Blockchain-based dynamic authorization method and system for personal data

The blockchain-based dynamic authorization method using NFTs empowers individuals to control personal data disclosure, addressing the lack of autonomy in existing systems by providing secure and transparent data access management.

TWI931777BActive Publication Date: 2026-07-11NAT TAIWAN UNIV OF SCI & TECH
0 Cites 0 Cited by

Patent Information

Application Number
TW113125369
Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-07-05
Publication Date
2026-07-11
Estimated Expiration
2044-07-04

Smart Images

  • Figure IMG-2_DRAW_113125369-A0304-14-0001-1
    Figure IMG-2_DRAW_113125369-A0304-14-0001-1
  • Figure IMG-2_DRAW_113125369-A0304-14-0002-2
    Figure IMG-2_DRAW_113125369-A0304-14-0002-2
  • Figure IMG-2_DRAW_04_A0101_DRAWINGS_1
    Figure IMG-2_DRAW_04_A0101_DRAWINGS_1
Patent Text Reader

Abstract

This disclosure presents a blockchain-based dynamic authorization method and system for personal data, enabling a data owner to dynamically authorize a data requester to use their data stored on a blockchain. The method includes the following steps: receiving a request from the data requester via a request interface to use one of the data owner's data; notifying the data owner of the usage request; receiving the data owner's consent via an authorization interface; generating an authorization certificate based on a blockchain non-fungible token and linking it to one of the data requester's blockchain wallets; receiving a request from the data requester to access one of the data owner's data via a data access interface; verifying that the data requester's blockchain wallet is linked to the authorization certificate created by the data owner; and, upon successful verification of the authorization certificate, providing the data owner's data stored on the blockchain to the data requester for access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the management of personal data, and in particular to the methods and systems by which owners of personal data dynamically authorize others to use their personal data. Prior Technology

[0002] In today's cloud-based internet age, our personal information is constantly being collected and used. Sometimes this collection and use is done with our consent; for example, when using certain online services, we are required to create an account and provide personal information such as our birthday, address, gender, and occupation. However, other types of personal information, such as our medical records, clinical treatments, and even physical examination data related to health, as well as our income and expenses related to tax payments, are often collected, recorded, and used by relevant organizations (such as health insurance agencies, medical institutions, and national tax authorities).

[0003] With the continuous advancement of big data and artificial intelligence technologies, especially personal data involving privacy, such as the aforementioned data, is frequently analyzed and utilized by government and academic institutions. The analysis results can then be used to formulate or develop policies, research findings, and industrial applications that benefit the public. For example, Taiwan's primary biomedical policy goal is to develop a precision health strategic industry, aiming to create a holistic precision health care system (such as early cancer detection, early treatment, and reduced mortality). Such goals require big data sharing platforms and mechanisms for a vast amount of personal health data. However, given that the personal data collected and stored by these institutions involves personal privacy, how to legally and compliantly utilize it while ensuring the protection of personal data privacy rights has become an urgent issue.

[0004] The burgeoning blockchain technology offers a secure and feasible data-sharing solution. Blockchain is a decentralized database technology whose core concept is packaging data into blocks. Each block contains a unique hash value calculated based on its own data, along with the hash of the previous block, thus forming a chain. These chains are then stored multiple times on a decentralized peer-to-peer network. This design makes the block content difficult to tamper with. Therefore, storing personal data on the blockchain can provide sharing while simultaneously ensuring the security of personal data. However, blockchain itself does not provide individuals with the right to autonomously control the privacy of their personal data—that is, the right to decide whether to disclose their personal data, and to what extent, when, how, and to whom it is disclosed. Summary of the Invention

[0005] The purpose of this disclosure is to provide a novel approach that allows individuals to dynamically and autonomously control their personal data. This means that individuals can decide whether to disclose their personal data, and to what extent, when, how, and to whom to disclose it, and can also dynamically modify these authorization conditions.

[0006] Therefore, this disclosure proposes a blockchain-based dynamic authorization method for personal data, which allows a data owner to dynamically authorize a data user to use their personal data stored on a blockchain. This method includes the following steps:

[0007] The recipient of the data request submits a request for use of one of the data owners' data through a request interface;

[0008] The user request will be communicated to the asset owner.

