Method, terminal and server for managing personal data

By encrypting personal data with a user's symmetric key and storing it in a blockchain-based system with cryptographic data, the method ensures users maintain control over their data, ensuring immutability and simplifying access across environments.

JP7796901B2Active Publication Date: 2026-01-09PIGNELA CAPITAL SA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024562240
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-04-20
Filing Date
2023-03-31
Publication Date
2026-01-09
Estimated Expiration
2043-03-31

Smart Images

  • Figure 0007796901000001
    Figure 0007796901000001
  • Figure 0007796901000002
    Figure 0007796901000002
  • Figure 0007796901000003
    Figure 0007796901000003
Patent Text Reader

Abstract

User's Personal Data (DP A The method for constructing the history of A ) and comprises: a symmetric encryption key (KS) associated with the user's profile A - The process for obtaining the user's personal data (DP A ) in collecting said personal data; (i) a symmetric encryption key (KS A ) for encrypting said personal data (E52); and (ii) a comprehensive database (BD C ) with the encrypted data ([B iA ]) i ), a step (E56) of recording said plurality of blocks (B i ) is the integrated graph (G C ) subgraph (SG A ) is organized based on the blockchain that constitutes the synthetic graph (G C The topology of the subgraph (SG A ) is associated with the dynamic non-fungible token of this user, step (E56).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to the general field of protection and management of users' personal data in communication networks.

[0002] In this context, the term "personal data" should be understood in a broad sense and refers to any data over which the user wishes to retain control.

[0003] By way of non-limiting example, the identity or address of a natural person, data based on bank transactions carried out by a natural or legal person, messages exchanged over a communications network, geolocation data of an individual, photographs or videos taken by an individual or received from a third party, or digital contracts constitute personal data within the meaning of the present invention. [Background technology]

[0004] In the current state of the art, a user's personal data is typically managed by the service provider to which the user subscribes.

[0005] For example, it is common for a user who has a bank account and a social network account to provide personal data to the banking organization and also to the operator of the social network.

[0006] This results in users losing control over their personal data, since it is very difficult for them to determine what processing is being carried out on their data by the service provider. Summary of the Invention

[0007] According to a first aspect, the present invention relates to a method for building a history of personal data of a user, the method being executed by a terminal of the user and comprising: - a step for obtaining a symmetric encryption key associated with a user's profile; -The process for collecting personal data of users; -In the course of collecting the personal data of the User, we collect and use the following personal data: (i) encrypting the personal data with the user's symmetric encryption key; and (ii) recording in a general database a number of blocks comprising said encrypted data, said blocks being organized according to a blockchain constituting a subgraph of a general graph, the topology of which is defined by a pre-constructed data model, the root block of which is associated with cryptographic data specific to this user;

[0008] According to a second aspect, the present invention relates to a management method executed by a computer system for managing personal data of a plurality of users, the method comprising managing a comprehensive database in which a plurality of blocks are recorded, each block comprising the encrypted personal data of one of said users, said plurality of blocks comprising encrypted personal data of the same user and organized according to blockchains constituting subgraphs of the same comprehensive graph, the topology of which is defined by a pre-constructed data model, and the root block of said subgraph is associated with cryptographic data specific to this user.

[0009] In one embodiment, the cryptographic data associated with a user is the user's dynamic non-fungible token.

[0010] In another embodiment, the cryptographic data associated with a user is the public key of the user's digital wallet.

[0011] Thus, in general, the invention proposes storing a personal data history of a user in a blockchain and associating it with cryptographic data specific to this one user, such as a dynamic non-fungible token of this user or the public key of a digital wallet held by this user. A user, in the sense of the invention, may in particular be a natural person or a legal entity.

[0012] In the following, the term "digital wallet" refers broadly to a hardware or software device for securely storing and managing digital files uniquely associated with one user, such as units of cryptocurrency and / or non-fungible tokens. In this context, a digital wallet comprises a public key associated with the user. Such a digital wallet allows electronic transactions with other parties, for example by exchanging units of cryptocurrency.

[0013] Thus, according to the invention, cryptographic data specific to a user, such as a dynamic non-fungible token or the public key of a digital wallet, points to an input node of a graph representing the personal data history of this user (or user) according to a mapping defined by a pre-constructed data model.

[0014] By associating all personal data with the block graph, the immutability of the data's history can be guaranteed by its probative value. Furthermore, if the cryptographic data is a dynamic non-fungible token, the invention ensures that the user remains the owner of all his or her personal data, past and future, by incorporating the personal data into the blockchain.

[0015] Additionally, associating all of a user's personal data with cryptographic data unique to the user allows the user to have portability of their data in heterogeneous environments, greatly simplifying access to new services for the user.

[0016] Indeed, if a user's knowledge (KYC in English, "Know Your Customer") is obtained for a first service (for example, when opening a bank account) by verifying his / her documents associated with cryptographic data (dynamic non-fungible token, public key of a digital wallet) in a first environment (for example, verification of identity, qualifications, eligibility, etc.) and the certificate resulting from this verification is incorporated into the data associated with this cryptographic data, then in a second environment, by obtaining this cryptographic data, it is possible to directly assign rights to this user for a second service (for example, reserving a vehicle) without having to perform another verification of his / her documents.

[0017] The present invention proposes to use cryptographic data unique to a user as a proof of the user's identity. If the cryptographic data is a non-fungible token, this data also exhibits the properties of non-repudiation and unforgeability. The non-fungible property of the token also ensures that this title of ownership cannot be copied or used without the user's knowledge (unlike, for example, a digital signature).

[0018] In the present invention, the use of cryptographic data specific to a user (non-fungible tokens, public keys of digital wallets) allows the activity of natural or legal persons to be traced in any environment. For example, if some cryptographic data, in particular non-fungible tokens, are held by a news organization (legal entity) and digital content created by this news organization is recorded in a comprehensive graph associated with this cryptographic data, it is very easy to prove that one of the digital content items came from this news organization in any environment.

[0019] In an example implementation, a proof of ownership consisting of cryptographic data unique to a user can be managed explicitly using the user's recognizable identity, whether natural or legal, or completely anonymously. A user can anonymously transmit digital information that relies on cryptographic data (non-fungible tokens, public keys of digital wallets, etc.), while a third party can verify that this information is truly associated with this cryptographic data.

[0020] In one embodiment, the blockchain is a distributed ledger in a peer network, a terminal is a peer of the network configured to store locally at least a portion of the subgraph, and the blocks are stored in a local database of the terminal.

[0021] This building and viewing of the user's personal data history by the user's terminal can be done asynchronously, can be done without a network connection, and can be resynchronized without compromising the functionality and security of the solution.

[0022] In one embodiment, a data model defines how branches of the subgraph comprise multiple blocks with encrypted personal data corresponding to time-stamped geolocation data of the terminal during the terminal's detected movement.

[0023] In this embodiment of the invention, the user's terminal detects movements, and when a new movement is detected, a new branch is created in the user's subgraph, a blockchain with encrypted time-stamped geolocation data is inserted into the branch along with the movement, and the branch is stopped when it is detected that the terminal's location has not changed for a predetermined time.

