IP Library Granted Patent US 11,057,189
Granted Patent B2
US 11,057,189 · App. 16/779,228 · Granted Jul 6, 2021

Providing data authorization based on blockchain

Inventors: Changzheng Wei (Hangzhou, CN); Ying Yan (Hangzhou, CN); Hui Zhang (Hangzhou, CN); Yujun Peng (Hangzhou, CN)
Assignee: Advanced New Technologies Co., Ltd.
H04L9/0637G06Q20/02G06Q20/0658H04L9/321H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,057,189
App. No.
16/779,228
Granted
Jul 6, 2021
Kind
B2
Abstract

Disclosed herein are methods, systems, and apparatus, including computer programs encoded on computer storage media, for providing blockchain-based data authorization. One of the methods includes receiving, by a blockchain node, a data acquisition transaction submitted by a data user for obtaining target data possessed by a data owner, determining, by the blockchain node, that the data user has obtained authorization of the target data, and executing, by the blockchain node, a smart contract invoked by the data acquisition transaction to provide one or more of the target data and a computational result of one or more predetermined computational operations performed based on the target data to the data user.

Claims (55)

1. A blockchain-based data authorization method, comprising:

receiving, by a blockchain node, a data acquisition transaction submitted by a data user for obtaining target data possessed by a data owner;

transmitting, by the blockchain node, the data acquisition transaction to a second blockchain node based on a blockchain consensus process;

determining, by the blockchain node, that the data user has obtained authorization of the target data;

executing, by the blockchain node, a smart contract invoked by the data acquisition transaction to provide one or more of the target data and a computational result of one or more predetermined computational operations performed based on the target data to the data user;

providing, by the blockchain node and based at least on the blockchain node and the second blockchain node executing the smart contract, the target data and the computational result to the data user, wherein a transaction execution result event based on the target data and the computational result are written in a transaction log by the smart contract, and wherein the transaction log is monitored and available to be acquired by the data user;

encrypting, by the blockchain node, the target data in a trusted execution environment (TEE) to obtain encrypted target data; and

storing, by the blockchain node, the encrypted target data to a database associated with the blockchain node;

wherein the executing the smart contract is performed in the TEE after reading the encrypted target data into the TEE and decrypting the encrypted target data,

wherein the smart contract is executed to provide the target data to the data user if the target data has low data privacy level, and the smart contract is executed to provide the computational result of the one or more predetermined computational operations if the target data has high data privacy level.

2. The method according to claim 1 , wherein the smart contract comprises a list of authorized users including the data user and the determining that the data user has obtained authorization of the target data is performed based on the list of authorized users.

3. The method according to claim 1 , further comprising:

invoking, by the blockchain node, a request interface defined in the smart contract based on an authorization request transaction submitted by the data user to cause the smart contract to write an authorization request event into the transaction log of the data owner; and

invoking, by the blockchain node, an authorization interface defined in the smart contract based on an authorization confirmation transaction submitted by the data owner to cause the smart contract to mark the data user as an authorized user.

4. The method according to claim 1 , wherein one or more operation rules of the one or more predetermined computational operations are predefined in the smart contract or are transferred into the smart contract through the data acquisition transaction.

5. The method according to claim 1 , wherein providing, by the blockchain node and based on, at least, the blockchain node and the second blockchain node executing the smart contract, the target data and the computational result to the data user comprises:

encrypting the target data and the computational result; and

storing the encrypted target data and the encrypted computational result within the transaction execution result event in the transaction log, wherein the encrypted target data and the encrypted computational result are configured to enable the data user to decrypt the encrypted target data and the encrypted computational result to obtain the target data and the computational result.

6. The method according to claim 1 , wherein the data acquisition transaction is a cyphertext of a privacy depository transaction, and executing the smart contract further comprises:

decrypting, by the blockchain node the cyphertext in the TEE to obtain the target data.

7. The method according to claim 1 , wherein the blockchain node stores a digital digest of the target data, the target data is stored by the data owner in a storage media other than a blockchain, and is retrieved by another smart contract from the storage media and transferred to the smart contract to perform the one or more predetermined computational operations.

