IP Library › Granted Patent US 11,455,417
Granted Patent B2
US 11,455,417 · App. 17/348,975 · Granted Sep 27, 2022

Data processing methods, apparatuses, and devices

Inventors: Renhui Yang (Hangzhou, CN); Shubo Li (Hangzhou, CN); Yuan Chen (Hangzhou, CN); Wenyu Yang (Hangzhou, CN); Qin Liu (Hangzhou, CN)
Assignee: Alipay (Hangzhou) Information Technology Co., Ltd.
G06F21/6227G06F21/602G06F21/64G06F21/78G06F2221/2129G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,455,417
App. No.
17/348,975
Granted
Sep 27, 2022
Kind
B2
Abstract

Embodiments of the present specification disclose data processing methods, apparatuses, and devices. One method comprises: obtaining an acquisition request for target data of a data owner; determining a trusted application (TAPP) for generating the target data based on decentralized identifier document (DID Doc) information of the data owner in response to the acquisition request; sending, to the TAPP, a target data generation request to use the TAPP to process data of the data owner obtained from a trusted institution; and receiving a processing result from the TAPP in response to the target data generation request.

Claims (64)

1. A computer-implemented method, comprising:

obtaining, by one or more processors and from a data user account, an acquisition request for accessing target data of a data owner;

determining, by the one or more processors, a trusted application (TAPP) for generating the target data based on correspondence information comprised in a decentralized identifier document (DID Doc) information of the data owner in response to the acquisition request, wherein the correspondence information describes a correspondence between the target data and the TAPP;

sending, by the one or more processors and to the TAPP, a target data generation request, wherein the target data generation request requests the TAPP to generate the target data based on processing data of the data owner using a data processing rule configured to hide private portions of the data of the data owner, the data of the data owner comprising the target data of the data owner, wherein the data of the data owner is obtained from a trusted institution, and wherein the private portions of the data of the data owner are unavailable to the data user account; and

receiving, by the one or more processors and from the TAPP, a processing result comprising the target data, wherein the processing result is obtained from processing the data of the data owner.

2. The computer-implemented method according to claim 1 , comprising:

before determining the TAPP for generating the target data, obtaining a program identifier of at least one TAPP; and

generating, based on the program identifier of at least one TAPP, a program binding request for requesting to store correspondence information between the target data and the TAPP in the DID Doc of the data owner.

3. The computer-implemented method according to claim 2 , wherein obtaining the program identifier of at least one TAPP comprises:

obtaining a program identifier selected by the data owner while registering a DID or publishing the target data.

4. The computer-implemented method according to claim 3 , wherein obtaining the program identifier selected by the data owner comprises:

obtaining the TAPP for generating the target data selected by the data owner from TAPPs supported by a target application when the DID is registered or published by the data owner using the target application.

5. The computer-implemented method according to claim 1 , wherein obtaining the acquisition request for the target data of the data owner comprises:

obtaining, from the data user account, the acquisition request, wherein the acquisition request requests to use a specified TAPP to generate the target data; and wherein

determining the TAPP for generating the target data comprises:

determining that the DID Doc of the data owner comprises correspondence information between the target data and the specified TAPP; and

determining the TAPP for generating the target data as the specified TAPP.

6. The computer-implemented method according to claim 5 , wherein the method further comprises:

before sending, to the TAPP, the target data generation request, obtaining a use authorization instruction of a usage right approver of the target data for the acquisition request; and

generating a use authorization verifiable statement based on the use authorization instruction, wherein the target data generation request comprises the use authorization verifiable statement.

7. The computer-implemented method according to claim 6 , wherein the method comprises:

after generating the use authorization verifiable statement, digitally signing, by a target application, the use authorization verifiable statement using a private key of the data owner to obtain a signed verifiable statement, wherein the private key is in a key pair generated after requesting to establish a correspondence between trusted hardware and a DID of the data owner using the target application, wherein the private key is stored in the trusted hardware, wherein a public key in the key pair is stored in the DID Doc of the data owner, and wherein the target data generation request comprises the signed verifiable statement.

8. The computer-implemented method according to claim 1 , wherein obtaining the acquisition request for the target data of the data owner comprises:

obtaining, from the data owner, the acquisition request for the target data of the data owner; and wherein determining the TAPP for generating the target data comprises:

determining TAPPs corresponding to the target data based on the DID Doc of the data owner; and

determining the TAPP for generating the target data from the TAPPs.

9. The computer-implemented method according to claim 8 , wherein the method comprises:

determining, based on the processing result, that the target data is al ready generated;

obtaining the target data from the TAPP that generates the target data; and

storing the target data in trusted hardware.

10. The computer-implemented method according to claim 1 , wherein the TAPP is installed in a trusted execution environment (TEE) of a server, and the TEE is isolated from an operating system of the server.

