Data asset processing method, device and system

By establishing off-chain accounts in a trusted environment and using a signature server for signing, the problem of data asset processing in off-chain payment scenarios is solved, achieving highly reliable data asset processing and broadening the application scenarios of data assets.

CN113095819BActive Publication Date: 2026-04-17BEIJING QIHOOD TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING QIHOOD TECHNOLOGY CO LTD
Filing Date
2020-01-08
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing technologies cannot effectively support the processing of data assets in off-chain payment scenarios, resulting in limited use of data assets.

Method used

In a trusted environment, an off-chain account is established, a private key is generated, and the off-chain account is signed by a signature server. The data asset is then processed by combining the private key and the account signature.

Benefits of technology

It enables highly reliable off-chain data asset processing, ensuring the security of every data asset transaction and expanding the application scenarios for data assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113095819B_ABST
    Figure CN113095819B_ABST
Patent Text Reader

Abstract

The application discloses a data asset processing method, device and system. The method comprises the following steps: establishing an off-chain account in a trusted environment, generating a private key of the off-chain account; requesting a signature server to sign the established off-chain account, saving the account signature returned by the signature server in the trusted environment; and performing data asset processing according to the private key and the account signature. The technical scheme has the beneficial effect of realizing a high-reliability off-chain data asset processing scheme, ensuring the security of each data asset processing through the setting of the signature server and the off-chain account and the use of the private key and the account signature, and greatly widening the use scenarios of the data assets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of blockchain technology, and more specifically to data asset processing methods, apparatus and systems. Background Technology

[0002] One of the most widespread applications of blockchain technology is the storage and trading of data assets. However, current technologies often only support operations on data assets on the blockchain, while there are many scenarios in people's lives where they hope to use off-chain payments, presenting new challenges. Summary of the Invention

[0003] In view of the above problems, the present invention is proposed to provide a data asset processing method, apparatus and system that overcomes or at least partially solves the above problems.

[0004] According to one aspect of the present invention, a data asset processing method is provided, comprising:

[0005] Establish an off-chain account in a trusted environment and generate the private key for the off-chain account;

[0006] The signature server is requested to sign the established off-chain account, and the account signature returned by the signature server is stored in the trusted environment.

[0007] Data assets are processed based on the private key and the account signature.

[0008] Optionally, the method further includes binding the established off-chain account to the on-chain account.

[0009] Optionally, the method further includes: after learning of the data asset staking task initiated by the on-chain account, performing simple payment verification on the data asset staking task;

[0010] After the simple payment verification is passed, a staking signature request is generated based on the identifier of the data asset staking task and the identifier of the off-chain account. The staking signature request is sent to the signature server, and the staking signature returned by the signature server is received.

[0011] The corresponding data assets are added to the off-chain account based on the pledge signature.

[0012] Optionally, the data asset processing based on the private key and the account signature includes:

[0013] A transaction signature is generated using the private key and the asset to be traded;

[0014] A data asset transaction request is generated based on the account signature and the transaction signature;

[0015] The data asset transaction request is sent to the transaction recipient in a trusted environment.

[0016] Optionally, the data asset processing based on the private key and the account signature includes:

[0017] Upon receiving a data asset transaction request from a transaction sender in a trusted environment, security verification is performed based on the account signature and transaction signature carried in the data asset transaction request.

[0018] Optionally, the data asset processing based on the private key and the account signature includes:

[0019] Generate a withdrawal signature using the private key and the assets to be withdrawn;

[0020] Initiate an on-chain withdrawal request based on the account signature of the off-chain account and the withdrawal signature;

[0021] The assets to be withdrawn are frozen in the off-chain account.

[0022] Optionally, the data asset processing based on the private key and the account signature further includes:

[0023] If no successful withdrawal message is received from the blockchain before the withdrawal validity period expires, the frozen assets awaiting withdrawal will be unfrozen.

[0024] Optionally, the data asset processing based on the private key and the account signature includes:

[0025] The number of times each type of data asset is processed is counted in the off-chain account, and the corresponding number of times is carried out when the corresponding data asset is processed.

[0026] According to another aspect of the present invention, a data asset processing apparatus is provided, comprising:

[0027] An off-chain account unit is suitable for establishing off-chain accounts in a trusted environment and generating the private key of the off-chain account;

[0028] An account signing unit is adapted to request a signing server to sign an established off-chain account and to store the account signature returned by the signing server in the trusted environment.

[0029] A data asset processing unit is adapted to process data assets based on the private key and the account signature.

[0030] Optionally, the off-chain account unit is also adapted to bind the established off-chain account to the on-chain account.

[0031] Optionally, the data asset processing unit is further adapted to perform simple payment verification on the data asset staking task after learning of the data asset staking task initiated by the on-chain account; after the simple payment verification is passed, generate a staking signature request based on the identifier of the data asset staking task and the identifier of the off-chain account, send the staking signature request to the signature server, receive the staking signature returned by the signature server, and add the corresponding data asset to the off-chain account according to the staking signature.

[0032] Optionally, the data asset processing unit is adapted to generate a transaction signature using the private key and the asset to be traded; generate a data asset transaction request based on the account signature and the transaction signature; and send the data asset transaction request to a transaction recipient in a trusted environment.

