obtain the data, and further data leakage is avoided.
[0035] In one example, after generating the response data, the first network-side device uploads the information in the data sharing process to the blockchain for evidence preservation. The information uploaded to the blockchain includes the identifier of the data applicant, the identifier of the sandbox, the identifier of the data provider, the information of the response data, and the signature of the data provider, etc. By uploading to the blockchain for evidence preservation, the traceability of the data sharing process is ensured. Here, the information of the response data may be the hash value of the shared data or the calculation result of the data.
[0036] The trusted computing environment according to this embodiment provides a trusted computing service and corresponds to a scenario where a data applicant requests access to a trusted computing sandbox. A security channel is built between the trusted computing environment and the first network-side device. After encrypting the private data with the public key of the trusted computing environment, the first network-side device puts it into the trusted computing environment through the security channel for calculation, and encrypts the calculation result with the public key of the data applicant for feedback.
[0037] The first network-side device in this embodiment is oriented towards the data provider and is deployed in the computer room or remote network of the institution. From a functional perspective, the first network-side device can function as the sandbox proxy module of the security sandbox system, specifically including an access layer, a communication layer, a sandbox management module, a data collection module, a data masking module, a data element management module, and a privacy calculation module. The access layer is used to provide the human-computer interaction function of sandbox management maintenance to the data provider, and specifically, it may be in the form of a command line or a user interface (abbreviated as "UI interface"). The communication layer is used to communicate with the second network-side device through the Google Remote Procedure Call Protocol (abbreviated as "GRPC protocol") interface and includes uplink messages such as sandbox release. The sandbox management module is responsible for the functions of creating, managing, and maintaining sandboxes and depends on the function support from the underlying privacy calculation module, data masking module, data collection module, and data element management module. The data collection module is responsible for collecting the original data. The data masking module is used to perform data masking processing on the collected data fields according to the set masking rules. The data element management module obtains the metadata information of shared data from the original database during the binding process of the original database, and stores and maintains the shared attributes and masking rules of the shared fields. The privacy calculation module constructs a trusted computing environment and a security channel, puts the privacy data into the trusted computing environment according to the computing requirements applied by the user, performs trusted computing, encrypts the calculation results, and feeds them back to the applying user.
[0038] The second network-side device in this embodiment is for the data applicant and may be deployed in the computer room or remote network of the data provider. Also, the first network-side device and the second network-side device may be deployed on the same server in the computer room of the center or in a cloud environment. From a functional perspective, the second network-side device can function as a sandbox service module of the security sandbox system. Specifically, it includes an access layer, a communication layer, a sandbox browsing module, a shared exchange module, a trusted computing module, and a data element information module. The access layer is used to provide the human-computer interaction function of sandbox access to the data applicant. Specifically, it may be in the form of a command line or a UI interface. The communication layer is used to communicate with the sandbox proxy module through the GRPC protocol interface and includes downlink messages such as sandbox queries, shared applications, computing applications, and result acquisitions. The sandbox browsing module is used to provide the functions of sandbox access, application, and information query to the data applicant and depends on the functional support from the underlying shared exchange module, trusted computing module, and data element information module. The shared exchange module is used for shared exchange sandboxes and provides the functions of access application and shared file download of the shared exchange sandboxes to the sandbox browsing module. The trusted computing module is used for trusted computing sandboxes. Regarding user privacy data, since the original data cannot leave the space of the data provider, the trusted computing module provides the functions of computing task application and result acquisition of the trusted computing sandboxes to the sandbox browsing module. The data element information module is used to obtain the metadata of the sandbox from the first network-side device and provide the metadata of the sandbox to the sandbox browsing module.