[0009] Receive consent from the individual asset owner through an authorized interface;

[0010] Generate an authorization certificate based on a blockchain-based non-fungible token and link it to the blockchain wallet of one of the asset demanders;

[0011] The data user requests access to the data owner's personal data through a data access interface;

[0012] The access interface verifies that the blockchain wallet of the user requesting the asset is linked to the authorization credential created by the asset owner; and

[0013] Once the authorization certificate is verified, the personal data access interface will store the personal data of the personal data owner in the blockchain and make it available to the personal data user.

[0014] In some embodiments of this disclosure, the disclosure may further include the following steps:

[0015] When the access interface detects that the authorization certificate has expired, the access interface automatically destroys the authorization certificate. Receive a request from the asset owner to destroy one of the license credentials through the license interface; and

[0016] Destroy the authorization certificate.

[0017] The blockchain can be a public chain, a private chain, a hybrid chain, or a consortium chain. Furthermore, the blockchain may contain single chains or multiple chains.

[0018] The authorization certificate is preferably a non-tradable, soul-bound, non-fungible token.

[0019] The above-mentioned and other objects and advantages of this disclosure are described in detail below with reference to the accompanying drawings, detailed description of the embodiments, and the claims. It should be understood that the accompanying drawings are merely for illustrating the spirit of this disclosure and should not be construed as defining the scope of this disclosure. For a definition of the scope of this disclosure, please refer to the appended claims. Simple Explanation of the Diagram

[0020] Figure 1 is a flowchart of the blockchain-based dynamic authorization method for personal data proposed in this disclosure.

[0021] Figure 2 is a schematic diagram of the blockchain-based dynamic authorization system for personal data proposed in this disclosure. Implementation

[0022] The term "personal data" or "personal information" as used in this disclosure refers to information that meets the definition of the Personal Data Protection Act of Taiwan, including information such as name, date of birth, national identity card number, passport number, personal characteristics, fingerprints, marital status, family, education, occupation, medical records, medical information, genetic information, sexual history, health examination results, criminal record, contact information, financial situation, social activities, and other information that can directly or indirectly identify an individual. That individual is referred to as the "personal data owner" in this disclosure.

[0023] The personal data of one or more data owners has been added to and stored on a blockchain by a "data manager" using the blockchain's block-building method, also known as mining. The relevant block-building method is well-known technology and will not be elaborated upon here. The term "data manager" in this disclosure refers to an organization responsible for collecting, managing, or maintaining personal data (such as health insurance organizations, medical institutions, tax authorities, financial institutions, operators of biobanks, etc.).

[0024] The blockchain can be a public blockchain (which is permissionless and can be used by the general public), a private blockchain (which is privately controlled and not publicly disclosed), a consortium blockchain (which is accessible only to a predetermined number of organizations or institutions), or a hybrid blockchain (a combination of public and private blockchains). The blockchain can contain a single blockchain or multiple blockchains.

[0025] Individuals or organizations intending to use the aforementioned personal data stored on this blockchain are referred to in this disclosure as "data requesters." Data requesters need permission to use the blockchain and will therefore have their own dedicated "wallet" on that blockchain. A blockchain wallet is a unique address, functioning similarly to an account for online services; it is a digital asset and management mechanism on the blockchain. The main functions of a blockchain wallet include generating and managing cryptographic key pairs (public and private keys) and signing transactions. Through this unique address, the blockchain wallet can be used to send and receive cryptocurrencies (such as Bitcoin and Ethereum) and the dynamic authorization from the data owner as described in this disclosure. The methods for building blockchain wallets are well-known technologies and will not be elaborated upon here.

[0026] The steps disclosed herein will be described in detail below.

[0027] First, this disclosure provides a request interface for a data requester to submit a "use request" for the personal data of a data owner. The "use request" referred to in this disclosure includes, but is not limited to, the data requester's identity information, the scope of the data to be used (a specific portion or all), the purpose of use, the date and time range of use, and the number of uses. This disclosure also includes an authorization interface for a data owner to agree to or refuse a use request, and to modify the use request (e.g., change the scope of the data, the date and time range of use, or the number of uses) before agreeing to it.

[0028] The request interface and the authorization interface are preferably (but not limited to) provided by a decentralized application (DApp). A DApp is an application built on blockchain technology. Unlike traditional centralized applications, DApps distribute data storage and processing across multiple nodes on the blockchain network during operation, rather than concentrating it on a single centralized server. Because data storage and processing are distributed across multiple nodes and use encryption technology, DApps typically have extremely high security.

