User Data Management Method and Related Devices
A user data management system with a blockchain platform and decentralized authentication enhances security by reducing single-point failure risks and enabling user oversight, addressing vulnerabilities in centralized data management.
Patent Information
- Application Number
- JP2023574498
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-06-04
- Filing Date
- 2022-05-06
- Publication Date
- 2025-07-30
- Estimated Expiration
- 2042-05-06
AI Technical Summary
Centralized user data management in mobile communication networks is vulnerable to single-point failures and Distributed Denial of Service (DDoS) attacks, increasing data security risks.
Implementing a user data management system that includes a data request device, a data storage device, and a blockchain platform to authenticate and authorize access requests, ensuring decentralization and anti-tampering, thereby reducing the risk of single-point failures and enhancing data security.
The system improves data security by minimizing data loss during attacks and ensuring user data is managed with precise permission controls, allowing users to monitor and manage their personal data effectively.
Smart Images

Figure 0007715840000001 
Figure 0007715840000002 
Figure 0007715840000003
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of data processing, and in particular, to user data management methods and related devices.
Background Art
[0002] User data management is one of the most central functions of a mobile communication network. The provision of user services and the normal operation of the network need to depend on user data management entities and related procedures. The user data management entity of a mobile network stores user and service subscription-related data, key information, etc., and serves as the key for implementing user authentication, authorization, and access control.
[0003] In current 2G to 5G core network architectures, each user has a lot of information such as subscription information, key information, and service information. User information is centrally managed in a single-point user data management device. The user data management device is connected to another control plane network entity or application server to provide data access services. For example, in the core network architecture of a 5G network, user information is managed by Unified Data Management (UDM). UDM can manage network user data in a single network element and can be combined with a user data repository. The user data repository stores user information. UDM is located on the control plane.
[0004] Since user information is managed by a centralized single-point user data management device, a single-point failure occurs and it is vulnerable to Distributed Denial of Service (DDoS) attacks. As a result, the data security risk increases.
Summary of the Invention
Means for Solving the Problem
[0005] Embodiments of the present application provide a user data management method and related devices to improve the security of user data.
[0006] A first aspect of the embodiments of the present application provides a user data management method. This method is used by a user data management system for managing user data. This system includes a data request device, a data storage device, and a blockchain platform. When the data request device needs to access the data storage device, the user data management system performs corresponding operations. Specifically, this method includes the step of the data request device sending a first request to the blockchain platform, where the first request indicates that the data request device needs to access the data storage device, and the first request includes the signature information and access type of the data request device. The data request device receives the first permission information sent by the blockchain platform, and the first permission information indicates whether the data request device has permission to access the data storage device, and the permission is related to the signature information and access type of the data request device. If the first permission information indicates that the data request device has permission to access the data storage device, the data request device sends a second request to the data storage device, and the second request includes an access address. In other words, the determination of whether the data request device has permission to access the data storage device is related to the signature information and access type of the data request device.
[0007] In this possible implementation, before accessing the data storage device, the data request device needs to obtain confirmation from the blockchain platform that the data request device has the corresponding permission. Since the blockchain platform has functions such as decentralization and anti-tampering, the blockchain platform with authentication and authorization functions has no risk of single point of failure, and even if the blockchain platform is subject to a distributed denial of service attack, the lost data is relatively small. As a result, the security of user data is improved. In another aspect, the first request includes an access type, and the access information is further refined, so that the blockchain platform can more accurately determine the permission corresponding to the first request.
[0008] In a possible implementation of the first aspect, the access type includes data writing and data reading. When the access type is data writing, the first request further includes an access address, or when the access type is data reading, the first permission information includes an access address.
[0009] In a possible implementation of the first aspect, after the data request device sends a second request to the data storage device, the method further includes the step of the data request device receiving confirmation information sent by the data storage device, where the confirmation information indicates that the data storage device has executed a task corresponding to the second request.
[0010] In this possible implementation, the data request device can know whether the data storage device has executed a task corresponding to the second request, and as a result, execute the corresponding response accordingly to increase the information obtained by the data request device.
[0011] In a possible implementation of the first aspect, before the data request device sends a first request to the blockchain platform, the method further includes the step of the data request device receiving a third request sent by the user device, where the third request indicates that the data request device sends a first request to the blockchain platform.
[0012] In a possible implementation of the first aspect, the signature information of the data request device includes the signature information of the user device.
[0013] In a possible implementation of the first aspect, the access type includes data writing, data deletion, data reading, and data modification.
[0014] In a possible implementation of the first aspect, after the data request device receives the confirmation information sent by the data storage device, the method further includes the step of the data request device sending task result information to the user device, where the task result information indicates whether the data storage device has completed the task corresponding to the first 2 request.
[0015] In this possible implementation, the user device can know whether the data storage device has executed the task corresponding to the second request, and as a result, can execute the corresponding response accordingly to increase the information obtained by the user device.
[0016] A second aspect of the embodiments of the present application provides a user data management method. This method is used by a user data management system for managing user data. The system includes a data request device, a data storage device, and a blockchain platform. When the data request device needs to access the data storage device, the user data management system performs corresponding operations. Specifically, the method includes the step of the data storage device receiving a second request from the data request device, where the second request includes an access address. The data storage device sends an access verification request to the blockchain platform, and the access verification request indicates that the data request device sends the second request to the data storage device. The data storage device receives second permission information sent by the blockchain platform, and the second permission information indicates whether the data storage device can execute a task corresponding to the second request. If the second permission information indicates that the data storage device can execute a task corresponding to the second request, the data storage device executes the corresponding task based on the second request.
[0017] In this possible implementation form, before accessing the data storage device, the data request device needs to obtain confirmation from the blockchain platform that the data request device has the corresponding permission. Since the blockchain platform has functions such as decentralization and anti-tampering, the blockchain platform with authentication and authorization functions has no risk of single point of failure, and even if the blockchain platform is attacked by the network, the lost data is relatively small. As a result, the security of user data is improved. In another aspect, the first request includes an access type, and the access information is further refined, so that the blockchain platform can more accurately determine the permission corresponding to the first request. In addition, only the related information of the user data is stored in the blockchain platform, and all the user data is stored in the data storage device, so the "blockchain expansion problem", "privacy problem", and "problem of forgotten rights" caused by data anti-tampering are avoided.
[0018] In a possible implementation form of the second aspect, after the data storage device executes the corresponding task based on the second request, the method further includes a step in which the data storage device sends response information to the blockchain platform, and the response information indicates that the data storage device has executed the task corresponding to the second request.
[0019] In a possible implementation form of the second aspect, after the data storage device executes the corresponding task based on the second request, the method further includes a step in which the data storage device sends confirmation information to the data request device, and the confirmation information indicates that the data storage device has executed the task corresponding to the second request.
[0020] A third aspect of the embodiments of the present application provides a user data management method. This method is used by a user data management system for managing user data. The system includes a data request device, a data storage device, and a blockchain platform. When the data request device needs to access the data storage device, the user data management system performs corresponding operations. Specifically, the method includes the step that the blockchain platform receives a first request sent by the data request device, where the first request indicates that the data request device needs to access the data storage device, and the first request includes the signature information and access type of the data request device. The blockchain platform determines whether the data request device can access the data storage device based on the signature information and access type of the data request device. The blockchain platform sends first permission information to the data request device, and the first permission information indicates whether the data request device can access the data storage device. The blockchain platform receives an access verification request sent by the data storage device, and the access verification request indicates that the data request device sends a second request to the data storage device. When the blockchain platform determines that the data request device can access the data storage device, the blockchain platform sends second permission information to the data storage device, and the second permission information indicates that the data storage device can execute the task corresponding to the second request.
[0021] Before accessing the data storage device, the data request device needs to obtain confirmation from the blockchain platform that the data request device has the corresponding permission. Since the blockchain platform has functions such as decentralization and tamper prevention, the blockchain platform with authentication and authorization functions has no risk of single point of failure, and even if the blockchain platform is attacked by the network, the lost data is relatively small. As a result, the security of user data is improved. In another aspect, the first request includes an access type, and the access information is further refined, so that the blockchain platform can more accurately determine the permission corresponding to the first request.