[0039] The blockchain, the first network-side device (sandbox proxy module), the second network-side device (sandbox service module), the trusted computing environment, the smart contract, and the service interface according to this embodiment constitute a security sandbox system. The security sandbox system adopts a distributed architecture and may be deployed on physical nodes or deployed in the form of a tenant in a cloud environment. The connection structure of each part in the security sandbox system is shown in FIG. 5. The sandbox proxy module communicates only with the sandbox service module, and the sandbox proxy modules cannot communicate with each other and are blocked from each other. When the sandbox proxy module is started, it is registered with the sandbox service module.
[0040] In one example, before deploying the second network-side device (sandbox service module), the blockchain environment and the trusted computing environment are deployed. Further, the certificate needs to be placed in the cert certificate directory, the smart contract to be installed is placed in the corresponding language directory under the contracts directory, the config / config.yaml configuration file is modified, the type of the blockchain platform to be docked is set, the address of the local storage DB is replaced, the config / config.yaml configuration file is modified, the related settings of the local docked blockchain platform are completed, the fabric setting platform includes the organization name, the peer and orderer addresses, and the certificate settings, the serviceinit command is executed, the sandbox service program is started, and the sandbox smart contract is installed and deployed.
[0041] In another example, a first network-side device (sandbox proxy module) is deployed. A proxy program needs to be deployed in the server environment of the mechanism, certificates need to be placed in the cert certificate directory, smart contracts that need to be installed are placed in the corresponding language directory under the contracts directory, the config / config.yaml configuration file is modified to set the type of the blockchain platform to dock, the address of the local storage DB is replaced, the config / config.yaml configuration file is modified to complete the relevant settings for the local blockchain platform to dock. The fabric platform includes the settings of the organization name, peer and orderer addresses and certificates. The agent--serviceip:port / <sandbox service id> command is executed to start the sandbox proxy program and install and deploy the sandbox smart contract.
[0042] In this embodiment, the first network-side device creates a sandbox for the data provider, and the sandbox serves as a safe and reliable environment for storing and processing data. When creating the sandbox, the first network-side device only collects the metadata of the data provider and does not need to obtain the original data, thus avoiding the leakage of privacy information due to the disclosure of the original data. Also, since the request data generated in response to the request of the data applicant is obtained by the data applicant through the second network-side device, compared with the sharing method of publicly disclosing the data to all users, it is further ensured that the data will not be leaked, and the security and reliability of the data sharing process can be guaranteed.
[0043] Another embodiment of the present application relates to a data sharing method and is applied to a second network-side device. In this embodiment, the second network-side device provides sandbox information so that a data applicant can query it, transfers a sandbox access request submitted by the data applicant to the first network-side device, and finally notifies the data applicant to obtain data. As shown in FIG. 6, the specific process includes at least the following steps 601 to 603, but is not limited thereto.
[0044] Step 601: Receive the information of the sandbox synchronized by the first network-side device, and provide the information of the sandbox so that the data applicant can query it. In this embodiment, the data provider provides and shares data, the first network-side device creates a sandbox for the data provider, and after releasing the sandbox, synchronizes the information of the sandbox to the second network-side device. In this step, the second network-side device receives the information of the sandbox synchronized by the first network-side device, and provides the information of the sandbox so that the data applicant can query it.
[0045] Thereby, the data applicant can issue a sandbox access request according to its own needs. The sandbox access request sent by the data applicant may be directed to a shared exchange type sandbox or a trusted computing type sandbox. Correspondingly, the data applicant can request to obtain some or all of the data or the calculation results of the data.
[0046] Step 602: Receive the sandbox access request submitted by the data applicant and transfer it to the first network-side device. After querying the information of the sandbox by the second network-side device, the data applicant sends a sandbox access request. This step is that the second network-side device receives the sandbox access request submitted by the data applicant and further transfers it to the first network-side device.
[0047] Step 603: Receive a response data generation notification from the first network-side device and notify the data applicant of obtaining the response data. In the previous step, the second network-side device transfers the sandbox access request submitted by the data applicant to the first network-side device, and the first network-side device processes the data according to the sandbox access request submitted by the data applicant. In this step, the second network-side device receives the response data generation notification from the first network-side device and notifies the data applicant of obtaining the response data.
