CN111934881A - Data right confirming method and device, storage medium and electronic device - Google Patents

Data right confirming method and device, storage medium and electronic device Download PDF

Info

Publication number
CN111934881A
CN111934881A CN202010676186.8A CN202010676186A CN111934881A CN 111934881 A CN111934881 A CN 111934881A CN 202010676186 A CN202010676186 A CN 202010676186A CN 111934881 A CN111934881 A CN 111934881A
Authority
CN
China
Prior art keywords
data
weight
determining
confirming
determined
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN202010676186.8A
Other languages
Chinese (zh)
Other versions
CN111934881B (en
Inventor
朱江
贺虎
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Kingsoft Cloud Network Technology Co Ltd
Original Assignee
Beijing Kingsoft Cloud Network Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Kingsoft Cloud Network Technology Co Ltd filed Critical Beijing Kingsoft Cloud Network Technology Co Ltd
Priority to CN202010676186.8A priority Critical patent/CN111934881B/en
Publication of CN111934881A publication Critical patent/CN111934881A/en
Application granted granted Critical
Publication of CN111934881B publication Critical patent/CN111934881B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/018Certifying business or products
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/60Digital content management, e.g. content distribution
    • H04L2209/603Digital right managament [DRM]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/101Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying security measures for digital rights management

Abstract

The application relates to a data right confirming method and device, a storage medium and an electronic device, wherein the method comprises the following steps: receiving a first right confirmation request initiated by a client, wherein the first right confirmation request is used for requesting to confirm right of right to be confirmed data; responding to the first right confirming request, and acquiring a plurality of reference right confirming results of a plurality of right confirming parties, wherein each reference object in the plurality of right confirming parties is used for confirming the right of the right to be confirmed data, and the plurality of right confirming parties correspond to the plurality of reference right confirming results in a one-to-one mode; and sending target indication information to the client, wherein the target indication information is used for indicating the right confirmation result of the to-be-confirmed right data determined according to the plurality of reference right confirmation results. The embodiment of the application solves the problem that the data right confirming mode in the related technology is poor in scheme applicability due to the fact that the data right confirming mode is only suitable for the scene of right confirming by a centralized mechanism.