[0033] Optionally, the data asset processing unit is adapted to perform security verification based on the account signature and transaction signature carried in the data asset transaction request after receiving a data asset transaction request sent by a transaction sender in a trusted environment.

[0034] Optionally, the data asset processing unit is adapted to generate a withdrawal signature using the private key and the asset to be withdrawn; initiate an on-chain withdrawal request based on the account signature of the off-chain account and the withdrawal signature; and freeze the asset to be withdrawn in the off-chain account.

[0035] Optionally, the data asset processing unit is adapted to unfreeze the frozen assets to be withdrawn if it does not receive a withdrawal success message sent off-chain before the withdrawal validity period.

[0036] Optionally, the data asset processing unit is adapted to count the number of times each type of data asset is processed in the off-chain account, and to carry the corresponding number of times identifier when performing the corresponding data asset processing.

[0037] According to another aspect of the present invention, a data asset processing system is provided, comprising: a signature server and one or more data asset processing devices as described in any of the preceding claims;

[0038] The signature server includes:

[0039] The signature request receiving unit is adapted to receive account signature requests sent by the data asset processing device;

[0040] The signing unit is adapted to perform an account signature on the off-chain account identifier in the account signature request and return it to the data asset processing device if the off-chain account identifier has not been signed before, so that the data asset processing device can perform data asset processing based on the off-chain account's private key and the account signature.

[0041] Optionally, the signature request receiving unit is also adapted to receive a staking signature request sent by the data asset processing device, wherein the staking signature request includes an identifier of the data asset staking task and an identifier of the off-chain account.

[0042] The signing unit is adapted to perform a pledge signature on the identifier of the data asset staking task and return it to the data asset processing device if the identifier of the data asset staking task has not been signed and the identifier of the off-chain account has been signed.

[0043] Optionally, the pledge signature request may also include the destination address of the pledged asset; the signature unit is further adapted to determine whether the destination address in the pledge signature request matches the address of the pledge contract on the blockchain, and if they do not match, refuse to pledge the identifier of the data asset pledge task.

[0044] According to another aspect of the present invention, an electronic device is provided, comprising: a processor; and a memory arranged to store computer-executable instructions, which, when executed, cause the processor to perform any of the methods described above.

[0045] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores one or more programs that, when executed by a processor, implement any of the methods described above.

[0046] As described above, the technical solution of this invention establishes an off-chain account in a trusted environment, generates a private key for the off-chain account, requests a signature server to sign the established off-chain account, stores the account signature returned by the signature server in the trusted environment, and processes data assets based on the private key and the account signature. The beneficial effect of this technical solution is that it achieves a highly reliable off-chain data asset processing scheme. Through the setup of the signature server and off-chain account, and the use of the private key and account signature, it ensures the security of every data asset processing transaction, greatly expanding the application scenarios of data assets.

[0047] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description

[0048] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0049] Figure 1 A flowchart illustrating a data asset processing method according to an embodiment of the present invention is shown.

[0050] Figure 2 A schematic diagram of the structure of a data asset processing apparatus according to an embodiment of the present invention is shown;

[0051] Figure 3 A schematic diagram of the structure of a data asset processing system according to an embodiment of the present invention is shown;

[0052] Figure 4 A schematic diagram of the structure of an electronic device according to an embodiment of the present invention is shown;

[0053] Figure 5 A schematic diagram of the structure of a computer-readable storage medium according to an embodiment of the present invention is shown. Detailed Implementation

[0054] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0055] The technical concept of this invention lies in establishing off-chain accounts through a trusted environment to ensure the security of off-chain data asset processing, and further providing security by providing signatures through a signature server. Specific embodiments are described below.

[0056] Figure 1 A flowchart illustrating a data asset processing method according to an embodiment of the present invention is shown. Figure 1 As shown, the method includes:

[0057] Step S110: Establish an off-chain account in a trusted environment and generate the private key for the off-chain account.

[0058] A Trusted Environment, also known as a Trusted Execution Environment, is typically a secure environment pre-set in chips, memory, etc., where corresponding programs are deployed, and the contents of this secure environment are protected from intrusion by the operating system, applications, etc. Data entering and leaving the Trusted Environment is encrypted to ensure high reliability.

[0059] The embodiments of this invention leverage the high reliability of a trusted environment. To prevent the misuse of on-chain account private keys, a new off-chain account is established within the trusted environment, and a dedicated private key is generated. Here, "on-chain" and "off-chain" are relative to the blockchain.

[0060] Step S120: Request the signature server to sign the established off-chain account and save the account signature returned by the signature server in a trusted environment.

[0061] The signature server can be understood as providing a persistent cloud-based signature service for uniqueness verification. For example, the signature server only signs an off-chain account's signature request for the first time, ensuring that the request originates from a pre-defined trusted environment. If an off-chain account sends multiple signature requests, it will not perform duplicate signing. Verification of data from a trusted environment is existing technology and will not be discussed in detail here.

[0062] Step S130: Process data assets based on the private key and account signature.

[0063] In this way, account signing can ensure that off-chain accounts are authenticated, while private keys can ensure the reliability of each data asset processing.