[0024] In one embodiment, the data model defines how multiple blocks containing encrypted personal data corresponding to digital actions of a terminal on a certain date or corresponding to data received from a third party on a certain date are attached to one block in a user's subgraph containing encrypted personal data corresponding to geolocation data of the terminal timestamped on that date.

[0025] Advantageously, this embodiment permits all of a user's digital actions to be dated and located, for example, it permits ensuring that a photograph taken by a user's terminal was taken on a certain date and while the terminal was in a certain location.

[0026] In certain embodiments of the present invention, personal geolocation data can be associated with an element attesting to the presence of the terminal at a certain location at a certain time, such as a signed attestation element provided by a carrier that is able to verify such attestation element by birthage.

[0027] In one embodiment, a method for constructing personal data of a user comprises incorporating into a subgraph of the user a digital agreement to which the user is a party, the agreement being encrypted with a public key of the user's terminal, a public key of at least one other party to the agreement, and a public key of a digital trust environment, said agreement comprising at least: - the user's symmetric encryption key encrypted with the public key of the digital trust environment; and -instructions executable by the Digital Trusted Environment for: (i) decrypting at least some of the user's personal data with a symmetric encryption key; (ii) verifying that the user-specific cryptographic data associated with the root block of the subgraph belongs to said user; (iii) analyze the decrypted personal data; and (iv) Provide the results of the above analysis to at least one party to the agreement.

[0028] In this embodiment of the invention, the method for managing personal data of a plurality of users comprises steps for managing a set of instances of a digital trusted environment, one of said instances being configured to: - executing instructions specified in a digital contract for analyzing a portion of personal data of at least one of said users that are parties to the contract, said contract comprising a symmetric encryption key of said at least one party to the contract encrypted with a public key of said instance of a digital trust environment, said symmetric encryption key being able to be used by said instance to decrypt said personal data to be analyzed; - Providing the results of said analysis to at least one party to the contract.

[0029] According to this aspect, the present invention proposes that the contract for analyzing the user's personal data is concluded in a trusted environment, not in the terminals of the contracting parties, so as not to disclose the personal data of the contracting parties. The conclusion in a trusted environment is also known to those skilled in the art as the English expression "confidential computing."

[0030] In a preferred embodiment, the contract incorporates a delegation of access rights to encrypted personal data for the exclusive use of a trusted environment in which the data is analyzed, the trusted environment being configured to decrypt and analyze all or part of the personal data of the parties to the contract and to transmit the results of the analysis to one or more of the parties to the contract.

[0031] Embodiments of the present invention advantageously enable the execution of contracts between heterogeneous parties, and in particular, enable portability of user data in the Metaverse™, including the execution of digital contracts that require analysis of the parties' personal data in the Metaverse™ while protecting that personal data.

[0032] In one embodiment, when the cryptographic data specific to a user is a dynamic non-fungible token, a method for constructing a history of personal data comprises generating at least one second dynamic non-fungible token for said user, and associating a subgraph of said subgraph with said second dynamic non-fungible token.

[0033] A user who owns a dynamic non-fungible token associated with the root of a subgraph comprising his or her personal data history can generate a token pointing to a part of this subgraph, for example a branch of this subgraph.

[0034] This feature advantageously allows users to keep parts of their history private.

[0035] The invention also relates to a terminal comprising a processor configured to: - a step for obtaining a symmetric encryption key associated with a user's profile; - the process for collecting personal data of users; and -In collecting the above personal data of the User: (i) encrypting the personal data with the user's symmetric encryption key; and (ii) recording a plurality of blocks comprising the encrypted data in an overall database, the plurality of blocks being organized based on blockchains constituting a subgraph of an overall graph, the topology of which is defined by a pre-constructed data model, and the root block of the subgraph being associated with cryptographic data (dynamic non-fungible token, public key of a digital wallet) specific to this user;

[0036] The present invention also relates to a server for managing personal data of multiple users, the server comprising a processor configured to manage a comprehensive database in which multiple blocks are recorded, each block comprising encrypted personal data of a user, multiple blocks comprising encrypted personal data of the same user and organized according to blockchains constituting subgraphs of the same comprehensive graph, the topology of the comprehensive graph being defined by a pre-constructed data model, and the root block of said subgraph being associated with cryptographic data specific to this user.

[0037] The comprehensive database used in the present invention may be centralized (for example, managed by a server for managing personal data) or decentralized (for example, managed by a server for managing personal data) or distributed.

[0038] The invention also relates to a computer program on a computer-executable storage medium, which comprises instructions adapted to carry out the method for establishing a personal data history as described above.

[0039] The invention also relates to a computer program on a computer-executable storage medium, said program comprising instructions adapted to carry out the method for managing personal data of a set of users as described above.

[0040] Each of these programs may use any programming language and may be in the form of source code, object code, or an intermediate code between source code and object code such as a partially compiled form, or any other desired form.

[0041] The invention also relates to a computer readable information medium or recording medium comprising instructions for the first computer program or the second computer program or the third computer program as described above.

[0042] The information medium or recording medium may be any entity or device capable of storing a program. For example, the medium may comprise a recording medium such as a ROM, for example a CD ROM or a microelectronic circuit ROM, a hard disk, a magnetic recording medium, for example a flash memory, etc.

[0043] On the other hand, the information medium or recording medium may be a transmissible medium such as an electrical or optical signal, which may be transmitted via an electrical or optical cable, by a wireless link, by a wireless optical link, or by other means.

[0044] In particular, the program according to the invention can be downloaded from an Internet-type network.

[0045] Alternatively, each information medium or recording medium may be an integrated circuit having a program embedded therein, adapted to perform or be used to perform one of the methods according to the invention.

[0046] Other characteristics and advantages of the invention will become apparent from the following description, taken in conjunction with the accompanying drawings, which show non-limiting exemplary embodiments. [Brief explanation of the drawings]

[0047] [Figure 1] FIG. 1 shows an instance of a terminal, a server for managing personal data and a digital trusted environment that can be used in a particular embodiment of the invention. [Figure 2A] FIG. 2A illustrates a composite graph that can be implemented in certain embodiments of the present invention. [Figure 2B] FIG. 2B shows a subgraph of the overall graph of FIG. 2A. [Figure 3A] FIG. 3A shows a contract proposal prepared by the first party. [Figure 3B] FIG. 3B shows the contract created after the second party accepts the contract proposal of FIG. 3A. [Figure 4]FIG. 4 illustrates the creation of a user account in a specific embodiment of the present invention. [Figure 5] FIG. 5 shows the main steps performed to build a user's personal data history. [Figure 6] FIG. 6 shows the main steps executed by the user's terminal to access the personal data of this user. [Figure 7] Figure 7 shows the main steps performed to create a contract. [Figure 8] Figure 8 shows the main steps that are performed to execute the contract. [Figure 9] FIG. 9 illustrates the hardware architecture of a terminal according to a particular embodiment of the invention. [Figure 10] FIG. 10 illustrates the hardware architecture of a server according to a specific embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0048] Figure 1 shows the terminal T of user A. A , the terminal T of the service provider SP SP A server SDP for managing personal data of multiple users, and multiple instances of a digital trust environment ECN i and interconnected by a communications network NET.