Description

Data right confirming method and device, storage medium and electronic device
Technical Field
The present application relates to the field of internet, and in particular, to a method and an apparatus for data right-confirming, a storage medium, and an electronic apparatus.
Background
Currently, there are some data/digital assets. Data/digital assets are non-monetary assets that are owned or controlled by property owners (e.g., internet users, internet platforms, etc.), exist in electronic data form, are held in daily activities for sale or are in the process of production.
For data/digital assets, the right confirmation is a crucial and important action, and the ownership relationship of the data/digital assets can be confirmed after the right confirmation. Currently, data/digital assets are typically authenticated by authorities. For example, for digital asset a, the authority of the digital asset a is authority B, and the validation of digital asset a may be performed by authority B. The digital certificates, etc. are secured in a similar manner to the data/digital assets.
However, the above-mentioned data authorization method is only applicable to a scenario in which authorization is performed by a centralized organization (for example, authorization is performed on data/digital assets, digital certificates, and the like), and has problems of poor applicability and easy occurrence of authorization errors.
Therefore, the data right confirming method in the related art has a problem of poor applicability of the scheme due to being only applicable to a scene where the right is confirmed by the centralized organization.
Disclosure of Invention
The application provides a data right confirming method and device, a storage medium and an electronic device, which at least solve the problem that a data right confirming mode in the related art has poor scheme applicability caused by being only suitable for a scene of right confirmation by a centralized mechanism.
According to an aspect of an embodiment of the present application, there is provided a data right confirming method, including: receiving a first right confirmation request initiated by a client, wherein the first right confirmation request is used for requesting to confirm right of right to be confirmed data; responding to the first right confirming request, and acquiring a plurality of reference right confirming results of a plurality of right confirming parties, wherein each reference object in the plurality of right confirming parties is used for confirming the right of the data to be confirmed, and the plurality of right confirming parties correspond to the plurality of reference right confirming results in a one-to-one mode; and sending target indication information to the client, wherein the target indication information is used for indicating a right confirmation result of the to-be-confirmed weight data determined according to the multiple reference right confirmation results.
Optionally, before the obtaining of the multiple reference right-confirming results of the multiple right-confirming parties, the method further includes: extracting a target data name of the to-be-confirmed data and a target data identification of the to-be-confirmed data from the first confirmation request; and determining the plurality of power determining parties according to the target data name and the target data identifier.
Optionally, the determining the plurality of determiners according to the target data name and the target data identifier includes: and matching the plurality of authority confirming parties from a target relational database by using the target data name and the target data identifier, wherein the target relational database stores the corresponding relation among the data name, the data identifier and the authority confirming party.
Optionally, the obtaining a plurality of reference right-confirming results of a plurality of right-confirming parties includes: respectively sending a second right confirming request to each of the plurality of right confirming parties, wherein the second right confirming request is used for requesting to confirm the right of the data to be confirmed; and respectively receiving the reference right confirming result returned by each of the plurality of right confirming parties.
Optionally, before the sending the target indication information to the client, the method further includes: determining a weight determining result of the to-be-determined weight data according to the plurality of reference weight determining results; and generating the target indication information according to the determined right result of the to-be-determined right data.
Optionally, in a case that the first right confirmation request is used for requesting to determine a right object of the to-be-confirmed right data, according to the plurality of reference right confirmation results, determining a right confirmation result of the to-be-confirmed right data includes at least one of: determining a first weight determination result of the to-be-determined weight data when all the weight objects of the to-be-determined weight data represented by the plurality of reference weight determination results are first objects, wherein the first weight determination result is used for representing that the weight object of the to-be-determined weight data is the first object; determining a second weight determining result of the to-be-determined weight data under the condition that the ownership objects of the to-be-determined weight data represented by the plurality of reference weight determining results are not the same object, wherein the second weight determining result is used for representing that the weight determining of the to-be-determined weight data fails; if the ownership objects of the to-be-authenticated data represented by the multiple reference ownership results are multiple reference objects, calculating an ownership probability corresponding to each reference object in the multiple reference objects according to the weight corresponding to each of the multiple ownership parties, wherein the ownership probability corresponding to each reference object is the probability that the ownership object of the to-be-authenticated data is the reference object; selecting a second object from the plurality of reference objects, wherein the second object is a reference object corresponding to the maximum weight-determining probability; and determining a third weight determination result of the to-be-determined weight data, wherein the third weight determination result is used for indicating that a ownership object of the to-be-determined weight data is the second object.
Optionally, in a case that the first right confirmation request is used for requesting to determine whether the to-be-confirmed-right data has a right relationship with a third object, the determining, according to the plurality of reference right confirmation results, a right confirmation result of the to-be-confirmed-right data includes at least one of: if the plurality of reference weight-determining results all indicate that the to-be-determined weight data has a weight relationship with the third object, determining a fourth weight-determining result of the to-be-determined weight data, wherein the fourth weight-determining result is used for representing that the weight-determining of the to-be-determined weight data is successful; determining a fifth weight confirmation result of the to-be-confirmed weight data if at least one of the plurality of reference weight confirmation results indicates that the to-be-confirmed weight data has a weight relationship with the third object, wherein the fifth weight confirmation result is used for indicating that the weight confirmation of the to-be-confirmed weight data is successful; determining a sixth weight confirmation result of the to-be-confirmed data if at least one of the plurality of reference weight confirmation results indicates that the to-be-confirmed data has no ownership relationship with the third object, wherein the sixth weight confirmation result is used for indicating that the weight confirmation of the to-be-confirmed data fails; determining a reference probability that the data to be determined has a ownership relationship with the third object according to a weight corresponding to each of the plurality of authorities if at least one of the plurality of reference authority determination results indicates that the data to be determined does not have an ownership relationship with the third object; determining a seventh weight determining result of the to-be-determined weight data when the reference probability is greater than or equal to a target probability threshold, wherein the seventh weight determining result is used for indicating that the weight determining of the to-be-determined weight data is successful; and determining an eighth weight determining result of the to-be-determined weight data when the reference probability is smaller than a target probability threshold, wherein the eighth weight determining result is used for indicating that the weight determining of the to-be-determined weight data fails.
According to another aspect of the embodiments of the present application, there is provided a data right confirming apparatus, including: the device comprises a receiving unit, a sending unit and a receiving unit, wherein the receiving unit is used for receiving a first right confirmation request initiated by a client, and the first right confirmation request is used for requesting to confirm right of right to be confirmed data; an obtaining unit, configured to obtain, in response to the first right determining request, multiple reference right determining results of multiple right determining parties, where each reference object in the multiple right determining parties is used to determine the right of the to-be-determined right data, and the multiple right determining parties are in one-to-one correspondence with the multiple reference right determining results; a sending unit, configured to send target indication information to the client, where the target indication information is used to indicate a result of determining the right of the to-be-determined right data, which is determined according to the multiple reference results of determining the right.
According to a further aspect of an embodiment of the present application, there is also provided a computer-readable storage medium having a computer program stored thereon, wherein the computer program is configured to perform the steps of any of the above method embodiments when executed.
According to a further aspect of an embodiment of the present application, there is also provided an electronic apparatus, including a memory and a processor, the memory storing a computer program therein, the processor being configured to execute the computer program to perform the steps in any of the above method embodiments.
In the embodiment of the application, a multi-party combined right confirmation mode is adopted, and a first right confirmation request initiated by a client is received, wherein the first right confirmation request is used for requesting to confirm right of right to be confirmed data; responding to the first right confirming request, and acquiring a plurality of reference right confirming results of a plurality of right confirming parties, wherein each reference object in the plurality of right confirming parties is used for confirming the right of the right to be confirmed data, and the plurality of right confirming parties correspond to the plurality of reference right confirming results in a one-to-one mode; target indication information is sent to a client, wherein the target indication information is used for indicating a right confirmation result of to-be-confirmed data determined according to a plurality of reference right confirmation results, and the target indication information can be applied to a scene in which a non-centralized mechanism confirms the right due to the fact that a plurality of right confirmation parties jointly confirm the right of to-be-confirmed data (such as data/digital assets, digital certificates and the like), so that the technical effects of improving the applicability of a data right confirmation scheme and ensuring the right confirmation success rate are achieved, and the problem that the scheme applicability is poor due to the fact that a data right confirmation mode in the related art is only applied to the scene in which the centralized mechanism confirms the right is solved.
Drawings
The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and together with the description, serve to explain the principles of the invention.
In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the embodiments or the prior art will be briefly described below, and it is obvious for those skilled in the art that other drawings can be obtained according to the drawings without inventive exercise.
FIG. 1 is a schematic diagram of a hardware environment for a data-validation method according to an embodiment of the present application;
FIG. 2 is a flow chart of an alternative method of data entitlement according to an embodiment of the present application;
FIG. 3 is a flow chart of an alternative method of unilateral authority according to an embodiment of the present application;
FIG. 4 is a flow diagram of an alternative method of data preemption in accordance with an embodiment of the present application;
FIG. 5 is a schematic diagram of an alternative data authorization apparatus according to an embodiment of the present application;
fig. 6 is a block diagram of an alternative electronic device according to an embodiment of the present application.
Detailed Description
In order to make the technical solutions better understood by those skilled in the art, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application, and it is obvious that the described embodiments are only partial embodiments of the present application, and not all embodiments. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present application.
It should be noted that the terms "first," "second," and the like in the description and claims of this application and in the drawings described above are used for distinguishing between similar elements and not necessarily for describing a particular sequential or chronological order. It is to be understood that the data so used is interchangeable under appropriate circumstances such that the embodiments of the application described herein are capable of operation in sequences other than those illustrated or described herein. Furthermore, the terms "comprises," "comprising," and "having," and any variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, system, article, or apparatus that comprises a list of steps or elements is not necessarily limited to those steps or elements expressly listed, but may include other steps or elements not expressly listed or inherent to such process, method, article, or apparatus.
First, partial nouns or terms appearing in the description of the embodiments of the present application are applicable to the following explanations:
1. the monitoring party: a supervisory party of data/digital assets, digital certificates, etc.
2. The right-determining party: an organization/company or other entity with property ownership determination capability and a natural person.
3. And (3) alliance: the system comprises a business group consisting of a plurality of members, and coalition members as participants participate in the construction of the network together.
4. And (3) joint right confirmation: the multi-party joint authorization determination may include, but is not limited to, one of the following scenarios:
1) a scenario that all parties need to jointly determine the rights when the rights of data/digital assets, digital certificates and the like are mainly multiple parties;
2) when the ownership system of the data/digital assets, the digital certificates and the like is a single party, a scene that the ownership system and a third party jointly confirm the right is needed;
3) when the authority affiliate of the data/digital assets, the digital certificate and the like is a plurality of parties, the scene of joint right confirmation of the authority affiliate parties and a third party is needed. Third parties herein include, but are not limited to, supervisors, regulatory agencies, system operators, and the like. Joint power-down may design a power-down tier mechanism.
5. Weight of the right-determining party: the weights of a plurality of weight determiners are defined, and the weights of different weight determiners may be the same or different.
