A data processing method and device based on blockchain

By using blockchain technology in Internet services, receiving and processing user's operational behavior data and page change data, creating verifiable statements and uploading them to the alliance blockchain, the data processing problems are solved, the data is securely stored and access management is realized, and the business service quality and dispute resolution efficiency is improved.

CN112861187BActive Publication Date: 2025-05-06ANT SHENGXIN (SHANGHAI) INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110121511.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-28
Publication Date
2025-05-06
Estimated Expiration
2041-01-28

AI Technical Summary

Technical Problem

During the Internet business processing process, users' operating behavior data and page change data are difficult to effectively handle, resulting in difficult to resolve business service quality and user disputes.

Method used

By receiving structured data and user information sent by the service server, obtaining digital identity information, creating verifiable statements, and uploading them to the alliance blockchain system to realize secure storage and access rights management of data.

Benefits of technology

It realizes the secure storage and authenticity of user operation behavior data and page change data, ensures that the data will not be tampered with, and through access rights management, user privacy is protected, and business service quality and dispute resolution efficiency are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112861187B_ABST
    Figure CN112861187B_ABST
Patent Text Reader

Abstract

The embodiments of this specification provide a data processing method and device based on blockchain, which method includes: receiving structured data of a target business and user information of a target user sent by a business service end; obtaining digital identity information of the target user based on the above user information; creating a verifiable declaration of structured data corresponding to the digital identity information based on the acquired digital identity information and structured data; and uploading the declaration content data of the created verifiable declaration to the alliance blockchain system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of blockchain technology, and in particular to a blockchain-based data processing method and device. Background Art

[0002] With the rapid development of Internet technology, more and more businesses can be conducted online through the Internet, such as commercial insurance business, financial management business, etc. In the process of handling business, users need to perform business-related operations, such as clicking certain buttons or entering business-related information, etc. However, after the business is completed, there may be disputes over the quality of business services or the user cannot enjoy the corresponding services. In this case, the relevant data in the user's business handling, such as operation behavior data, page change data, etc., is particularly important. Therefore, how to reasonably process the data in the process of users performing business has become a technical problem that needs to be solved urgently. Summary of the invention

[0003] The embodiment of this specification provides a data processing method based on blockchain. The method includes: receiving structured data of a target business and user information of a target user sent by a business service end. Obtaining digital identity information of the target user based on the user information. Creating a verifiable statement of structured data corresponding to the digital identity information based on the digital identity information and the structured data. Uploading the statement content data of the verifiable statement to the alliance blockchain system.

[0004] The embodiment of this specification also provides a data processing method based on blockchain. The method includes: obtaining structured data of the target business. Generating access permission information for each data acquisition agency for the structured data. Sending the structured data and the access permission information to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to the alliance blockchain system.

[0005] The embodiment of this specification also provides a data processing device based on blockchain. The device includes: a first receiving module, receiving the structured data of the target business and the user information of the target user sent by the business service end. An acquisition module, acquiring the digital identity information of the target user based on the user information. A creation module, creating a verifiable statement of the structured data corresponding to the digital identity information based on the digital identity information and the structured data. A first uploading module, uploading the declaration content data of the verifiable statement to the alliance blockchain system.

[0006] The embodiment of this specification also provides a data processing device based on blockchain. The device includes: an acquisition module, which acquires structured data of a target business. A generation module, which generates access permission information of each data acquisition agency for the structured data. A sending module, which sends the structured data and the access permission information to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system.

[0007] The embodiment of this specification also provides a data processing device based on blockchain, including: a processor. And a memory arranged to store computer executable instructions, the executable instructions, when executed, cause the processor to: receive structured data of a target business and user information of a target user sent by a business service end. Obtain digital identity information of the target user based on the user information. Create a verifiable statement of structured data corresponding to the digital identity information based on the digital identity information and the structured data. Upload the statement content data of the verifiable statement to the alliance blockchain system.

[0008] The embodiment of the present specification also provides a data processing device based on blockchain, including: a processor. And a memory arranged to store computer executable instructions, wherein when the executable instructions are executed, the processor: obtains structured data of a target business. Generates access permission information for each data acquisition agency for the structured data. Sends the structured data and the access permission information to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system.

[0009] The embodiment of this specification also provides a storage medium for storing computer executable instructions, which implement the following process when executed: receiving structured data of a target business and user information of a target user sent by a business service end. Obtaining digital identity information of the target user based on the user information. Creating a verifiable statement of structured data corresponding to the digital identity information based on the digital identity information and the structured data. Uploading the statement content data of the verifiable statement to the alliance blockchain system.

[0010] The embodiment of this specification also provides a storage medium for storing computer executable instructions, which implement the following process when executed: obtaining structured data of a target business. Generating access permission information for each data acquisition agency for the structured data. Sending the structured data and the access permission information to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0012] Figure 1 A schematic diagram of a first application scenario of a blockchain-based data processing method provided in an embodiment of this specification;

[0013] Figure 2 A schematic diagram of a second application scenario of the blockchain-based data processing method provided in the embodiments of this specification;

[0014] Figure 3 A schematic diagram of a first flow chart of a blockchain-based data processing method provided in an embodiment of this specification;

[0015] Figure 4 A schematic diagram of a Merkle tree constructed in a blockchain-based data processing method provided in an embodiment of this specification;

[0016] Figure 5 A second flow chart of the blockchain-based data processing method provided in the embodiments of this specification;

[0017] Figure 6 A schematic diagram of structured data obtained in the blockchain-based data processing method provided in an embodiment of this specification;

[0018] Figure 7 A third flow chart of the blockchain-based data processing method provided in the embodiments of this specification;

[0019] Figure 8 A schematic diagram of the interactive process of the blockchain-based data processing method provided in the embodiments of this specification;

[0020] Fig. 9 A schematic diagram of the first module composition of a blockchain-based data processing device provided in an embodiment of this specification;

[0021] Fig.10 A schematic diagram of the second module composition of the blockchain-based data processing device provided in the embodiments of this specification;

[0022] Fig.11 A schematic diagram of the structure of a blockchain-based data processing device provided in an embodiment of this specification. DETAILED DESCRIPTION

[0023] In order to enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this application.

[0024] Figure 1 A schematic diagram of the first application scenario of the blockchain-based data processing method provided in the embodiments of this specification, such as Figure 1 As shown, the application scenario includes a terminal device, a business server, an authorization management server, and a consortium blockchain system. The terminal device may be a mobile phone, a tablet computer, a computer, or the like. A business client is installed on the terminal device. The business client may be an independent application (APP) installed on the terminal device, or a small program embedded in some independent application, or a web page, etc.

[0025] Specifically, when a user executes a target business through a terminal device, the user's operation behavior data and page change data when executing the target business are collected through the terminal device, and the collected operation behavior data and page change data are sent to the business server. The business server generates structured data of the user executing the target business based on the operation behavior data and page change data; the business server sends the user's user information and the structured data to the authorization management server, and the authorization management server obtains the user's digital identity information based on the user's user information. Among them, in a specific implementation, the digital identity information can be a decentralized identity (Decentralized Identity, DID). The authorization management server creates a verifiable declaration of the structured data corresponding to the digital identity information; and uploads the declaration content data of the verifiable declaration to the alliance blockchain, so that the alliance blockchain constructs a Merkle tree corresponding to the declaration content data, thereby realizing the storage of structured data in the alliance blockchain system.