[0049] In the embodiment described here, the server SDP for managing personal data is configured to provide: - Personal data history service HIST; and -GES-CONT services for managing digital contracts using all or part of said personal data.

[0050] As explained in more detail below, the personal data history service HIST allows users who subscribe to the service to build and maintain their personal data history from their mobile devices, and gives this history probative value and ensures its portability by associating it with a dynamic non-fungible token that is the property of the user.

[0051] The GES-CONT service for managing contracts allows a digital contract between at least two parties to be concluded in the Digital Trusted Environment ECN without disclosing the personal data of these parties. In this respect, and as will be explained below, the digital contracts managed by the invention incorporate a delegation of access rights to the personal data of the user for the Digital Trusted Environment ECN.

[0052] In the embodiment described here, the server SDP for managing personal data also comprises a module GES-ECN for managing this Digital Trust Environment ECN.

[0053] This Digital Trusted Environment (ECN) constitutes a protected environment ("Trusted Execution Environment") in which contracts can be concluded between two or more parties (users, service providers, etc., who may be natural or legal persons).

[0054] In the embodiment described here, the module for managing digital trust environments GES-ECN of the server for managing personal data SDP can manage a variable number of instances ECN of the digital trust environment ECN depending on the number of contracts to be concluded. i , ECN j It is configured to dynamically manage the network.

[0055] In the embodiment described herein, the above-mentioned instance of the digital trust environment ECN i , ECN j are cloned by the module GES-ECN. All of these cloned instances have the same module EXEC-CONT for concluding the contract and a rewritable non-volatile memory M ECN Public key stored in KPUB ECN and the associated private key KPRIV ECN and an identical key pair comprising:

[0056] In the example we will discuss here, terminal T A is a mobile phone.

[0057] In this example, user A receives a message from the personal data management server SDP (aupres du serveur SDP) on his own terminal T A The application APP has been downloaded and installed on the server, and this application allows user A to access the services provided by the server, in particular the personal data history service HIST and the GES-CONT service for managing digital contracts.

[0058] The application APP comprises a cryptographic module MCY.

[0059] In the embodiment described here, the application APP also comprises a GEN-CONT module for generating a contract, by means of which the terminal T A The user of the Digital Trust Environment ECN shall be able to create a contract with one or more other parties intended to be concluded in the Digital Trust Environment ECN. This process will be explained in more detail below with reference to Figure 7.

[0060] Figure 1 shows the state of terminal T after user A opens an account via a server SDP for managing personal data and subscribes to the history data service HIST for his / her personal data. A To open this account, please use terminal T. A The steps E40 to E45 executed by the terminal T will be explained later with reference to FIG. 4. After opening this account, in this example, A Rewritable non-volatile memory M A comprises the following: - identifier LOG / MP (login name, password) that allows user A to access his account through the local application APP; -Private key KPRIV A and public key KPUB A a key pair comprising: - symmetric encryption key KS A and -un identifiant unique confidential ID A .

[0061] In the embodiment described here, terminal T A is the terminal T A The device comprises a module MDD for detecting the movement of the vehicle.

[0062] In this example, the module for detecting movements MDD comprises an artificial intelligence IA, a GPS geolocation module and a movement detector MVT, which detects, for example, the movement of a terminal T A It is equipped with accelerometer and gyroscope sensors to measure linear acceleration, attitude and angular velocity of the robot.

[0063] The module for detecting this movement MDD receives the time-stamped personal geolocation data DP of user A. GEO A The data is generated based on a date T i In the real world, terminal T A Position P where i Equipped with.

[0064] In the embodiment described here, terminal T A also comprises a camera CAM and a payment application PAY. The photographs taken by the camera CAM and the transactions carried out using the application PAY are stored in a personal data DP of user A, which represent digital actions carried out by user A. DigAct A Other digital operations are possible, not shown, for example, the terminal T A The sending or receiving of messages (emails, short messages, etc.) is performed using the messaging application.

[0065] In the embodiment described here, terminal T A also collects personal data DP obtained from third parties, e.g. from management services, banks, insurance companies, commercial organisations, etc. 3rdP A is configured to manage

[0066] Generally, user A's personal data is A It is written as Data DP A is, for example, personal geolocation data DP GEO A , personal data DP representing digital behavior DigAct A , and personal data DP obtained from third parties 3rdP A Equipped with.

[0067] In the embodiment described here, the server SDP stores a centralized comprehensive database BD C Equipped with a centralized comprehensive database BD C stores an encrypted history of personal data of all users who subscribe to the service HIST.

[0068] In the embodiment described here, the encrypted personal data of multiple users is organized according to an n-dimensional blockchain.

[0069] In the embodiment described here, this n-dimensional blockchain is a general directed acyclic graph G C The overall directed acyclic graph G C The topology is defined by a pre-constructed data model, which is described below with reference to FIGS. 2A and 2B.

[0070] This blockchain creates an updatable distributed ledger across a peer network.

[0071] In the embodiment described here, the user's terminal is a peer in this network. Here, the user has subscribed to the history data service HIST for his personal data. For example, the terminal T A will locally store: - A local database BD with the user's own encrypted personal data A and -User's own encrypted personal data DP A A comprehensive graph G with a history of C The subgraph SG of A Copy of.

[0072] Therefore, terminal T A By exploiting the ownership of graphs, it can operate without a network connection and asynchronously.

[0073] Thus, in the embodiment described here and as will be explained later with reference to FIG. 5, the new personal data DP to be recorded A Terminal T A When detected, personal data DPA is the terminal T A The encryption module MCY of the terminal T A Local database BD A and stored in terminal T A By Terminal T A Locally (local au terminal T A ) Subgraph SG A Then, when connections are possible, the overall graph G C It can be synchronized with the blockchain (avant d'etre synchronisees, lorsqu'une connexion le permet, avec la chaine de blocs du graphe general G c ).

[0074] Synchronization between multiple peers (pairs) is performed using the integrated database BD C When a peer generates or receives a new block, it adds the new block to its copy of the ledger and then sends the block to its peer nodes. When those peer nodes receive the block, they verify that the new block is valid. If the block is valid, they include the block in their ledger and then send the block to their peer nodes.

[0075] FIG. 2A shows a general database BD managed by a server SDP for managing personal data. C All users T of the historical data service HIST are stored in A , T k The overall graph G represents the organization of encrypted personal data. C An example is shown below.

[0076] In this example, the overall graph G C is a subgraph SG A and the subgraph SG A is a comprehensive database BDC or local database BD A Encrypted personal data DP of user A in A Here, it is assumed that these databases are synchronized.

[0077] As mentioned above, the overall graph G C (Therefore, specifically, the subgraph SG A The topology is defined by a pre-built data model.

[0078] Figure 2B shows the encrypted personal data DP of user A based on a specific data model. A The subgraph SG representing the organization of A is shown in more detail.

[0079] In the particular case of this data model, the subgraph SG A is a directed acyclic graph. A In particular, the root BR A and a set of branches made up of a number of blocks interconnected by a number of arcs.

[0080] In the embodiment described here, terminal T A The module MDD for detecting the movement of the real-world terminal T A The device is adapted to detect the type of displacement, for example, displacement by car or displacement by foot.