[0022] In a possible implementation of the third aspect, after the blockchain platform sends the second permission information to the data storage device, the method further includes the step of the blockchain platform receiving the response information sent by the data storage device, where the response information indicates that the data storage device has executed the task corresponding to the second request. The blockchain platform records the task corresponding to the second request, executed by the data storage device, in the distributed ledger based on the response message.
[0023] In this possible implementation, since transactions such as access to user data are recorded in the distributed ledger, user data is not completely managed by the mobile communication network provider. The user has full permission to acknowledge and manage the user's personal data, and the user can know whether the mobile communication network provider uses the user information appropriately and effectively protects the user information.
[0024] In a possible implementation of the third aspect, when the access type is data reading, the first permission information includes an access address.
[0025] The fourth aspect of the present application provides a data request device. The data request device has a function of implementing the method in any one of the first aspect or a possible implementation form of the first aspect. This function may be implemented by hardware or by hardware that executes corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned functions, for example, a first transmission module.
[0026] The fifth aspect of the present application provides a data storage device. The data storage device has a function of implementing the method in any one of the second aspect or a possible implementation form of the second aspect. This function may be implemented by hardware or by hardware that executes corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned functions, for example, a first reception module.
[0027] The sixth aspect of the present application provides a blockchain platform device. The blockchain platform device has a function of implementing the method in any one of the third aspect or a possible implementation form of the third aspect. This function may be implemented by hardware or by hardware that executes corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned functions, for example, a first reception module.
[0028] The seventh aspect of the present application provides a data request device. The data request device includes at least one processor, a memory, an input / output (I / O) interface, and computer-executable instructions stored in the memory and executable on the processor. When the computer-executable instructions are executed by the processor, the processor executes the method in any one of the first aspect or a possible implementation form of the first aspect.
[0029] The eighth aspect of the present application provides a data storage device. The data storage device includes at least one processor, a memory, an input / output (I / O) interface, and computer-executable instructions stored in the memory and executable on the processor. When the computer-executable instructions are executed by the processor, the processor executes the method in any one of the second aspect or a possible implementation form of the second aspect.
[0030] The ninth aspect of the present application provides a blockchain platform device. Blockchain platform The device includes at least one processor, a memory, an input / output (I / O) interface, and computer-executable instructions stored in the memory and executable on the processor. When the computer-executable instructions are executed by the processor, the processor executes the method in any one of the third aspect or a possible implementation form of the third aspect.
[0031] The tenth aspect of the present application provides a computer-readable storage medium storing one or more computer-executable instructions. When the computer-executable instructions are executed by the processor, the processor executes the method in any one of the first aspect or a possible implementation form of the first aspect.
[0032] The eleventh aspect of the present application provides a computer-readable storage medium storing one or more computer-executable instructions. When the computer-executable instructions are executed by the processor, the processor executes the method in any one of the second aspect or a possible implementation form of the second aspect.
[0033] The twelfth aspect of the present application provides a computer-readable storage medium storing one or more computer-executable instructions. When the computer-executable instructions are executed by the processor, the processor executes the method in any one of the third aspect or a possible implementation form of the third aspect.
[0034] A thirteenth aspect of the present application provides a computer program product storing one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes the method in any one of the first aspect or a possible implementation form of the first aspect.
[0035] A fourteenth aspect of the present application provides a computer program product storing one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes the method in any one of the second aspect or a possible implementation form of the second aspect.
[0036] A fifteenth aspect of the present application provides a computer program product storing one or more computer-executable instructions. When the computer-executable instructions are executed by a processor, the processor executes the method in any one of the third aspect or a possible implementation form of the third aspect.
[0037] A sixteenth aspect of the present application provides a chip system. The chip system includes at least one processor, and the at least one processor is configured to implement the function in any one of the first aspect or a possible implementation form of the first aspect. In a possible design, the chip system may further include a memory. The memory is configured to store program instructions and data required for the artificial intelligence model processing device. The chip system may include a chip, or may include a chip and other individual components.
[0038] The 17th aspect of the present application provides a chip system. The chip system includes at least one processor, and the at least one processor is configured to implement the functions in any one of the 2nd aspect or the possible implementation forms of the 2nd aspect. In a possible design, the chip system may further include a memory. The memory is configured to store program instructions and data required for an artificial intelligence model-based data processing device. The chip system may include a chip, or may include a chip and other individual components.
[0039] The 18th aspect of the present application provides a chip system. The chip system includes at least one processor, and the at least one processor is configured to implement the functions in any one of the 3rd aspect or the possible implementation forms of the 3rd aspect. In a possible design, the chip system may further include a memory. The memory is configured to store program instructions and data required for an artificial intelligence model-based data processing device. The chip system may include a chip, or may include a chip and other individual components.
[0040] According to the above technical solutions, it can be understood that the embodiments of the present application have the following advantages.
[0041] In the embodiments of the present application, when a data request device needs to execute an operation on data, the data request device needs to obtain the first permission information sent by the blockchain platform in order to avoid the risk of single-point failure and attack from the network and have high data security. In another aspect, since the first request sent by the data request device includes the signature information of the data request device, it is guaranteed that this operation is permitted by the user, and it is guaranteed that the user can know whether the mobile communication network provider is properly using the user information, effectively protecting the user information for security.
Brief Description of the Drawings
[0042]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Best Mode for Carrying Out the Invention
[0043] Embodiments of the present application provide a user data management method and related devices to improve user information security.
[0044] The following describes embodiments of the present application with reference to the accompanying drawings. It is obvious that the described embodiments are only part of, not all of, the embodiments of the present application. Those skilled in the art will recognize that the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems due to the development of technology and the emergence of new scenarios.
[0045] In the specification, claims, and accompanying drawings of the present application, terms such as "first", "second", etc. are intended to distinguish similar objects and do not necessarily indicate a specific order or sequence. Since such terms are interchangeable in appropriate situations, it should be understood that the embodiments described in this specification can be implemented in an order other than the order illustrated or described in this specification. Further, the terms "including" and "having" and any other variations are intended to be non-exclusive inclusion. For example, a process, method, system, product, or device that includes a list of steps or units is not necessarily limited to the explicitly listed steps or units, and can include other steps or units that are not explicitly listed and are not specific to such a process, method, product, or device.
[0046] User data management is one of the most central functions of a mobile communication network. The provision of user services and the normal operation of the network need to depend on user data management entities and related procedures. The user data management entity of a mobile network stores user and service subscription-related data, key information, etc., and serves as a key for implementing user authentication, authorization, and access control.
[0047] In the current core network architectures from 2G to 5G, each user has a lot of information such as subscription information, key information, and service information. User information is processed in a centralized single-point user data management device. The user data management device is connected to another control plane network entity or application server to provide data access and fetch services. As shown in Figure 1, for example, the user data management entities in 2G, 3G, 4G, and Internet Protocol Multimedia Subsystem (IMS) architectures are the Home Location Register (HLR) and the Home Subscriber Server (HSS), and these entities interface with another control plane network function entity or application server to provide access and fetch services. As shown in Figure 2, for example, in the core network architecture of the 5G network, user information is managed by Unified Data Management (UDM). UDM manages network user data in a single element and may be paired with a user data repository. The user data repository stores user information. UDM is located on the control plane.
[0048] Based on the aforementioned mobile communication network, the user data management method in the embodiments of this application will be described below.