[0026] Optionally, in a specific implementation, the verifiable declaration of structured data corresponding to the target user's digital identity information is created through a digital identity blockchain system, and a specific form of the digital identity blockchain system can be a DID blockchain system. Figure 2 A schematic diagram of a second application scenario of the blockchain-based data processing method provided in the embodiments of this specification, such as Figure 2 As shown in the figure, the application scenario includes terminal equipment, business server, authorization management server, alliance blockchain system and DID blockchain system. Figure 2 For more information about the terminal equipment and service end in the system shown, please refer to Figure 1 The relevant introduction in will not be repeated here.

[0027] Figure 2 The application scenarios shown are similar to Figure 1 The difference is that after the authorization management server obtains the digital identity information of the user based on the user's user information, the authorization management server publishes the digital identity information and structured data to the DID blockchain system, and the DID blockchain system constructs a verifiable statement of the structured data corresponding to the digital identity information. After creating a verifiable statement of the structured data corresponding to the digital identity information, the DID blockchain returns the declaration content data of the created verifiable statement and the identification information of the verifiable statement to the authorization management server; then, the authorization management server uploads the declaration content data of the verifiable statement to the alliance blockchain, so that the alliance blockchain constructs a Merkle tree corresponding to the declaration content data, thereby realizing the storage of structured data in the alliance blockchain.

[0028] It should be noted that the above Figure 1 and Figure 2 These are just two possible application scenarios of the blockchain-based data processing method provided in the embodiments of this specification, and do not constitute a limitation on the application scenarios of the blockchain-based data processing method provided in the embodiments of this specification.

[0029] In addition, it should be noted that the target business mentioned in the embodiments of this specification can be any business, such as commercial insurance underwriting business, commodity trading business, etc.

[0030] Figure 3 The first flow chart of the data processing method based on blockchain provided in the embodiment of this specification is applied to the authorization management server, such as Figure 3 As shown, the method comprises at least the following steps:

[0031] Step 102: Receive structured data of the target service and user information of the target user sent by the service server.

[0032] The user information may be identification information of the target user at the service server, account information of the target user at the service server, or identity document information of the target user, etc. Of course, the user information may also be other information, as long as it can identify the target user, and the embodiments of this specification will not be described one by one.

[0033] The above structured data is structured data of relevant data generated when the target user executes the target business. The above relevant data can be user operation behavior data, page change data, etc. The above structured data is generated based on the above relevant data. Among them, the above operation behavior data can be collected by pre-embedding in the business client.

[0034] Optionally, in a specific implementation, after the business service end receives the operation behavior data of the target user performing the target business and the page change data of the business client when the target user performs the target business reported by the business client, the operation behavior data and the page change data are associated, and structured data corresponding to the associated operation behavior data are generated. Specifically, the above-mentioned association of the operation behavior data and the page change data can be determined based on the operation time corresponding to each operation behavior data and the change time corresponding to each page change data, and the page change caused by each operation behavior is thereby associated with the page change data.

[0035] For example, in a specific implementation, the time when the target user clicks the "Buy Now" control is 13:12:06 on December 18, 2019, and the time when the business client jumps from the "Insurance Details" page to the "Important Tips" page is also 13:12:06 on December 18, 2019. Since the time when the user performs the above operation behavior is consistent with the time when the page changes, it can be considered that the page change is caused by the target user's click operation on the "Buy Now" control, and therefore the operation behavior is associated with the above page change.

[0036] Of course, it should be noted that when associating the operation behavior data and the page change data based on the operation time corresponding to the operation behavior data and the change time corresponding to the page change, the association condition can be that the operation time is consistent with the change time, or that the change time is later than the operation time, and the time difference is less than or equal to the preset value.

[0037] After determining the structured data of the target user executing the target business and the user information of the target user, the business server sends the structured data of the target user and the user information of the target user to the authorization management server.

[0038] Step 104: Acquire the digital identity information of the target user based on the above user information.

[0039] The digital identity information may be expressed in a variety of forms, and one possible form is DID.

[0040] Step 106: Create a verifiable statement of the structured data corresponding to the digital identity information based on the digital identity information and the structured data.

[0041] The declaration content data of the above-mentioned verifiable declaration is actually the above-mentioned structured data, and the above-mentioned verifiable declaration is used to declare the structured data corresponding to the target user.

[0042] Step 108, uploading the declaration content data of the verifiable declaration to the alliance blockchain system.

[0043] Among them, in the embodiments of this specification, the declaration content data of the verifiable declaration is stored in the alliance blockchain system using a Merkle tree. Optionally, in order to facilitate understanding of the storage form of the declaration content data mentioned in the embodiments of this specification in the alliance blockchain system, the following will be explained with diagrams. For example, in a specific implementation, a schematic diagram of the Merkle tree corresponding to the declaration content constructed by the alliance blockchain is as follows: Figure 4 shown.

[0044] In the embodiments of this specification, the declaration content data of the verifiable declaration is stored in the form of a Merkle tree in the alliance blockchain system. In this way, different degrees of signature verification are granted to data with different privacy levels, thereby achieving the protection of user privacy data.

[0045] Optionally, in a specific implementation, before uploading the declaration content data of the verifiable declaration to the alliance blockchain, in order to protect the security of the declaration content data, the declaration content data may also be encrypted, and the encrypted ciphertext data may be uploaded to the alliance blockchain system.

[0046] In particular, during specific implementation, the Advanced Encryption Standard (AES) may be used to encrypt the above-mentioned declaration content data.

[0047] In the blockchain-based data processing method provided in the embodiment of this specification, after obtaining the structured data of the target user when executing the target business, the authorization management server creates a verifiable declaration of the structured data corresponding to the digital identity information based on the digital identity information of the target user and the structured data; then uploads the declaration content data of the verifiable declaration to the alliance blockchain system, thereby realizing the storage of the declaration content data in the alliance blockchain, ensuring that the declaration content data will not be tampered with, that is, ensuring the security and authenticity of the declaration content data; in addition, in the embodiment of this specification, the data when the target user executes the target business is stored in the form of structured data, which can facilitate the subsequent positioning of abnormal data and the construction of a Merkle tree corresponding to the structured data.

[0048] To facilitate understanding of the method provided in the embodiments of this specification, the specific implementation process of each of the above steps will be described in detail below.

[0049] Optionally, in a specific implementation, in the above step 104, obtaining the digital identity information of the target user based on the user information may include at least the following two implementation methods:

[0050] Method 1:

[0051] The digital identity information corresponding to the target user is searched from the pre-generated digital identity information corresponding to each user.

[0052] Optionally, in a specific implementation, when the target user is not performing business on the authorization management server for the first time, since the digital identity information corresponding to the target user has been created when the target user performed business through the authorization management server for the first time, and the mapping relationship between the user information and the digital identity information of each user is stored in the authorization management server, therefore, when the target user is not performing business on the authorization management server for the first time, the digital identity information corresponding to the target user can be matched from the above mapping relationship based on the target user's identity information.

[0053] Method 2:

[0054] The digital identity information corresponding to the target user is created based on the user information of the target user.

[0055] Optionally, in a specific implementation, when the target user performs a service through the authorization management platform for the first time, it is necessary to create the digital identity information corresponding to the target user. Specifically, the digital identity information of the target user is created based on one or more pieces of information in the user information of the target user.