[0081] In the exemplary embodiment described here, based on a pre-constructed data model, the subgraph of a user's personal data comprises, among other things, a branch for each of the user's detected movements.

[0082] For example, in Figure 2B: Each of the branches F1 to F3 has a terminal T ATime-stamped personal geolocation data (DP) captured during car trips detected by GEO A a plurality of encrypted blocks; - each of the branches F4 to F5 has a terminal T A Time-stamped personal geolocation data DP acquired during walking movements detected by GEO A The method comprises a plurality of encrypted blocks comprising:

[0083] This example is non-limiting and other types of movement not shown may be envisioned.

[0084] As shown in more detail for branch F5, each branch associated with a movement comprises a sequence of blocks, and each block B i is the encrypted geolocation P i and date T i and an encrypted geolocation P i and date T i During the movement associated with this branch F5, A is the instant T i At position P i indicates that it existed in

[0085] When the module for detecting the movement MDD detects that the movement has been completed, for example, by detecting the movement of the terminal T A The branch stops when it is detected that the position of has not changed. If a new movement is detected, a new branch is created.

[0086] The example in Figure 2B shows three blocks B i-1 , B i , B i+1 is shown in more detail, and the three blocks B i-1 , B i , B i+1 is the terminal T during foot movement. A consecutive time T i-1 , T i , Ti+1 Position P i-1 ,P i , P i+1 Based on the blockchain mechanism, each block B i is the block's own encrypted data plus the output hash of the previous block, H([B i-1 A ]) Due to the properties of hash functions, any changes to the contents of a block are immediately visible in later blocks.

[0087] In the particular data model described here, the branches associated with detected movements of a user's terminal constitute the main skeleton of the user's subgraph.

[0088] In the embodiment described here, the subgraph SG A Also, terminal T A encrypted personal data DP of user A obtained during a digital operation performed by DigAct A The device includes a plurality of blocks each including:

[0089] In the embodiment described here, the subgraph SG A also contains User A's encrypted personal data DP obtained from a third party. 3rdP A The device includes a plurality of blocks each including:

[0090] In the embodiment described herein, a block comprising data associated with a digital action on a certain date or received from a third party on a certain date is included in a subgraph SG A In this case, the date and the terminal T of the date A The block is associated with the geographic location of the

[0091] In such an embodiment, by way of example, FIG. 2B shows: -The device is at position P i-1 Time T existed in i-1 Node B has an encrypted photo PIX captured by a camera CAM.k ; -The device is at position P i+1 Time T existed in i+1 Node B has the encrypted contract AG received from the third party. r .

[0092] This subgraph is enriched with the user's personal data and dynamically evolves.

[0093] Very advantageously, the personal data DP of user A 3rdP A A subgraph SG of the blockchain A This ensures that the history of the data cannot be tampered with and that the data is authentic when verified by an external trusted third party.

[0094] As known to those skilled in the art, in order to give a graph probative power, data generated by an external trusted third party (e.g., another blockchain) must be incorporated into the graph, for example, periodically. For example, a terminal can send a hash of the last block of the graph to this trusted third party, which generates information from this hash, and the information signed by the trusted third party is incorporated into the graph.

[0095] In certain embodiments, a user's personal data history is linked to a dynamic non-fungible token by a server SDP for managing personal data.

[0096] For example, as described below with reference to FIG. 4, the output hash of the root block of a subgraph of a user's historical data can be associated by the server SDP with cryptographic data assigned to this user by the server (e.g., a dynamic non-fungible token or a public key of a digital wallet).

[0097] The following describes one embodiment of the present invention. In this embodiment, cryptographic data unique to a user is stored as a non-fungible token (NFT). ATherefore, the present invention allows users to share their personal data history with their dynamic non-fungible tokens (NFTs). A It is possible to link it to.

[0098] In certain embodiments of the present invention, User A creates a dynamic non-fungible token NFT A and at least one second non-fungible token (NFT) A 2 can generate its own subgraph SG A can be associated with this second non-fungible token.

[0099] Here, user A and service provider SP have subscribed to the GES-CONT service for managing digital contracts, and an instance ECN of the Digital Trust Environment ECN i Digital contract intended to be concluded by ECN A,SP The parties wish to draft the contract in such a way that no personal data of the contracting parties is disclosed during the conclusion of the contract.

[0100] Terminal T of the service provider SP SP has downloaded the application GEN-CONT for generating a contract from the server SDP, and the application GEN-CONT is running on the terminal T. A Compatible with the APP application downloaded by the terminal T A ) shall be deemed to be

[0101] It is assumed that the user of the terminal SDP uses the application GEN-CONT, has opened an account with the server SDP for managing personal data, and has subscribed to the GES-CONT service for managing contracts.

[0102] After opening this account, terminal T SPRewritable non-volatile memory M SP In this example, it comprises: -Identifier LOG / MP (login name, password) that allows the user to access their account via the local application GEN-CONT; -Private key KPRIV SP and public key KPUB SP a key pair comprising: - symmetric encryption key KS SP and -Secret Unique Identifier ID SP .

[0103] In the embodiment described here, the service provider SP uses its application GEN-CONT to create a contract proposal. ECN* A,SP In the embodiment described herein, the contract proposal specifies the analyses to be performed on the user's data, the frequency of the analyses, the length of the contract, the format of the results, and the rules for disseminating the results.

[0104] Contract Proposal AG ECN* A, SP An example of this is shown in Figure 3A. This proposal comprises: -Digital Trust Environment ECN Instance ECN i a literal description DLII that can be interpreted by the i It is possible to do so by using personal data DP A The code to perform the analysis: CODE; -The personal data DP of A that the ECN digital trust environment should analyze (sur lesquelles l'environnement de confiance numerique ECN doit porter cette analyze) Aa descriptive DDP, where the descriptive DDP is, for example, a category of personal data (geo-located time-stamped data, photos, messages, etc.) and an associated time range (personal data detected between this day and that day, etc.); - contract start date DD, contract end date DF and contract period PER (debut date DD, end date DF and execution period PER); -Format FORM that the digital trust environment should use to return the results of the analysis to the different parties A, SP; - an instance of a digital trust environment (ECN) configured to execute contracts i The common public key KPUB ECN The encryption key KS of the party SP encrypted with SP and -Service provider's private key KPRIV SP Sign this contract proposal using SIG SP .

[0105] Public Key KPUB ECN The encryption key KS encrypted with SP , [KS SP ECN ] is written as follows.

[0106] Terminal T A When this encrypted contract proposal is obtained, the public key KPUB of the service provider SP is SP Signed with SIG SP Verify.

[0107] Terminal T A If User A accepts the contract proposal, User A will be granted access to the Digital Trust Environment instance ECN i The common public key KPUBECN Your own encryption key KS encrypted with A Insert your private key, KPRIV, into this completed proposal. A By signing with your own signature SIG A Insert this into the contract proposal and create a contract AG ECN A, SP Create (il y insere sa cle de chiffrement KS A chiffree avec la cle publique KPUB ECN commune aux instances ECN, de l'environnement de confiance numerique, signe cette proposition completee avec sa cle privee KPRIV A , et insere sa signature SIG A dans la proposition de contrat pour former le contrat AG ECN A; SP ). Public key KPUB ECN The encryption key KS encrypted with A , [KS A ECN ] is written as follows.