[0064] visible, Figure 1 The method shown implements a highly reliable off-chain data asset processing solution. By setting up a signature server and off-chain accounts, and using private keys and account signatures, the security of each data asset processing is ensured, greatly expanding the application scenarios of data assets.

[0065] In one embodiment of the present invention, the above method further includes binding the established off-chain account to the on-chain account.

[0066] After an off-chain account is created, it can be used, but it does not contain any data assets. If a user has data assets in their on-chain account, they can transfer those assets to the off-chain account through staking. Both on-chain and off-chain accounts can be identified by their respective identifiers, more specifically, by their account addresses. Therefore, it is simply a matter of binding the off-chain account address to the on-chain account address.

[0067] In one embodiment of the present invention, the method further includes: after learning of a data asset staking task initiated by an on-chain account, performing simple payment verification on the data asset staking task; after the simple payment verification is passed, generating a staking signature request based on the identifier of the data asset staking task and the identifier of the off-chain account, sending the staking signature request to the signature server, receiving the staking signature returned by the signature server, and adding the corresponding data asset to the off-chain account based on the staking signature.

[0068] Specifically, a staking contract can be deployed on the blockchain. When a user initiates a data asset staking task through their on-chain account (e.g., a staking request to a staking contract address), the linked off-chain account can detect this through eavesdropping. This allows the off-chain account to perform SPV (Simplified Payment Verification) on the data asset staking task. Upon successful verification, a staking signature request can be generated based on the identifier of the data asset staking task (e.g., the hash value of the transaction number) and the identifier of the off-chain account (e.g., the address), and then sent to the signature server. This step is to prevent an on-chain account from being linked to multiple off-chain accounts simultaneously.

[0069] Imagine an on-chain account as a user's total assets, while each off-chain account is like a wallet. Users can allocate their total assets across these wallets. For example, a user might have 100 cryptocurrencies, placing 40 in off-chain account A and 60 in off-chain account B, with a maximum total of 100. However, in this scenario, if off-chain accounts A and B both detect the same cryptocurrency staking task, without uniqueness verification, it's possible for both accounts to deposit 100 cryptocurrencies into their own accounts – a situation that obviously needs to be avoided.

[0070] Therefore, a signature server is needed to perform the staking signature. The signature server's job is to perform the staking signature only once for each staking. In this way, if off-chain account A sends a staking signature request first and signs it successfully, then if off-chain account B sends a staking signature request later, it will not receive a staking signature and will be unable to add the corresponding data assets to off-chain account B.

[0071] In one embodiment of the present invention, the above method of processing data assets based on private key and account signature includes: generating a transaction signature using private key and asset to be traded; generating a data asset transaction request based on account signature and transaction signature; and sending the data asset transaction request to a transaction recipient in a trusted environment.

[0072] In off-chain transactions between accounts, a signature server is no longer required, facilitating offline operations. For the initiator, a transaction signature needs to be generated using the private key and the asset to be traded. Then, a data asset transaction request is generated based on the account signature and the transaction signature. Essentially, the data asset transaction request needs to include both the account signature (security authentication of the account) and the transaction signature (security authentication of the transaction).

[0073] In one embodiment of the present invention, the data asset processing based on the private key and account signature in the above method includes: after receiving a data asset transaction request sent by a transaction sender in a trusted environment, performing security verification based on the account signature and transaction signature carried in the data asset transaction request. For the recipient of an off-chain account transaction, after receiving the data asset transaction request, it is necessary to perform security verification based on the account signature and transaction signature carried in the data asset transaction request.

[0074] In one embodiment of the present invention, the above method of processing data assets based on private key and account signature includes: generating a withdrawal signature using private key and assets to be withdrawn; initiating an on-chain withdrawal request based on the account signature and withdrawal signature of the off-chain account; and freezing the assets to be withdrawn in the off-chain account.

[0075] Off-chain accounts also allow for the withdrawal of data assets. It's important to note that this "cash" doesn't necessarily refer to physical currency; it can be asset information recorded in personal accounts at banks or financial institutions—essentially "cash" relative to the data asset itself. Withdrawals can generally only be initiated through off-chain accounts. To prevent "double-spending"—the same data asset being paid out twice—the assets to be withdrawn must be frozen in the off-chain account. This is because withdrawals take time; if the assets are not frozen during this period, it could lead to transactions between off-chain accounts using those same assets.

[0076] Of course, withdrawals may fail due to network or node failures. Therefore, in one embodiment of the present invention, the data asset processing based on the private key and account signature further includes: if a successful withdrawal message is not received from the blockchain before the withdrawal validity period, the frozen assets to be withdrawn are unfrozen. To ensure reliability, the withdrawal validity period can be determined based on the blockchain block height. For example, if the current block height is 100, the withdrawal must be completed before the blockchain height reaches 120; otherwise, the withdrawal will fail.

[0077] In one embodiment of the present invention, the above method of processing data assets based on private keys and account signatures includes: counting the number of times each type of data asset is processed in an off-chain account, and carrying the corresponding number of times identifier when performing corresponding data asset processing.