11. The computer-implemented method according to claim 10 , wherein the data of the data owner is obtained by the TAPP from the trusted institution through a predetermined interface of the TEE.

12. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

obtaining, from a data user account, an acquisition request for accessing target data of a data owner;

determining a trusted application (TAPP) for generating the target data based on correspondence information comprised in a decentralized identifier document (DID Doc) information of the data owner in response to the acquisition request, wherein the correspondence information describes a correspondence between the target data and the TAPP;

sending, to the TAPP, a target data generation request, wherein the target data generation request requests the TAPP to generate the target data based on processing data of the data owner using a data processing rule configured to hide private portions of the data of the data owner, the data of the data owner comprising the target data of the data owner, wherein the data of the data owner is obtained from a trusted institution, and wherein the private portions of the data of the data owner are unavailable to the data user account; and

receiving, from the TAPP, a processing result comprising the target data, wherein the processing result is obtained from processing the data of the data owner.

13. The non-transitory, computer-readable medium according to claim 12 , comprising:

before determining the TAPP for generating the target data, obtaining a program identifier of at least one TAPP; and

generating, based on the program identifier of at least one TAPP, a program binding request for requesting to store correspondence information between the target data and the TAPP in the DID Doc of the data owner.

14. The non-transitory, computer-readable medium according to claim 13 , wherein obtaining the program identifier of at least one TAPP comprises:

obtaining a program identifier selected by the data owner while registering a DID or publishing the target data.

15. The non-transitory, computer-readable medium according to claim 14 , wherein obtaining the program identifier selected by the data owner comprises:

obtaining the TAPP for generating the target data selected by the data owner from TAPPs supported by a target application when the DID is registered or published by the data owner using the target application.

16. The non-transitory, computer-readable medium according to claim 12 , wherein obtaining the acquisition request for the target data of the data owner comprises:

obtaining, from the data user account, the acquisition request, wherein the acquisition request requests to use a specified TAPP to generate the target data; and wherein determining the TAPP for generating the target data comprises:

determining that the DID Doc of the data owner comprises correspondence information between the target data and the specified TAPP; and

determining the TAPP for generating the target data as the specified TAPP.

17. The non-transitory, computer-readable medium according to claim 16 , wherein the operations comprise:

before sending, to the TAPP, the target data generation request, obtaining a use authorization instruction of a usage right approver of the target data for the acquisition request; and

generating a use authorization verifiable statement based on the use authorization instruction, wherein the target data generation request comprises the use authorization verifiable statement.

18. The non-transitory, computer-readable medium according to claim 17 , wherein the operations comprise:

after generating the use authorization verifiable statement, digitally signing, by a target application, the use authorization verifiable statement using a private key of the data owner to obtain a signed verifiable statement, wherein the private key is in a key pair generated after requesting to establish a correspondence between trusted hardware and a DID of the data owner using the target application, wherein the private key is stored in the trusted hardware, wherein a public key in the key pair is stored in the DID Doc of the data owner, and wherein the target data generation request comprises the signed verifiable statement.

19. The non-transitory, computer-readable medium according to claim 12 , wherein obtaining the acquisition request for the target data of the data owner comprises:

obtaining, from the data owner, the acquisition request for the target data of the data owner; and wherein determining the TAPP for generating the target data comprises:

determining TAPPs corresponding to the target data based on the DID Doc of the data owner; and

determining the TAPP for generating the target data from the TAPPs.

20. A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

obtaining, from a data user account, an acquisition request for accessing target data of a data owner;

determining a trusted application (TAPP) for generating the target data based on correspondence information comprised in a decentralized identifier document (DID Doc) information of the data owner in response to the acquisition request, wherein the correspondence information describes a correspondence between the target data and the TAPP;

sending, to the TAPP, a target data generation request, wherein the target data generation request requests the TAPP to generate the target data based on processing data of the data owner using a data processing rule configured to hide private portions of the data of the data owner, the data of the data owner comprising the target data of the data owner, wherein the data of the data owner is obtained from a trusted institution, and wherein the private portions of the data of the data owner are unavailable to the data user account; and

receiving, from the TAPP, a processing result comprising the target data, wherein the processing result is obtained from processing the data of the data owner.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: YANG, RENHUI; LI, SHUBO; CHEN, YUAN; YANG, WENYU; LIU, QIN
To: ALIPAY (HANGZHOU) INFORMATION TECHNOLOGY CO., LTD.
Reel/Frame 057323/0486 →
Priority Claims (1)
CN 202010922306.8 · Sep 4, 2020 · national
Continuity (1)
Related Publication 20210312073A1 · Oct 7, 2021
Cited By (2)
US 12,430,463 US 12,572,695