[0108] Contract AG thus created ECN A, SP The contract is shown in Figure 3B. ECN A, SP the delegation of authority over the encrypted personal data of the parties A and SP, in the instance of the Digital Trust Environment ECN in which the data is analyzed; i This document is incorporated by reference in its entirety for the exclusive use of

[0109] In the embodiment described herein, the agreement AG ECN A, SP is the public key KPUB of the contract party A and SP A , KPUBSP and all instances of ECN in the Digital Trust Environment i The common public key KPUB ECN and signed.

[0110] Party A and SP and any instance of Digital Trust Environment ECN i Each of the parties can decrypt the contract using a private key that only they possess.

[0111] The conclusion of a contract by an instance of a digital trusted environment will now be described with reference to FIG.

[0112] Figure 4 illustrates the main steps performed in a particular embodiment of the invention to create a user's account and assign a dynamic non-fungible token to the user. For illustrative purposes, assume that user A's terminal T A Create an account for User A and manage personal data from the server SDP. A Consider creating a

[0113] The present invention is directly applicable to other embodiments in which the user-specific cryptographic data is not a dynamic non-fungible token, particularly where the cryptographic data consists of a public key of a digital wallet.

[0114] In step E40, terminal T A A user A creates his account using the personal data history service HIST provided by the server SDP. For this purpose, in the embodiment described here, the user A transfers the personal data history service HIST from the server SDP for managing personal data to his terminal T. A Use the pre-downloaded local application APP to get the following on your device T A Memory M A Record to: -Identifier LOG / MP (login name, password) for accessing user A's account via the local application APP; -Private key KPRIV A and public key KPUB A a key pair comprising: - symmetric encryption key KS A and -Secret Unique Identifier ID A .

[0115] These elements (identifier, key pair, symmetric encryption key, unique identifier) ​​are preferably stored in the terminal T A generated by, for example, a local application APP.

[0116] These are preferably terminal T A Memory M A is saved in

[0117] In step E42, terminal T A is its secret unique identifier ID A The data structure SG A Route Block BR A Incorporated into the root block BR A Let KS be the symmetric encryption key. A This encrypted data block is then decoded as H[BR A A ]. The output hash of the root block, H([BR A A ]) applies a hash function H to the encrypted data block [BR A A ] is calculated by applying

[0118] In step E43, the root block BR A is still terminal T A Symmetric encryption key KS A The block descriptor DESC encrypted with RA This encrypted descriptor is associated with [DESC RA A ] is written as follows.

[0119] Route Block BR A Descriptor DESC RA is, for example, the string "root block". This descriptor allows the symmetric encryption key KS A Any person with A It is possible to find (retrouver)

[0120] The choice of descriptors can be arbitrary, but in a preferred embodiment of the present invention the choice of descriptors is defined in a pre-built data model, which includes, for example, a contract regarding which descriptors should be used.

[0121] In the embodiment described here, the root block does not have a hash that links it to one or more previous data blocks.

[0122] In step E44, the encrypted root block [BR A A ] is terminal T A Local database BD A , its encrypted descriptor [DESC RA A ]. The encrypted root block [BR A ] and its associated encrypted descriptor [DESC RA A ] are sent to the server SDP when a network connection is available. They are stored in the comprehensive database BD C The encrypted root block [BR A ] is the comprehensive graph G C can be synchronized with.

[0123] In step E45, terminal T A is the graph SG A Route Block BR A The output hash H([BR A A]) to the server SDP for managing personal data.

[0124] In step E46, the server for managing personal data SDP is configured to manage the dynamic non-fungible token NFT A Create a new root block, grant its ownership to user A (dont il accorde la propriete a l'utilisateur A), and generate the output hash H([BR A A ]) into this dynamic non-fungible token NFT A Associate with.

[0125] User A's symmetric encryption key KS A Unless you hold A A ]) cannot be found in any other encrypted block, so the output hash H([BR A A ]) with user A's data.

[0126] Figure 5 shows the user's personal data DP A , the main steps performed to build a history of, for example, user A's personal data.

[0127] In the embodiments described herein, the data may be of any type, for example, declarative data or data with attestation elements such as digital signatures or embedded secure links.

[0128] As mentioned above, personal data DP A is the terminal T A During the detected movement of the terminal T, for example, during a movement action (walking, riding a bike, running, driving a car, etc.), A Geo-located time-stamped personal data DP GEO A Such data may be stored in a mobile terminal T A consecutive time T i-1, T i , T i+1 GPS location of P i-1 , P i , P i+1 Equipped with.

[0129] As mentioned above, personal data DP A For example, taking photos or videos, exchanging messages, A Interactions using applications on terminal T A Personal data (DP) corresponding to digital actions carried out DigAct A may be.

[0130] As mentioned above, personal data DP A Personal data (DP) obtained from third parties, such as management services, banks, insurance companies, commercial organisations, etc. 3rdP A may be.

[0131] In the embodiment described here, personal data DP A is the terminal T A In a variant, at least some of the data is incorporated into the user's terminal only with the user's explicit permission.

[0132] In step E50, terminal T A is the personal data DP that should be included in the personal data history of user A. i A shall be detected.

[0133] In step E52, the personal data DP i A is the graph SG A Block B i The position of this block in the graph is determined by a pre-built data model.

[0134] As described above with reference to FIG. i comprises the following: -Root Block BR A Excluding graph SG A Block B in i Multiple blocks B upstream of k Each output hash H k and -Personal Data DP i A .

[0135] Terminal T A is the symmetric encryption key KS A Block B i This encrypted data block is called [B i A Block B i The output hash H([B i A ]) applies a hash function H to an encrypted data block [B i A ] is calculated by applying

[0136] In step E54, the encrypted block B i is the descriptor of this block DESC i Descriptor DESC i is selected based on the pre-constructed data model agreement. i Also, terminal T A Symmetric encryption key KS A This encrypted descriptor is then written as [DESC i A ] is written as follows.

[0137] for example: -Terminal T on June 4, 2021 A The data was acquired during a car ride on the terminal T. A Geo-located time-stamped personal data DP GEO A Data block B comprising i The descriptor associated with DESC i could be the string "2021 / 06 / 04||by car"; -27 / 07 / 2021 Terminal T A Personal data (DP) corresponding to the digital behavior of DigAct A Data block B comprising i The descriptor associated with DESC i can be the string "2021 / 07 / 27||Photo" or "2021 / 07 / 27||Email"; -08 / 04 / 2022 Terminal T A Personal data DP obtained from third parties 3rdP A Data block B comprising i The descriptor associated with DESC i could be the string "2022 / 04 / 08||Bank".

[0138] In step E56, the encrypted data block [B i A ] is the encrypted descriptor [DESC i A ], and terminal T A Local database BD A The encrypted descriptor [DESC i A ] is the encrypted data block [B i A ] is displayed when a network connection is available. C can be synchronized with.