[0049] As shown in FIG. 3, an embodiment of the present application provides a user data management method. The user data management system in the present application includes a data request device, a blockchain platform, and a data storage device. The data request device is a device that needs to execute an operation corresponding to user data, and may be a device such as a Data Subject (DS), a Data Controller (DC), and a Data Processor (DP), or may be a user device, an access network device, and a core network element. The user device may be a terminal device such as a notebook computer, a tablet computer, a computer, an LTE assistant terminal, an NR assistant terminal, an assistant, a semi-active tag, an active tag, a wireless relay station, an LTE mobile phone, an NR mobile phone, etc. The access network device may be an access network device such as a macro base station, a pole base station, a long term evolution (LTE) base station, an evolved NodeB (eNB), a wireless Relay station, a Femto base station, a Pico base station, and a next generation NodeB (gNB). The core network element may be a core network element such as an authentication server or a session management server. The embodiment of the present application may be used in an existing 5G system, and may also be used in various future communication systems and scenarios such as the Internet of Vehicles, large-scale user access, satellite communication, and cellular communication.
[0050] The blockchain platform is configured to store data operations, policy management transactions, and data pointers. The data pointer points to user data stored in a data storage device. Specifically, in one aspect, the blockchain platform implements decentralization and implements access authentication, authorization, and access control logic. In another aspect, all data operations and policy management are recorded in an immutable distributed ledger. The access record includes the storage address of the personal user data and the access policy. In the embodiments of the present application, by using functions such as decentralization, tamper resistance, traceability, and transparency of the blockchain platform, the centralized trust mode is eliminated. Specifically, the blockchain platform functions as an authentication and authorization server, and the blockchain platform executes authentication and authorization for all operations of the data request device. Furthermore, the blockchain Platform The smart contract deployed thereon is responsible for automatic access control management, and the blockchain Platform is responsible for an immutable logging system and is configured to record any access operation to the data within the chain.
[0051] The data storage device is configured to store the user's personal data, and since the user's personal data is not stored in the blockchain platform, it solves the "blockchain expansion problem", "privacy problem", and "problem of forgotten rights" caused by preventing data tampering of the blockchain platform.
[0052] In the embodiments of the present application, the user device can initiate an access request for user data, and the operator network function device, that is, the data control device DC or the data processing device DP, can also initiate an access request for user data. The details will be described individually below.
[0053] 1. The user device starts an operation request for user data.
[0054] As shown in FIG. 4, the procedure of the user data management method in an embodiment of the present application includes the following steps.
[0055] In 401, the user device sends a third request to the data request device.
[0056] When the user device requests the data storage device to execute a corresponding task, the user device sends a third request to the data request device. The third request indicates that the data request device sends the first request to the blockchain platform, and the third request includes the signature information of the user device.
[0057] Specifically, as shown in FIG. 5, in a possible implementation form, when a user needs to open an account, the following steps may be executed.
[0058] In step a, the user device, that is, the data subject, sends an account opening request to the Customer Relation Management (CRM) device or the Business Operation Support System (BOSS) of the mobile service provider. The account opening request indicates that the user needs to create a new user account, and the account opening request includes the user information corresponding to the user.
[0059] In step b, the CRM device receives the account opening request sent by the user device, and then executes user data verification based on the user information in the account opening request. If the user data verification for the user's user information is successful, that is, if the preset user conditions are met, for example, if the user's user information is accurate and valid, or if the user's user information complies with the relevant laws and regulations, the CRM device creates a customer record for the user, and the CRM device sends synchronization information to the BOSS, whereby the BOSS synchronizes the user information with the CRM device based on the synchronization information.
[0060] In step c, the BOSS receives the synchronization information sent by the CRM, synchronizes the user information with the CRM device based on the synchronization information, then the BOSS creates a customer data record, and sends synchronization success information to the CRM, whereby the CRM transfers the synchronization success information to the user device, and the synchronization success information indicates that the user data has been generated normally and the CRM device has been synchronized with the BOSS normally.
[0061] In step d, the CRM device receives the synchronization success information sent by the BOSS, transfers the synchronization success information to the user device, and the synchronization success information sent to the user device can trigger the user device to start a transaction request, that is, a third request.
[0062] In step e, the user device receives the synchronization success information sent by the CRM device, and then the user device starts a transaction request to the CRM device and the BOSS, and the transaction request indicates that the BOSS starts a transaction registry Treg, that is, a first request, to the blockchain platform.
[0063] Specifically, as shown in FIG. 6, in a possible implementation form, when a user needs to delete an account, the following steps, that is, the user device sends an account deletion request to data request devices such as a CRM device and a BOSS, and the account deletion request is a third request, may be executed.
[0064] Specifically, as shown in FIG. 7, in a possible implementation form, when a user needs to access personal user data, the following steps, that is, the user device sends a data reading request to data request devices such as a CRM device and a BOSS, and the data reading request is a third request, may be executed.
[0065] At 402, the data request device sends a first request to the blockchain platform.
[0066] The data request device sends the first request to the blockchain platform. The first request indicates that the data request device needs to access the data storage device. The first request includes the signature information and access type of the data request device. The signature information of the data request device is used by the blockchain platform to determine the permission corresponding to the first request.
[0067] In the present embodiment of the present application, the access type may be data writing shown in FIG. 5, data deletion shown in FIG. 6, and data reading shown in FIG. 7. In addition, the access type in this embodiment of the present application may alternatively be another type, such as data modification. This is not particularly limited in this specification.
[0068] In this embodiment of the present application, the first request includes signature information and access type of the data request device. Additionally, in this embodiment of the present application, the first request may include user device information or related information regarding a task that the user device requests to execute on the data storage device. For example, when the access type is data writing, the first request further includes an access address, and the access address may be a data pointer. This is not particularly limited in this specification.
[0069] In this embodiment of the present application, the signature information of the data request device may include the signature information of the data request device, or the signature information of the user device, or the electronic signature information of the data request device and the signature information of the user device, or other information that can indicate the data request device or the user device. This is not particularly limited in this specification. In this embodiment of the present application, the signature information may be an electronic signature or identification information such as an ID. This is not particularly limited in this specification.
[0070] In this embodiment of the present application, the data request device is a device other than the user device, for example, a core network element or an access network device. Additionally, the data request device may alternatively be a user device such as a terminal. When the data request device is a user device, step 401 is not executed, and the user device directly sends the first request to the blockchain platform. This is not particularly limited in this specification.
[0071] Specifically, as shown in FIG. 5, in a possible implementation form, when a user needs to open an account, the following steps may be executed, that is, after a data request device, such as BOSS, receives a transaction started by a user device, BOSS starts a transaction registry Treg request to the blockchain platform, that is, the first request. The transaction Treg request, that is, the first request, includes user information, a data pointer, an access policy, that is, an access type, and the user's digital signature. The digital signature is used by the blockchain platform to determine whether the request was started by the user, that is, to determine the reliability of the first request, and then to determine whether the first request is known to the user and confirmed by the user, so as to determine the permission corresponding to the first request.
[0072] Specifically, as shown in FIG. 6, in a possible implementation form, when a user needs to delete an account, the following steps may be executed, that is, a data request device, such as a CRM device and BOSS, deletes the user relationship and the user's subscription relationship, and sends a Tdereg request to the blockchain platform, where the Tdereg request includes the user's signature information and access type, and the Tdereg request is the first request.
[0073] Specifically, as shown in FIG. 7, in a possible implementation form, when a user needs to access personal user data, the following steps may be executed, that is, a data control device and a data processing device, such as a CRM device and BOSS, send a Tdata data read request, that is, the first request, to the blockchain platform.
[0074] In 403, the blockchain platform sends the first permission information to the data request device.
[0075] When the blockchain platform determines that the data request device can access the data storage device based on the signature information, the blockchain platform sends the first permission information to the data request device, and the first permission information indicates whether the data request device can access the data storage device.
[0076] In a possible implementation, when the access type is data reading, the first permission information further includes an access address, and the access address may be a data pointer.