[0048] In this embodiment, the second network-side device provides the information of the sandbox so that the data applicant can query it, so that the data applicant can start a sandbox access request according to the demand and obtain the response data. In addition, the second network-side device can receive the sandbox access request submitted by the data applicant and transfer it to the first network-side device, and can also realize the submission of the sandbox access request from the data applicant. By notifying the data applicant who submits the sandbox access request of obtaining the response data, the data applicant can obtain the requested data, avoid the data being publicly available to all users, and ensure that the private data does not leak.
[0049] One embodiment of the present application relates to a network-side device. As shown in FIG. 7, configured to create a sandbox for the data provider and synchronize the information of the created sandbox to the second network-side device. The sandbox is bound to the original database, and the information of the sandbox includes a creation module 701 including the metadata of the original database, and configured to receive a sandbox access request initiated by a data requester and transferred by a second network-side device, the sandbox access request carrying metadata of request data, a receiving module 702; a collecting module 703 configured to collect original data queried based on the metadata of the request data in the original database bound to the sandbox; a generating module 704 configured to generate response data for the sandbox access request according to the collected original data, and notify the data requester that the second network-side device obtains the response data from the sandbox.
[0050] In one example, the creating module 701 may be further configured to determine a service type provided by the sandbox according to a sandbox creation request of a data provider, and the service type includes shared exchange and trusted computing.
[0051] In one example, when the service type provided by the sandbox is shared exchange, the generating module 704 may be further configured to perform masking processing on the original data collected by the collecting module 703, perform encryption processing on the data after the masking processing, and use the data after the encryption processing as the response data for the sandbox access request.
[0052] In one example, when the service type provided by the sandbox is trusted computing, the generating module 704 may be further configured to perform encryption processing on the original data collected by the collecting module 703, push the original data after the encryption processing to a trusted computing environment for calculation, perform encryption processing on the calculation result, and use the calculation result after the encryption processing as the response data for the sandbox access request.
[0053] In one example, after receiving a sandbox access request initiated by a data requester and transferred by a second network-side device, the first network-side device may further include an approval module (not shown) configured to generate an approval document in response to the sandbox access request initiated by the data requester and notify the data provider to approve the sandbox access request.
[0054] In one example, the first network-side device may further include an on-chain module (not shown). After synchronizing the information of the created sandbox to the second network-side device, the on-chain module is configured to upload the creation information of the sandbox to the blockchain. The creation information includes one or any combination of the identifier of the sandbox, the identifier of the data provider, and the metadata of the original database. After generating the response data for the sandbox access request, the on-chain module is configured to upload the generation information of the response data to the blockchain. The generation information includes one or any combination of the identifier of the sandbox, the identifier of the data requester, the identifier of the data provider, the information of the response data, and the signature of the data provider.
[0055] The network-side device according to this embodiment can create a sandbox for the data provider, and the sandbox stores and processes data as a secure and reliable environment. When creating the sandbox, the first network-side device does not need to obtain the original data, and only collects the metadata of the data provider, thereby avoiding the leakage of privacy information due to the disclosure of the original data. In addition, since the request data generated in response to the request of the data requester is obtained by the data requester through the second network-side device, compared with the sharing method of publicly disclosing data to all users, it is further ensured that the data will not be leaked, and the security and reliability of the data sharing process can be guaranteed.
[0056] One embodiment of the present application relates to a network-side device. As shown in FIG. 8, a receiving module 801 configured to receive information of a sandbox synchronized by a first network-side device and provide the information of the sandbox so that a data applicant can query; a transfer module 802 configured to transfer a sandbox access request submitted by a data applicant to a first network-side device; a notification module 803 configured to, when receiving a response data generation notification of a first network-side device, notify a data applicant that response data is obtained from a sandbox.