[0078] To prevent the misuse of signatures and private keys, the frequency of each type of data asset can be tracked in off-chain accounts. For example, if a user has previously initiated 6 withdrawal operations through an off-chain account, the on-chain withdrawal request will then include a count identifier indicating a current count of 7, preventing the same asset from being processed multiple times. This also effectively addresses the issue of resending the same request after a power outage on the terminal hosting the trusted environment resumes operation.

[0079] Figure 2 A schematic diagram of a data asset processing apparatus according to an embodiment of the present invention is shown. Figure 2 As shown, the data asset processing device 200 includes:

[0080] Off-chain account unit 210 is suitable for establishing off-chain accounts in a trusted environment and generating private keys for off-chain accounts.

[0081] A Trusted Environment, also known as a Trusted Execution Environment, is typically a secure environment pre-set in chips, memory, etc., where corresponding programs are deployed, and the contents of this secure environment are protected from intrusion by the operating system, applications, etc. Data entering and leaving the Trusted Environment is encrypted to ensure high reliability.

[0082] The embodiments of this invention leverage the high reliability of a trusted environment. To prevent the misuse of on-chain account private keys, a new off-chain account is established within the trusted environment, and a dedicated private key is generated. Here, "on-chain" and "off-chain" are relative to the blockchain.

[0083] Account signing unit 220 is adapted to request a signing server to sign the established off-chain account and to store the account signature returned by the signing server in a trusted environment.

[0084] The signature server can be understood as providing a persistent cloud-based signature service for uniqueness verification. For example, the signature server only signs an off-chain account's signature request for the first time, ensuring that the request originates from a pre-defined trusted environment. If an off-chain account sends multiple signature requests, it will not perform duplicate signing. Verification of data from a trusted environment is existing technology and will not be discussed in detail here.

[0085] Data asset processing unit 230 is adapted to process data assets based on private keys and account signatures.

[0086] In this way, account signing can ensure that off-chain accounts are authenticated, while private keys can ensure the reliability of each data asset processing.

[0087] visible, Figure 2 The device shown implements a highly reliable off-chain data asset processing solution. By setting up a signature server and off-chain accounts, and using private keys and account signatures, it ensures the security of every data asset processing transaction and greatly expands the application scenarios of data assets.

[0088] In one embodiment of the present invention, the off-chain account unit 210 in the above-described apparatus is further adapted to bind the established off-chain account to the on-chain account.

[0089] After an off-chain account is created, it can be used, but it does not contain any data assets. If a user has data assets in their on-chain account, they can transfer those assets to the off-chain account through staking. Both on-chain and off-chain accounts can be identified by their respective identifiers, more specifically, by their account addresses. Therefore, it is simply a matter of binding the off-chain account address to the on-chain account address.

[0090] In one embodiment of the present invention, the data asset processing unit 230 in the above-described apparatus is further adapted to perform simple payment verification on the data asset staking task after learning of the data asset staking task initiated by the on-chain account; after the simple payment verification is passed, a staking signature request is generated according to the identifier of the data asset staking task and the identifier of the off-chain account, the staking signature request is sent to the signature server, and the staking signature returned by the signature server is received; and the corresponding data asset is added to the off-chain account according to the staking signature.

[0091] Specifically, a staking contract can be deployed on the blockchain. When a user initiates a data asset staking task through their on-chain account (e.g., a staking request to a staking contract address), the linked off-chain account can detect this through eavesdropping. This allows the off-chain account to perform SPV (Simplified Payment Verification) on the data asset staking task. Upon successful verification, a staking signature request can be generated based on the identifier of the data asset staking task (e.g., the hash value of the transaction number) and the identifier of the off-chain account (e.g., the address), and then sent to the signature server. This step is to prevent an on-chain account from being linked to multiple off-chain accounts simultaneously.

[0092] Imagine an on-chain account as a user's total assets, while each off-chain account is like a wallet. Users can allocate their total assets across these wallets. For example, a user might have 100 cryptocurrencies, placing 40 in off-chain account A and 60 in off-chain account B, with a maximum total of 100. However, in this scenario, if off-chain accounts A and B both detect the same cryptocurrency staking task, without uniqueness verification, it's possible for both accounts to deposit 100 cryptocurrencies into their own accounts – a situation that obviously needs to be avoided.

[0093] Therefore, a signature server is needed to perform the staking signature. The signature server's job is to perform the staking signature only once for each staking. In this way, if off-chain account A sends a staking signature request first and signs it successfully, then if off-chain account B sends a staking signature request later, it will not receive a staking signature and will be unable to add the corresponding data assets to off-chain account B.

[0094] In one embodiment of the present invention, the data asset processing unit 230 in the above-described apparatus is adapted to generate a transaction signature using a private key and the asset to be traded; generate a data asset transaction request based on the account signature and the transaction signature; and send the data asset transaction request to a transaction recipient in a trusted environment.

[0095] In off-chain transactions between accounts, a signature server is no longer required, facilitating offline operations. For the initiator, a transaction signature needs to be generated using the private key and the asset to be traded. Then, a data asset transaction request is generated based on the account signature and the transaction signature. Essentially, the data asset transaction request needs to include both the account signature (security authentication of the account) and the transaction signature (security authentication of the transaction).