[0077] Specifically, after receiving the first request sent by the data request device, the blockchain platform determines the permission of the first request based on the signature information and the access type of the data request device included in the first request. The digital signature information has unique authenticity and reliability. Therefore, the digital signature can be used to uniquely determine the data request device. The digital signature is used by the blockchain platform to determine whether the request was initiated by the user device, that is, to determine the reliability of the first request, and to determine whether the first request is known to the user device and confirmed by the user device, so as to determine the permission corresponding to the first request, that is, to determine whether the data request device sending the first request has the permission to access the data storage device, and enable the data storage device to execute the corresponding task. If the blockchain platform determines that the data request device can access the data storage device, that is, Data request device has the corresponding permission, the blockchain platform sends the first permission information to the data request device, and the first permission information indicates that the data request device can access the data storage device, that is, the first request has the permission corresponding to the task corresponding to the first request.
[0078] Specifically, as shown in FIG. 5, in a possible implementation form, when a user needs to open an account, the following step, that is, the blockchain platform may execute the step of checking the relevant information included in the transaction Treg request, which includes whether the registration and account opening transaction was initiated by the user device, the access policy corresponding to the request, that is, the access type, whether the signature is a valid digital signature of the user device, and the like. After it is determined that the user has the relevant permissions, for example, the user device has the permission to read and write all personal user data and policy data, the blockchain platform sends the first permission information to the data request device.
[0079] Specifically, as shown in FIG. 6, in a possible implementation form, when a user needs to delete an account, the following step, that is, the blockchain platform may execute the step of checking the relevant information included in the transaction Tdereg request, which includes whether the account deletion transaction was initiated by the user device, the access type corresponding to the request, whether the signature is a valid digital signature of the user, and the like. After it is determined that the user has the relevant permissions, for example, the user has the permission to delete all personal user data and policy data, the blockchain platform sends the first permission information to the data request device.
[0080] Specifically, as shown in FIG. 7, in a possible implementation, when a user needs to read personal user data, the following steps, i.e., the step where the blockchain platform checks the relevant information included in the transaction Tdata request, may be executed. This includes whether the access transaction was initiated by the user, whether the signature is a valid digital signature of the user, etc. After determining that the user has the relevant permissions, for example, determining that the user has permission to access all personal user data and policy data, the blockchain platform sends the first permission information to the data request device. The first permission information includes an access address, and the address may be a data pointer.
[0081]
[0082] After the data request device receives the first permission information, if the first permission information indicates that the data request device has permission to access the data storage device, the data request device knows that the blockchain platform has determined that the data request device can access the data storage device. Then, the data request device sends a second request to the data storage device. The second request indicates that the data storage device should execute a task corresponding to the second request. The second request includes the user's signature information.
[0083] Specifically, as shown in FIG. 5, in a possible implementation, when a user needs to open an account, the following step, i.e., the step where the data request device sends a second request to the data storage device. The second request includes the user's signature information, data pointer Type which task information is included, and the second request indicates that the data storage device should write data for the user, and the data address is provided by the data pointer. The step may be executed.
[0084] Specifically, as shown in FIG. 6, in a possible implementation form, when a user needs to delete an account, the following steps are performed, that is, the data request device sends a second request to the data storage device. The second request includes the user's signature information and data point Type which includes any task information, and the second request indicates that the data storage device deletes the user's user data, and the data address may be provided by the data pointer. This step may be executed.
[0085] Specifically, as shown in FIG. 7, in a possible implementation form, when a user needs to access personal user data, the following steps are performed, that is, the data request device sends a second request to the data storage device. The second request includes the user's signature information and data point Type which includes any task information, and the second request indicates that the data storage device sends the user data corresponding to the second request to the data request device, and the data address may be provided by the data pointer. This step may be executed.
[0086] The data storage device sends an access verification request to the blockchain platform.
[0087] Since the second request indicates that the data storage device executes the corresponding task, after the data storage device receives the second request sent by the data request device, the data storage device needs to determine whether the second request has permission for the task. In this case, the data storage device sends an access verification request to the blockchain platform. The access verification request indicates that the data request device sends the second request to the data storage device, and the access verification request includes the related information of the second request. Thereby, the blockchain platform determines the permission information of the second request based on the related information of the second request.
[0088] In 406, the blockchain platform sends the second permission information to the data storage device.
[0089] After the blockchain platform receives the access verification request sent by the data storage device, the blockchain platform determines whether the second request has the corresponding permission based on the relevant information of the second request in the access verification request, that is, whether the data storage device can access the data storage device. Next, the blockchain platform sends the second permission information to the data storage device, and the second permission information can indicate whether the data storage device can execute the task corresponding to the second request.
[0090] In 407, the data storage device receives the second permission information and executes the task corresponding to the second request.
[0091] The data storage device receives the second permission information sent by the blockchain platform, and the second permission information indicates whether the data storage device can execute the task corresponding to the second request, that is, whether the data storage device can execute the task corresponding to the second request by the permission of the user device corresponding to the signature information included in the second request. If the second permission information indicates that the data storage device can execute the task corresponding to the second request, the data storage device can execute the task corresponding to the second request after receiving the second permission information.
[0092] Specifically, as shown in FIG. 5, in a possible implementation form, when a user needs to open an account, the following steps, that is, after the data storage device receives the second permission information and determines that it can execute the task corresponding to the second request, based on the data pointer in the second request, the step of writing the corresponding data, where the data address is provided by the data pointer, may be executed.
[0093] Specifically, as shown in FIG. 6, in a possible implementation form, when a user needs to delete an account, the following steps, that is, after the data storage device receives the second permission information and determines that it can execute the task corresponding to the second request, based on the data pointer in the second request, the step of deleting the user's user data, where the data address can be provided by the data pointer, may be executed.
[0094] Specifically, as shown in FIG. 7, in a possible implementation form, when a user needs to access personal user data, the following steps, that is, after the data storage device receives the second permission information and determines that it can execute the task corresponding to the second request, based on the second request, the step of sending the user data corresponding to the second request to the data request device, where the data address can be provided by the data pointer, may be executed.
[0095] At 408, the data storage device sends the response information to the blockchain platform.
[0096] After completing the task corresponding to the second request, the data storage device sends the response information to the blockchain platform. The response information indicates that the data storage device has completed the task corresponding to the second request. The response information includes related information of the task, such as the result information of the task, the identification information of the user who initiated the task, the execution policy of the task, and the related information of the data storage device that executes the task.
[0097] At 409, the blockchain platform receives the response information and records the response information in the distributed ledger.
[0098] The blockchain platform receives the response information sent by the data storage device, and the response information indicates that the data storage device has completed the task corresponding to the second request. Accordingly, the response information includes related information of the task, such as the result information of the task, the identification information of the user who starts the task, the execution policy of the task, and the related information of the data storage device that executes the task. Next, the blockchain platform can broadcast the related information of the task to each node of the blockchain platform. After all nodes obtain consensus, the blockchain platform records the related information of the task in an immutable distributed ledger on the blockchain platform. Each node of the blockchain platform records the complete related information of the task, and the storage of each node is independent and at the same level.
[0099] Specifically, as shown in FIG. 5, in a possible implementation form, when a user needs to open an account, the following steps, that is, the blockchain platform confirms and receives the response information sent by the data storage device, and records the transaction Treg in the distributed ledger, may be executed.
[0100] Specifically, as shown in FIG. 6, in a possible implementation form, when a user needs to delete an account, the following steps, that is, the blockchain platform confirms and receives the response information sent by the data storage device, and records the transaction Tdereg in the distributed ledger, may be executed.
[0101] [[ID=ID=12]]Specifically, as shown in FIG. 7, in a possible implementation form, when a user needs to access personal user data, the following steps, that is, the blockchain platform confirms and receives the response information sent by the data storage device, and records the transaction Tdata in the distributed ledger, may be executed.
[0102] At 410, the data storage device sends the confirmation information to the data request device.
[0103] The data storage device sends a confirmation message to the data request device, and the confirmation message indicates that the data storage device has completed the task corresponding to the second request.
[0104] In this embodiment of the present application, the data storage device may first execute step 408 and then execute step 410, or first execute step 410 and then execute step 408, or execute the two steps simultaneously. This is not particularly limited in this specification.
[0105] At 411, the data storage device sends the task result information to the user device.
[0106] The data storage device sends the task result information to the user device, and the task result information indicates whether the data storage request device has completed the task corresponding to the 2 request.