[0029] The architecture of this decentralized application is divided into a front-end (i.e., the aforementioned request interface, authorization interface, etc.) and a back-end (the smart contracts, which will be discussed later). The front-end interface is not stored on the blockchain, but is (but not limited to) a regular web application (providing one or more web pages) using technologies such as HTML, CSS, and JavaScript, running on a traditional or decentralized web server. The back-end smart contracts, which handle business logic, data storage, and transaction processing, are stored on the blockchain, with a copy existing on each node.

[0030] Decentralized applications (Decentralized Applications) and smart contracts, which will be used later in this disclosure, are both important mechanisms of blockchain. In this disclosure, the decentralized application provides a request interface and an authorization interface, allowing asset requesters and owners to interact with smart contracts on the blockchain and use their functions. Specifically, asset requesters or owners access the front-end request interface or authorization interface through a web browser on a mobile phone, computer, or other device, and then interact with the back-end smart contracts through these interfaces. The back-end smart contracts receive requests, execute the corresponding business logic, and return the results to the front-end interface. Simultaneously, all transactions and state changes are recorded on the blockchain and broadcast to all nodes.

[0031] Next, as shown in Figure 1, this disclosure receives a request from a user to use one of an asset owner's personal assets through the request application interface. Once submitted, the request will be reviewed by the asset manager. This disclosure may also provide a similar request application interface or authorization interface, as well as a management and review interface based on a decentralized application. Further details will not be repeated here.

[0032] After the data administrator approves the request, this disclosure will then notify the relevant data owner of the usage requirement. The notification may be delivered to the data owner via email, SMS, or other mechanisms. In addition to the aforementioned usage requirement, the notification will also include a link to access the authorized usage interface.

[0033] The asset owner agrees to, rejects, or modifies the usage request through the authorization interface. If the asset owner agrees to the usage request (or the modified usage request), the smart contract corresponding to the authorization interface then generates an authorization certificate based on a blockchain token and "stores" it in the asset requester's blockchain wallet. This authorization certificate records the content of the aforementioned usage request (or modified usage request) (such as the scope of assets used, the date and time range of use, the number of times used, etc.). Here, "stores" is a colloquial term; more precisely, it means that the authorization certificate is linked to the unique address of the blockchain wallet.

[0034] Tokens are mechanisms for issuing, managing, transferring, and trading on a blockchain, representing various assets or values. Tokens include currencies (such as Bitcoin and Ethereum), physical assets (such as gold, real estate, and art), and specific rights or functions (such as voting rights and access rights). Tokens use blockchain technology to ensure security and transparency, and can be tracked and recorded on the blockchain, thereby ensuring the authenticity and immutability of the token's issuance, management, transfer, and trading.

[0035] This authorization certificate is a type of non-fungible token (NFT). Unlike cryptocurrency tokens (such as Bitcoin and Ethereum), NFTs are not fungible, and each NFT has a unique identity. Therefore, each authorization certificate based on NFT, generated by the consent of each asset owner for each user's use of the asset, is unique and non-fungible.

[0036] Preferably, this authorization certificate is a special type of non-tradable, non-transferable so-called soul-bound non-fungible token (NFT). The term "soul-bound" implies a close connection between this NFT and its holder, who possesses special rights to the corresponding asset.

[0037] As previously stated, the creation and management of this authorization credential are accomplished through one of the smart contracts provided in this disclosure. A smart contract is an automated computer program that executes on a blockchain. It contains pre-written code that automatically performs calculations when specific conditions are met to implement pre-planned business logic and tracks related transactions and decisions. Smart contracts are commonly used to manage digital assets (such as the aforementioned tokens), execute transactions, and implement decentralized services.

[0038] The code for a smart contract is typically stored on every node of the blockchain (each node has an identical copy of the smart contract). When a smart contract is deployed to the blockchain, its code and initial state are recorded in a block and broadcast throughout the blockchain network. Each participating node receives and stores the smart contract's code and state locally. Therefore, all nodes have an identical copy of the smart contract. When the smart contract is triggered for execution, each node executes the same contract code and updates its state based on the execution result. These results are also broadcast throughout the blockchain network and verified and recorded by each node. In this way, the state and operational results of the smart contract can be verified and recorded on all nodes of the blockchain network, thus ensuring its transparency, security, and immutability.

[0039] If the asset owner agrees to the usage request, the authorized user interface initiates the corresponding smart contract, creates a non-fungible token representing the authorization certificate, and links it to the asset requester's blockchain wallet. In other words, the decentralized application (DAPI) of the authorized user interface is the interface through which the asset owner interacts with the blockchain, and the smart contract is the code that implements the business logic and functionality behind the DAPI. Note that smart contracts can be shared by multiple DAPIs, and are not limited to a single DAPI.