[0096] In one embodiment of the present invention, the data asset processing unit 230 in the above-described apparatus is adapted to perform security verification based on the account signature and transaction signature carried in the data asset transaction request after receiving a data asset transaction request sent by a transaction sender in a trusted environment. For the recipient of an off-chain account transaction, after receiving the data asset transaction request, it is necessary to perform security verification based on the account signature and transaction signature carried in the data asset transaction request.

[0097] In one embodiment of the present invention, the data asset processing unit 230 of the above-described apparatus is adapted to generate a withdrawal signature using a private key and the asset to be withdrawn; initiate an on-chain withdrawal request based on the account signature and withdrawal signature of the off-chain account; and freeze the asset to be withdrawn in the off-chain account.

[0098] Off-chain accounts also allow for the withdrawal of data assets. It's important to note that this "cash" doesn't necessarily refer to physical currency; it can be asset information recorded in personal accounts at banks or financial institutions—essentially "cash" relative to the data asset itself. Withdrawals can generally only be initiated through off-chain accounts. To prevent "double-spending"—the same data asset being paid out twice—the assets to be withdrawn must be frozen in the off-chain account. This is because withdrawals take time; if the assets are not frozen during this period, it could lead to transactions between off-chain accounts using those same assets.

[0099] Of course, withdrawals may fail due to network or node failures. Therefore, in one embodiment of the present invention, the data asset processing unit 230 in the above-described apparatus is adapted to unfreeze the frozen assets to be withdrawn if it does not receive a withdrawal success message sent off-chain before the withdrawal validity period. To ensure reliability, the withdrawal validity period can be determined based on the blockchain block height. For example, if the current block height is 100, the withdrawal must be completed before the blockchain height reaches 120; otherwise, the withdrawal will fail.

[0100] In one embodiment of the present invention, the data asset processing unit 230 in the above-described apparatus is adapted to count the number of times each type of data asset is processed in the off-chain account, and to carry the corresponding number of times identifier when performing the corresponding data asset processing.

[0101] To prevent the misuse of signatures and private keys, the frequency of each type of data asset can be tracked in off-chain accounts. For example, if a user has previously initiated 6 withdrawal operations through an off-chain account, the on-chain withdrawal request will then include a count identifier indicating a current count of 7, preventing the same asset from being processed multiple times. This also effectively addresses the issue of resending the same request after a power outage on the terminal hosting the trusted environment resumes operation.

[0102] Figure 3 A schematic diagram of the structure of a data asset processing system according to an embodiment of the present invention is shown. Figure 3 As shown, the data asset processing system 300 includes: a signature server 310, and one or more data asset processing devices 200 as described in any of the above embodiments;

[0103] The signature server 310 includes a signature request receiving unit 311, adapted to receive account signature requests sent by the data asset processing device.

[0104] The signature unit 312 is adapted to perform an account signature on the off-chain account identifier in the account signature request and return it to the data asset processing device if the identifier of the off-chain account has not been signed, so that the data asset processing device can perform data asset processing based on the private key of the off-chain account and the account signature.

[0105] The signature server can be implemented with multiple nodes and driven by the BFT (Byzantine Fault Tolerance) consensus algorithm to prevent single point of failure from causing loss of user data assets.

[0106] In one embodiment of the present invention, in the above system, the signature request receiving unit 311 is further adapted to receive a staking signature request sent by the data asset processing device. The staking signature request includes an identifier of the data asset staking task and an identifier of the off-chain account. The signature unit 312 is adapted to perform a staking signature on the identifier of the data asset staking task and return it to the data asset processing device if the identifier of the data asset staking task has not been signed and the identifier of the off-chain account has been signed. This is to ensure that a data asset staking task is signed only once, and that the source of the staking signature request must be an off-chain account that has already been signed in a trusted environment.

[0107] In one embodiment of the present invention, the pledge signature request in the above system further includes the destination address of the pledged asset. The signature unit 312 is also adapted to determine whether the destination address in the pledge signature request matches the address of the pledge contract on the blockchain. If they do not match, the pledge signature of the identifier of the data asset pledge task is rejected. In this way, the on-chain pledge contract, the signature server, and the data asset processing device in the trusted environment are organically integrated into a single system.

[0108] In summary, the technical solution of this invention establishes an off-chain account in a trusted environment, generates a private key for the off-chain account, requests a signature server to sign the established off-chain account, stores the account signature returned by the signature server in the trusted environment, and processes data assets based on the private key and account signature. The beneficial effects of this technical solution are that it achieves a highly reliable off-chain data asset processing scheme. Through the setting of the signature server, the off-chain account, and the use of the private key and account signature, the security of each data asset processing is ensured, greatly expanding the application scenarios of data assets. The signature server can be driven by the BFT consensus algorithm to avoid single points of failure and ensure the security of users' data assets; the settings of the trusted environment, off-chain account, withdrawal validity period, and withdrawal frequency identifier can effectively avoid problems caused by double-spending and withdrawal failures.