[0107] In this embodiment of the present application, the user device initiates a request to access user data. In addition, the operator network function device, that is, the data control device DC or the data processing device DP, can also initiate a request to access user data. Details will be described below.
[0108] 2. The operator network function device can initiate an operation request for user data.
[0109] As shown in FIG. 8, the procedure of the user data management method in an embodiment of the present application includes the following steps.
[0110] At 801, the data request device sends a first request to the blockchain platform.
[0111] The data request device sends a first request to the blockchain platform. The first request indicates that the data request device needs to access the data storage device. The first request includes signature information, user information, and access type of the data request device, i.e., the network function device. The user information is information about the user corresponding to the user data that the network function device needs to access. The signature information of the data request device is used by the blockchain platform to determine the permission corresponding to the first request.
[0112] In this embodiment of the present application, the access type may be data writing, data deletion, and data reading. In addition, the access type in this embodiment of the present application may alternatively be another type. This is not particularly limited herein.
[0113] In this embodiment of the present application, the first request includes signature information and access type of the data request device. In addition, in this embodiment of the present application, the first request may include user device information or related information about the task that the user device requests to execute on the data storage device. For example, when the access type is data writing, the first request may further include an access address, and the access address may be a data pointer. This is not particularly limited herein.
[0114] In this embodiment of the present application, the signature information may be an electronic signature or identification information such as an ID. This is not particularly limited herein.
[0115] In 802, the blockchain platform sends the first permission information to the data request device.
[0116] When the blockchain platform determines that the data request device can access the data storage device based on the signature information, the blockchain platform sends the first permission information to the data request device, and the first permission information indicates whether the data request device can access the data storage device.
[0117] In a possible implementation, when the access type is data reading, the first permission information further includes an access address, and the access address may be a data pointer.
[0118] Specifically, after receiving the first request sent by the data request device, the blockchain platform determines the permission of the first request based on the signature information and access type of the data request device included in the first request. The digital signature information has unique authenticity and reliability. Therefore, the digital signature can be used to uniquely determine the data request device. By using the digital signature, the blockchain platform determines whether the request was initiated by the user device, that is, determines the reliability of the first request, and determines whether the first request is known to the user device and confirmed by the user device, and determines the permission corresponding to the first request, that is, determines whether the data request device sending the first request has permission to access the data storage device, and enables the data storage device to execute the corresponding task. After the blockchain platform determines that the data request device can access the data storage device, that is, the first request has the corresponding permission, the blockchain platform sends the first permission information to the data request device, and the first permission information indicates that the data request device can access the data storage device, that is, the first request has the permission corresponding to the task corresponding to the first request.
[0119] In 803, the data request device sends a second request to the data storage device.
[0120] After the data request device receives the first permission information, if the first permission information indicates that the data request device has permission to access the data storage device, the data request device knows that the blockchain platform has determined that the data request device can access the data storage device. Then, the data request device sends a second request to the data storage device, and the second request indicates that the data storage device executes a task corresponding to the second request. The second request includes the signature information of the data request device.
[0121] In 804, the data storage device sends an access verification request to the blockchain platform.
[0122] Since the second request indicates that the data storage device executes the corresponding task, after the data storage device receives the second request sent by the data request device, the data storage device needs to determine whether the second request has permission for the task. In this case, the data storage device sends an access verification request to the blockchain platform, and the access verification request indicates that the data request device sends a second request to the data storage device. The access verification request includes the related information of the second request. Thereby, the blockchain platform determines the permission information of the second request based on the related information of the second request.
[0123] In 805, the blockchain platform sends the second permission information to the data storage device.
[0124] After the blockchain platform receives an access verification request sent by a data storage device, the blockchain platform determines whether the second request has the corresponding permission based on the relevant information of the second request in the access verification request, that is, whether the data storage device can access the data storage device. Next, the blockchain platform sends the second permission information to the data storage device, and the second permission information can indicate whether the data storage device can execute the task corresponding to the second request.
[0125] In 806, the data storage device receives the second permission information and executes the task corresponding to the second request.
[0126] The data storage device receives the second permission information sent by the blockchain platform, and the second permission information indicates whether the data storage device can execute the task corresponding to the second request, that is, whether the data storage device can execute the task corresponding to the second request by the permission of the user device corresponding to the signature information included in the second request. If the second permission information indicates that the data storage device can execute the task corresponding to the second request, the data storage device can execute the task corresponding to the second request after receiving the second permission information.
[0127] In 807, the data storage device sends response information to the blockchain platform.
[0128] After completing the task corresponding to the second request, the data storage device sends response information to the blockchain platform. The response information indicates that the data storage device has completed the task corresponding to the second request. The response information includes related information of the task, such as result information of the task, identification information of the user who starts the task, execution policy of the task, and related information of the data storage device that executes the task.
[0129] In 808, the blockchain platform receives response information and records the response information in the distributed ledger.
[0130] The blockchain platform receives response information sent by the data storage device, and the response information indicates that the data storage device has completed a task corresponding to the second request. Accordingly, the response information includes related information of the task, such as the result information of the task, the identification information of the data request device that starts the task, the execution policy of the task, and the related information of the data storage device that executes the task. Next, the blockchain platform can broadcast the related information of the task to each node of the blockchain platform. After all nodes obtain consensus, the blockchain platform records the related information of the task in an immutable distributed ledger on the blockchain platform. Each node of the blockchain platform records the complete related information of the task, and the storage of each node is independent and at the same level.
[0131] In 809, the data storage device sends confirmation information to the data request device.
[0132] The blockchain platform sends a confirmation message to the data request device, and the confirmation message indicates that the data storage device has completed a task corresponding to the second request.
[0133] In this embodiment of the present application, the data storage device may first execute step 807 and then execute step 809, or first execute step 809 and then execute step 807, or execute the two steps simultaneously. This is not particularly limited in this specification.
[0134] Hereinafter, the data request device in the embodiments of the present application will be described. FIG. 9 provides a data request device 900 according to an embodiment of the present application. The data request device may be the data request device of FIGS. 4 to 8. The data request device 900 includes the following modules.
[0135] The first transmission module 901 is configured to send a first request to the blockchain platform, where the first request indicates that the data request device needs to access the data storage device, and the first request includes the signature information and access type of the data request device. For specific implementation forms, refer to step 402 in FIG. 4 where the data request device sends the first request to the blockchain platform, and step 801 in FIG. 8 where the data request device sends the first request to the blockchain platform. Details will not be described again here.
[0136] The first reception module 902 is configured to receive the first permission information sent by the blockchain platform, where the first permission information indicates whether the data request device has permission to access the data storage device, and the permission is related to the signature information and access type of the data request device. For specific implementation forms, refer to step 403 in FIG. 4 where the blockchain platform sends the first permission information to the data request device, and step 802 in FIG. 8 where the blockchain platform sends the first permission information to the data request device. Details will not be described again here.
[0137] The second transmission module 903 is configured to send a second request to the data storage device when the first permission information indicates that the data request device has permission to access the data storage device, and the second request includes an access address. For specific implementation forms, refer to step 404 in FIG. 4 where the data request device sends a second request to the data storage device, and step 803 in FIG. 8 where the data request device sends a second request to the data storage device. Details are not described again here.
[0138] The second reception module 904 is configured to receive confirmation information sent by the data storage device, and the confirmation information indicates that the data storage device has executed a task corresponding to the second request. For specific implementation forms, refer to step 410 in FIG. 4 where the data storage device sends the confirmation information to the data request device, and step 809 in FIG. 8 where the data storage device sends the confirmation information to the data request device. Details are not described again here.
[0139] The third reception module 905 is configured to receive a third request sent by the user device, and the third request indicates that the data request device sends a first request to the blockchain platform. For specific implementation forms, refer to step 401 in FIG. 4 where the user device sends a third request to the data request device. Details are not described again here.
[0140] In this embodiment, the data request device 900 can execute the operations executed by the data request device in the embodiment shown in any one of FIGS. 4 to 8. Details are not described again here.