According to one aspect of the embodiments of the present application, a method for data right-confirming is provided. Alternatively, in the present embodiment, the data authorization method may be applied to a hardware environment formed by the terminal 101 and the server 103 as shown in fig. 1. As shown in fig. 1, a server 103 is connected to a terminal 101 through a network, which may be used to provide services (such as game services, application services, etc.) for the terminal or a client installed on the terminal, and a database may be provided on the server or separately from the server for providing data storage services for the server 103, and the network includes but is not limited to: the terminal 101 is not limited to a PC, a mobile phone, a tablet computer, and the like. The data right confirming method in the embodiment of the present application may be executed by the server 103, the terminal 101, or both the server 103 and the terminal 101. The terminal 101 executing the data authorization method according to the embodiment of the present application may also be executed by a client installed thereon.
Fig. 2 is a flowchart of an alternative data right-confirming method according to an embodiment of the present application, and as shown in fig. 2, the method may include the following steps:
step S202, receiving a first right confirmation request initiated by a client, wherein the first right confirmation request is used for requesting to confirm right of the right to be confirmed data;
step S204, responding to the first right confirming request, and acquiring a plurality of reference right confirming results of a plurality of right confirming parties, wherein each reference object in the plurality of right confirming parties is used for confirming the right of the right to be confirmed data, and the plurality of right confirming parties correspond to the plurality of reference right confirming results one by one;
step S206, sending target indication information to the client, wherein the target indication information is used for indicating the right determining result of the to-be-determined right data determined according to the plurality of reference right determining results.
Through the steps S202 to S206, a first right confirmation request initiated by the client is received, where the first right confirmation request is used to request to confirm right to be confirmed to the right data; responding to the first right confirming request, and acquiring a plurality of reference right confirming results of a plurality of right confirming parties, wherein each reference object in the plurality of right confirming parties is used for confirming the right of the right to be confirmed data, and the plurality of right confirming parties correspond to the plurality of reference right confirming results in a one-to-one mode; target indication information is sent to the client, wherein the target indication information is used for indicating the weight determining result of the to-be-determined weight data determined according to the multiple reference weight determining results, so that the problem that a data weight determining mode in the related technology is poor in scheme applicability due to the fact that the data weight determining mode is only suitable for a scene in which the weight is determined by a centralized mechanism is solved, the applicability of a data weight determining scheme is improved, and the success rate of the weight determining is ensured.
In the technical solution provided in step S202, a first request for determining right initiated by the client is received, where the first request for determining right is used to request to determine right for the data to be determined.
In the related art, the data right may be determined in a single-party right determination manner. Taking the resources to be authenticated as digital assets as an example, as shown in fig. 3, the unilateral authentication method includes the following steps:
step S302, a request for authority confirmation is initiated.
A client or other device may initiate a request to determine the entitlement of a digital asset that requests a determination of whether object a is entitled to the digital asset.
In step S304, the ownership owner/supervisor/administrator/other third party of the digital asset receives the request for authorization.
The request for entitlement may be received as an entitler by a rightist, a supervisor, an authority, or other third party (e.g., a system operator) of the digital asset.
Step S306, judge whether to have the right.
The authorizer may determine whether object a is authorized for the digital asset, and if so, perform step S308, otherwise, perform step S310.
In step S308, the authentication is successful.
And the right confirming party judges that the object A has the right to the digital asset, the right confirming is successful, and a right confirming success indication is returned to the client.
And step S310, refuting.
The right confirming party judges that the object A has no right for the digital asset, the right confirming fails, the right confirming request is rejected, and a right confirming failure indication is returned to the client.
The data right determining method in this embodiment may be applied to a scenario of performing multi-party joint right determination on digital resources (data/digital assets, digital certificates, and digital certificates). For example, in a digital asset right-determining scenario, a joint right-determining mechanism/scheme may be configured on the basis of a single-party right-determining mechanism/scheme to satisfy the application scenario of joint right-determining.
The pending rights data may be data/digital assets, digital certificates, etc., as well as other types of digital resources. For example, the pending rights data may be: identification cards, driving licenses, deposit certificates, prescriptions, graduation certificates, academic certificates, house property cards, network transaction records, and the like.
The user can use the client to authorize the data to be authenticated. On the interface of the client, the user can input the relevant information of the data to be authenticated so as to authenticate the data to be authenticated. The related information may be input through an input box or obtained by recognizing an uploaded image of the pending right data. The relevant information entered may include, but is not limited to, at least one of: a target data identification of the to-be-confirmed-right data, a target data name of the to-be-confirmed-right data, a generation date of the to-be-confirmed-right data (e.g., a ownership generation date), and the like.
After acquiring the relevant information of the input to-be-confirmed-right data, the client may generate a first right confirmation request, where the first right confirmation request is used to request to confirm the right of the to-be-confirmed-right data, and send the first right confirmation request to the server or other control devices for performing right confirmation control. In this embodiment, a server is taken as an example for explanation, and the data right determining method in this embodiment is also applicable to other similar devices.
In the technical solution provided in step S204, in response to the first right determining request, a plurality of reference right determining results of a plurality of right determining parties are obtained, where each reference object in the plurality of right determining parties is used for determining the right of the right to be determined data, and the plurality of right determining parties and the plurality of reference right determining results are in one-to-one correspondence.
After receiving the first right confirming request, the server may obtain a plurality of reference right confirming results of a plurality of right confirming parties. Each of the plurality of authorities is configured to authorize the data to be authenticated, that is, a plurality of joint authorities, which may include, but are not limited to, at least one of the following: the authority of the data to be determined belongs to a relationship person, a monitoring party, a management organization, a system operator and the like.
The multi-party joint right-determining scenario may be various, and may include but is not limited to one of the following:
1) when the rights of data/digital assets, digital certificates and the like are multiple parties, the scenes of joint right determination of the parties of the rights are needed;
2) when the ownership system of the data/digital assets, the digital certificates and the like is a single party, the ownership system needs to be united and authenticated by a third party;
3) when the rights of data/digital assets, digital certificates and the like are multiple parties, the situation that all the parties of the rights are united with the third party to determine the rights is required.
The third party may be a single party or a plurality of parties, and may include but is not limited to at least one of the following: a supervisor, a management authority, a system operator, etc. Different digital resources (e.g., data/digital assets, digital certificates, etc.) may or may not be the same as their corresponding third parties. The multiple right determiners in the joint right determination scenario may be configured as needed, which is not limited in this embodiment.
The plurality of power determiners are in one-to-one correspondence with the plurality of reference power determination results, that is, each power determiner returns one reference power determination result. The reference weight-determining result of each weight-determining party may be a weight-determining result of the weight-determining party for treating the weight-determining data. Different weight determination scenarios may have different corresponding weight determination results.
For example, the first right-determining request may be used to request to determine a right object of the to-be-determined right data, and a corresponding right-determining result is used to represent the right object of the to-be-determined right data.
For another example, the first right-confirming request may be used to request to determine whether there is a right relationship between the data to be confirmed and the specific object, and the corresponding right-confirming result is used to indicate that the right-confirming is passed (has a right relationship), or the right-confirming is successful; or, the user may indicate that the right is not passed (has no ownership relationship), or that the right fails.
For another example, the first right confirmation request may be used to determine whether the resource information of the to-be-confirmed data is correct (e.g., whether the resource information is correct, whether the ownership relationship in the resource information is correct, etc.). The corresponding right confirming result is used for indicating that the right confirming is successful (the resource information is correct); or, it is used to indicate that the right-confirming fails (the resource information is incorrect).
It should be noted that, the sending and receiving the right-confirming request and each right-confirming party may be a node in the distributed identity system, for example, a member node on a federation chain of the same federation, a member node on an intra-group federation chain of the same group, or a member node on an open federation chain, and the architecture of the distributed identity system may be configured as required, which is not specifically limited in this embodiment.
In the technical solution provided in step S206, target indication information is sent to the client, where the target indication information is used to indicate a weight determination result of the to-be-determined weight data determined according to a plurality of reference weight determination results.
According to a plurality of reference weight determining results, the weight determining result of the to-be-determined weight data can be determined. That is, a plurality of power determiners jointly determine the power of the power data to be determined. In different right determining scenes, the corresponding joint right determining results can be different.
For example, the first right-determining request may be used to request to determine a right object of the to-be-determined right data, and the joint right-determining result is used to represent the right object of the to-be-determined right data.
For another example, the first right-confirming request may be used to request to determine whether there is a right relationship between the pending right data and the specific object, and the joint right-confirming result is used to indicate that the right-confirming is successful (has a right relationship); or, it is used to indicate that the right-confirming fails (has no ownership relationship).
For another example, the first right confirmation request may be used to determine whether the resource information of the to-be-confirmed data is correct (e.g., whether the resource information is correct, whether the ownership relationship in the resource information is correct, etc.). The joint right-confirming result is used for indicating that the right-confirming is successful (the resource information is correct) or indicating that the right-confirming is failed (the resource information is incorrect).
The server can generate target indication information based on the joint right-determining result, wherein the target indication information is used for indicating the joint right-determining result, and the target indication information is returned to the client so as to display the target indication information through the client.
Optionally, in this embodiment, after receiving the first right confirmation request initiated by the client, the validity of the right to be confirmed data may be checked, and the result of checking the right to be confirmed data may be obtained; and sending indication information to the client under the condition that the verification result is used for indicating that the check of the to-be-confirmed data fails, wherein the indication information is used for indicating that the check of the to-be-confirmed data fails.
After receiving the first right confirmation request, the server may first perform validity check on the right confirmation data, determine whether the first right confirmation request is valid, for example, whether the first right confirmation request conforms to a data rule of a data type of the right confirmation data, whether an object applying for the right confirmation is an object that allows the right confirmation request to be initiated for the right confirmation data, and obtain a check result of the right confirmation data.
If the verification result is used for indicating that the to-be-confirmed data is not verified, it may be determined that the to-be-confirmed data is illegal, and the server may send indication information to the client, where the indication information is used for indicating that the to-be-confirmed data is not verified. After receiving the indication information, the client may display a prompt message on a display interface thereof to prompt that the pending right data check fails.
If the verification result is used for indicating that the data to be authenticated passes the verification, a plurality of reference authentication results of a plurality of authentication parties can be further obtained. In addition, the data to be authenticated may be directly transmitted to a plurality of authenticators for authentication determination, and validity check and the like may be determined by each authenticator.
It should be noted that, one data identifier and the authority determiner may be in a one-to-many relationship (each data identifier corresponds to a specific plurality of authorities), and the process of determining the corresponding authority may be regarded as a process of validity check; or a many-to-many relationship (a plurality of data identifications correspond to a plurality of determiners), and validity checking may be performed before determining the corresponding determiners.
As an alternative embodiment, before obtaining the multiple reference right-confirming results of the multiple right-confirming parties, the method further includes:
s11, extracting the target data name of the data to be authenticated and the target data identification of the data to be authenticated from the first authentication request;
and S12, determining a plurality of authority confirming parties according to the target data name and the target data identification.
The first authorization request may carry a name of the target data to be authorized and a target data identifier of the data to be authorized, and may also carry a generation date, an authorization date, an issuance date, and the like of the data to be authorized, and different information may be written into different fields of the first authorization request.
The server can extract the target data name and the target data identification in the first right confirming request, and confirm a plurality of right confirming parties of the data to be confirmed according to the target data name and the target data identification.
For example, the data to be authenticated may be a degree certificate issued by a plurality of schools in a joint culture, and the first authentication request may carry an identifier of the degree certificate (for identifying the degree certificate for requesting authentication) and a degree certificate number. According to the identification and the number of the academic certificate, a plurality of authority-determining parties of the academic certificate can be determined, and the plurality of authority-determining parties can comprise: a plurality of schools, a academic department, etc.