[0057] The network-side device according to this embodiment provides information of the sandbox so that a data applicant can query, so that the data applicant can start a sandbox access request according to demand and obtain response data. By receiving a sandbox access request submitted by a data applicant and transferring it to a first network-side device, it is also possible to realize the submission of a sandbox access request from the data applicant. By notifying a data applicant who submits a sandbox access request that response data is obtained, the data applicant can obtain the requested data, avoid the data being made public to all users, and ensure that private data is not leaked.
[0058] It should be noted that each module according to the above embodiment of the present application is a logical module. In actual applications, one logical unit may be one physical unit, may be a part of one physical unit, or may be realized by a combination of multiple physical units. Also, in order to emphasize the innovative part of the present application, in this embodiment, units not closely related to the solution of the technical problems mentioned in the present application are not introduced, but this does not mean that there are no other units in this embodiment.
[0059] Embodiments of the present application further provide a data sharing system, including a first network-side device and a second network-side device that can implement the above data sharing method.
[0060] Embodiments of the present application further provide an electronic device. As shown in FIG. 9, it includes at least one processor 901 and a memory 902 communicatively connected to the at least one processor 901. At least one executable instruction for the at least one processor 901 is stored in the memory 902. When the instruction is executed by the at least one processor 901, the at least one processor 901 can execute the above data sharing method.
[0061] The memory 902 and the processor 901 are connected by a bus. The bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors 901 and the memory 902. The bus can further connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are all well known in the art and will not be described further herein. The bus interface provides an interface between the bus and the transceiver. The transceiver may be one element or multiple elements such as multiple receivers and transmitters, and provides a unit for communicating with various other devices on the transmission medium. The data processed by the processor 901 is transmitted via the antenna in a wireless medium. Further, the antenna can also receive data and transmit it to the processor 901.
[0062] The processor 901 is responsible for managing the bus and normal processing, and can also provide various functions including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory 902 may be used to store data used when the processor 901 executes operations.
[0063] The above product can execute the method according to the embodiment of the present application, has a functional module corresponding to the execution of the method and beneficial effects. For technical details not described in detail in this embodiment, reference may be made to the method according to the embodiment of the present application.
[0064] The embodiment of the present application further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the above data sharing method is realized.
[0065] Those skilled in the art can understand that all or part of the steps of the method in the above embodiment can be realized by a program issuing instructions to related hardware, and the program is stored in a storage medium and includes a plurality of instructions for causing a device (such as a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the method in each embodiment of the present application. The above-mentioned storage medium includes various media that can store program codes, such as a USB memory, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0066] The above embodiments are provided for those skilled in the art to implement and use the present application. Those skilled in the art can make various changes and modifications to the above embodiments without departing from the inventive concept of the present application. Therefore, the protection scope of the present application is not limited to the above embodiments and should conform to the maximum scope of the innovative features described in the claims.
Claims
1. A data sharing method, which is applied to a device on the first network side, creating a sandbox for a data provider and synchronizing information of the sandbox to a device on the second network side, wherein the sandbox is bound to an original database and the information includes metadata of the original database; receiving a sandbox access request initiated by a data applicant and transferred by the device on the second network side, wherein the sandbox access request carries metadata of request data; collecting original data queried based on the metadata of the request data in the original database bound to the sandbox; generating response data for the sandbox access request according to the collected original data, and notifying the data applicant that the device on the second network side obtains the response data from the sandbox; A data sharing method comprising the above steps.
2. The step of creating a sandbox for a data provider includes: determining a service type provided by the sandbox according to a sandbox creation request of the data provider, wherein the service type includes shared exchange and trusted computing; creating the sandbox according to the service type; The data sharing method according to Claim 1, comprising the above steps.
3. The step of generating response data for the sandbox access request includes: when the service type provided by the sandbox is shared exchange, performing a masking process on the original data, performing an encryption process on the data after the masking process, and using the data after the encryption process as the response data for the sandbox access request; The data sharing method according to Claim 2, comprising the above steps.