[0141] Hereinafter, the data storage device in the embodiments of the present application will be described. FIG. 10 provides a data storage device 1000 according to an embodiment of the present application. The data storage device may be the data storage device of FIGS. 4 to 8. The data storage device 1000 includes the following modules.
[0142] The first receiving module 1001 is configured to receive a second request from a data requesting device, where the second request includes an access address. For specific implementation forms, refer to step 404 in FIG. 4 where the data requesting device sends a second request to the data storage device, and step 803 in FIG. 8 where the data requesting device sends a second request to the data storage device. Details will not be described again here.
[0143] The first transmitting module 1002 is configured to send an access verification request to the blockchain platform, where the access verification request indicates that the data requesting device sends a second request to the data storage device. For specific implementation forms, refer to step 405 in FIG. 4 where the data storage device sends an access verification request to the blockchain platform, and step 804 in FIG. 8 where the data storage device sends an access verification request to the blockchain platform. Details will not be described again here.
[0144] The second receiving module 1003 is configured to receive second permission information sent by the blockchain platform, where the second permission information indicates whether the data storage device can execute a task corresponding to the second request. For specific implementation forms, refer to step 406 in FIG. 4 where the blockchain platform sends the second permission information to the data storage device, and step 805 in FIG. 8 where the blockchain platform sends the second permission information to the data storage device. Details will not be described again here.
[0145] When the second permission information indicates that the data storage device can execute the task corresponding to the second request, the execution module 1004 is configured to execute the corresponding task based on the second request. For specific implementation forms, refer to step 407 in FIG. 4 where the data storage device receives the second permission information and executes the task corresponding to the second request, and step 806 in FIG. 8 where the data storage device receives the second permission information and executes the task corresponding to the second request. Details are not described again here.
[0146] The second transmission module 1005 is configured to transmit response information to the blockchain platform, and the response information indicates that the data storage device has executed the task corresponding to the second request. For specific implementation forms, refer to step 408 in FIG. 4 where the data storage device transmits the response information to the blockchain platform, and step 807 in FIG. 8 where the data storage device transmits the response information to the blockchain platform. Details are not described again here.
[0147] The third transmission module 1006 is configured to transmit confirmation information to the data request device, and the confirmation information indicates that the data storage device has executed the task corresponding to the second request. For specific implementation forms, refer to step 410 in FIG. 4 where the data storage device transmits the confirmation information to the data request device, and step 809 in FIG. 8 where the data storage device transmits the confirmation information to the data request device. Details are not described again here.
[0148] In this embodiment, the data storage device 1000 can execute the operations executed by the data storage device in the embodiment shown in any one of FIGS. 4 to 8. Details are not described again here.
[0149] Hereinafter, the blockchain platform device in the embodiments of the present application will be described. FIG. 11 provides a blockchain platform device 1100 according to an embodiment of the present application. The blockchain platform device may be the blockchain platform device of FIGS. 4 to 8. The blockchain platform device 1100 includes the following modules.
[0150] The first receiving module 1101 is configured to receive a first request sent by a data request device, where the first request indicates that the data request device needs to access a data storage device, and the first request includes signature information and an access type of the data request device. For specific implementation forms, refer to step 402 in FIG. 4 where the data request device sends the first request to the blockchain platform, and step 801 in FIG. 8 where the data request device sends the first request to the blockchain platform. Details will not be described again here.
[0151] The determination module 1102 is configured to determine whether the data request device can access the data storage device based on the signature information and the access type of the data request device. For specific implementation forms, refer to step 403 in FIG. 4 where the blockchain platform sends the first permission information to the data request device, and step 802 in FIG. 8 where the blockchain platform sends the first permission information to the data request device. Details will not be described again here.
[0152] The first transmission module 1103 is configured to transmit first permission information to the data request device, where the first permission information indicates whether the data request device can access the data storage device. For specific implementation forms, refer to step 403 in FIG. 4 where the blockchain platform transmits the first permission information to the data request device, and step 802 in FIG. 8 where the blockchain platform transmits the first permission information to the data request device. Details will not be elaborated here again.
[0153] The second receiving module 1104 is configured to receive an access verification request transmitted by the data storage device, where the access verification request indicates that the data request device transmits a second request to the data storage device. For specific implementation forms, refer to step 405 in FIG. 4 where the data storage device transmits the access verification request to the blockchain platform, and step 804 in FIG. 8 where the data storage device transmits the access verification request to the blockchain platform. Details will not be elaborated here again.
[0154] When the blockchain platform device determines that the data request device can access the data storage device, the second transmission module 1105 is configured to transmit second permission information to the data storage device, where the second permission information indicates that the data storage device can execute a task corresponding to the second request. For specific implementation forms, refer to step 406 in FIG. 4 where the blockchain platform transmits the second permission information to the data storage device, and step 805 in FIG. 8 where the blockchain platform transmits the second permission information to the data storage device. Details will not be elaborated here again.
[0155] The third receiving module 1106 is configured to receive response information transmitted by the data storage device, where the response information indicates that the data storage device has executed a task corresponding to the second request. For specific implementation forms, refer to step 408 in FIG. 4 where the data storage device transmits the response information to the blockchain platform, and step 807 in FIG. 8 where the data storage device transmits the response information to the blockchain platform. Details are not described again here.
[0156] The recording module 1107 is configured to record, in the distributed ledger, the task corresponding to the second request executed by the data storage device based on the response message. For specific implementation forms, refer to step 409 in FIG. 4 where the blockchain platform receives the response information and records the response information in the distributed ledger, and step 808 in FIG. 8 where the blockchain platform receives the response information and records the response information in the distributed ledger. Details are not described again here.
[0157] In this embodiment, the blockchain platform device 1100 can execute the operations executed by the blockchain platform device in the embodiment shown in any one of FIGS. 4 to 8. Details are not described again here.
[0158] FIG. 12 is a schematic diagram of the structure of a data request device according to an embodiment of the present application. The data request device 1200 can include one or more processors 1201 and a memory 1205. The memory 1205 stores one or more application programs and data. In some implementation solutions, the memory 1205 may be further integrated with the processor 1201. In some other implementation solutions, the memory is arranged outside the chip and connected to the processor 1201 via a circuit or an interface. The processor 1201 may be a central processing unit (CPU) (similarly, the CPU may be used as the processor of another device hereinafter, but the details will not be described again).
[0159] The memory 1205 may be a volatile memory or a persistent memory. The program stored in the memory 1205 can include one or more modules, and each module can include a series of instruction operations on the data request device. Further, the processor 1201 may be configured to communicate with the memory 1205 and execute a series of instruction operations in the memory 1205 on the data request device 1200.
[0160] The processor 1201 is configured to execute a computer program in the memory 1205, and as a result, the data request device 1200 is configured to send a first request to the blockchain platform by the data request device, the first request indicating that the data request device needs to access the data storage device, the first request including the signature information and access type of the data request device, and to receive the first permission information sent by the blockchain platform by the data request device, the first permission indicating whether the data request device has permission to access the data storage device, the permission being related to the signature information and access type of the data request device, and if the first permission information indicates that the data request device has permission to access the data storage device, the data request device is configured to send a second request to the data storage device, the second request including an access address. For specific embodiments, refer to steps 401 to 411 of the embodiment shown in FIG. 4 and steps 801 to 809 of the embodiment shown in FIG. 8. Details are not described again here.
[0161] The data request device 1200 may further include one or more power supplies 1202, one or more wired or wireless network interfaces 1203, one or more input / output interfaces 1204, and / or one or more operating systems such as Windows Server (trademark), Mac OS X (trademark), Unix (trademark), Linux (registered trademark), and FreeBSD (trademark).
[0162] The data request device 1200 can execute the operations performed by the data request device in the embodiment shown in any one of FIGS. 4 to 8. Details are not described again here.
[0163] FIG. 13 is a schematic diagram of the structure of a data storage device according to an embodiment of the present application. The data storage device 1300 can include one or more processors 1301 and a memory 1305. The memory 1305 stores one or more application programs or data.