Through the embodiment, the plurality of power determiners are determined based on the data names and the data identifications, the accuracy of determining the power determiners can be ensured, and the efficiency of determining the power determiners is improved.
As an alternative embodiment, determining the plurality of determiners according to the target data name and the target data identifier includes:
and S21, matching a plurality of authority confirming parties from a target relational database by using the target data name and the target data identifier, wherein the target relational database stores the corresponding relation among the data name, the data identifier and the authority confirming parties.
In order to improve the efficiency of determining the authority determining party, a target relational database may be configured in advance, and the target relational database may store corresponding relationships among data names, data identifiers and authority determining parties of different resources. The target relation library may store a plurality of target relation tables, each corresponding to a resource type, for storing a corresponding relation between the data identifier of the resource type and the authority determining party.
For example, for the academic degree certificate and the property certificate, different target relationship tables may be used to store the correspondence between the academic degree certificate number and the right-determining party, and the correspondence between the property certificate number and the right-determining party, respectively.
The server may match multiple authoritative parties from the target relational library using the target data name and the target data identification. The target relational database may be a database local to the server or a database communicatively connected to the server via a network.
The server can firstly use the target data name to determine a target relation table matched with the target data name in a target relation library; then, the multiple right-determining parties are matched from the target relation table by using the target data identification.
By the embodiment, the right determining party of the data to be determined is matched from the target relational database, so that the determining efficiency of the right determining party can be improved.
As an alternative embodiment, obtaining a plurality of reference right-confirming results of a plurality of right-confirming parties comprises:
s31, respectively sending a second right confirming request to each of the plurality of right confirming parties, wherein the second right confirming request is used for requesting to confirm right to be confirmed right data;
and S32, respectively receiving the reference right confirming result returned by each of the plurality of right confirming parties.
Each of the authorities may correspond to an authority node, which may be a network node, such as a server, a terminal device, or other device. After receiving the first request for authority, the server may send a second request for authority to each of the plurality of authorities, e.g., to an authority node corresponding to each authority.
The second right confirmation request is used for requesting to confirm the right of the data to be confirmed, and may be a forwarded first right confirmation request or a right confirmation request regenerated according to information carried in the first right confirmation request. The generation manner of the second authorization request may be set as needed, which is not limited in this embodiment.
For one right determining party, after receiving the second right determining request, the right determining party may determine the right of the data to be determined, for example, determine the right of the data to be determined according to the target data identifier carried in the second right determining request, so as to obtain a reference right determining result. After obtaining the reference right-confirming request, the right-confirming party may return the reference right-confirming result to the server. The server can respectively receive the reference right-confirming results returned by the respective right-confirming parties.
By the embodiment, the right confirmation results of the plurality of right confirmation parties are obtained by sending the right confirmation requests to the respective right confirmation parties, so that the method is applicable to a distributed network architecture, data right confirmation under the cross-platform and other scenes is realized, and meanwhile, the accuracy of the right confirmation results can be ensured.
As an optional embodiment, before sending the target indication information to the client, the method further includes:
s41, determining the right result of the data to be determined according to the multiple reference right determining results;
s42, according to the result of the right determination of the data to be determined, target indication information is generated.
In order to obtain the target indication information, joint right confirming results of a plurality of right confirming parties can be determined firstly. If there are multiple right-determining parties, the server may obtain a reference right-determining result of each right-determining party, and determine a right-determining result of the to-be-determined right data according to the multiple reference right-determining results, for example, synthesize the multiple reference right-determining results to obtain a combined right-determining result.
The joint weight-determining result may be obtained by combining a plurality of reference weight-determining results based on a previously agreed consensus or agreed rule. According to the joint right confirmation result, indication information of the joint right confirmation result, that is, target indication information, may be generated.
According to the embodiment, the combined right confirming result is obtained by fusing the right confirming results of the plurality of right confirming parties, and the indication information of the combined right confirming result is generated, so that the method and the device can be suitable for various right confirming scenes, and the accuracy of the combined right confirming is improved.
Alternatively, in this embodiment, the first right confirmation request may be used to request to determine the ownership object of the to-be-confirmed-weight data, that is, to request to determine to which object the to-be-confirmed-weight data belongs, and correspondingly, each reference right confirmation result is used to indicate the ownership object of the to-be-confirmed-weight data determined by each right confirming party.
As an alternative embodiment, determining the result of the right of the to-be-determined right data according to a plurality of reference results of the right determination includes:
and S51, when all the ownership objects of the to-be-authenticated data represented by the plurality of reference ownership determining results are the first objects, determining a first ownership determining result of the to-be-authenticated data, wherein the first ownership determining result is used for representing that the ownership objects of the to-be-authenticated data are the first objects.
If the ownership objects of the to-be-authenticated data represented by the plurality of reference ownership determining results are the same and are all the first objects, it can be determined that the to-be-authenticated data and the first objects have ownership relationship. The server can determine a first right confirmation result of the to-be-confirmed data, wherein the first right confirmation result is used for indicating that a ownership object of the to-be-confirmed data is a first object.
For example, the authorized party of the data to be authorized has a plurality of: the system comprises a right affiliate of the data to be authenticated, a monitoring party, a management mechanism (such as a management center of the authenticated data), and a system operating party (an operating party of the authenticated system), wherein if the authentication results of the authentication parties are the same right, the combined authentication result is used for indicating that the right object of the data to be authenticated is the right.
As another optional implementation manner, determining the weight determination result of the to-be-determined weight data according to a plurality of reference weight determination results includes:
and S52, determining a second right determination result of the to-be-determined data when the ownership objects of the to-be-determined data represented by the plurality of reference right determination results are not the same object, wherein the second right determination result is used for representing that the right determination of the to-be-determined data fails.
The joint right-determining rule may be: each party must be authorized to pass. If the ownership objects of the to-be-authenticated data represented by the multiple reference ownership determining results are not the same object, it can be determined that the ownership relationship of the to-be-authenticated data is abnormal, and if the ownership of the to-be-authenticated data fails, a second ownership determining result of the to-be-authenticated data can be determined, and the second ownership determining result is used for representing that the ownership of the to-be-authenticated data fails.
The scene in which the ownership objects of the to-be-confirmed data represented by the multiple reference confirmation results are not the same object may be multiple, for example, each reference confirmation result is used to indicate that the ownership object of the to-be-confirmed data is a certain object, but the ownership objects represented by the multiple reference confirmation results are not the same object, and for example, a part of the reference confirmation results is used to indicate that the ownership object of the to-be-confirmed data is a certain object, and another part of the reference confirmation results is used to indicate that the ownership object of the to-be-confirmed data cannot be confirmed, that is, the ownership object of the to-be-confirmed data cannot be confirmed, or other similar scenes may also be available.
For example, the authorized party of the data to be authorized has a plurality of: the ownership system person, the supervisor, the management organization and the system operation party of the data to be authenticated, and the authentication results of the ownership system person, the supervisor and the system operation party of the data to be authenticated are as follows: the result of the authority confirmation of one authority is as follows: another owner. The joint right-confirming result is used for indicating that the right-confirming of the right-to-be-confirmed data fails.
As another alternative implementation, determining the weight determination result of the to-be-determined weight data according to a plurality of reference weight determination results includes:
s53, when the ownership objects of the data to be determined represented by the multiple reference right determination results are multiple reference objects, calculating right determination probabilities corresponding to the reference objects according to the weights corresponding to the respective right determination parties, wherein the right determination probabilities corresponding to the reference objects are the probabilities that the ownership objects of the data to be determined are the reference objects;
s54, selecting a second object from the plurality of reference objects, wherein the second object is the reference object corresponding to the maximum weight-determining probability;
and S55, determining a third right determination result of the to-be-determined right data, wherein the third right determination result is used for indicating that the ownership object of the to-be-determined right data is a second object.
The joint right-determining rule may be: determining whether the weight determination is successful according to the weight. If the ownership objects of the to-be-authenticated data represented by the multiple reference authentication results are not the same object, that is, multiple reference objects, the server may calculate the authentication probability of each reference object according to the weight corresponding to each authentication party, where the authentication probability is the probability that the ownership object of the to-be-authenticated data is the reference object.
The corresponding probabilities of different determiners may be the same (e.g., the same share and the same weight, 1 person and 1 ticket, and the weight of each ticket is the same) or different (e.g., different shares and weights, and the number of tickets is calculated according to the weight). In obtaining the reference weight-determining result of each weight-determining party, votes can be cast on the reference object indicated by the reference weight-determining result, and the number of votes (weight-determining probability) of each reference object can be calculated according to the weight. The number of tickets may be normalized probability or non-normalized probability, and the manner of calculating the weight-determining probability according to the weight of the weight-determining party may be set as needed, which is not limited in this embodiment.
After obtaining the weight-determining probabilities of the respective reference objects, a reference object (second object) with the highest weight-determining probability may be selected from the multiple reference objects as the ownership object of the to-be-determined weight data, and a third weight-determining result may be generated, where the third weight-determining result is used to indicate that the ownership object of the to-be-determined weight data is the second object.
For example, the authorized party of the data to be authorized has a plurality of: the weight of the data to be determined belongs to the relationship person (weight 0.1), the supervisor (weight 0.4), the management organization (weight 0.4), the system operator (weight 0.1), and the weight determination results of the relationship person, the supervisor and the management organization of the data to be determined are: the result of the first right person and the right of the system operator is: the second right person. And calculating to obtain the right probability of the first right person as 0.9 and the right probability of the second right person as 0.1, and then using the joint right determination result to indicate that the right object of the data to be determined is the first right person.
By the embodiment, the ownership object of the data to be authenticated is determined by configuring different authorization rules, so that the applicability and flexibility of the data authorization mode can be improved.
Optionally, in this embodiment, the first right-confirming request is used to request to determine whether the pending right data and the third object have a right relationship, that is, to request to determine whether the third object is a right object of the pending right data, and correspondingly, each reference right-confirming result is used to indicate whether each right-confirming party determines that the pending right data and the third object have a right relationship.
As an alternative embodiment, determining the result of the right of the to-be-determined right data according to a plurality of reference results of the right determination includes:
and S61, in the case that the plurality of reference weight-determining results all indicate that the to-be-determined data has the ownership relationship with the third object, determining a fourth weight-determining result of the to-be-determined data, wherein the fourth weight-determining result is used for indicating that the weight-determining of the to-be-determined data is successful.
If the plurality of reference weight-determining results all indicate that the pending weight data has the ownership relationship with the third object, it may be determined that the pending weight data has the ownership relationship with the third object. The server may determine a fourth right determination result of the to-be-determined-right data, where the fourth right determination result is used to indicate that the right determination of the to-be-determined-right data is successful, and the to-be-determined-right data has a right relationship with the third object.
For example, the first entitlement request is for requesting a determination of whether the pending entitlement data has an entitlement relationship with the target owner. The authorized party of the data to be authorized is multiple: the ownership of the data to be authenticated is a relationship person, a monitoring party, a management mechanism and a system operation party, if the authentication results of all the authentication parties are as follows: and if the right confirmation is successful, the combined right confirmation result is used for indicating that the right confirmation is successful, and the right relation exists between the to-be-confirmed right data and the target right person.