[0139] Graph SG showing the history of user A's personal data A The whole is terminal T A Note that it is not necessary for the data to be stored permanently in the terminal T. A Local database BD A The periodic update of the collection of blocks in may be governed, for example, by the data model and by the current state of the graph. AThe strategy for maintaining partial history can be based on functionality selection (data required for functionality and building undeniable history) and performance (latency of accessing blocks in a local database vs. latency of online access).

[0140] Terminal T A Personal data by DP A The construction and browsing of the history can be performed asynchronously, can be performed without a network connection (hors reseau), and can be resynchronized without compromising the functionality and security of the solution.

[0141] Figure 6 shows the main steps performed by a user's terminal for referencing the user's personal data. For example, the terminal T of user A A The personal data of the user DP carried out by A The steps are explained in detail below for reference.

[0142] Symmetric key KS A The encrypted block [B i A ] is also the same symmetric encryption key KS A The descriptor of the block encrypted by i A ].

[0143] On the other hand, data block B i Access to the is performed using the associated descriptor DESC i This is done by:

[0144] User A uses the descriptor DESC i Suppose we want to reference a block associated with . The descriptor consists, for example, of the string "2021 / 06 / 04||by car".

[0145] In step E60, the user selects descriptors based on pre-built data model conventions.

[0146] In step E62, this descriptor DESC i is the user's symmetric key KS A and the encrypted descriptor [DESC i A ] is generated.

[0147] In step E64, the encrypted descriptor [DESC i A ] corresponds to the encrypted block [B i A ] is identified.

[0148] In step E66, the encrypted block [B i A ] is terminal T A symmetric key KS A and the decoded block B i is generated.

[0149] In step E68, the decrypted block B is decoded according to the user's needs. i The contents of the personal data DP can be presented to the user A. A Graph of SG A is the graph SG A The hierarchical structure (parent-child links) between the blocks of the SG can be used to reconstruct the SG blocks. A ) This hierarchy can be deduced from the hashes contained in the data blocks.

[0150] Subgraph SG A The structure of personal data DP A or advantageously before the decryption of the personal data DP A Note that after decoding of

[0151] Graph SGA The integrity of the terminal T A can be verified by

[0152] Figure 7 shows the main steps to be performed to create a contract between at least two parties, for example, a user A and his personal data DP A Agreement AG intended to be concluded in the Digital Trust Environment ECN with a service provider SP wishing to carry out the analysis of ECN A, SP Consider creating one.

[0153] In the embodiment described here, in a general step E700, a server SDP for managing personal data is connected to a set of instances ECN of a digital trusted environment. i , ECN j , instance ECN i , ECN j manages the ECN instance, which is a duplicate of the ECN instance. i , ECN j As mentioned above, all these instances use the same module EXEC-CONT for executing the contract and the public key KPUB. ECN and the private key KPRIV ECN In the embodiment described here, the instance comprises an aggregate graph G C These are created or destroyed depending on the number of contracts recorded in the database.

[0154] In step E70, Party SP submits a contract proposal AG between Party SP and Party A. ECN* A, SP Prepare the following.

[0155] This contract proposal AG ECN* A, SP As shown in Figure 3A, the -Digital Trust Environment ECN Instance ECN i and / or the instance ECN i Personal data of ADP A The code to perform the analysis: CODE; -Digital Trust Environment ECN Instance ECN i A literal description DLII that can be interpreted by the following, and / or the instance ECN i It is possible to do so by using personal data DP A The code to perform the analysis: CODE; -A's personal data DP that should be subject to the above analysis by the Digital Trust Environment ECN A a description of the DDP, where the description is, for example, a category of personal data (geo-located time-stamped data, photos, messages, etc.) and an associated time range (personal data detected between this day and that day, etc.); - Contract start date DD, contract end date DF and contract period PER; -Format FORM that the Digital Trust Environment should use to return the results of the analysis to the separate parties A and SP; - an instance of a digital trust environment (ECN) configured to execute contracts i The common public key KPUB ECN The encryption key KS of the party SP encrypted with SP .

[0156] In step E71, party SP acquires its private key KPRIV SP Contract Proposal AG ECN* A, SP This signature is called SIG SP It is written as follows.

[0157] In step E72, the party SP submits the contract proposal AG ECN* A, SP and signature SIG SP is sent to Party A.

[0158] Party A submits contract proposal AG ECN* A, SPIf so, in step E73, the terminal T A is A's private key KPRIV A Contract Proposal AG ECN* A, SP This signature is called SIG A It is written as follows.

[0159] In step E74, terminal T A Contract Proposal AG ECN* A, SP This signature SIG A and different instances of digital trust environments,ECN i The common public key KPUB ECN Your public key encrypted with KPUB A Insert the public key KPUB ECN Public key encrypted with KPUB A [KPUB A ECN ] is written as follows.

[0160] Contract proposal AG initiated by Party SP and accepted by Party A ECN* A, SP is the contract AG executed between Party A and SP. ECN A, SP may be eligible as

[0161] In step E75, two signatures SIG SP , SIG A Contract AG ECN A, SP is the public key KPUB of party A and SP A , KPUB SP and different instances of digital trust environments,ECN i The common public key KPUB ECN The contract is encrypted asymmetrically with [AG ECN A, SP ] is written as follows.

[0162] In step E76, contract AG ECN A, SP But the descriptor DESC ECNA, SP Associated with descriptor AG ECN A, SP For example, the descriptor DESC is the string "Agreement between A and SP". ECN A, SP is the public key KPUB of party A and SP A , KPUB SP and different instances of digital trust environments,ECN i The common public key KPUB ECN The descriptor encrypted in this way is written as [DESC ECN A, SP ] is written as follows.

[0163] Therefore, parties A and SP and any instance of the Digital Trust Environment ECN i Each of the keys has a private key KPRIV A , KPRIV SP , KPRIV ECN The contract can be decrypted using

[0164] In step E78, the encrypted contract [AG ECN A, SP ] and its encrypted descriptor [DESC ECN A, SP ] is the graph SG of user A. A and comprehensive graph G C will be incorporated into

[0165] Encrypted contract [AG ECN A, SP ] is the comprehensive graph G C It is indistinguishable in

[0166] In the embodiment described here, the overall graph G C Encrypted contracts in [AG ECN A, SP ] is available and this agreement is available on this server's GraphSG SP The server SP is notified that the software has been installed in the server (E79).

[0167] Figure 8 shows the main steps performed for the conclusion of a contract according to a particular embodiment of the invention. As an example, a digital trust environment instance ECN is created between a user A and a service provider SP. i Agreement AG intended to be concluded by ECN A, SP Consider concluding the following.

[0168] As mentioned above, the encrypted contract is stored in the graph SG of user A and SP. A , S.G. SP , and the overall graph G C It is recorded in.

[0169] In one embodiment of the present invention, users create their graph SG A , S.G. SP Or Comprehensive Graph G C To this end, and as described above with reference to Figure 6, users use a descriptor to identify the contract in the blockchain. The descriptor may consist, for example, of the string "contract".

[0170] In a variant, an instance of a digital trust environment ECN i However, the overall graph G C The above verification will be carried out.

[0171] Step E80 is executed repeatedly, for example at regular intervals. A Based on the contract descriptors, A Or Comprehensive Graph G C Search for the encrypted contract [AG] present in

[0172] Terminal T A is an encrypted contract [AG ECN A, SP ], in step E81, the encrypted contract [AG ECN A, SP ] with your own private key KPRIV A Decrypt with.