[0109] It should be noted that:

[0110] The algorithms and displays provided herein are not inherently related to any particular computer, virtual device, or other equipment. Various general-purpose devices can also be used in conjunction with the teachings herein. The required structure for constructing such devices is apparent from the above description. Furthermore, this invention is not directed to any particular programming language. It should be understood that the contents of the invention described herein can be implemented using various programming languages, and the above description of specific languages ​​is for the purpose of disclosing the best mode of implementation of the invention.

[0111] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of the invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0112] Similarly, it should be understood that, in order to simplify the invention and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the invention, various features of the invention are sometimes grouped together in a single embodiment, figure, or description thereof. However, this disclosure should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, inventive aspects lie in fewer than all features of a single foregoing disclosed embodiment. Therefore, the claims following the detailed description are hereby expressly incorporated into this detailed description, wherein each claim itself is a separate embodiment of the invention.

[0113] Those skilled in the art will understand that modules in the device of the embodiments can be adaptively changed and placed in one or more devices different from that embodiment. Modules, units, or components in the embodiments can be combined into a single module, unit, or component, and further, they can be divided into multiple sub-modules, sub-units, or sub-components. Except where at least some of such features and / or processes or units are mutually exclusive, any combination can be used to combine all features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all processes or units of any method or device so disclosed. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) may be replaced by an alternative feature that serves the same, equivalent, or similar purpose.

[0114] Furthermore, those skilled in the art will understand that although some embodiments described herein include certain features but not others included in other embodiments, combinations of features from different embodiments are intended to be within the scope of the invention and form different embodiments. For example, in the following claims, any of the claimed embodiments can be used in any combination.

[0115] The various component embodiments of the present invention can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components in the data asset processing apparatus and system according to embodiments of the present invention. The present invention can also be implemented as a device or apparatus program (e.g., a computer program and computer program product) for performing part or all of the methods described herein. Such programs implementing the present invention can be stored on a computer-readable medium or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.

[0116] For example, Figure 4 A schematic diagram of an electronic device according to an embodiment of the present invention is shown. The electronic device 400 includes a processor 410 and a memory 420 arranged to store computer-executable instructions (computer-readable program code). The memory 420 may be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. The memory 420 has a storage space 430 for storing computer-readable program code 431 for performing any of the method steps described above. For example, the storage space 430 for storing computer-readable program code may include various computer-readable program codes 431 respectively for implementing the various steps in the methods described above. The computer-readable program code 431 can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, CDs, memory cards, or floppy disks. Such computer program products are typically, for example... Figure 5 The aforementioned computer-readable storage medium. Figure 5A schematic diagram of a computer-readable storage medium according to an embodiment of the present invention is shown. The computer-readable storage medium 500 stores computer-readable program code 431 for performing the method steps according to the present invention, which can be read by the processor 410 of an electronic device 400. When the computer-readable program code 431 is executed by the electronic device 400, it causes the electronic device 400 to perform the various steps of the method described above. Specifically, the computer-readable program code 431 stored in the computer-readable storage medium can perform the methods shown in any of the above embodiments. The computer-readable program code 431 can be compressed in a suitable form.

[0117] It should be noted that the above embodiments are illustrative of the invention and not restrictive, and that those skilled in the art can devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The invention can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In the unit claims enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third, etc., does not indicate any order. These words can be interpreted as names.

[0118] Embodiments of the present invention disclose A1, a data asset processing method, comprising:

[0119] Establish an off-chain account in a trusted environment and generate the private key for the off-chain account;

[0120] The signature server is requested to sign the established off-chain account, and the account signature returned by the signature server is stored in the trusted environment.

[0121] Data assets are processed based on the private key and the account signature.

[0122] A2. The method as described in A1, wherein the method further includes:

[0123] The off-chain account is linked to the on-chain account.

[0124] A3. The method as described in A2, wherein the method further includes:

[0125] After learning of the data asset staking task initiated by the on-chain account, a simple payment verification is performed on the data asset staking task;

[0126] After the simple payment verification is passed, a staking signature request is generated based on the identifier of the data asset staking task and the identifier of the off-chain account. The staking signature request is sent to the signature server, and the staking signature returned by the signature server is received.

[0127] The corresponding data assets are added to the off-chain account based on the pledge signature.

[0128] A4. The method as described in A1, wherein the data asset processing based on the private key and the account signature includes:

[0129] A transaction signature is generated using the private key and the asset to be traded;

[0130] A data asset transaction request is generated based on the account signature and the transaction signature;

[0131] The data asset transaction request is sent to the transaction recipient in a trusted environment.

[0132] A5. The method as described in A1, wherein the data asset processing based on the private key and the account signature includes:

[0133] Upon receiving a data asset transaction request from a transaction sender in a trusted environment, security verification is performed based on the account signature and transaction signature carried in the data asset transaction request.

[0134] A6. The method as described in A1, wherein the data asset processing based on the private key and the account signature includes:

[0135] Generate a withdrawal signature using the private key and the assets to be withdrawn;

[0136] Initiate an on-chain withdrawal request based on the account signature of the off-chain account and the withdrawal signature;

[0137] The assets to be withdrawn are frozen in the off-chain account.