[0056] Optionally, in a specific implementation, the step 106, creating a verifiable statement of the structured data corresponding to the digital identity information based on the digital identity information and the structured data, specifically includes the following steps 1 and 2:

[0057] Step 1: Upload the target user’s digital identity information and structured data to the digital identity blockchain system, and create a verifiable statement based on the target user’s digital identity information and structured data through the digital identity blockchain system;

[0058] Step 2: Receive the identification information and content data of the verifiable statement returned by the digital identity blockchain system.

[0059] Among them, in a specific implementation, a specific form of the above-mentioned digital identity blockchain system can be a DID blockchain system. That is, in the embodiment of this specification, the specific creation process of the above-mentioned verifiable statement is executed in the DID blockchain system. When the DID blockchain system completes the creation of the above-mentioned verifiable statement, it returns the identification information of the created verifiable statement and the statement content data of the verifiable statement to the authorization management server.

[0060] Specifically, in the embodiments of the present specification, the above-mentioned verifiable declaration is actually structured data used to declare the target user when executing the target business.

[0061] Optionally, the generated verifiable declaration content data actually includes multiple pieces of operation behavior data, and each piece of operation behavior data is represented in a structured form. For example, a specific content of the above declaration content data is as follows:

[0062] Operation behavior data 1: operation time, operation page ID, operation page area ID;

[0063] Operation behavior data 2: operation time, operation page ID, editing information;

[0064] Operation behavior data 3: operation time, operation page ID, and page change data.

[0065] That is, each operation behavior data contains multiple data contents, but some data contents may involve the privacy information of the target user, such as the operation behavior data for "editing the insured", which involves the user's personal information. Therefore, this data content cannot be opened to certain data acquisition agencies. Therefore, in the embodiment of this specification, in order to open different data to different data acquisition agencies, it is necessary to generate different access permission information for different data acquisition agencies. Therefore, the method provided in the embodiment of this specification also includes the following steps:

[0066] Receive the access permission information of the data acquisition agency for the above-mentioned declared content data sent by the business service end; upload the access permission information to the alliance blockchain system.

[0067] Among them, it should be noted that different data acquisition agencies have different access permission information corresponding to them. The above access permission information includes the access permission values ​​corresponding to each data content in the declared content data. The above access permission values ​​include a first numerical value and a second numerical value. The first numerical value indicates that the data acquisition agency has the permission to access the data content, and the second numerical value indicates that the data acquisition agency does not have the permission to access the data content.

[0068] Generally speaking, when the access permission value corresponding to a certain data content is a first value, the content value of the data content is returned to the data acquisition agency. When the access permission value corresponding to a certain data content is a second value, the hash value corresponding to the data content is returned to the data acquisition agency.

[0069] Optionally, in a specific implementation, the access permission information corresponding to each of the above-mentioned data acquisition agencies can be generated on the business service end. Specifically, the business service end can generate the access permission information corresponding to each data acquisition agency by defining an index. Specifically, the index contains multiple key-value pairs, where the key represents the data content in the declared content data, and the value represents the access permission value of the data acquisition agency to the content data.

[0070] For ease of understanding, the following examples are given to illustrate.

[0071] For example, in a specific implementation, assuming that the content of the verifiable declaration includes data content 1, data content 2, data content 3, data content 4, and data content 5, a specific representation of the index corresponding to a certain data acquisition mechanism generated is as follows:

[0072] {Data content 1-0; Data content 2-1; Data content 3-0; Data content 4-0; Data content 5-0}

[0073] Among them, when the value corresponding to a certain data content is 0, it indicates that the data acquisition agency can obtain the data value of the data content. When the value corresponding to a certain data content is 1, it indicates that the data acquisition agency cannot obtain the data content and can only obtain the hash value corresponding to the data content.

[0074] Therefore, when the data acquisition agency obtains the declaration content data of the above-mentioned verifiable declaration, if the authority value corresponding to a certain data content is 0, then the declaration content data carries the data value of the data content; if the authority value corresponding to a certain data content is 1, then the declaration content data carries the hash value of the data content.

[0075] For example, in a specific implementation, a specific form of the defined index is as follows:

[0076]

[0077] Based on the above index, the content data of the verifiable statement shared with the data acquisition agency is as follows:

[0078]

[0079] Of course, this is just an illustrative description and does not constitute a limitation on the embodiments of this specification.

[0080] Optionally, after generating the access permission information corresponding to the data acquisition agency, the business server may directly upload the access permission information to the alliance blockchain system for storage, or send the access permission information to the authorization management server, and upload the access permission information to the alliance blockchain system for storage through the authorization management server.

[0081] The method provided in the embodiments of this specification can determine which data contents in the declared content data to share with each data acquisition agency by defining the access permission information corresponding to each data acquisition agency, thereby sharing different data contents with different data acquisition agencies, thereby ensuring the privacy of user behavior data.

[0082] Optionally, in a specific implementation, after executing the above step 108, that is, after uploading the declaration content data of the verifiable declaration to the alliance blockchain system, the method provided in the embodiment of this specification further includes the following process:

[0083] Receive an authorization request from a business service end to authorize a target data acquisition agency to access the declaration content data of a verifiable declaration; and grant the target data acquisition agency permission to access the declaration content data of the verifiable declaration according to the authorization request.

[0084] The authorization request contains the digital identity information of the target data acquisition agency, the identification information of the verifiable declaration, and the access permission information corresponding to the target data acquisition agency.

[0085] Optionally, each data acquisition agency may obtain its corresponding digital identity information in advance through the authorization management server. In specific implementation, each data acquisition agency may send its own relevant information to the authorization management server, and create its corresponding digital identity information through the authorization management server.

[0086] Specifically, after the operation of uploading the structured data corresponding to the target business is completed, the operation of granting the target data acquisition agency the permission information to access the declaration content data of the verifiable declaration is executed. In a specific implementation, after the operation of uploading the structured data is completed, a prompt message pops up on the current page of the business client asking whether to authorize the data acquisition agency to access the declaration content data of the verifiable declaration, and operation buttons such as "Yes", "No" or "Go to Authorization" and "Do not authorize for the time being" are displayed on the interface. If the user clicks the "Yes" or "Go to Authorization" operation button, the operation of granting the data acquisition agency the permission to access the declaration content data of the verifiable declaration is triggered.

[0087] In fact, in the specific implementation, when the user clicks the "Yes" or "Go to Authorization" operation button, it is equivalent to sending an instruction message to the business server to execute the authorization of the data acquisition agency to access the declaration content data of the verifiable declaration. Of course, if the user clicks the "Yes" or "Go to Authorization" operation button, a list of authorized data acquisition agencies will pop up on the current page. The user can select the data acquisition agency that needs to be authorized in the data acquisition agency list that pops up, and the data acquisition agency selected by the user will be used as the above-mentioned target data acquisition agency.

[0088] When the business service end receives the instruction sent by the client to execute the authorization for the target data acquisition agency to access the declaration content data of the verifiable declaration, it determines the access permission information corresponding to the target data acquisition agency, generates an authorization request based on the access permission information corresponding to the target data acquisition agency, the digital identity information of the target data acquisition agency and the identification information of the verifiable declaration that needs to be accessed, and sends the authorization request to the authorization management server end; after receiving the above authorization request sent by the business service end, the authorization management server end executes the authorization of the target data acquisition agency to access the declaration content data of the verifiable declaration based on the authorization request.