As another optional implementation manner, determining the weight determination result of the to-be-determined weight data according to a plurality of reference weight determination results includes:
and S62, in the case that at least one of the plurality of reference weight-determining results indicates that the to-be-determined weight data has a ownership relationship with the third object, determining a fifth weight-determining result of the to-be-determined weight data, wherein the fifth weight-determining result is used for indicating that the weight-to-be-determined weight data is successfully determined.
The joint right-determining rule may be: any 1 party does the right to pass, or any multiple (less than the total number of parties) does the right to pass. If at least one of the plurality of reference weight confirmation results indicates that the to-be-confirmed weight data has a weight relationship with the third object, it may be determined that the weight confirmation passes (the weight confirmation succeeds). The server may determine a fifth weight-determining result of the to-be-determined-weight data, where the fifth weight-determining result is used to indicate that the weight-determining of the to-be-determined-weight data is successful.
For example, the first entitlement request is for requesting a determination of whether the pending entitlement data has an entitlement relationship with the target owner. The authorized party of the data to be authorized is multiple: if the authority result of at least one authority confirming party is: and determining the right, wherein the joint right determination result is used for indicating that the right determination is successful, and the right relation exists between the to-be-determined right data and the target right person.
As another alternative implementation, determining the weight determination result of the to-be-determined weight data according to a plurality of reference weight determination results includes:
and S63, in the case that at least one of the plurality of reference right confirming results indicates that the to-be-confirmed right data does not have a ownership relationship with the third object, determining a sixth right confirming result of the to-be-confirmed right data, wherein the sixth right confirming result is used for indicating that the right confirming of the to-be-confirmed right data fails.
The joint right-determining rule may be: each party must be granted the right to pass. If at least one of the plurality of reference weight confirmation results indicates that the pending weight data does not have a ownership relationship with the third object, it may be determined that the weight confirmation is not passed (weight confirmation failure). The server may determine a sixth right confirmation result of the to-be-confirmed-weight data, where the sixth right confirmation result is used to indicate that the right confirmation of the to-be-confirmed-weight data fails.
For example, the first entitlement request is for requesting a determination of whether the pending entitlement data has an entitlement relationship with the target owner. The authorized party of the data to be authorized is multiple: if the authority result of at least one authority confirming party is: and if the right confirmation fails, the combined right confirmation result is used for indicating that the right confirmation fails, and the to-be-confirmed right data does not have the ownership relationship with the target ownership person.
As another alternative implementation, determining the weight determination result of the to-be-determined weight data according to a plurality of reference weight determination results includes:
s64, in case that at least one of the plurality of reference right confirming results indicates that the to-be-confirmed right data has no ownership relationship with the third object, determining a reference probability that the to-be-confirmed right data has ownership relationship with the third object according to the weight corresponding to each of the plurality of right confirming parties;
s65, determining a seventh weight determining result of the weight data to be determined under the condition that the reference probability is greater than or equal to the target probability threshold, wherein the seventh weight determining result is used for indicating that the weight determination of the weight data to be determined is successful;
and S66, determining an eighth weight determining result of the to-be-determined weight data under the condition that the reference probability is smaller than the target probability threshold, wherein the eighth weight determining result is used for indicating that the weight determining of the to-be-determined weight data fails.
The joint right-determining rule may be: determining whether the weight determination is successful according to the weight. If at least one of the plurality of reference weight-determining results indicates that the to-be-determined weight data does not have a weight relationship with the third object, the server may calculate a reference probability that the to-be-determined weight data has a weight relationship with the third object according to the weight corresponding to each weight-determining party, where the reference probability is a probability that the to-be-determined weight data has a weight relationship with the third object.
The corresponding probabilities of different determiners may be the same (e.g., the same share and the same weight, 1 person and 1 ticket, and the weight of each ticket is the same) or different (e.g., different shares and weights, and the number of tickets is calculated according to the weight). In obtaining the reference weight-determining result of each weight-determining party, votes may be cast on the weight-determining result indicated by the reference weight-determining result, and the number of votes (reference probability) having a weight relationship between the to-be-determined weight data and the third object may be calculated according to the weight. The reference probability may be a normalized probability or a non-normalized probability, and the way of calculating the reference probability according to the weight of the weight determiner may be set as needed, which is not limited in this embodiment.
After the reference probability is obtained, the reference probability may be compared to a target probability threshold. If the reference probability is greater than or equal to the target probability threshold, it may be determined that there is a ownership relationship between the pending weight data and the third object. The server may determine a seventh right confirmation result of the to-be-confirmed-weight data, where the seventh right confirmation result is used to indicate that the right confirmation of the to-be-confirmed-weight data is successful. If the reference probability is less than the target probability threshold, it may be determined that there is no weight relationship between the pending weight data and the third object. The server may determine an eighth right determining result of the to-be-determined-right data, where the eighth right determining result is used to indicate that the right determining of the to-be-determined-right data fails.
For example, the first entitlement request is for requesting a determination of whether the pending entitlement data has an entitlement relationship with the target owner. The authorized party of the data to be authorized is multiple: the weight of the data to be determined belongs to the relationship person (weight 0.1), the supervisor (weight 0.4), the management organization (weight 0.4), the system operator (weight 0.1), and the weight determination results of the relationship person, the supervisor and the management organization of the data to be determined are: the right confirmation is passed, and the right confirmation result of the system operator is as follows: the authentication fails. The reference probability of passing the right determination obtained by calculation is 0.9 and is greater than the probability threshold of 0.8 (the target probability threshold can be configured as required), and then the joint right determination result is used for indicating that the right determination of the data to be determined is successful.
By the embodiment, whether the right relation exists between the data to be determined and the specific object is determined by configuring different right determining rules, so that the applicability and flexibility of the data right determining mode can be improved.
It should be noted that, in this embodiment, in order to ensure the security and efficiency of information transmission, the information carried in the authorization request may be encrypted, or the authorization request carries a characteristic value of the digital resource, and the like. The type and the right-determining scene of the data to be determined are optional examples, and the data right-determining scheme in the embodiment is applicable to other types of resources and right-determining scenes.
The following explains a data right determining method in the embodiment of the present application with an alternative example. The data authority scenario in this example applies to a digital asset authority scenario, where the data to be authenticated is a digital asset (like a digital certificate, a digital certificate), the authority request is used to request to determine whether a target authority has an authority relationship with the digital asset, and the authority determining method includes: the system comprises a digital asset ownership system person (digital asset ownership system person 1, digital asset ownership system person 2, …, digital asset ownership system person N), a third party (supervision party, management structure, system operator), wherein the ownership system person refers to a person, organization and the like having an affiliation with the digital asset. The ownership affiliate can be an ownership of the digital asset, or can be another type of ownership affiliate, for example, the digital certificate is a transaction certificate, and the ownership affiliate can be both parties to a transaction.
As shown in fig. 4, the flow of the data right confirming method in this example includes the following steps:
step S402, a request for authority confirmation is initiated.
A client or other device may initiate a request to determine the entitlement of a digital asset that requests a determination of whether object B is entitled to the digital asset.
In step S404, the plurality of authorities receive the authority confirmation requests respectively.
The server, after receiving the request for determining rights, may determine a plurality of parties for determining rights to the digital asset, including: the ownership of the digital asset 1, the ownership of the digital asset 2, …, the ownership of the digital asset N, the third party 1 (the supervising party), the third party 2 (the management structure), the third party 3 (the system operator), and forwards the request for the right to each of the authorities.
Step S406, determine whether the right is available.
Each authority determiner may determine whether the object B has the right to the digital asset, and if all the authorities determine the right, step S408 is performed, otherwise, step S410 is performed.
In step S408, the authentication is successful.
And each right confirming party judges that the object B has the right to the digital asset, the right confirmation is successful, and a right confirmation success indication is returned to the client.
And step S410, refuting.
If any of the entitlers determines that the object B has no right for the digital asset, the entitlements fail, the entitlements request is rejected, and an indication of the failed entitlements is returned to the client.
It should be noted that, the right-determining rule agreed based on the agreed consensus, the optional right-determining rule may include, but is not limited to, the following:
1) share same weight (1 person 1 ticket, each ticket has the same weight);
2) different weights (ticket number is calculated according to weight size) of different stocks;
3) each party must be right and pass;
4) any 1 party is right to pass;
5) any number of parties (less than the total number of parties) are granted a pass.
By the example, on the basis of the single-party right confirming mechanism/scheme, a combined right confirming mechanism/scheme is created to meet the application scene of combined right confirming, so that the method can be suitable for various combined right confirming scenes, the applicability of the data right confirming scheme is improved, and the accuracy of the right confirming result is ensured.
It should be noted that, for simplicity of description, the above-mentioned method embodiments are described as a series of acts or combination of acts, but those skilled in the art will recognize that the present application is not limited by the order of acts described, as some steps may occur in other orders or concurrently depending on the application. Further, those skilled in the art should also appreciate that the embodiments described in the specification are preferred embodiments and that the acts and modules referred to are not necessarily required in this application.
Through the above description of the embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by software plus a necessary general hardware platform, and certainly can also be implemented by hardware, but the former is a better implementation mode in many cases. Based on such understanding, the technical solutions of the present application may be embodied in the form of a software product, which is stored in a storage medium (e.g., ROM/RAM, magnetic disk, optical disk) and includes instructions for enabling a terminal device (e.g., a mobile phone, a computer, a server, or a network device) to execute the method according to the embodiments of the present application.
According to another aspect of the embodiments of the present application, there is also provided a data right confirming device for implementing the data right confirming method. Fig. 5 is a schematic diagram of an alternative data authorization apparatus according to an embodiment of the present application, and as shown in fig. 5, the apparatus may include:
(1) a receiving unit 52, configured to receive a first right confirmation request initiated by a client, where the first right confirmation request is used to request to confirm right to be confirmed to the right data;
(2) an obtaining unit 54, connected to the receiving unit 52, configured to obtain, in response to the first right determining request, multiple reference right determining results of multiple right determining parties, where each reference object in the multiple right determining parties is used to determine right of the right to be determined data, and the multiple right determining parties correspond to the multiple reference right determining results in a one-to-one manner;
(3) and a sending unit 56, connected to the obtaining unit 54, configured to send target indication information to the client, where the target indication information is used to indicate a right confirmation result of the to-be-confirmed right data determined according to the multiple reference right confirmation results.
It should be noted that the receiving unit 52 in this embodiment may be configured to execute the step S202, the obtaining unit 54 in this embodiment may be configured to execute the step S204, and the sending unit 56 in this embodiment may be configured to execute the step S206.
Through the module, a first right confirmation request initiated by a client is received, wherein the first right confirmation request is used for requesting to confirm right of the right to be confirmed data; responding to the first right confirming request, and acquiring a plurality of reference right confirming results of a plurality of right confirming parties, wherein each reference object in the plurality of right confirming parties is used for confirming the right of the right to be confirmed data, and the plurality of right confirming parties correspond to the plurality of reference right confirming results in a one-to-one mode; target indication information is sent to the client, wherein the target indication information is used for indicating the weight determining result of the to-be-determined weight data determined according to the multiple reference weight determining results, so that the problem that a data weight determining mode in the related technology is poor in scheme applicability due to the fact that the data weight determining mode is only suitable for a scene in which the weight is determined by a centralized mechanism is solved, the applicability of a data weight determining scheme is improved, and the success rate of the weight determining is ensured.