[0040] The creation, transfer, and destruction of the aforementioned authorization credentials based on blockchain tokens, as well as transaction records, are stored on the blockchain as part of the smart contract state of each node. Therefore, this information has a copy on each node of the blockchain.

[0041] A user's blockchain wallet containing an authorization credential created by a user asset owner signifies that the user has been authorized by the user asset owner to use the latter's assets. The user accesses the user asset through a resource access interface provided in this disclosure. Like the request interface and the authorization interface, this resource access interface is preferably also a decentralized application frontend, and its operation will invoke a corresponding smart contract. This smart contract can be the same as or different from the smart contracts of the resource request interface and the authorization interface.

[0042] Therefore, when a user requests access to an asset owner's personal data through this access interface, the access interface invokes its corresponding smart contract. This smart contract verifies that the user's blockchain wallet is linked to the authorization certificate created by the asset owner, and that the access conforms to the usage requirements recorded in the authorization certificate (such as the scope of personal data used, the date and time range of use, and the number of uses). Then, after the access is verified by the smart contract, the smart contract decrypts and reassembles the relevant personal data stored on the blockchain and provides it to the user through the access interface.

[0043] When the smart contract detects that a user's blockchain wallet has expired its authorization certificate (e.g., it has exceeded its recorded usage period or reached the required usage count), the smart contract will automatically burn the tokens associated with that authorization certificate. Burning tokens on the blockchain means permanently removing them from the supply, typically by sending them to a special address (called a burn address or zero address). Once the tokens are sent to this address, they can no longer be used because their private keys are no longer available, thus the tokens are permanently lost. Token burning is an irreversible operation; once a token is burned, it cannot be recovered.

[0044] In addition to automatically destroying expired authorization tokens through the smart contract of the aforementioned asset access interface, an asset owner can also request the cancellation of previously created, still-valid, usage authorizations at any time through the aforementioned authorization usage interface. This is also achieved by destroying the tokens of the already created usage authorizations through the smart contract of the authorization usage interface.

[0045] Furthermore, a resource owner can modify an existing, valid usage license at any time through the aforementioned licensing interface (e.g., changing the resource scope, the date and time range of use, or the number of uses). The implementation involves a smart contract within the licensing interface first destroying the existing usage license token, then creating a new, blockchain-based licensing certificate and linking it to the resource user's blockchain wallet. This new licensing certificate records the modified usage requirements (such as the resource scope, the date and time range of use, and the number of uses).

[0046] This disclosure also provides a system for implementing the aforementioned dynamic authorization of personal data. As shown in Figure 2, this system comprises the following components:

[0047] A blockchain 10 comprises a plurality of decentralized nodes 102 connected via a network. This blockchain can be a public, private, hybrid, or consortium blockchain. It can also consist of a single blockchain or multiple blockchains. An asset owner's assets have been added to and stored on node 102 of this blockchain by an asset manager according to the blockchain's block-building method.

[0048] A first decentralized application 20 includes a front-end request interface 202 and a back-end first smart contract 204. The request interface 202 runs on a first server 104, allowing a resource requester to submit a request to use the resource of the resource owner. The first server 104 is one of the nodes 102, which may be a web server, and the request interface runs on a web application of that web server. The resource requester accesses the web application and uses the authorization request interface 202 through a web browser on a mobile phone, computer, or other device.

[0049] A second decentralized application 30 includes a front-end authorization interface 302 and a back-end second smart contract 304. The authorization interface 302 runs on a second server 106, allowing the data owner to agree to, reject, or modify a request to use their data. The second server 106 is one of the nodes 102, which may be a web server, and the authorization interface runs on a web application within that web server. The data owner accesses the web application and uses the authorization interface 302 through a web browser on a mobile phone, computer, or other device.

[0050] The first server 104 and the second server 106 can be the same server. The first smart contract 204 and the second smart contract 304 can be the same smart contract. The first and second smart contracts 204 and 304 are stored on the blockchain and a copy exists on each node 102.

[0051] After the first smart contract 204 is initiated via the request application interface 202, it transmits the usage request to an asset manager. Upon approval by the asset manager, the first smart contract 204 notifies the asset owner of the usage request. The asset owner, upon receiving the notification, accesses the authorization interface 302 to agree, refuse, or modify and agree to the usage request. If the asset owner agrees to the usage request, or agrees after modification, the authorization interface 302 initiates the second smart contract 304. The second smart contract 304 generates an authorization certificate based on a blockchain token and links this authorization certificate to the blockchain wallet 50 of one of the asset requesters.