[0164] The memory 1305 may be a volatile memory or a persistent memory. The program stored in the memory 1305 can include one or more modules, and each module can include a series of instruction operations on the data storage device. Further, the processor 1301 may be configured to communicate with the memory 1305 and execute a series of instruction operations in the memory 1305 on the data storage device 1300.
[0165] The processor 1301 is configured to execute a computer program in the memory 1305. As a result, the data storage device 1300 is configured to receive a second request of a data request device by the data storage device, the second request including an access address, and to send an access verification request to a blockchain platform by the data storage device, the access verification request being configured to indicate that the data request device sends a second request to the data storage device, and to receive second permission information sent by the blockchain platform by the data storage device, the second permission information being configured to indicate whether the data storage device can execute a task corresponding to the second request, and when the second permission information indicates that the data storage device can execute a task corresponding to the second request, the data storage device is configured to execute a corresponding task based on the second request. For specific embodiments, refer to steps 401 to 411 of the embodiment shown in FIG. 4 and steps 801 to 809 of the embodiment shown in FIG. 8. Details will not be described again here.
[0166] The data storage device 1300 can further include one or more power supplies 1302, one or more wired or wireless network interfaces 1303, one or more input / output interfaces 1304, and / or one or more operating systems such as Windows Server (trademark), Mac OS X (trademark), Unix (trademark), Linux (registered trademark), and FreeBSD (trademark).
[0167] In this embodiment, the data storage device 1300 can execute the operations performed by the data storage device of the embodiment shown in any one of FIGS. 4 to 8. Details will not be described again here.
[0168] FIG. 14 is a schematic diagram of the structure of a blockchain platform device according to an embodiment of the present application. The blockchain platform device 1400 can include one or more processors 1401 and a memory 1405. The memory 1405 stores one or more application programs or data.
[0169] The memory 1405 may be volatile memory or persistent memory. The program stored in the memory 1405 can include one or more modules, and each module can include a series of instruction operations on the blockchain platform device. Further, the processor 1401 may be configured to communicate with the memory 1405 and execute a series of instruction operations in the memory 1405 on the blockchain platform device 1400.
[0170] Processor 1401 is configured to execute a computer program in memory 1405, and as a result, blockchain platform device 1400 executes a first request sent by a data request device on the blockchain platform, the first request indicating that the data request device needs to access a data storage device, the first request including signature information and an access type of the data request device, and is configured to determine by the blockchain platform whether the data request device can access the data storage device based on the signature information and the access type of the data request device, and is configured to send first permission information to the data request device by the blockchain platform, the first permission information indicating whether the data request device can access the data storage device, and receives an access verification request sent by the data storage device by the blockchain platform, the access verification request indicating that the data request device sends a second request to the data storage device, and if the blockchain platform determines that the data request device can access the data storage device, sends second permission information to the data storage device by the blockchain platform, the second permission information indicating that the data storage device can execute a task corresponding to the second request. For specific embodiments, refer to steps 401 to 411 of the embodiment shown in FIG. 4 and steps 801 to 809 of the embodiment shown in FIG. 8. Details are not described again here.
[0171] The blockchain platform device 1400 can further include one or more power supplies 1402, one or more wired or wireless network interfaces 1403, one or more input / output interfaces 1404, and / or one or more operating systems such as Windows Server (trademark), Mac OS X (trademark), Unix (trademark), Linux (registered trademark), and FreeBSD (trademark).
[0172] The blockchain platform device 1400 can execute the operations performed by the blockchain platform device in the embodiment shown in any one of FIGS. 4 to 8. For details, it will not be described again here.
[0173] FIG. 15 is a schematic diagram of the structure of a user data management system 1500 according to an embodiment of the present application. The user data management system 1500 can include a data request device 1501, a data storage device 1502, and a blockchain platform device 1503. The data request device 1501 can execute the operations performed by the data request device in the embodiment shown in any one of FIGS. 4 to 8. The data storage device 1502 can execute the operations performed by the data storage device in the embodiment shown in any one of FIGS. 4 to 8. The blockchain platform device 1503 can execute the operations performed by the blockchain platform device in the embodiment shown in any one of FIGS. 4 to 8.
[0174] For the sake of simplicity of description, those skilled in the art will clearly understand that for the detailed operation processes of the foregoing systems, devices, and units, reference may be made to the corresponding processes in the embodiments of the foregoing methods. For details, it will not be described again here.
[0175] In some embodiments provided in this application, it will be understood that the disclosed systems, devices, and methods can also be implemented in other ways. For example, the described embodiments of the devices are merely examples. For example, the division into units is only a logical function division, and in actual embodiments, other divisions may be possible. For example, multiple units or components may be coupled or integrated into another system, some functions may be ignored, or may not be executed. Further, the shown or described mutual coupling or direct coupling or communication connection may be implemented via some interfaces. The indirect coupling or communication connection between devices or units may be implemented in an electrical, mechanical, or other form.
[0176] The units described as separate parts may or may not be physically separate, and the parts shown as units may or may not be physical units. In other words, they may be arranged in one place, or may be distributed over multiple network units. To achieve the objectives of the solution of the embodiments, some or all of the units may be selected based on actual requirements.
[0177] In addition, the functional units in the embodiments of this application may be integrated into one processing unit, each of the units may physically exist alone, or two or more units may be integrated into one unit. The integrated unit may be implemented in the form of hardware, or may be implemented in the form of a software functional unit.
[0178] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, the integrated unit may be stored in a computer-readable storage medium. Based on such an understanding, essentially, the technical solution of this application, or the part that contributes to the prior art, or all or part of the technical solution, may also be implemented in the form of a software product. The computer software product includes several instructions stored in a storage medium and used to instruct a computer device (which may be a personal computer, a server, a network device, etc.) to execute all or part of the steps of the method described in the embodiments of this application. The aforementioned storage medium includes any medium that can store program codes, such as a USB flash drive, a removable hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
Description of Reference Signs
[0179] 900 Data Request Device 901 First Transmission Module 902 First Reception Module 903 Second Transmission Module 904 Second Reception Module 905 Third Reception Module 1000 Data Storage Device 1001 First Reception Module 1002 First Transmission Module 1003 Second Reception Module 1004 Execution Module 1005 Second Transmission Module 1006 Third Transmission Module 1100 Blockchain Platform Device 1101 First Reception Module 1102 Judgment Module 1103 First Transmission Module 1104 Second Reception Module 1105 Second Transmission Module 1106 Third Receiving Module 1107 Recording Module 1200 Data Request Device 1201 Processor 1202 Power Supply 1203 Wired or Wireless Network Interface 1204 Input / Output Interface 1205 Memory 1300 Data Storage Device 1301 Processor 1302 Power Supply 1303 Wired or Wireless Network Interface 1304 Input / Output Interface 1305 Memory 1400 Blockchain Platform Device 1401 Processor 1402 Power Supply 1403 Wired or Wireless Network Interface 1404 Input / Output Interface 1405 Memory 1500 User Data Management System 1501 Data Request Device 1502 Data Storage Device 1503 Blockchain Platform
Claims
1. A user data management method, comprising: a step in which a data request device sends a first request to a blockchain platform, the first request indicating that the data request device needs to access a data storage device, the first request including signature information and an access type of the data request device, and the blockchain platform determines whether the first request was initiated by a user device and determines whether the first request is known and confirmed by the user device; a step in which the data request device receives first permission information sent by the blockchain platform, the first permission information indicating whether the data request device has permission to access the data storage device, the permission being related to the signature information and the access type of the data request device; a step in which, when the first permission information indicates that the data request device has permission to access the data storage device, the data request device sends a second request to the data storage device, the second request including an access address; The method comprising the above steps.
2. The access type includes data writing and data reading, when the access type is data writing, the first request further includes the access address, or when the access type is data reading, the first permission information includes the access address. The method according to claim 1.