[0089] In addition, it should be noted that, in some other specific implementations, when the user performs the operation of authorizing the target data acquisition agency to access the declaration content data of the verifiable declaration, the user can directly send the corresponding authorization indication information to the authorization management server through the business client; that is, in a specific implementation, the authorization management server receives the indication information sent by the user to grant the target data acquisition agency the right to access the declaration content data of the verifiable declaration, wherein the indication information carries the digital identity information of the target data acquisition agency and the identification information of the verifiable declaration; the authorization management server determines the access permission information corresponding to the target data acquisition agency based on the digital identity information of the target data acquisition agency, and then executes the authorization of the target data acquisition agency to access the declaration content data of the verifiable declaration based on the digital identity information of the target data acquisition structure, the identification information of the verifiable declaration and the access permission information.

[0090] Optionally, in a specific implementation, the above-mentioned granting the target data acquisition agency the right to access the declaration content data of the verifiable declaration according to the authorization request specifically includes the following process:

[0091] The authorization request is sent to the alliance blockchain system so that the alliance blockchain system determines the transaction hash value corresponding to the authorization request; the transaction hash value is obtained from the alliance blockchain system, and the transaction hash value and the digital identity information of the target data acquisition agency are returned to the business service end accordingly.

[0092] Among them, the above transaction hash value can be used to obtain content data of the verifiable statement from the alliance blockchain.

[0093] Optionally, in a specific implementation, after obtaining the transaction hash value from the alliance blockchain system and returning the transaction hash value and the digital identity information of the target data acquisition agency to the business service end accordingly, the method provided in the embodiment of this specification further includes the following steps:

[0094] Receive a data query request sent by a target data acquisition agency for querying declaration content data of a verifiable declaration; wherein the data query request carries identification information of the verifiable declaration; determine the declaration content data of the verifiable declaration shared with the target data acquisition agency based on the access permission information corresponding to the target data acquisition agency and the identification information of the verifiable declaration, and send the declaration content data to the target data acquisition agency, so that the target data acquisition agency verifies the acquired declaration content data based on the transaction hash value.

[0095] Optionally, in a specific implementation, after the target data acquisition agency is authorized, the transaction hash value and the digital identity information of the target data acquisition agency are returned to the business service end, thereby completing the authorization operation for the target data acquisition agency.

[0096] Specifically, after completing the authorization operation on the target data acquisition agency, the business service end sends the identification information of the above-mentioned verifiable declaration and the transaction hash value to the target data acquisition agency.

[0097] When the target data acquisition agency needs to query the content data of the verifiable declaration, it sends a data query request to the authorization management server, wherein the data query request carries the identification information of the verifiable declaration and the digital identity information of the target data acquisition agency; the authorization management server determines the declaration content data that needs to be returned to the target data acquisition agency based on the data query request, and returns it to the target data acquisition agency; the target data acquisition agency verifies the acquired declaration content data based on the pre-acquired transaction hash value.

[0098] The data processing method based on blockchain provided in the embodiments of this specification has at least the following beneficial effects:

[0099] After obtaining the structured data of the target business, the authorization management server creates a verifiable declaration of the structured data corresponding to the digital identity information based on the digital identity information of the target user and the structured data; then uploads the declaration content data of the verifiable declaration to the alliance blockchain system, thereby realizing the storage of the declaration content data in the alliance blockchain, ensuring that the declaration content data will not be tampered with, that is, ensuring the security and authenticity of the declaration content data; in addition, in the embodiment of this specification, the data when the target user executes the target business is stored in the form of structured data, which can facilitate the subsequent positioning of abnormal data and the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition agency, it can be decided which data content in the declaration content data to share with the data acquisition agency, thereby realizing the sharing of different data content for different data acquisition agencies, thereby ensuring the privacy of user behavior data; by associating the operation behavior data with the page change data through time, the explainability of each operation behavior can be achieved.

[0100] Corresponding to the method provided in the above embodiment of this specification, based on the same idea, the embodiment of this specification also provides a data processing method based on blockchain, which is applied to the business service end. Figure 5 A second flow chart of a blockchain-based data processing method provided in an embodiment of this specification is as follows: Figure 5 Said method at least comprises the following steps:

[0101] Step 202: Obtain structured data of the target business.

[0102] Step 204: Generate access permission information for each data acquisition agency for the structured data.

[0103] Step 206: Send the structured data and access permission information to the authorization management server, so that the authorization management server uploads the structured data and access permission information to the alliance blockchain system.

[0104] Among them, in the embodiments of this specification, the above-mentioned structured data is stored in the alliance blockchain system using a Merkle tree.

[0105] Optionally, in a specific implementation, in the above step 202, obtaining structured data of the target user executing the target service specifically includes the following process:

[0106] Obtain the operation behavior data of the target user when executing the target business on the client, and obtain the page change data of the client when the target user executes the target business on the client; associate the operation behavior data with the page change data, and construct the above structured data according to the operation behavior granularity.

[0107] Specifically, the operation behavior data includes the operation time corresponding to each operation behavior, and the page change data includes the change time corresponding to each page change;

[0108] Accordingly, the above-mentioned associating the operation behavior data with the page change data specifically includes the following process:

[0109] For each operation behavior in the operation behavior data, determine the change time that is consistent with the operation time corresponding to the operation behavior; determine the page change corresponding to the change time that is consistent with the operation time as the page change associated with the operation behavior, and establish an association relationship between the operation behavior and the page change associated with it.

[0110] The specific process of obtaining the structured data of the target user executing the target service may refer to the aforementioned method embodiment, which will not be described in detail here.

[0111] Optionally, in a specific implementation, a specific form of the structured data of the target user executing the target service obtained is as follows: Figure 6 Of course, Figure 6 This is merely an illustrative description and does not constitute a limitation on the embodiments of this specification.

[0112] In addition, it should be noted that in the embodiments of the present specification, by associating user operation behavior data with page change data, the explainability of certain user operation behaviors can be achieved through page changes, which has lower management costs and retrieval costs compared to achieving explainability of user operation behaviors in the form of recorded videos.

[0113] Among them, the above Figure 5 The specific implementation process of each step in the illustrated embodiment can be referred to the aforementioned method embodiment, which will not be repeated here.

[0114] Optionally, in a specific implementation, the alliance blockchain system stores the declaration content data of the verifiable declaration corresponding to the above structured data, and the verifiable declaration is created by the authorization management server; accordingly, after executing the above step 206, that is, sending the structured data and access permission information to the authorization management server, the method provided in the embodiment of this specification further includes the following steps:

[0115] Receive indication information sent by a target user to authorize a target data acquisition agency to access the declaration content data of a verifiable declaration corresponding to the structured data; wherein the indication information carries the digital identity information of the target data acquisition agency and the identification information of the verifiable declaration; determine the access permission information of the target data acquisition agency for the verifiable declaration based on the digital identity information of the target data acquisition agency and the identification information of the verifiable declaration; generate an authorization request for requesting authorization for the target data acquisition agency to access the declaration content data of the verifiable declaration based on the digital identity information of the target data acquisition agency, the identification information of the verifiable declaration and the access permission information, and send the authorization request to the authorization management server so that the authorization management server executes the operation of granting the target data acquisition agency permission to access the content data of the verifiable declaration.