[0052] A third decentralized application 40 includes a front-end data access interface 402 and a back-end third smart contract 404. The data access interface 402 runs on a third server 108, allowing the data requester to access the data of the data owner. The third server 108 is one of the nodes 102, and the data access interface 402 can provide data access, for example, through an API, for the application running on the third server 108. The data requester uses the data access interface 402 through a query program on a computer or other device.

[0053] When a user requests access to the user's personal assets via the personal asset access interface 402, the interface calls its corresponding third smart contract 404. The third smart contract 404 verifies whether the user's blockchain wallet 50 is linked to the authorization certificate created by the user and whether it meets the usage requirements stated in the authorization certificate. After verification, the third smart contract 404 decrypts and reassembles the relevant personal assets stored on the blockchain and provides them to the user via the personal asset access interface 402. If the third smart contract 404 detects that the authorization certificate linked to the user's blockchain wallet 50 has expired, it will automatically destroy the tokens associated with that authorization certificate.

[0054] The asset owner can also request the cancellation of a previously created, yet-to-expire usage license at any time through the aforementioned licensing interface 302. This is achieved by destroying the tokens associated with the created usage license through the second smart contract 304 of the licensing interface 302.

[0055] The asset owner can also modify an existing, valid usage license at any time through the aforementioned licensing interface 302. This is achieved by first destroying the existing usage license token through the second smart contract 302 of the licensing interface 302, and then creating a new, blockchain-based licensing certificate and linking it to the asset requester's blockchain wallet 50. This new licensing certificate records the modified usage requirements.

[0056] The third server 108 may be the same server as the first server 104 or the second server 106. The third smart contract 404 may be the same smart contract as the first smart contract 204 or the second smart contract 304. The third smart contract 404 is stored on the blockchain and a copy exists on each node 102.

[0057] The detailed description of the specific embodiments above is intended to more clearly illustrate the features and spirit of this invention, and is not intended to limit the scope of this invention with the specific embodiments disclosed above. On the contrary, the aim is to cover various modifications and equivalent arrangements within the scope of the patent claims to be made for this invention.

[0058] 10: Blockchain 20: The First Decentralized Application 102: Blockchain Node 202: Request Interface 104: First Server 204: The First Smart Contract 106: Second Server 30: Second Decentralized Application 108: Third Server 302: Authorized Use Interface 40: Third Decentralized Applications 304: Second Smart Contract 402: Personal Data Access Interface 50: Blockchain Wallets for Individuals with Personal Data Needs 404: Third Smart Contract

Claims

1. A blockchain-based method for dynamic authorization of personal data, allowing a data owner to dynamically authorize a data requester to use a data stored on a blockchain. The method includes the following steps: receiving a request from the data requester via a request interface to use the data stored on the blockchain by the data owner; notifying the data owner of the usage request; receiving consent from the data owner via an authorization interface, or a modified consent from the data owner via the authorization interface; generating an authorization certificate corresponding to the usage request, based on a non-fungible and non-tradable token on the blockchain, and linking it to the blockchain wallet of the data requester. The authorization certificate contains the content of the usage request or the modified usage request, wherein... The authorization certificate records the scope, date and time range, and frequency of the data in the usage request as part of the smart contract state; it receives a request from the data requester to access the data of the data owner through a data access interface; it verifies that the data requester's blockchain wallet is linked to the authorization certificate created by the data owner, and determines whether the access conforms to the scope, date and time range, and frequency of the data recorded in the authorization certificate; and when the authorization certificate is verified, it provides the data of the data owner stored in the blockchain to the data requester for access; wherein, if the data requester's blockchain wallet is linked to the authorization certificate created by the data owner, and the request conforms to the usage request content contained in the authorization certificate, it means that the data requester has obtained the authorization from the data owner to use the data.

2. The blockchain-based dynamic authorization method for personal data as described in Request 1 further includes the following steps: When the data access interface detects that the authorization credential has expired, the authorization credential is automatically destroyed.

3. The blockchain-based dynamic authorization method for personal data as described in Request 1 further includes the following steps: receiving a request from the data owner to destroy the authorization certificate through the authorization interface; and destroying the authorization certificate.