3. After the step in which the data request device sends a second request to the data storage device, the method further includes: a step in which the data request device receives confirmation information sent by the data storage device, the confirmation information indicating that the data storage device has executed a task corresponding to the second request. The method according to claim 1.
4. Before the step in which the data request device sends a first request to the blockchain platform, the method includes: The step in which the data request device receives a third request transmitted by the user device, wherein the third request indicates that the data request device transmits the first request to the blockchain platform, further comprising the step of, the method according to claim 3.
5. The method according to claim 4, wherein the signature information of the data request device includes the signature information of the user device.
6. A user data management method, comprising: A step in which a data storage device receives a second request from a data request device, wherein the second request includes an access address; A step in which the data storage device transmits an access verification request to a blockchain platform, wherein the access verification request indicates that the data request device transmits the second request to the data storage device; A step in which the data storage device receives second permission information transmitted by the blockchain platform, wherein the second permission information indicates whether the data storage device can execute a task corresponding to the second request based at least on the permission of a user device corresponding to signature information included in the second request; When the second permission information indicates that the data storage device can execute the task corresponding to the second request, a step in which the data storage device executes the corresponding task based on the second request A method comprising.
7. After the step in which the data storage device executes the corresponding task based on the second request, the method further comprises: A step in which the data storage device transmits response information to the blockchain platform, wherein the response information indicates that the data storage device has executed the task corresponding to the second request, the method according to claim 6.
8. After the step in which the data storage device executes the corresponding task based on the second request, the method further comprises: A step in which the data storage device transmits confirmation information to the data request device, wherein the confirmation information indicates that the data storage device has executed the task corresponding to the second request, the method according to claim 6.
9. A user data management method, comprising: a step in which a blockchain platform receives a first request transmitted by a data request device, wherein the first request indicates that the data request device needs to access a data storage device, and the first request includes signature information and an access type of the data request device; a step in which the blockchain platform determines whether the first request was initiated by a user device and whether the first request is known and confirmed by the user device, and determines whether the data request device can access the data storage device based on the signature information and the access type of the data request device; a step in which the blockchain platform transmits first permission information to the data request device, wherein the first permission information indicates whether the data request device can access the data storage device; a step in which the blockchain platform receives an access verification request transmitted by the data storage device, wherein the access verification request indicates that the data request device transmits a second request to the data storage device; a step in which when the blockchain platform determines that the data request device can access the data storage device, the blockchain platform transmits second permission information to the data storage device, wherein the second permission information indicates that the data storage device can execute a task corresponding to the second request; The method comprising the above steps.
10. After the step in which the blockchain platform transmits the second permission information to the data storage device, the method further comprises: a step in which the blockchain platform receives response information transmitted by the data storage device, wherein the response information indicates that the data storage device has executed the task corresponding to the second request. The step in which the blockchain platform responds to the second request and records the task executed by the data storage device in a distributed ledger based on the response information The method according to claim 9, further comprising
11. The method according to claim 9, wherein when the access type is data reading, the first permission information includes an access address.
12. A data request device, A first transmission module configured to transmit a first request to a blockchain platform, wherein the first request indicates that the data request device needs to access a data storage device, the first request includes signature information and an access type of the data request device, and the blockchain platform determines whether the first request was initiated by a user device and whether the first request is known and confirmed by the user device; a first transmission module A first reception module configured to receive first permission information transmitted by the blockchain platform, wherein the first permission information indicates whether the data request device has permission to access the data storage device, and the permission is related to the signature information and the access type of the data request device; a first reception module A second transmission module configured to transmit a second request to the data storage device when the first permission information indicates that the data request device has permission to access the data storage device, wherein the second request includes an access address; a second transmission module A data request device comprising
13. The access type includes data writing and data reading, When the access type is the data writing, the first request further includes the access address, or The data request device according to claim 12, wherein when the access type is the data reading, the first permission information includes the access address.
14. The data request device A second receiving module configured to receive the confirmation information transmitted by the data storage device, wherein the confirmation information indicates that the data storage device has executed a task corresponding to the second request, and further comprising the second receiving module, the data request device according to claim 12.
15. The data request device A third receiving module configured to receive a third request transmitted by the user device, wherein the third request indicates that the data request device transmits the first request to the blockchain platform, and further comprising the third receiving module, the data request device according to claim 14.
16. A data storage device A first receiving module configured to receive a second request of the data request device, wherein the second request includes an access address, and the first receiving module; A first transmitting module configured to transmit an access verification request to the blockchain platform, wherein the access verification request indicates that the data request device transmits the second request to the data storage device, and the first transmitting module; A second receiving module configured to receive second permission information transmitted by the blockchain platform, wherein the second permission information indicates whether the data storage device can execute a task corresponding to the second request based at least on permission of a user device corresponding to signature information included in the second request, and the second receiving module; An execution module configured to execute the corresponding task based on the second request when the second permission information indicates that the data storage device can execute the task corresponding to the second request A data storage device comprising.
17. The data storage device A second transmitting module configured to transmit response information to the blockchain platform, wherein the response information indicates that the data storage device has executed the task corresponding to the second request, and further comprising the second transmitting module, the data storage device according to claim 16.
18. The data storage device A third transmission module configured to transmit confirmation information to the data request device, the confirmation information indicating that the data storage device has executed the task corresponding to the second request, further comprising a third transmission module, the data storage device according to claim 16.
19. A blockchain platform device, A first receiving module configured to receive a first request transmitted by a data request device, the first request indicating that the data request device needs to access a data storage device, the first request including signature information and an access type of the data request device, and a first receiving module; A determination module configured to determine whether the first request was initiated by a user device, determine whether the first request is known and confirmed by the user device, and determine whether the data request device can access the data storage device based on the signature information and the access type of the data request device; A first transmission module configured to transmit first permission information to the data request device, the first permission information indicating whether the data request device can access the data storage device, and a first transmission module; A second receiving module configured to receive an access verification request transmitted by the data storage device, the access verification request indicating that the data request device transmits a second request to the data storage device, and a second receiving module; A second transmission module configured to transmit second permission information to the data storage device when the blockchain platform device determines that the data request device can access the data storage device, the second permission information indicating that the data storage device can execute a task corresponding to the second request, and a second transmission module including a blockchain platform device.
20. The blockchain platform device is A third receiving module configured to receive response information transmitted by the data storage device, wherein the response information indicates that the data storage device has executed the task corresponding to the second request, and the third receiving module; A recording module configured to record the task executed by the data storage device corresponding to the second request in a distributed ledger based on the response information; The blockchain platform device according to claim 19, further comprising. **Claim 21** A computer-readable storage medium, wherein the computer-readable storage medium includes instructions or code, and when the instructions are executed on a computer, the computer is enabled to execute the method according to any one of claims 1 to 5. **Claim 22** A computer-readable storage medium, wherein the computer-readable storage medium includes instructions or code, and when the instructions are executed on a computer, the computer is enabled to execute the method according to any one of claims 6 to 8. **Claim 23** A computer-readable storage medium, wherein the computer-readable storage medium includes instructions or code, and when the instructions are executed on a computer, the computer is enabled to execute the method according to any one of claims 9 to 11. **Claim 24** A computer program, wherein the computer program includes program code, and when the program code is executed by a computer, the computer is enabled to execute the method according to any one of claims 1 to 5. **Claim 25** A computer program, wherein the computer program includes program code, and when the program code is executed by a computer, the computer is enabled to execute the method according to any one of claims 6 to 8. **Claim 26** A computer program, the computer program including program code, the computer being enabled to execute the method according to any one of claims 9 to 11 when the program code is executed by the computer.
27. A user data management system comprising a data request device according to any one of claims 12 to 15, a data storage device according to any one of claims 16 to 18, and a blockchain platform device according to claim 19 or 20.
Citation Information
Patent Citations
Registration and authorization method, device and system
JP2019522412A
Threat information sharing based on blockchain
US20200358801A1
Degeneratuion method and information processor
WO2008099453A1
Information processing device, information storage device, server, information processing system, information processing method, and program
WO2014030427A1