[0138] A7. The method described in A6, wherein the data asset processing based on the private key and the account signature further includes:

[0139] If no successful withdrawal message is received from the blockchain before the withdrawal validity period expires, the frozen assets awaiting withdrawal will be unfrozen.

[0140] A8. The method as described in any one of A1-A7, wherein the data asset processing based on the private key and the account signature includes:

[0141] The number of times each type of data asset is processed is counted in the off-chain account, and the corresponding number of times is carried out when the corresponding data asset is processed.

[0142] Embodiments of the present invention also disclose B9, a data asset processing apparatus, comprising:

[0143] An off-chain account unit is suitable for establishing off-chain accounts in a trusted environment and generating the private key of the off-chain account;

[0144] An account signing unit is adapted to request a signing server to sign an established off-chain account and to store the account signature returned by the signing server in the trusted environment.

[0145] A data asset processing unit is adapted to process data assets based on the private key and the account signature.

[0146] B10. The apparatus as described in B9, wherein...

[0147] The off-chain account unit is also suitable for binding the established off-chain account with the on-chain account.

[0148] B11. The apparatus as described in B10, wherein...

[0149] The data asset processing unit is further adapted to perform simple payment verification on the data asset staking task after learning of the data asset staking task initiated by the on-chain account; after the simple payment verification is passed, generate a staking signature request based on the identifier of the data asset staking task and the identifier of the off-chain account, send the staking signature request to the signature server, receive the staking signature returned by the signature server, and add the corresponding data asset to the off-chain account according to the staking signature.

[0150] B12. The apparatus as described in B9, wherein...

[0151] The data asset processing unit is adapted to generate a transaction signature using the private key and the asset to be traded; generate a data asset transaction request based on the account signature and the transaction signature; and send the data asset transaction request to a transaction recipient in a trusted environment.

[0152] B13. The apparatus as described in B9, wherein...

[0153] The data asset processing unit is adapted to perform security verification based on the account signature and transaction signature carried in the data asset transaction request after receiving a data asset transaction request sent by a transaction sender in a trusted environment.

[0154] B14. The apparatus as described in B9, wherein...

[0155] The data asset processing unit is adapted to generate a withdrawal signature using the private key and the asset to be withdrawn; initiate an on-chain withdrawal request based on the account signature of the off-chain account and the withdrawal signature; and freeze the asset to be withdrawn in the off-chain account.

[0156] B15. The apparatus as described in B14, wherein...

[0157] The data asset processing unit is adapted to unfreeze the frozen assets pending withdrawal if it does not receive a withdrawal success message sent off-chain before the withdrawal validity period.

[0158] B16. The apparatus as described in any one of B9-B15, wherein,

[0159] The data asset processing unit is adapted to count the number of times each type of data asset is processed in the off-chain account, and to carry the corresponding number of times when performing the corresponding data asset processing.

[0160] Embodiments of the present invention also disclose C17, a data asset processing system, comprising: a signature server and one or more data asset processing devices as described in any one of B9-B16;

[0161] The signature server includes:

[0162] The signature request receiving unit is adapted to receive account signature requests sent by the data asset processing device;

[0163] The signing unit is adapted to perform an account signature on the off-chain account identifier in the account signature request and return it to the data asset processing device if the off-chain account identifier has not been signed before, so that the data asset processing device can perform data asset processing based on the off-chain account's private key and the account signature.

[0164] C18. The system as described in C17, wherein...

[0165] The signature request receiving unit is also adapted to receive a staking signature request sent by the data asset processing device, wherein the staking signature request includes an identifier of the data asset staking task and an identifier of the off-chain account.

[0166] The signing unit is adapted to perform a pledge signature on the identifier of the data asset staking task and return it to the data asset processing device if the identifier of the data asset staking task has not been signed and the identifier of the off-chain account has been signed.

[0167] C19. The system as described in C18, wherein the pledge signature request also includes the destination address of the pledged assets;

[0168] The signature unit is also adapted to determine whether the destination address in the pledge signature request matches the address of the pledge contract on the blockchain. If they do not match, the signature unit refuses to pledge the identifier of the data asset staking task.

[0169] Embodiments of the present invention also disclose D20, an electronic device comprising: a processor; and a memory arranged to store computer-executable instructions, which, when executed, cause the processor to perform a method as described in any one of A1-A8.

[0170] Embodiments of the present invention also disclose E21, a computer-readable storage medium, wherein the computer-readable storage medium stores one or more programs, which, when executed by a processor, implement the method as described in any one of A1-A8.

Claims

1. A data asset processing method, comprising: Establish an off-chain account in a trusted environment and generate the private key for the off-chain account; The signature server is requested to sign the established off-chain account, and the account signature returned by the signature server is stored in the trusted environment. Bind the established off-chain account to the on-chain account; A staking contract is deployed on the blockchain. After learning of a data asset staking task initiated by the on-chain account, a simple payment verification is performed on the data asset staking task. The simple payment verification is used to verify whether the on-chain account is simultaneously bound to multiple off-chain accounts. After the simple payment verification is passed, a staking signature request is generated based on the identifier of the data asset staking task and the identifier of the off-chain account. The staking signature request is sent to the signature server, and the staking signature returned by the signature server is received. The corresponding data assets are added to the off-chain account based on the pledged signature; Data assets are processed based on the private key and the account signature.