[0173] In step E82, terminal T A determines whether a contract is scheduled to be concluded based on the contract start date DD, contract end date DF, and contract period PER. If applicable, the terminal T A In step E83, one instance of the digital trusted environment ECN i notify the same.

[0174] In step E84, the above-mentioned one instance ECN of the digital trusted environment i is an encrypted contract [AG ECN A, SP ] and obtain your own private key KPRIV ECN Decrypt with.

[0175] As described above with reference to Figure 3B, the encrypted contract AG ECN A, SP The instance ECN i Public key of KPUB ECN symmetric encryption keys KS of each of the parties encrypted with A , K.S. SP (respectively [KS A ECN ], [KS SP ECN ]).

[0176] In step E85, the instance ECN i is your private key KPRIV ECN Decrypt the encryption key encrypted with KS A , K.S. SP Get.

[0177] The contract is an instance of the Digital Trust Environment (ECN). i The agreement will be concluded by the parties under the terms of the agreement.

[0178] In step E86, the instance ECN idetermines which personal data of the parties should be subject to analysis based on the description DDP, and performs the analysis by interpreting the interpretable literal description DLII or by executing the code CODE included in the contract. During this analysis, the necessary personal data of the parties is i with the party's symmetric encryption key.

[0179] By following the parent-child links defined by the hash of the blockchain for the subgraph of the parties, the instance ECN i is a cryptographic data unique to the user, e.g., a subgraph SG A Route Block BR A Dynamic non-fungible tokens associated with NFTs A , belongs to user A (e.g., user A's public key KPUB A It is possible to verify the identity of the individual (that is, the individual is associated with the individual), reconstruct the entire history of this person's personal data, and perform an analysis of the personal data covered by the described DDP.

[0180] In step E87, the instance ECN i The RES is formatted as a result of the analysis in accordance with the FORM specified in the contract. i This result is used to obtain the public key KPUB of party A and SP. A , KPUB SP The result of this encryption is denoted as [RES].

[0181] In step E88, the result RES is calculated based on the descriptor DESC RES Descriptor DESC RES is, for example, the string "Result of the conclusion of a contract between A and SP." RES is the public key KPUB of party A and SP A , KPU SP The descriptor thus encrypted is written as [DESCRES ] is written as follows.

[0182] In step E89, the encrypted result [RES] and its encrypted descriptor [DESC RES ] is the comprehensive graph G C and the subgraph SG of the parties to the contract A , S.G. SP and notified to the device of the person involved.

[0183] As described above with reference to FIG. A When a user A creates his / her account using the personal data history data service HIST provided by the server SDP, the server SDP for managing personal data stores cryptographic data (e.g., dynamic non-fungible token NFT) A or a public key for a digital wallet), grants its ownership to User A, and associates the history of encrypted personal data with this encrypted data.

[0184] 9 shows the hardware architecture of a terminal according to the invention, which comprises in particular a processor 10, a read-only memory 11 (of the "ROM" type), a rewritable non-volatile memory 12 (for example of the "EEPROM" or "Flash NAND" type), a rewritable volatile memory 13 (of the "RAM" type) and a communication interface 14.

[0185] The read-only memory 11 constitutes a recording medium according to an exemplary embodiment of the present invention, is readable by the processor 10, and stores a first computer program P1 according to an exemplary embodiment of the present invention. In a variant, the first computer program P1 is stored in a rewritable non-volatile memory 12.

[0186] The first computer program P1 enables the terminal to carry out the method for building a personal data history according to the invention.

[0187] 10 shows the hardware architecture of a server for managing personal data according to the invention. The server comprises, inter alia, a processor 20, a read-only memory 21 (of the "ROM" type), a rewritable non-volatile memory 22 (for example of the "EEPROM" or "Flash NAND" type), a rewritable volatile memory 23 (of the "RAM" type), and a communication interface 24.

[0188] The read-only memory 21 constitutes a recording medium according to an exemplary embodiment of the present invention, is readable by the processor 20, and stores a second computer program P2 according to an exemplary embodiment of the present invention. In a variant, the second computer program P2 is stored in the rewritable non-volatile memory 12.

[0189] The second computer program P2 enables the server for managing personal data to execute the method for managing personal data of a plurality of users according to the invention.

Claims

1. User (A)'s personal data (DP A ) of said user (A), A ) and - a symmetric encryption key (Ks) associated with the profile of said user (A) A a step (E40) for obtaining - the user's personal data (DP A a step (E50) for collecting - the personal data (DP) of the user (A) A ) in the collection of: (i) the symmetric encryption key (Ks) of this user A a step (E52) for encrypting said personal data; and (ii) Comprehensive Database (BD) C ) and the encrypted data ([B iA ]) i ) and a step (E56) of recording the plurality of blocks (B i ) is the overall graph (G C ) subgraph (SG A ) and the topology of the overall graph is defined by a pre-constructed data model, and the subgraph (SG A ) Route Block (BR A ) is the dynamic non-fungible token (NFT) of this user (A). A ) step (E56) A method comprising:

2. The blockchain is a distributed ledger in a peer network, and the terminal (T A ) is the subgraph (SG A a peer of said network configured to locally store at least a portion of said plurality of blocks (B i ) is the terminal (T A ) local database (BD A 2. The method for building a history of personal data according to claim 1, wherein the history of personal data is stored in a storage device.

3. The data model allows the subgraph (SG A ) branch of the terminal (T A ) detected moving terminal (T A ) a plurality of blocks (B) having encrypted personal data corresponding to the time-stamped geolocation data of i 2. The method for constructing a personal data history according to claim 1, wherein the method further defines how the personal data history is provided.

4. The data model allows for the generation of a plurality of blocks (B) containing encrypted personal data corresponding to digital operations of the terminal on a certain date or corresponding to data received from a third party on a certain date. k , B r ) is the subgraph (SG A ) at the terminal (T A one block (B) having the encrypted personal data corresponding to the geolocation data of i 4. The method for constructing a history of personal data according to claim 3, wherein how the personal data is linked to the user's personal information is specified.

5. The method further comprises: A ) and a digital contract ([AG ECN A, SP ]), and said contract is transmitted to said terminal (T A ) public key (KPUB A ), the public key (KPUB) of at least one other party to the agreement SP ), and the public key of the Digital Trust Environment (KPUB ECN ), and said agreement includes at least: - the public key of the digital trust environment (KPUB ECN ) encrypted with the symmetric encryption key ([KS A ]); and executable by said Digital Trusted Environment: (i) the personal data (DP) of the user A ) by dividing at least a portion of the symmetric encryption key (K A ) for decoding; (ii) the subgraph (SG A ) of the root block (BR A ) associated with the dynamic non-fungible token (NFT) A ) belongs to said user (A); (iii) to analyze the decrypted personal data; and (iv) providing the results of said analysis to at least one party to said agreement; 2. The method for building a history of personal data according to claim 1, comprising instructions (DLII, CODE).

