Trusted Hardware Data Management via Decentralized Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data management methods lack convenience and reliability for users, particularly in ensuring the authenticity and validity of data assets in the digital era, as they fail to effectively prevent the publication of false data description information and ensure secure data management.

Innovation Solution

A trusted hardware-based data management method that utilizes decentralized identifiers and trusted institutions to verify the authenticity of data description information, ensuring that only valid data is published and managed, by obtaining data description information, requesting verification from trusted institutions, and publishing if the verification is successful.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional data management methods are used, then data publication is simple and fast, but the authenticity and reliability of data description information cannot be ensured

Engineering Contradiction:
Improveauthenticity of data description informationVSAvoidcomplexity of data management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted institution as an intermediary between the data owner and data users. This trusted institution verifies the authenticity of data description information and provides verification results, thereby ensuring data reliability without requiring complex peer-review systems. The intermediary handles the verification process centrally, maintaining simplicity while improving trustworthiness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual verification mechanisms with automated cryptographic verification. The trusted hardware performs cryptographic operations to generate and verify proof information automatically, substituting manual review processes with machine-executable verification protocols. This reduces the complexity of human-mediated verification while enhancing reliability through cryptographic guarantees.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If verification mechanisms are added to ensure data authenticity, then reliability improves, but operation convenience deteriorates

Engineering Contradiction:
Improvereliability of data managementVSAvoidconvenience of data publication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted hardware automatically performs verification operations without requiring manual intervention from the data owner. The system uses self-service mechanisms where the trusted hardware autonomously generates proof information and interacts with the trusted institution, eliminating the need for users to manually verify data authenticity and maintaining operational convenience.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The verification process is performed in advance during data publication, before data is made available to users. The trusted hardware generates verification proof and obtains verification results beforehand, so that when data is published, the reliability assurance is already in place. This preliminary verification eliminates the need for ongoing verification operations that would complicate data access and usage.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If trusted hardware verification is implemented, then false information publication is prevented, but system complexity increases

Engineering Contradiction:
Improveprevention of false informationVSAvoidcomplexity of verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the verification functionality into a separate trusted hardware module that is bound to the data owner's decentralized identifier. This extracted verification component handles all cryptographic operations and interactions with the trusted institution, isolating the complexity from the main data management system. The core system only needs to integrate with the trusted hardware interface, maintaining simplicity while enabling robust verification.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If decentralized identifier binding is used, then data ownership and authenticity are verified, but the management process becomes more complex

Engineering Contradiction:
Improveverification of data ownershipVSAvoidsimplicity of data management process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted hardware is designed to perform multiple functions: storing the binding between decentralized identifier and data, generating cryptographic proof, verifying data description information, and managing verification processes. This multi-functional trusted hardware consolidates what would otherwise require separate systems, maintaining operational simplicity while providing comprehensive verification capabilities for data ownership and authenticity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3965359B1Trusted hardware-based data management methods, apparatuses, and devices
Publication Date: 2023.12.20 ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
  • EP3965359B1 patent drawingFigure 1
  • EP3965359B1 patent drawingFigure 2~3
  • EP3965359B1 patent drawingFigure 4~5

AI summary

Embodiments of the present specification disclose a trusted hardware-based data management method, apparatus, and device. The solutions include the following: a data owner can register a personal decentralized identifier based on a blockchain technology, and establish a binding relationship between the decentralized identifier of the data owner and trusted hardware, so that after obtaining data description information used to describe target data of the data owner that can be provided by a trusted institution, the trusted hardware can request the trusted institution to verify whether the trusted institution stores user service data needed for generating the target data. If the trusted institution stores the user service data needed for generating the target data, the data owner can publish the data description information by using the trusted hardware, so that the data owner can conveniently manage a data asset by using the trusted hardware.