4. The blockchain-based dynamic authorization method for personal data, as described in Request 1, further includes the following steps: receiving a request from the data owner to modify one of the usage requirements through the authorization interface; destroying the authorization certificate; and generating an authorization certificate corresponding to the modified usage requirement and another blockchain-based non-fungible token, and linking it to the data requester's blockchain wallet.

5. The blockchain-based dynamic authorization method for personal data as described in Request 1, wherein the blockchain is a public chain, a private chain, a hybrid chain, or a consortium chain.

6. The blockchain-based dynamic authorization method for personal data as described in request item 1, wherein the blockchain comprises a single chain or multiple chains.

7. The blockchain-based dynamic authorization method for personal data as described in Request 1, wherein the usage requirement includes part or all of the personal data to be used, the purpose of use, the date and time range of use, and the number of times it will be used.

8. The blockchain-based dynamic authorization method for personal data as described in Request 1, wherein the authorization credential is a non-tradable, soul-bound, non-fungible token.

9. The blockchain-based dynamic authorization method for personal data as described in Request 1, wherein the request interface, the authorization interface, and the data access interface are provided by a decentralized application or by a single decentralized application, respectively.

10. The blockchain-based dynamic authorization method for personal data as described in Request 9, wherein each decentralized application implements the functions of the request interface, the authorization interface, and the data access interface through a corresponding smart contract.

11. A blockchain-based dynamic authorization system for personal data, enabling a data owner to dynamically authorize a data requester to use one of their data, the system comprising: a blockchain containing a plurality of nodes, wherein the data of the data owner has been added to and stored on the nodes of the blockchain according to the blockchain's block construction method; and a first decentralized application comprising a front-end request application interface and a back-end first smart contract, wherein, The request interface allows the user to submit a request to use the asset from the asset owner. A first smart contract notifies the asset owner of the usage request. This first smart contract is stored on each of the nodes. A first server, one of the nodes, runs the request interface. A second decentralized application includes a front-end authorization interface and a back-end second smart contract. The authorization interface allows the asset owner to agree to, reject, or modify the usage request before agreeing to the request. Upon the asset owner's agreement to the usage request, or after modification, the second smart contract generates an authorization certificate based on a blockchain-based non-fungible token and links this certificate to the asset user's blockchain wallet. This authorization certificate contains the content of the original usage request or the modified usage request. The second smart contract is stored on each of the nodes. A second server, one of the nodes, runs the authorization interface. A third decentralized application includes a front-end asset access interface and a back-end third smart contract. The asset access interface allows a user to submit a request to access the assets of the asset owner. The third smart contract verifies whether the user's blockchain wallet is connected to the authorization certificate created by the asset owner, and whether the request conforms to the usage requirements contained in the authorization certificate. After the above verification, the third smart contract provides the asset owner's assets stored on the blockchain to the user through the asset access interface. The third smart contract is stored on each of these nodes. A third server, which is one of these nodes, runs the asset access interface.

12. A blockchain-based dynamic authorization system for personal data, as in request item 11, wherein when a third smart contract discovers that the authorization credential has expired, the third smart contract automatically destroys the authorization credential.

13. The blockchain-based dynamic authorization system for personal data as described in request item 11, wherein the second smart contract destroys the authorization credential after the authorization interface receives a request from the specific data owner to destroy the authorization credential.

14. The blockchain-based dynamic authorization system for personal data as described in claim 11, wherein after the authorization interface receives a request from the specific data owner to modify one of the usage requirements, the second smart contract destroys the authorization certificate; and the second smart contract generates another authorization certificate based on a blockchain non-fungible token for the modified usage requirement and links it to the data requester's blockchain wallet.

15. A blockchain-based dynamic authorization system for personal data, as requested in item 11, wherein the blockchain is a public chain, a private chain, a hybrid chain, or a consortium chain.

16. A blockchain-based dynamic authorization system for personal data, as in request item 11, wherein the blockchain comprises a single chain or multiple chains.

17. A blockchain-based dynamic authorization system for personal data, as in request item 11, wherein the usage requirement includes part or all of the personal data to be used, the purpose of use, the date and time range of use, and the number of times it will be used.

18. A blockchain-based dynamic authorization system for personal data, as in request item 11, wherein the authorization certificate is a non-tradable, soul-bound, non-fungible token.

19. The blockchain-based dynamic authorization system for personal data as described in request item 11, wherein the first server, the second server, and the third server are the same server.

20. The blockchain-based dynamic authorization system for personal data as described in claim 11, wherein the first smart contract, the second smart contract, and the third smart contract are the same smart contract.