[0116] Among them, the specific implementation process of each of the above steps can be referred to the aforementioned method embodiment, which will not be repeated here.

[0117] To facilitate understanding of the method provided in the embodiment of this specification, the method provided in the embodiment of this specification will be introduced below in the form of interaction between the business server and the authorization management server. Figure 7 A third flow chart of a data processing method based on blockchain provided in an embodiment of this specification is as follows: Figure 7 As shown, the method comprises at least the following steps:

[0118] Step 302: The business service end obtains the operation behavior data of the target user when executing the target business, and obtains the page change data of the client when the target user executes the target business.

[0119] Step 304, associate the above operation behavior data with the page change data, and construct structured data according to the operation behavior granularity.

[0120] Step 306: Generate access permission information for each data acquisition agency for the structure.

[0121] Step 308: Send the structured data, access permission information, and user information of the target user to the authorization management server.

[0122] Step 310: The authorization management server obtains the digital identity information of the target user based on the user information of the target user.

[0123] In step 312, the authorization management server uploads the digital identity information and structured data to the digital identity blockchain system, so that the digital identity blockchain system creates a verifiable statement of the structured data corresponding to the digital identity information.

[0124] Step 314, the authorization management server obtains the identification information and statement content data of the verifiable statement returned by the digital identity blockchain system.

[0125] In step 316, the authorization management server uploads the declaration content data and access permission information of the verifiable declaration to the alliance blockchain system, so that the alliance blockchain system stores the access permission information and constructs a Merkle tree corresponding to the declaration content data.

[0126] Optionally, in a specific implementation, the data processing method based on blockchain provided in the embodiment of this specification may involve a business service end, an authorization management service end, a DID blockchain system, a consortium blockchain system, and a data acquisition agency when executed; therefore, the interactive flow chart of the data processing method based on blockchain provided in the embodiment of this specification is as follows: Figure 8 As shown, it at least includes the data chain stage, the authorization stage and the data verification stage, which specifically include the following steps:

[0127] Data on-chain stage:

[0128] Step 402: The business server obtains the target user's operation behavior data for executing the target business and the page change data of the business client.

[0129] In step 404, the business server associates the operation behavior data with the page change data, and constructs structured data based on the associated data.

[0130] Step 406: The business service end generates access permission information for each data acquisition agency for the structured data.

[0131] Step 408: The business server sends the structured data, access permission information, and user information of the target user to the authorization management server.

[0132] Step 410: The authorization management server obtains the digital identity information of the target user based on the user information.

[0133] Step 412: The authorization management server sends the target user's digital identity information and structured data to the DID blockchain system.

[0134] In step 414, the DID blockchain system creates a verifiable statement of structured data corresponding to the target user's digital identity information.

[0135] In step 416, the DID blockchain returns the identification information and statement content data of the created verifiable statement to the authorization management server.

[0136] In step 418, the authorization management server uploads the declaration content data and access permission information of the verifiable declaration to the alliance blockchain system.

[0137] Step 420: The consortium blockchain system stores the access permission information and constructs a Merkle tree corresponding to the declaration content data.

[0138] Authorization phase:

[0139] Step 422, the business service end receives the instruction information triggered by the target user to authorize the target data acquisition agency to access the declaration content data of the above-mentioned verifiable declaration.

[0140] The above instruction information carries the digital identity information of the target data acquisition agency and the identification information of the verifiable declaration.

[0141] Step 424 , the business service end determines the target data acquisition agency's access permission information for the declaration content data of the verifiable declaration based on the digital identity information of the target data acquisition agency and the identification information of the verifiable declaration.

[0142] Step 426: The business service end generates an authorization request for requesting authorization for the target data acquisition agency to access the declaration content data of the verifiable declaration based on the digital identity information of the target data acquisition agency, the identification information of the verifiable declaration, and the access permission information.

[0143] Step 428: The business server sends the authorization request to the authorization management server.

[0144] Step 430: The authorization management server sends the authorization request to the alliance blockchain system.

[0145] Step 432: The alliance blockchain system determines the transaction hash value corresponding to the target data acquisition agency based on the authorization request.

[0146] In step 434, the authorization management server obtains the transaction hash value and the digital identity information of the target data acquisition agency from the alliance blockchain system.

[0147] Step 436: The authorization management server sends the transaction hash value and the identification information of the verifiable declaration to the business server.

[0148] Data verification stage:

[0149] Step 438: The authorization management server receives a data query request sent by the target data organization for querying the declaration content data of the verifiable declaration.

[0150] The above data query request carries the identification information of the verifiable declaration and the digital identity information of the target data acquisition agency.

[0151] Step 440: The authorization management server determines the declaration content data to be shared with the target data acquisition agency.

[0152] Step 442: the authorization management server sends the declaration content data to the target data acquisition agency.

[0153] In step 444, the target data acquisition agency verifies the acquired declaration content data through the alliance blockchain system based on the transaction hash value.

[0154] The blockchain-based data processing method provided in the embodiments of this specification has at least the following beneficial effects: obtaining structured data of the target user when executing the target business and uploading the structured data to the alliance blockchain system for storage, thereby realizing the storage of the structured data in the alliance blockchain, ensuring that the structured data will not be tampered with, that is, ensuring the security and authenticity of the structured data; in addition, in the embodiments of this specification, the data when the target user executes the target business is stored in the form of structured data, which can facilitate the subsequent positioning of abnormal data and the construction of a Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition agency, it can be decided which data content in the declared content data to share with the data acquisition agency, thereby realizing the sharing of different data content for different data acquisition agencies, thereby ensuring the privacy of user behavior data; by associating the operation behavior data with the page change data through time, the explainability of each operation behavior can be achieved.

[0155] Corresponding to this manual Figure 3 The method provided in the embodiment is based on the same idea. The embodiment of this specification also provides a data processing device based on blockchain for executing the method of this specification. Figure 3 The method provided by the illustrated embodiment, Fig. 9 The first module composition diagram of the blockchain-based data processing device provided in the embodiment of this specification is as follows: Fig. 9 As shown, the device at least includes:

[0156] The first receiving module 502 is used to receive structured data of a target service and user information of a target user sent by a service server;

[0157] An acquisition module 504 is used to acquire the digital identity information of the target user based on the user information;

[0158] A creation module 506, configured to create a verifiable statement of the structured data corresponding to the digital identity information based on the digital identity information and the structured data;

[0159] The first uploading module 508 is used to upload the declaration content data of the verifiable declaration to the alliance blockchain system.

[0160] Among them, the device provided in the embodiments of this specification can realize Figure 3 All the steps of the method provided by the illustrated embodiment will not be repeated here.

[0161] The blockchain-based data processing device provided in the embodiment of the present specification has at least the following beneficial effects: after obtaining the structured data of the target user when executing the target business, the authorization management service end creates a verifiable declaration of the structured data corresponding to the digital identity information based on the digital identity information of the target user and the structured data; then the declaration content data of the verifiable declaration is uploaded to the alliance blockchain system, thereby realizing the storage of the declaration content data in the alliance blockchain, ensuring that the declaration content data will not be tampered with, that is, ensuring the security and authenticity of the declaration content data; in addition, in the embodiment of the present specification, the data when the target user executes the target business is stored in the form of structured data, which can facilitate the subsequent positioning of abnormal data and the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition agency, it can be determined which data content in the declaration content data is shared with the data acquisition agency, thereby realizing the sharing of different data content for different data acquisition agencies, thereby ensuring the privacy of user behavior data; the operation behavior data and the page change data are associated through time, so that the interpretability of each operation behavior can be achieved.