6. At least one second dynamic non-fungible token (NFT) associated with the user. A 2 ), and a second dynamic non-fungible token (NFT A 2 ) to the subgraph (SG A) A 2 2. The method for constructing a personal data history of claim 1, comprising the steps of:

7. A management method executed by a server (SDP) for managing personal data of a plurality of users, the method comprising: i ) is recorded in the comprehensive database (BD C ), and each block (B i ) comprises the encrypted personal data of one of the users, and the plurality of blocks (B i ) comprises the encrypted personal data of the same user and has the same overall graph (G C ) subgraph (SG A ) is organized based on the blockchain that constitutes the overall graph (G C The topology of the subgraph (SG) is defined by a pre-constructed data model. A ) Route Block (BR A ) is the dynamic non-fungible token (NFT) of this user (A). A ) and The method comprises a step (E700) for managing a series of instances of a digital trusted environment, one of the instances comprising: - executes instructions (DLII, CODE) specified in a digital contract (AG ECN A, SP ) for analyzing a portion of said personal data (DP A ) of at least one user party to said contract, said contract comprising a symmetric encryption key ([KS A ]) of said at least one party to said contract encrypted with a public key (KPUB ECN ) of said instance of a Digital Trust Environment, said symmetric encryption key ([KS A ]) being able to be used by said instance to decrypt said personal data to be analyzed; - providing the results of said analysis to at least one party to said agreement; How it is configured and managed.

8. A management method executed by a server (SDP) for managing personal data of multiple users, the method comprising managing a comprehensive database (BD C) in which multiple blocks (B i) are recorded, each block (B i) comprising the encrypted personal data of one of the users, the multiple blocks (B i) comprising the encrypted personal data of the same user and organized based on blockchains constituting subgraphs (SG A) of the same comprehensive graph (G C), the topology of the comprehensive graph (G C) being defined by a pre-constructed data model, and the root block (BR A) of the subgraph (SG A) being associated with a dynamic non-fungible token (NFT A) of this user (A), The method comprises, for each of the plurality of users: providing said user's terminal with a local application that enables said terminal to create a symmetric encryption key (KS A ), said symmetric encryption key (KS A ) enabling said terminal to encrypt said root block (BR A ); receiving an output hash H([BR AA ]) of the encrypted root block (BR A ) from the user's terminal; creating the dynamic non-fungible token (NFT A ), assigning it to the user, and associating it with the output hash H([BR AA ]).

9. - A symmetric encryption key (KS) associated with the profile of the user (A) A ) for obtaining the - the user's personal data (DP A ) for collecting the - the personal data (DP) of the user (A) A ) in the collection of: (i) the symmetric encryption key (Ks) of this user A a step (E52) for encrypting said personal data; and (ii) Comprehensive Database (BD) C ) and the encrypted data ([B iA ]) i ) and a step (E56) of recording the plurality of blocks (B i ) is the overall graph (G C ) subgraph (SG A ) is organized based on the blockchain that constitutes the overall graph (G C The topology of the subgraph (SG) is defined by a pre-constructed data model. A ) Route Block (BR A ) is the dynamic non-fungible token (NFT) of this user (A). A ) associated with step (E56), A terminal (T) comprising a processor configured to execute A ).

10. A server (SDP) for managing personal data of multiple users, which stores multiple blocks (B i ) is recorded in the comprehensive database (BD C ), wherein each block (B i ) comprises the encrypted personal data of one of the users, and the plurality of blocks (B i ) comprises the encrypted personal data of the same user and has the same overall graph (G C ) subgraph (SG A ) is organized based on the blockchain that constitutes the overall graph (G C The topology of the subgraph (SG) is defined by a pre-constructed data model. A ) Route Block (BR A ) is the dynamic non-fungible token (NFT) of this user (A). A ) and The processor is configured to manage a set of instances of a digital trusted environment, one of the instances comprising: - executes instructions (DLII, CODE) specified in a digital contract (AG ECN A, SP ) for analyzing a portion of said personal data (DP A ) of at least one user party to said contract, said contract comprising a symmetric encryption key ([KS A ]) of said at least one party to said contract encrypted with a public key (KPUB ECN ) of said instance of a Digital Trust Environment, said symmetric encryption key ([KS A ]) being able to be used by said instance to decrypt said personal data to be analyzed; - providing the results of said analysis to at least one party to said agreement; The server (SDP) is configured to:

11. A server (SDP) for managing personal data of multiple users, the server comprising a processor configured to manage a comprehensive database (BD C) in which multiple blocks (B i) are recorded, each block (B i) comprising the encrypted personal data of one of the users, the multiple blocks (B i) comprising the encrypted personal data of the same user and organized based on blockchains constituting subgraphs (SG A) of the same comprehensive graph (G C), the topology of the comprehensive graph (G C) being defined by a pre-constructed data model, and the root block (BR A) of the subgraph (SG A) being associated with a dynamic non-fungible token (NFT A) of this user (A), The server (SDP) receives, for each of the plurality of users, providing said user's terminal with a local application that enables said terminal to create a symmetric encryption key (KS A ), said symmetric encryption key (KS A ) enabling said terminal to encrypt said root block (BR A ); receiving an output hash H([BR AA ]) of the encrypted root block (BR A ) from the user's terminal; creating the dynamic non-fungible token (NFT A ), assigning it to the user, and associating it with the output hash H([BR AA ]).

12. A computer program (P1) comprising instructions for carrying out the method for building a personal data history according to any one of claims 1 to 6 when executed by a computer.

13. A computer program (P2) comprising instructions for carrying out the method for managing personal data of a plurality of users according to claim 7 or 8 when executed by a computer.

14. Performing a method for constructing a personal data history according to any one of claims 1 to 6 for a plurality of users; and executing a server (SDP)-executed management method for managing the personal data of the plurality of users, comprising: The management method comprises managing a comprehensive database (BD C ) in which multiple blocks (B i ) are recorded, each block (B i ) comprising the encrypted personal data of one of the users, the multiple blocks (B i ) comprising the encrypted personal data of the same user and organized based on a blockchain constituting a subgraph (SG A ) of the same comprehensive graph (G C ), the topology of the comprehensive graph (G C ) being specified by a pre-constructed data model, and the root block (BR A ) of the subgraph (SG A ) being associated with the dynamic non-fungible token (NFT A ) of this user (A).

15. A system comprising a plurality of user terminals, each of which is configured by a terminal (T A ) according to claim 9; a server (SDP) for managing personal data of the plurality of users, The server comprises a processor configured to manage a comprehensive database (BD C) in which multiple blocks (B i ) are recorded, each block (B i ) comprising the encrypted personal data of one of the users, the multiple blocks (B i ) comprising the encrypted personal data of the same user and organized based on a blockchain constituting a subgraph (SG A ) of the same comprehensive graph (G C ), the topology of the comprehensive graph (G C ) being specified by a pre-constructed data model, and the root block (BR A ) of the subgraph (SG A ) being associated with the dynamic non-fungible token (NFT A ) of this user (A), the system.

Citation Information

Patent Citations

  • Barrel unit sake storage state data management and ownership certificate management system

    JP2022045382A

  • Provision of location-specific user information

    US20210092613A1

  • Blockchain-based user privacy data providing methods and apparatuses

    US20210326476A1