4. The step of generating response data for the sandbox access request includes: When the service type provided by the sandbox is trusted computing, encrypt the original data, push the encrypted original data to a trusted computing environment for calculation, encrypt the calculation result, and use the encrypted calculation result as the response data of the sandbox access request The data sharing method according to claim 2, including the above steps
5. After the step of receiving the sandbox access request initiated by the data requester and transferred by the second network side device, before the step of collecting the original data queried based on the metadata of the request data in the original database bound to the sandbox In response to the sandbox access request initiated by the data requester, notify the data provider to approve the sandbox access request When the approval is successful, execute the step of collecting the original data queried based on the metadata of the request data in the original database bound to the sandbox The data sharing method according to claim 1, further including the above steps
6. After the step of synchronizing the information of the created sandbox to the second network side device The step of uploading the creation information of the sandbox to the blockchain, where the creation information includes one or any combination of the identifier of the sandbox, the identifier of the data provider, and the metadata of the original database After the step of generating the response data of the sandbox access request, the step of uploading the generation information of the response data to the blockchain The generation information includes one or any combination of the identifier of the sandbox, the identifier of the data requester, the identifier of the data provider, the information of the response data, and the signature of the data provider The data sharing method according to claim 1, further including the above steps
7. A data sharing method, which is applied to a second network side device Receiving information of a sandbox synchronized by a first network-side device and providing the information of the sandbox so that a data applicant can make an inquiry, wherein the sandbox is bound to an original database, and the information includes metadata of the original database; Transferring a sandbox access request submitted by the data applicant to the first network-side device, wherein the sandbox access request carries metadata of request data; Notifying the data applicant to obtain response data from the sandbox when receiving a response data generation notification of the first network-side device; A data sharing method including the above steps.
8. A network-side device, comprising: A creation module configured to create a sandbox for a data provider and synchronize information of the sandbox to a second network-side device, wherein the sandbox is bound to an original database, and the information includes metadata of the original database; A receiving module configured to receive a sandbox access request initiated by a data applicant transferred by the second network-side device, wherein the sandbox access request carries metadata of request data; A collection module configured to collect original data queried based on the metadata of the request data in the original database bound to the sandbox; A generation module configured to generate response data for the sandbox access request according to the collected original data, and notify the data applicant to obtain the response data from the sandbox by the second network-side device; A network-side device including the above modules.
9. A network-side device, comprising: A receiving module configured to receive information of a sandbox synchronized by a first network-side device and provide the information of the sandbox so that a data applicant can make an inquiry, wherein the sandbox is bound to an original database, and the information includes metadata of the original database; A transfer module configured to transfer a sandbox access request submitted by the data applicant to the first network-side device, wherein metadata of request data is carried in the sandbox access request; A notification module configured to notify the data applicant to obtain response data from the sandbox when receiving a response data generation notification from the first network-side device; A network-side device including the above.
10. A data sharing system including the network-side device according to Claim 8 or the network-side device according to Claim 9.
11. An electronic device, including at least one processor; a memory communicably connected to the at least one processor, wherein executable instructions for the at least one processor are stored in the memory, and when the instructions are executed by the at least one processor, the at least one processor can execute the data sharing method according to Claim 1, or the at least one processor can execute the data sharing method according to Claim 7.
12. A computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the data sharing method according to Claim 1 is realized, or the data sharing method according to Claim 7 is realized.
Citation Information
Patent Citations
Private information distribution management method, private information identification device in private information distribution management system, private information using environment identification device, private information providing device, private information using device, disclosure use rule determination program. and program for each device.
JP2003345931A
Generation device, generation method, and verification device
JP2021077941A
Server device, data processing method, and communication program
JP2021114141A
System and method for prevention of malware attacks on data
US20140007228A1