[0162] Corresponding to this manual Figure 5 The method provided in the embodiment is based on the same idea. The embodiment of this specification also provides a data processing device based on blockchain for executing the method of this specification. Figure 5 The method provided by the illustrated embodiment, Fig.10 A schematic diagram of the second module composition of the blockchain-based data processing device provided in the embodiment of this specification is as follows: Fig.10 As shown, the device at least includes:

[0163] An acquisition module 602 is used to acquire structured data of a target business;

[0164] A generating module 604, configured to generate access permission information for each data acquisition agency with respect to the structured data;

[0165] The sending module 606 is used to send the structured data and the access permission information to the authorization management server, so that the authorization management server uploads the structured data and the access permission information to the alliance blockchain system.

[0166] Among them, the device provided in the embodiments of this specification can realize Figure 5 All the steps of the method provided by the illustrated embodiment will not be repeated here.

[0167] The blockchain-based data processing device provided in the embodiments of this specification has at least the following beneficial effects: obtaining structured data of the target user when executing the target business and uploading the structured data to the alliance blockchain system for storage, thereby realizing the storage of the structured data in the alliance blockchain, ensuring that the structured data will not be tampered with, that is, ensuring the security and authenticity of the structured data; in addition, in the embodiments of this specification, the data when the target user executes the target business is stored in the form of structured data, which can facilitate the subsequent positioning of abnormal data and the construction of a Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition agency, it can be decided which data content in the declared content data to share with the data acquisition agency, thereby realizing the sharing of different data content for different data acquisition agencies, thereby ensuring the privacy of user behavior data; by associating the operation behavior data with the page change data through time, the explainability of each operation behavior can be achieved.

[0168] Furthermore, based on the above Figure 3 The method shown in this specification also provides a data processing device based on blockchain, such as Fig.11 shown.

[0169] The data processing device based on blockchain may have relatively large differences due to different configurations or performances, and may include one or more processors 701 and memory 702, and the memory 702 may store one or more storage applications or data. Among them, the memory 702 may be a short-term storage or a persistent storage. The application stored in the memory 702 may include one or more modules (not shown in the figure), and each module may include a series of computer executable instruction information in the data processing device based on blockchain. Furthermore, the processor 701 may be configured to communicate with the memory 702 to execute a series of computer executable instruction information in the memory 702 on the data processing device based on blockchain. The data processing device based on blockchain may also include one or more power supplies 703, one or more wired or wireless network interfaces 704, one or more input and output interfaces 705, one or more keyboards 706, etc.

[0170] In a specific embodiment, a blockchain-based data processing device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer executable instruction information in the blockchain-based data processing device, and the one or more programs are configured to be executed by one or more processors, including computer executable instruction information for performing the following:

[0171] Receive structured data of the target business and user information of the target user sent by the business server;

[0172] Acquire digital identity information of the target user based on the user information;

[0173] Creating, based on the digital identity information and the structured data, a verifiable statement of the structured data corresponding to the digital identity information;

[0174] The declaration content data of the verifiable declaration is uploaded to the alliance blockchain system.

[0175] Optionally, the blockchain-based data processing device provided in the embodiments of this specification can realize Figure 3 All the steps of the method provided by the illustrated embodiment will not be repeated here.

[0176] The blockchain-based data processing device provided in the embodiments of the present specification has at least the following beneficial effects: after obtaining the structured data of the target user when executing the target business, the authorization management server creates a verifiable declaration of the structured data corresponding to the digital identity information based on the digital identity information of the target user and the structured data; then the declaration content data of the verifiable declaration is uploaded to the alliance blockchain system, thereby realizing the storage of the declaration content data in the alliance blockchain, ensuring that the declaration content data will not be tampered with, that is, ensuring the security and authenticity of the declaration content data; in addition, in the embodiments of the present specification, the data when the target user executes the target business is stored in the form of structured data, which can facilitate the subsequent positioning of abnormal data and the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition agency, it can be determined which data content in the declaration content data is shared with the data acquisition agency, thereby realizing the sharing of different data content for different data acquisition agencies, thereby ensuring the privacy of user behavior data; the operation behavior data and the page change data are associated through time, so that the explainability of each operation behavior can be achieved.

[0177] Furthermore, based on the above Figure 5 The method shown in this specification also provides a data processing device based on blockchain, such as Fig.11 shown.

[0178] In a specific embodiment, a blockchain-based data processing device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer executable instruction information in the blockchain-based data processing device, and the one or more programs are configured to be executed by one or more processors, including computer executable instruction information for performing the following:

[0179] Obtain structured data of the target business;

[0180] Generate access permission information for each data acquisition agency for the structured data;

[0181] The structured data and the access permission information are sent to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system.

[0182] Optionally, the blockchain-based data processing device provided in the embodiments of this specification can realize Figure 5 All the steps of the method provided by the illustrated embodiment will not be repeated here.

[0183] The blockchain-based data processing device provided in the embodiments of this specification has at least the following technical effects: obtaining structured data of the target user when executing the target business and uploading the structured data to the alliance blockchain system for storage, thereby realizing the storage of the structured data in the alliance blockchain, ensuring that the structured data will not be tampered with, that is, ensuring the security and authenticity of the structured data; in addition, in the embodiments of this specification, the data when the target user executes the target business is stored in the form of structured data, which can facilitate the subsequent positioning of abnormal data and the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition agency, it can be decided which data content in the declared content data to share with the data acquisition agency, thereby realizing the sharing of different data content for different data acquisition agencies, thereby ensuring the privacy of user behavior data; by associating the operation behavior data with the page change data through time, the explainability of each operation behavior can be achieved.

[0184] Furthermore, based on the above Figure 3 The method shown in the specification also provides a storage medium for storing computer executable instruction information. In a specific embodiment, the storage medium can be a USB flash drive, an optical disk, a hard disk, etc. When the computer executable instruction information stored in the storage medium is executed by the processor, the following process can be implemented:

[0185] Receive structured data of the target business and user information of the target user sent by the business server;

[0186] Acquire digital identity information of the target user based on the user information;

[0187] Creating, based on the digital identity information and the structured data, a verifiable statement of the structured data corresponding to the digital identity information;

[0188] The declaration content data of the verifiable declaration is uploaded to the alliance blockchain system.

[0189] Optionally, the computer executable instruction information stored in the storage medium provided in the embodiments of this specification can be implemented when executed by the processor. Figure 3 All the steps of the method provided by the illustrated embodiment will not be repeated here.

[0190] The computer executable instruction information stored in the storage medium provided in the embodiment of the present specification has at least the following beneficial effects when executed by the processor: after obtaining the structured data of the target user when executing the target business, the authorization management server creates a verifiable declaration of the structured data corresponding to the digital identity information based on the digital identity information of the target user and the structured data; then uploads the declaration content data of the verifiable declaration to the alliance blockchain system, thereby realizing the storage of the declaration content data in the alliance blockchain, ensuring that the declaration content data will not be tampered with, that is, ensuring the security and authenticity of the declaration content data; in addition, in the embodiment of the present specification, the data when the target user executes the target business is stored in the form of structured data, which can facilitate the subsequent positioning of abnormal data and the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition agency, it can be determined which data content in the declaration content data is shared with the data acquisition agency, thereby realizing the sharing of different data content for different data acquisition agencies, thereby ensuring the privacy of user behavior data; the operation behavior data and the page change data are associated through time, so that the interpretability of each operation behavior can be achieved.