As an alternative embodiment, the apparatus further comprises:
the device comprises an extracting unit, a judging unit and a judging unit, wherein the extracting unit is used for extracting a target data name of the data to be authenticated and a target data identification of the data to be authenticated from a first authentication request before acquiring a plurality of reference authentication results of a plurality of authentication parties;
and the first determining unit is used for determining a plurality of power determining parties according to the target data name and the target data identifier.
As an alternative embodiment, the first determination unit includes:
and the matching module is used for matching a plurality of authority confirming parties from the target relational database by using the target data name and the target data identifier, wherein the target relational database stores the corresponding relation among the data name, the data identifier and the authority confirming parties.
As an alternative embodiment, the obtaining unit includes:
the sending module is used for respectively sending a second right confirming request to each of the plurality of right confirming parties, wherein the second right confirming request is used for requesting to confirm the right of the right to be confirmed data;
and the receiving module is used for respectively receiving the reference right confirming result returned by each of the plurality of right confirming parties.
As an alternative embodiment, the apparatus further comprises:
the second determining unit is used for determining the right determining result of the to-be-determined right data according to the multiple reference right determining results before the target indication information is sent to the client;
and the generating unit is used for generating the target indication information according to the right determining result of the to-be-determined right data.
Optionally, in this embodiment, the first right confirmation request is used to request to determine a right object of the data to be confirmed.
As an optional implementation, the second determining unit includes:
the first determining module is used for determining a first right determining result of the to-be-determined right data under the condition that all right objects of the to-be-determined right data represented by the multiple reference right determining results are first objects, wherein the first right determining result is used for representing that the right objects of the to-be-determined right data are the first objects.
As another optional embodiment, the second determination unit includes:
and the second determining module is used for determining a second right determining result of the to-be-determined right data under the condition that the ownership objects of the to-be-determined right data represented by the plurality of reference right determining results are not the same object, wherein the second right determining result is used for representing that the right determination of the to-be-determined right data fails.
As still another optional implementation, the second determining unit includes:
the calculation module is used for calculating the weight determining probability corresponding to each reference object in the plurality of reference objects according to the weight corresponding to each weight determining party in the plurality of weight determining parties when the weight objects of the to-be-determined weight data represented by the plurality of reference weight determining results are the plurality of reference objects, wherein the weight determining probability corresponding to each reference object is the probability that the weight object of the to-be-determined weight data is the each reference object;
the selecting module is used for selecting a second object from the plurality of reference objects, wherein the second object is the reference object corresponding to the maximum weight-determining probability;
and the third determining module is used for determining a third right determining result of the to-be-determined right data, wherein the third right determining result is used for indicating that a right object of the to-be-determined right data is a second object.
Optionally, in this embodiment, the first permission request is used to request to determine whether the pending permission data and the third object have a permission relationship.
As an optional implementation, the second determining unit includes:
and the fourth determining module is used for determining a fourth weight determining result of the to-be-determined weight data under the condition that the plurality of reference weight determining results all indicate that the to-be-determined weight data has the ownership relationship with the third object, wherein the fourth weight determining result is used for indicating that the weight determining of the to-be-determined weight data is successful.
As another optional embodiment, the second determination unit includes:
a fifth determining module, configured to determine a fifth weight determining result of the to-be-determined weight data if at least one of the multiple reference weight determining results indicates that the to-be-determined weight data has a ownership relationship with the third object, where the fifth weight determining result is used to indicate that the weight determining of the to-be-determined weight data is successful;
as still another optional implementation, the second determining unit includes:
and a sixth determining module, configured to determine a sixth weight determining result of the to-be-determined weight data if at least one of the multiple reference weight determining results indicates that the to-be-determined weight data does not have a ownership relationship with the third object, where the sixth weight determining result is used to indicate that the weight determining of the to-be-determined weight data fails.
As still another optional implementation, the second determining unit includes:
a seventh determining module, configured to determine, when at least one of the multiple reference right determining results indicates that the to-be-determined right data does not have a ownership relationship with the third object, a reference probability that the to-be-determined right data has an ownership relationship with the third object according to a weight corresponding to each of the multiple right determining parties;
the eighth determining module is configured to determine a seventh weight determining result of the to-be-determined weight data when the reference probability is greater than or equal to the target probability threshold, where the seventh weight determining result is used to indicate that the weight determining of the to-be-determined weight data is successful;
and the ninth determining module is used for determining an eighth weight determining result of the to-be-determined-weight data under the condition that the reference probability is smaller than the target probability threshold, wherein the eighth weight determining result is used for indicating that the weight determining of the to-be-determined-weight data fails.
It should be noted here that the modules described above are the same as the examples and application scenarios implemented by the corresponding steps, but are not limited to the disclosure of the above embodiments. It should be noted that the modules described above as a part of the apparatus may be operated in a hardware environment as shown in fig. 1, and may be implemented by software, or may be implemented by hardware, where the hardware environment includes a network environment.
According to another aspect of the embodiments of the present application, there is also provided an electronic device for implementing the above-mentioned data right confirming method, where the electronic device may be a server, a terminal, or a combination thereof.
Fig. 6 is a block diagram of an alternative electronic device according to an embodiment of the present application, and as shown in fig. 6, the electronic device includes a memory 602 and a processor 604, the memory 602 stores a computer program, and the processor 604 is configured to execute steps in any one of the method embodiments described above through the computer program.
Optionally, in this embodiment, the electronic apparatus may be located in at least one network device of a plurality of network devices of a computer network.
Optionally, in this embodiment, the processor may be configured to execute the following steps by a computer program:
s1, receiving a first right confirming request initiated by a client, wherein the first right confirming request is used for requesting to confirm right to be confirmed to right data;
s2, responding to the first right confirming request, obtaining a plurality of reference right confirming results of a plurality of right confirming parties, wherein each reference object in the plurality of right confirming parties is used for confirming right of the right to be confirmed data, and the plurality of right confirming parties correspond to the plurality of reference right confirming results one by one;
and S3, sending target indication information to the client, wherein the target indication information is used for indicating the right result of the to-be-confirmed right data determined according to the plurality of reference right confirming results.
Alternatively, it can be understood by those skilled in the art that the structure shown in fig. 6 is only an illustration, and the electronic device may also be a terminal device such as a smart device (e.g., an Android Mobile phone, an iOS Mobile phone, etc.), a tablet computer, a palmtop computer, and an MID (Mobile Internet Devices), a PAD, etc. Fig. 6 is a diagram illustrating a structure of the electronic device. For example, the electronic device may also include more or fewer components (e.g., network interfaces, etc.) than shown in FIG. 6, or have a different configuration than shown in FIG. 6.
The memory 602 may be used to store software programs and modules, such as program instructions/modules corresponding to the data authorization method and apparatus in the embodiments of the present application, and the processor 604 executes various functional applications and data processing by running the software programs and modules stored in the memory 602, that is, implementing the data authorization method described above. The memory 602 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 602 may further include memory located remotely from the processor 604, which may be connected to the terminal over a network. Examples of such networks include, but are not limited to, the internet, intranets, local area networks, mobile communication networks, and combinations thereof.
The memory 602 may be, but is not limited to, specifically configured to store data change record information of one or more objects.
As an example, as shown in fig. 6, the memory 602 may include, but is not limited to, the receiving unit 52, the obtaining unit 54, and the sending unit 56 in the data right determining apparatus. In addition, the data authorization device may further include, but is not limited to, other module units in the data authorization device, which is not described in this example again.
Optionally, the transmitting device 606 is used for receiving or sending data via a network. Examples of the network may include a wired network and a wireless network. In one example, the transmission device 606 includes a NIC (Network Interface Controller) that can be connected to a router via a Network cable and other Network devices so as to communicate with the internet or a local area Network. In one example, the transmission device 606 is an RF (Radio Frequency) module, which is used for communicating with the internet in a wireless manner.
Furthermore, the electronic device may further include: a connection bus 608 for connecting the respective module components in the electronic apparatus.
Optionally, the specific examples in this embodiment may refer to the examples described in the above embodiments, and this embodiment is not described herein again.
Those skilled in the art will appreciate that all or part of the steps in the methods of the above embodiments may be implemented by a program instructing hardware associated with the terminal device, where the program may be stored in a computer-readable storage medium, and the storage medium may include: flash disks, ROM (Read-Only Memory), RAM (Random Access Memory), magnetic or optical disks, and the like.
According to still another aspect of an embodiment of the present application, there is also provided a storage medium. Alternatively, in the present embodiment, the storage medium may be a program code for executing the data right determining method.
Optionally, in this embodiment, the storage medium may be located on at least one of a plurality of network devices in a network shown in the above embodiment.
Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps:
s1, receiving a first right confirming request initiated by a client, wherein the first right confirming request is used for requesting to confirm right to be confirmed to right data;
s2, responding to the first right confirming request, obtaining a plurality of reference right confirming results of a plurality of right confirming parties, wherein each reference object in the plurality of right confirming parties is used for confirming right of the right to be confirmed data, and the plurality of right confirming parties correspond to the plurality of reference right confirming results one by one;
and S3, sending target indication information to the client, wherein the target indication information is used for indicating the right result of the to-be-confirmed right data determined according to the plurality of reference right confirming results.
Optionally, the specific example in this embodiment may refer to the example described in the above embodiment, which is not described again in this embodiment.
Optionally, in this embodiment, the storage medium may include, but is not limited to: various media capable of storing program codes, such as a U disk, a ROM, a RAM, a removable hard disk, a magnetic disk, or an optical disk.
The above-mentioned serial numbers of the embodiments of the present application are merely for description and do not represent the merits of the embodiments.
The integrated unit in the above embodiments, if implemented in the form of a software functional unit and sold or used as a separate product, may be stored in the above computer-readable storage medium. Based on such understanding, the technical solution of the present application may be substantially implemented or a part of or all or part of the technical solution contributing to the prior art may be embodied in the form of a software product stored in a storage medium, and including instructions for causing one or more computer devices (which may be personal computers, servers, network devices, or the like) to execute all or part of the steps of the method described in the embodiments of the present application.
In the above embodiments of the present application, the descriptions of the respective embodiments have respective emphasis, and for parts that are not described in detail in a certain embodiment, reference may be made to related descriptions of other embodiments.
In the several embodiments provided in the present application, it should be understood that the disclosed client may be implemented in other manners. The above-described embodiments of the apparatus are merely illustrative, and for example, the division of the units is only one type of division of logical functions, and there may be other divisions when actually implemented, for example, a plurality of units or components may be combined or may be integrated into another system, or some features may be omitted, or not executed. In addition, the shown or discussed mutual coupling or direct coupling or communication connection may be an indirect coupling or communication connection through some interfaces, units or modules, and may be in an electrical or other form.
The units described as separate parts may or may not be physically separate, and parts displayed as units may or may not be physical units, may be located in one place, or may be distributed on a plurality of network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution provided in the embodiment.
In addition, functional units in the embodiments of the present application may be integrated into one processing unit, or each unit may exist alone physically, or two or more units are integrated into one unit. The integrated unit can be realized in a form of hardware, and can also be realized in a form of a software functional unit.
The foregoing is only a preferred embodiment of the present application and it should be noted that those skilled in the art can make several improvements and modifications without departing from the principle of the present application, and these improvements and modifications should also be considered as the protection scope of the present application.