2. The method of claim 1, wherein, The data asset processing based on the private key and the account signature includes: A transaction signature is generated using the private key and the asset to be traded; A data asset transaction request is generated based on the account signature and the transaction signature; The data asset transaction request is sent to the transaction recipient in a trusted environment.

3. The method of claim 1, wherein, The data asset processing based on the private key and the account signature includes: Upon receiving a data asset transaction request from a transaction sender in a trusted environment, security verification is performed based on the account signature and transaction signature carried in the data asset transaction request.

4. The method of claim 1, wherein, The data asset processing based on the private key and the account signature includes: Generate a withdrawal signature using the private key and the assets to be withdrawn; Initiate an on-chain withdrawal request based on the account signature of the off-chain account and the withdrawal signature; The assets to be withdrawn are frozen in the off-chain account.

5. The method of claim 4, wherein, The data asset processing based on the private key and the account signature also includes: If no successful withdrawal message is received from the blockchain before the withdrawal validity period expires, the frozen assets awaiting withdrawal will be unfrozen.

6. The method of any one of claims 1-5, wherein, The data asset processing based on the private key and the account signature includes: The number of times each type of data asset is processed is counted in the off-chain account, and the corresponding number of times is carried out when the corresponding data asset is processed.

7. A data asset processing apparatus, comprising: An off-chain account unit is suitable for establishing off-chain accounts in a trusted environment, generating private keys for the off-chain accounts, and also suitable for binding the established off-chain accounts to on-chain accounts. An account signing unit is adapted to request a signing server to sign the established off-chain account and to store the account signature returned by the signing server in the trusted environment. A data asset processing unit is suitable for deploying staking contracts on a blockchain. Upon learning of a data asset staking task initiated by an on-chain account, it performs simple payment verification on the data asset staking task. This simple payment verification verifies whether the on-chain account is simultaneously bound to multiple off-chain accounts. After successful simple payment verification, a staking signature request is generated based on the identifier of the data asset staking task and the identifier of the off-chain account. The staking signature request is sent to a signature server, and a staking signature is received from the signature server. The corresponding data asset is added to the off-chain account based on the staking signature. The unit is also suitable for processing data assets based on the private key and the account signature.

8. The apparatus of claim 7, wherein, The data asset processing unit is adapted to generate a transaction signature using the private key and the asset to be traded; generate a data asset transaction request based on the account signature and the transaction signature; and send the data asset transaction request to a transaction recipient in a trusted environment.

9. The apparatus of claim 7, wherein, The data asset processing unit is adapted to perform security verification based on the account signature and transaction signature carried in the data asset transaction request after receiving a data asset transaction request sent by a transaction sender in a trusted environment.

10. The apparatus of claim 7, wherein, The data asset processing unit is adapted to generate a withdrawal signature using the private key and the asset to be withdrawn; initiate an on-chain withdrawal request based on the account signature of the off-chain account and the withdrawal signature; and freeze the asset to be withdrawn in the off-chain account.

11. The apparatus of claim 10, wherein, The data asset processing unit is adapted to unfreeze the frozen assets pending withdrawal if it does not receive a withdrawal success message sent off-chain before the withdrawal validity period.

12. The apparatus according to any one of claims 7-11, wherein, The data asset processing unit is adapted to count the number of times each type of data asset is processed in the off-chain account, and to carry the corresponding number of times when performing the corresponding data asset processing.

13. A data asset processing system, comprising: A signature server and one or more data asset processing devices as described in any one of claims 7-12; The signature server includes: The signature request receiving unit is adapted to receive account signature requests sent by the data asset processing device; The signing unit is adapted to perform an account signature on the off-chain account identifier in the account signature request and return it to the data asset processing device if the off-chain account identifier has not been signed before, so that the data asset processing device can perform data asset processing based on the off-chain account's private key and the account signature.

14. The system of claim 13, wherein, The signature request receiving unit is also adapted to receive a staking signature request sent by the data asset processing device, wherein the staking signature request includes an identifier of the data asset staking task and an identifier of the off-chain account. The signing unit is adapted to perform a pledge signature on the identifier of the data asset staking task and return it to the data asset processing device if the identifier of the data asset staking task has not been signed and the identifier of the off-chain account has been signed.

15. The system of claim 13, wherein, The pledge signature request shown also includes the destination address of the pledged assets; The signature unit is also adapted to determine whether the destination address in the pledge signature request matches the address of the pledge contract on the blockchain. If they do not match, the signature unit refuses to pledge the identifier of the data asset staking task.

16. An electronic device, comprising: The electronic device includes: a processor; and a memory arranged to store computer-executable instructions, which, when executed, cause the processor to perform the method as described in any one of claims 1-6.

17. A computer readable storage medium, wherein, The computer-readable storage medium stores one or more programs that, when executed by a processor, implement the method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Blockchain offline transaction method and system based on identification authentication

    CN110348853A

  • On-chain asset pledge financing system and method through off-chain settlement

    CN110648227A

  • System and method for scaling blockchain networks with secure off-chain payment hubs

    US20190139037A1