[0191] Furthermore, based on the above Figure 5 The method shown in the specification also provides a storage medium for storing computer executable instruction information. In a specific embodiment, the storage medium can be a USB flash drive, an optical disk, a hard disk, etc. When the computer executable instruction information stored in the storage medium is executed by the processor, the following process can be implemented:

[0192] Obtain structured data of the target business;

[0193] Generate access permission information for each data acquisition agency for the structured data;

[0194] The structured data and the access permission information are sent to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system.

[0195] Optionally, the computer executable instruction information stored in the storage medium provided in the embodiments of this specification can be implemented when executed by the processor. Figure 5 All the steps of the method provided by the illustrated embodiment will not be repeated here.

[0196] The computer executable instruction information stored in the storage medium provided in the embodiment of this specification has at least the following beneficial effects when executed by the processor: obtaining the structured data of the target user when executing the target business and uploading the structured data to the alliance blockchain system for storage, thereby realizing the storage of the structured data in the alliance blockchain, ensuring that the structured data will not be tampered with, that is, ensuring the security and authenticity of the structured data; in addition, in the embodiment of this specification, the data when the target user executes the target business is stored in the form of structured data, which can facilitate the subsequent positioning of abnormal data and the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition agency, it can be determined which data content in the declaration content data is shared with the data acquisition agency, thereby realizing the sharing of different data content for different data acquisition agencies, thereby ensuring the privacy of user behavior data; by associating the operation behavior data with the page change data through time, the explainability of each operation behavior can be achieved.

[0197] In the 1990s, improvements to a technology could be clearly distinguished as hardware improvements (for example, improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the method flow). However, with the development of technology, many improvements to the method flow today can be regarded as direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages ​​and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.

[0198] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.

[0199] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0200] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0201] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0202] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instruction information. These computer program instruction information can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instruction information executed by the processor of the computer or other programmable data processing device generates a method for implementing the process in the flowchart. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0203] These computer program instruction information can also be stored in a computer readable memory that can guide a computer or other programmable data processing device to work in a specific manner, so that the instruction information stored in the computer readable memory produces a manufactured product including an instruction information device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0204] These computer program instruction information can also be loaded into a computer or other programmable data processing device so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instruction information executed on the computer or other programmable device for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0205] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0206] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0207] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instruction information, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0208] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0209] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0210] The present application may be described in the general context of computer-executable instruction information executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0211] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0212] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A data processing method based on blockchain, the method comprising: Receive structured data of the target business and user information of the target user sent by the business server; Acquire digital identity information of the target user based on the user information; Creating, based on the digital identity information and the structured data, a verifiable statement of the structured data corresponding to the digital identity information; The declaration content data of the verifiable declaration is uploaded to the alliance blockchain system; the alliance blockchain system stores the declaration content data of the verifiable declaration in the form of a Merkle tree to grant different degrees of verification to data with different privacy levels; the declaration content data includes multiple pieces of operation behavior data, and each piece of the operation behavior data is represented in a structured form; Receiving access permission information of the data acquisition agency for the declaration content data sent by the business service end; different data acquisition agencies correspondingly open different declaration content data; The access permission information is uploaded to the consortium blockchain system.

2. The method according to claim 1, after uploading the content data of the verifiable statement to the alliance blockchain system, the method further comprises: Receive an authorization request sent by the business service end to authorize a target data acquisition agency to access the declaration content data of the verifiable declaration; wherein the authorization request carries the digital identity information of the target data acquisition agency, the identification information of the verifiable declaration, and the access permission information corresponding to the target data acquisition agency; Granting the target data acquisition agency permission to access the statement content data of the verifiable statement is performed according to the authorization request.

3. The method according to claim 2, wherein the step of granting the target data acquisition agency the right to access the statement content data of the verifiable statement according to the authorization request comprises: Sending the authorization request to the alliance blockchain system so that the alliance blockchain system determines a transaction hash value corresponding to the authorization request; The transaction hash value is obtained from the alliance blockchain system, and the transaction hash value and the digital identity information of the target data acquisition agency are returned to the business service end accordingly.

4. The method according to claim 3, after obtaining the transaction hash value from the alliance blockchain system and returning the transaction hash value and the digital identity information of the target data acquisition agency to the business service end in correspondence, the method further comprises: Receiving a data query request sent by the target data acquisition agency for querying the declaration content data of the verifiable declaration; wherein the data query request carries the identification information of the verifiable declaration and the digital identity information of the target data acquisition agency; The declaration content data of the verifiable declaration shared with the target data acquisition agency is determined based on the access permission information corresponding to the target data acquisition agency and the identification information of the verifiable declaration, and the declaration content data is sent to the target data acquisition agency so that the target data acquisition agency verifies the acquired declaration content data based on the transaction hash value.

5. The method of claim 1, wherein creating a verifiable statement of the structured data corresponding to the digital identity information based on the digital identity information and the structured data comprises: Uploading the digital identity information of the target user and the structured data to a digital identity blockchain system, and creating the verifiable claim based on the digital identity information of the target user and the structured data through the digital identity blockchain system; Receive identification information of the verifiable statement and content data of the verifiable statement returned by the digital identity blockchain system.

6. A data processing method based on blockchain, the method comprising: Obtain structured data of the target business; Generate access rights information for each data acquisition organization; Different data acquisition agencies open different declaration content data accordingly; The structured data and the access permission information are sent to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system; the consortium blockchain system stores the declaration content data of a verifiable declaration corresponding to the structured data, and the verifiable declaration is created by the authorization management server; the consortium blockchain system stores the declaration content data of the verifiable declaration in the form of a Merkle tree to grant different degrees of signature verification to data of different privacy levels; the declaration content data includes multiple pieces of operation behavior data, and each piece of the operation behavior data is represented in a structured form.

7. The method according to claim 6, after sending the structured data and the access permission information to the authorization management server, the method further comprises: Receiving instruction information sent by a target user to authorize a target data acquisition agency to access the declaration content data of the verifiable declaration corresponding to the structured data; wherein the instruction information carries the digital identity information of the target data acquisition agency and the identification information of the verifiable declaration; Determining access permission information of the target data acquisition institution for the verifiable statement according to the digital identity information of the target data acquisition institution and the identification information of the verifiable statement; Based on the digital identity information of the target data acquisition agency, the identification information of the verifiable declaration and the access permission information, an authorization request is generated for requesting authorization for the target data acquisition agency to access the declared content data of the verifiable declaration, and the authorization request is sent to the authorization management server so that the authorization management server executes the operation of granting the target data acquisition agency permission to access the content data of the verifiable declaration.

8. The method according to claim 6, wherein obtaining structured data of the target business comprises: Acquire operation behavior data of a target user when executing the target service on a client, and acquire page change data of the client when the target user executes the target service on the client; The operation behavior data is associated with the page change data, and the structured data is constructed according to the operation behavior granularity.