Claims (10)

1. A method for data authentication, comprising:
receiving a first right confirmation request initiated by a client, wherein the first right confirmation request is used for requesting to confirm right of right to be confirmed data;
responding to the first right confirming request, and acquiring a plurality of reference right confirming results of a plurality of right confirming parties, wherein each reference object in the plurality of right confirming parties is used for confirming the right of the data to be confirmed, and the plurality of right confirming parties correspond to the plurality of reference right confirming results in a one-to-one mode;
and sending target indication information to the client, wherein the target indication information is used for indicating a right confirmation result of the to-be-confirmed weight data determined according to the multiple reference right confirmation results.
2. The method of claim 1, wherein prior to said obtaining a plurality of reference validation results for a plurality of validation parties, the method further comprises:
extracting a target data name of the to-be-confirmed data and a target data identification of the to-be-confirmed data from the first confirmation request;
and determining the plurality of power determining parties according to the target data name and the target data identifier.
3. The method of claim 2, wherein determining the plurality of determiners based on the target data name and the target data identification comprises:
and matching the plurality of authority confirming parties from a target relational database by using the target data name and the target data identifier, wherein the target relational database stores the corresponding relation among the data name, the data identifier and the authority confirming party.
4. The method of claim 1, wherein obtaining the plurality of reference weight-determining results of the plurality of weight-determining parties comprises:
respectively sending a second right confirming request to each of the plurality of right confirming parties, wherein the second right confirming request is used for requesting to confirm the right of the data to be confirmed;
and respectively receiving the reference right confirming result returned by each of the plurality of right confirming parties.
5. The method according to any of claims 1 to 4, wherein prior to said sending target indication information to said client, said method further comprises:
determining a weight determining result of the to-be-determined weight data according to the plurality of reference weight determining results;
and generating the target indication information according to the determined right result of the to-be-determined right data.
6. The method according to claim 5, wherein in the case that the first right confirmation request is used for requesting to determine the ownership object of the pending right data, determining the right confirmation result of the pending right data according to the plurality of reference right confirmation results comprises at least one of:
determining a first weight determination result of the to-be-determined weight data when all the weight objects of the to-be-determined weight data represented by the plurality of reference weight determination results are first objects, wherein the first weight determination result is used for representing that the weight object of the to-be-determined weight data is the first object;
determining a second weight determining result of the to-be-determined weight data under the condition that the ownership objects of the to-be-determined weight data represented by the plurality of reference weight determining results are not the same object, wherein the second weight determining result is used for representing that the weight determining of the to-be-determined weight data fails;
if the ownership objects of the to-be-authenticated data represented by the multiple reference ownership results are multiple reference objects, calculating an ownership probability corresponding to each reference object in the multiple reference objects according to the weight corresponding to each of the multiple ownership parties, wherein the ownership probability corresponding to each reference object is the probability that the ownership object of the to-be-authenticated data is the reference object; selecting a second object from the plurality of reference objects, wherein the second object is a reference object corresponding to the maximum weight-determining probability; and determining a third weight determination result of the to-be-determined weight data, wherein the third weight determination result is used for indicating that a ownership object of the to-be-determined weight data is the second object.
7. The method according to claim 5, wherein in a case that the first right confirmation request is for requesting a determination of whether the pending right data has a ownership relationship with a third object, the determining a right confirmation result of the pending right data according to the plurality of reference right confirmation results comprises at least one of:
if the plurality of reference weight-determining results all indicate that the to-be-determined weight data has a weight relationship with the third object, determining a fourth weight-determining result of the to-be-determined weight data, wherein the fourth weight-determining result is used for representing that the weight-determining of the to-be-determined weight data is successful;
determining a fifth weight confirmation result of the to-be-confirmed weight data if at least one of the plurality of reference weight confirmation results indicates that the to-be-confirmed weight data has a weight relationship with the third object, wherein the fifth weight confirmation result is used for indicating that the weight confirmation of the to-be-confirmed weight data is successful;
determining a sixth weight confirmation result of the to-be-confirmed data if at least one of the plurality of reference weight confirmation results indicates that the to-be-confirmed data has no ownership relationship with the third object, wherein the sixth weight confirmation result is used for indicating that the weight confirmation of the to-be-confirmed data fails;
determining a reference probability that the data to be determined has a ownership relationship with the third object according to a weight corresponding to each of the plurality of authorities if at least one of the plurality of reference authority determination results indicates that the data to be determined does not have an ownership relationship with the third object; determining a seventh weight determining result of the to-be-determined weight data when the reference probability is greater than or equal to a target probability threshold, wherein the seventh weight determining result is used for indicating that the weight determining of the to-be-determined weight data is successful; and determining an eighth weight determining result of the to-be-determined weight data when the reference probability is smaller than a target probability threshold, wherein the eighth weight determining result is used for indicating that the weight determining of the to-be-determined weight data fails.
8. A data right determining apparatus, comprising:
the device comprises a receiving unit, a sending unit and a receiving unit, wherein the receiving unit is used for receiving a first right confirmation request initiated by a client, and the first right confirmation request is used for requesting to confirm right of right to be confirmed data;
an obtaining unit, configured to obtain, in response to the first right determining request, multiple reference right determining results of multiple right determining parties, where each reference object in the multiple right determining parties is used to determine the right of the to-be-determined right data, and the multiple right determining parties are in one-to-one correspondence with the multiple reference right determining results;
a sending unit, configured to send target indication information to the client, where the target indication information is used to indicate a result of determining the right of the to-be-determined right data, which is determined according to the multiple reference results of determining the right.
9. A computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to carry out the method of any one of claims 1 to 7 when executed.
10. An electronic device comprising a memory and a processor, characterized in that the memory has stored therein a computer program, the processor being arranged to execute the method of any of claims 1 to 7 by means of the computer program.
CN202010676186.8A 2020-07-14 2020-07-14 Data right determining method and device, storage medium and electronic device Active CN111934881B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202010676186.8A CN111934881B (en) 2020-07-14 2020-07-14 Data right determining method and device, storage medium and electronic device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202010676186.8A CN111934881B (en) 2020-07-14 2020-07-14 Data right determining method and device, storage medium and electronic device