8. A computer-implemented system, comprising:

one or more computers, and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform operations comprising:

receiving, by a blockchain node, a data acquisition transaction submitted by a data user for obtaining target data possessed by a data owner;

transmitting, by the blockchain node, the data acquisition transaction to a second blockchain node based on a blockchain consensus process;

determining, by the blockchain node, that the data user has obtained authorization of the target data;

executing, by the blockchain node, a smart contract invoked by the data acquisition transaction to provide one or more of the target data and a computational result of one or more predetermined computational operations performed based on the target data to the data user;

providing, by the blockchain node and based at least on the blockchain node and the second blockchain node executing the smart contract, the target data and the computational result to the data user, wherein a transaction execution result event based on the target data and the computational result are written in a transaction log by the smart contract, and wherein the transaction log is monitored and available to be acquired by the data user;

encrypting, by the blockchain node, the target data in a trusted execution environment (TEE) to obtain encrypted target data; and

storing, by the blockchain node, the encrypted target data to a database associated with the blockchain node;

wherein the executing the smart contract is performed in the TEE after reading the encrypted target data into the TEE and decrypting the encrypted target data,

wherein the smart contract is executed to provide the target data to the data user if the target data has low data privacy level, and the smart contract is executed to provide the computational result of the one or more predetermined computational operations if the target data has high data privacy level.

9. The computer-implemented system according to claim 8 , wherein the smart contract comprises a list of authorized users including the data user and the determining that the data user has obtained authorization of the target data is performed based on the list of authorized users.

10. The computer-implemented system according to claim 8 , further comprising:

invoking, by the blockchain node, a request interface defined in the smart contract based on an authorization request transaction submitted by the data user to cause the smart contract to write an authorization request event into the transaction log of the data owner; and

invoking, by the blockchain node, an authorization interface defined in the smart contract based on an authorization confirmation transaction submitted by the data owner to cause the smart contract to mark the data user as an authorized user.

11. The computer-implemented system according to claim 8 , wherein one or more operation rules of the one or more predetermined computational operations are predefined in the smart contract or are transferred into the smart contract through the data acquisition transaction.

12. The computer-implemented system according to claim 8 , wherein providing, by the blockchain node and based on, at least, the blockchain node and the second blockchain node executing the smart contract, the target data and the computational result to the data user comprises:

encrypting the target data and the computational result; and

storing the encrypted target data and the encrypted computational result within the transaction execution result event in the transaction log, wherein the encrypted target data and the encrypted computational result are configured to enable the data user to decrypt the encrypted target data and the encrypted computational result to obtain the target data and the computational result.

13. The computer-implemented system according to claim 8 , wherein the data acquisition transaction is a cyphertext of a privacy depository transaction, and executing the smart contract further comprises:

decrypting, by the blockchain node the cyphertext in the TEE to obtain the target data.

14. The computer-implemented system according to claim 8 , wherein the blockchain node stores a digital digest of the target data, the target data is stored by the data owner in a storage media other than a blockchain, and is retrieved by another smart contract from the storage media and transferred to the smart contract to perform the one or more predetermined computational operations.

15. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

receiving, by a blockchain node, a data acquisition transaction submitted by a data user for obtaining target data possessed by a data owner;

transmitting, by the blockchain node, the data acquisition transaction to a second blockchain node based on a blockchain consensus process;

determining, by the blockchain node, that the data user has obtained authorization of the target data;

executing, by the blockchain node, a smart contract invoked by the data acquisition transaction to provide one or more of the target data and a computational result of one or more predetermined computational operations performed based on the target data to the data user;

providing, by the blockchain node and based at least on the blockchain node and the second blockchain node executing the smart contract, the target data and the computational result to the data user, wherein a transaction execution result event based on the target data and the computational result are written in a transaction log by the smart contract, and wherein the transaction log is monitored and available to be acquired by the data user;

encrypting, by the blockchain node, the target data in a trusted execution environment (TEE) to obtain encrypted target data; and

storing, by the blockchain node, the encrypted target data to a database associated with the blockchain node;

wherein the executing the smart contract is performed in the TEE after reading the encrypted target data into the TEE and decrypting the encrypted target data,

wherein the smart contract is executed to provide the target data to the data user if the target data has low data privacy level, and the smart contract is executed to provide the computational result of the one or more predetermined computational operations if the target data has high data privacy level.

16. The non-transitory, computer-readable medium of claim 15 , wherein the smart contract comprises a list of authorized users including the data user and the determining that the data user has obtained authorization of the target data is performed based on the list of authorized users.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2025
From: ADVANCED NEW TECHNOLOGIES CO., LTD.
To: ANTCHAIN TECHNOLOGY PTE. LTD.
Reel/Frame 070253/0064 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2021
From: WEI, CHANGZHENG; YAN, YING; ZHANG, HUI; PENG, YUJUN
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 055316/0250 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2020
From: WEI, CHANGZHENG; YAN, YING; ZHANG, HUI; PENG, YUJUN
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 054015/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053754/0625 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053743/0464 →