9. The method according to claim 8, wherein the operation behavior data includes the operation time corresponding to each operation behavior, and the page change data includes the change time corresponding to each page change; The associating the operation behavior data with the page change data includes: For each operation behavior in the operation behavior data, determining a change time that is consistent with the operation time corresponding to the operation behavior; The page change corresponding to the change time consistent with the operation time is determined as the page change associated with the operation behavior, and an association relationship between the operation behavior and the associated page change is established.

10. A data processing device based on blockchain, the device comprising: A first receiving module receives structured data of a target service and user information of a target user sent by a service server; An acquisition module, for acquiring digital identity information of the target user based on the user information; A creation module, which creates a verifiable statement of the structured data corresponding to the digital identity information based on the digital identity information and the structured data; The first uploading module uploads the declaration content data of the verifiable declaration to the alliance blockchain system; the alliance blockchain system stores the declaration content data of the verifiable declaration in the form of a Merkle tree to grant different degrees of signature verification to data with different privacy levels; the declaration content data includes multiple operation behavior data, and each operation behavior data is represented in a structured form; A second receiving module receives access permission information of a data acquisition agency for the declaration content data sent by the business service end; different data acquisition agencies are correspondingly open to different declaration content data; The second uploading module uploads the access permission information to the alliance blockchain system.

11. The apparatus of claim 10, further comprising: A third receiving module receives an authorization request sent by the business service end to authorize a target data acquisition agency to access the declaration content data of the verifiable declaration; wherein the authorization request carries the digital identity information of the target data acquisition agency, the identification information of the verifiable declaration, and the access permission information corresponding to the target data acquisition agency; An execution module is configured to grant the target data acquisition agency the authority to access the declaration content data of the verifiable declaration according to the authorization request.

12. The apparatus according to claim 11, wherein the execution module comprises: A first sending unit sends the authorization request to the alliance blockchain system, so that the alliance blockchain system determines a transaction hash value corresponding to the authorization request; An acquisition unit, which acquires the transaction hash value from the alliance blockchain system; The second sending unit returns the transaction hash value and the digital identity information of the target data acquisition organization to the business service end accordingly.

13. The apparatus of claim 12, further comprising: A fourth receiving module receives a data query request sent by the target data acquisition agency for querying the declaration content data of the verifiable declaration; wherein the data query request carries the identification information of the verifiable declaration and the digital identity information of the target data acquisition agency; A determination module determines the declaration content data of the verifiable declaration shared with the target data acquisition agency based on the access permission information corresponding to the target data acquisition agency and the identification information of the verifiable declaration, and sends the declaration content data to the target data acquisition agency, so that the target data acquisition agency verifies the acquired declaration content data based on the transaction hash value.

14. A data processing device based on blockchain, the device comprising: Acquisition module, to obtain structured data of target business; A generation module generates access permission information for each data acquisition agency; Different data acquisition agencies open different declaration content data accordingly; A sending module sends the structured data and the access permission information to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system; the consortium blockchain system stores the declaration content data of a verifiable declaration corresponding to the structured data, and the verifiable declaration is created by the authorization management server; the consortium blockchain system stores the declaration content data of the verifiable declaration in the form of a Merkle tree to grant different degrees of verification to data of different privacy levels; the declaration content data includes multiple pieces of operation behavior data, and each piece of the operation behavior data is represented in a structured form.

15. The apparatus of claim 14, further comprising: A receiving module receives instruction information sent by a target user to authorize a target data acquisition agency to access the declaration content data of the verifiable declaration corresponding to the structured data; wherein the instruction information carries the digital identity information of the target data acquisition agency and the identification information of the verifiable declaration; A determination module, which determines access permission information of the target data acquisition institution for the verifiable statement based on the digital identity information of the target data acquisition institution and the identification information of the verifiable statement; A generating module, which generates an authorization request for requesting authorization for the target data acquisition institution to access the declaration content data of the verifiable declaration based on the digital identity information of the target data acquisition institution, the identification information of the verifiable declaration, and the access permission information; The sending module sends the authorization request to the authorization management server, so that the authorization management server executes the operation of granting the target data acquisition agency the right to access the content data of the verifiable declaration.

16. The device according to claim 14, wherein the acquisition module comprises: An acquisition unit, which acquires operation behavior data of a target user when executing the target service on a client, and acquires page change data of the client when the target user executes the target service on the client; The construction unit associates the operation behavior data with the page change data, and constructs the structured data according to the operation behavior granularity.

17. A data processing device based on blockchain, comprising: processor; as well as a memory arranged to store computer executable instructions which, when executed, cause the processor to: Receive structured data of the target business and user information of the target user sent by the business server; Acquire digital identity information of the target user based on the user information; Creating, based on the digital identity information and the structured data, a verifiable statement of the structured data corresponding to the digital identity information; The declaration content data of the verifiable declaration is uploaded to the alliance blockchain system; the alliance blockchain system stores the declaration content data of the verifiable declaration in the form of a Merkle tree to grant different degrees of verification to data with different privacy levels; the declaration content data includes multiple pieces of operation behavior data, and each piece of the operation behavior data is represented in a structured form; Receiving access permission information of the data acquisition agency for the declaration content data sent by the business service end; different data acquisition agencies correspondingly open different declaration content data; The access permission information is uploaded to the consortium blockchain system.

18. A data processing device based on blockchain, comprising: processor; as well as a memory arranged to store computer executable instructions which, when executed, cause the processor to: Obtain structured data of the target business; Generate access permission information for each data acquisition agency; different data acquisition agencies correspondingly open different declaration content data; The structured data and the access permission information are sent to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system; the consortium blockchain system stores the declaration content data of a verifiable declaration corresponding to the structured data, and the verifiable declaration is created by the authorization management server; the consortium blockchain system stores the declaration content data of the verifiable declaration in the form of a Merkle tree to grant different degrees of signature verification to data of different privacy levels; the declaration content data includes multiple pieces of operation behavior data, and each piece of the operation behavior data is represented in a structured form.

19. A storage medium for storing computer executable instructions, wherein the executable instructions implement the following process when executed: Receive structured data of the target business and user information of the target user sent by the business server; Acquire digital identity information of the target user based on the user information; Creating, based on the digital identity information and the structured data, a verifiable statement of the structured data corresponding to the digital identity information; The declaration content data of the verifiable declaration is uploaded to the alliance blockchain system; the alliance blockchain system stores the declaration content data of the verifiable declaration in the form of a Merkle tree to grant different degrees of verification to data with different privacy levels; the declaration content data includes multiple pieces of operation behavior data, and each piece of the operation behavior data is represented in a structured form; Receiving access permission information of the data acquisition agency for the declaration content data sent by the business service end; different data acquisition agencies correspondingly open different declaration content data; The access permission information is uploaded to the consortium blockchain system.

20. A storage medium for storing computer executable instructions, wherein the executable instructions implement the following process when executed: Obtain structured data of the target business; Generate access permission information for each data acquisition agency; different data acquisition agencies correspondingly open different declaration content data; The structured data and the access permission information are sent to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system; the consortium blockchain system stores the declaration content data of a verifiable declaration corresponding to the structured data, and the verifiable declaration is created by the authorization management server; the consortium blockchain system stores the declaration content data of the verifiable declaration in the form of a Merkle tree to grant different degrees of signature verification to data of different privacy levels; the declaration content data includes multiple pieces of operation behavior data, and each piece of the operation behavior data is represented in a structured form.

Citation Information

Patent Citations

  • Business behavior backtracking processing method, device, equipment and system

    CN111539813A