Publications (2)

Publication Number Publication Date
CN111934881A true CN111934881A (en) 2020-11-13
CN111934881B CN111934881B (en) 2023-07-07

Family

ID=73312948

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202010676186.8A Active CN111934881B (en) 2020-07-14 2020-07-14 Data right determining method and device, storage medium and electronic device

Country Status (1)

Country Link
CN (1) CN111934881B (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112700327A (en) * 2021-01-08 2021-04-23 北京金山云网络技术有限公司 User confirmation method, device and system in financial scene
CN117808472A (en) * 2024-02-29 2024-04-02 中国科学院信息工程研究所 Data ownership element abstraction and right-confirming method, data transaction method and device

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100191817A1 (en) * 2004-02-09 2010-07-29 Nokia Corporation Multimedia Message Transfer
CN106559385A (en) * 2015-09-25 2017-04-05 阿里巴巴集团控股有限公司 A kind of data authentication method and apparatus
CN107566116A (en) * 2017-06-15 2018-01-09 中国银联股份有限公司 The method and device of registration is really weighed for digital asset
CN107580022A (en) * 2017-08-02 2018-01-12 国家计算机网络与信息安全管理中心 A kind of data-sharing systems and method
WO2020019519A1 (en) * 2018-07-27 2020-01-30 平安科技(深圳)有限公司 Task allocation method and apparatus

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100191817A1 (en) * 2004-02-09 2010-07-29 Nokia Corporation Multimedia Message Transfer
CN106559385A (en) * 2015-09-25 2017-04-05 阿里巴巴集团控股有限公司 A kind of data authentication method and apparatus
CN107566116A (en) * 2017-06-15 2018-01-09 中国银联股份有限公司 The method and device of registration is really weighed for digital asset
CN107580022A (en) * 2017-08-02 2018-01-12 国家计算机网络与信息安全管理中心 A kind of data-sharing systems and method
WO2020019519A1 (en) * 2018-07-27 2020-01-30 平安科技(深圳)有限公司 Task allocation method and apparatus

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112700327A (en) * 2021-01-08 2021-04-23 北京金山云网络技术有限公司 User confirmation method, device and system in financial scene
CN117808472A (en) * 2024-02-29 2024-04-02 中国科学院信息工程研究所 Data ownership element abstraction and right-confirming method, data transaction method and device

Also Published As

Publication number Publication date
CN111934881B (en) 2023-07-07

Similar Documents

Publication Publication Date Title
CN110519062B (en) Identity authentication method, authentication system and storage medium based on block chain
CN111970129B (en) Data processing method and device based on block chain and readable storage medium
CN112115205B (en) Cross-chain trust method, device, equipment and medium based on digital certificate authentication
EP4178155A1 (en) Blockchain-based certification audit data sharing and integrity verification system, device, and method thereof
CN112165382B (en) Software authorization method and device, authorization server side and terminal equipment
CN111897879B (en) Transaction record sharing method and device based on blockchain network and electronic equipment
CN112000744A (en) Signature method and related equipment
CN109118377A (en) A kind of processing method, system and the electronic equipment of the Claims Resolution event based on block chain
CN112448946A (en) Log auditing method and device based on block chain
CN111934881A (en) Data right confirming method and device, storage medium and electronic device
CN110321730A (en) A kind of method, block chain node and the storage medium of operation data processing
CN113569263A (en) Secure processing method and device for cross-private-domain data and electronic equipment
CN104469736A (en) Data processing method, server and terminal
CN109241762A (en) Assets information acquisition methods, device and computer equipment based on block chain technology
CN110838067A (en) Real estate transaction data processing method, device, server and storage medium
CN111931230A (en) Data authorization method and device, storage medium and electronic device
CN110941840A (en) Data processing method, system and terminal
CN108540335B (en) Management method and management device for equipment analysis report
CN108090371B (en) Data processing method, data tracking method, data processing device and data tracking device
CN112036884B (en) Signature method and related equipment
KR102174687B1 (en) Secret electronic voting system and method
KR20220079736A (en) Method and system for managing user reputation based on blockchain
CN106034023A (en) User equipment, authentication server, identity authentication method and identity authentication system
KR102544764B1 (en) Method for generating user pseudo information identifier using temporary identifier issued on user terminal and system therefor
US20240146537A1 (en) Computer-readable recording medium storing data management program, data management method, and data management apparatus

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant