A data verification method, device, equipment and medium based on blockchain
By pre-cacheting the set of blocks to be selected in the blockchain network on the first terminal, the problem that the service processing terminal cannot verify the validity of the electronic certificate when offline is solved, and effective verification of the electronic certificate and normal operation of the service processing in the offline state are realized.
Patent Information
- Application Number
- CN202010329707.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2040-04-23
AI Technical Summary
When the service processing terminal is offline, the validity of the electronic certificate cannot be verified, resulting in the service being unable to process it normally.
By pre-cacheting the set of to-selected blocks in the blockchain network, including the electronic certificate of the end user, on the first terminal, when disconnected from the blockchain network, the set of to-selected blocks can be read from the local cache and obtaining block information to verify the validity of the electronic certificate.
Ensure that the validity of electronic documents can be effectively verified without a network connection, avoid interruptions in business processing, improve business processing efficiency, and ensure the accuracy and authenticity of electronic documents.
Smart Images

Figure CN113554435B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain technology, and in particular to a blockchain-based data verification method, device, equipment and medium. Background Art
[0002] Documents are the basis for proving the identity of the document holder, such as identity cards, passports, Hong Kong and Macau passes, motor vehicle driver's licenses, etc., which can be used to record the user's identity information; in some occasions where the identity information of the document holder needs to be determined, the document holder can prove his or her identity by providing relevant documents. At the same time, the document is updated as the user's identity information changes. For example, if the document is an identity card, when the user's registered address changes, the user needs to apply for a new identity card; when the user applies for a new identity card, only the new identity card is valid.
[0003] In practice, when the business processing terminal is offline, the user can only provide the certificate (such as card-type certificate, file-type certificate) to the business processing terminal. However, the certificate only stores static user information and cannot verify the validity of the certificate, resulting in the inability to process the business normally. Summary of the invention
[0004] The embodiments of the present application provide a blockchain-based data verification method, device, equipment and medium, which can improve the authenticity of electronic certificates.
[0005] On the one hand, an embodiment of the present application provides a data verification method based on blockchain, including:
[0006] When the first terminal is not connected to the blockchain network, the first terminal receives a processing request for a target service from the second terminal;
[0007] The first terminal reads a set of blocks to be selected from a local cache, wherein the blocks to be selected in the set of blocks to be selected all include the electronic certificate of the terminal user of the second terminal, and the blocks to be selected in the set of blocks to be selected are read from the blockchain network by the first terminal when the first terminal is in a connected state with the blockchain network;
[0008] The first terminal obtains the block information of the to-be-selected block in the to-be-selected block set, determines the update time of the electronic certificate of the terminal user according to the block information of the to-be-selected block in the to-be-selected block set, and verifies the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time;
[0009] The first terminal processes the target service according to the valid electronic certificate.
[0010] Optionally, the block information includes a timestamp, and the method of determining the update time of the electronic certificate of the terminal user based on the block information of the selected block in the selected block set includes: the first terminal obtains a first time corresponding to the timestamp of the selected block in the selected block set, and obtains the system time of the first terminal as the second time; the first terminal obtains the time interval between the first time and the second time; the first terminal determines the selected block with the smallest time interval in the selected block set as the target block; the first terminal determines the time corresponding to the timestamp of the target block as the update time of the electronic certificate of the terminal user.
[0011] Optionally, the block information includes a block height, and the method of determining the update time of the electronic certificate of the terminal user based on the block information of the selected block in the selected block set includes: the first terminal obtains the selected block with the largest block height from the selected block set as the target block; and the first terminal determines the time corresponding to the timestamp of the target block as the update time of the electronic certificate of the terminal user.
[0012] Optionally, the block information includes a signature of a third terminal, and the method of determining the update time of the electronic certificate of the terminal user according to the block information of the to-be-selected block in the to-be-selected block set includes: the first terminal obtains a public key of the third terminal; the first terminal verifies the signature of the third terminal using the public key of the third terminal; the first terminal determines the to-be-selected block in the to-be-selected block set that has passed the verification as an authentication block; the first terminal determines the block with the highest block height in the authentication block as a target block; the first terminal determines the time corresponding to the timestamp of the target block as the update time of the electronic certificate of the terminal user.
[0013] Optionally, the method further includes: verifying the validity of the electronic certificate in the selected block in the selected block set according to the update time, including: if the update time is within the first time period, then the first terminal determines that the electronic certificate in the target block is valid.
[0014] Optionally, the method further includes: the first terminal receives a change request from the second terminal for the electronic certificate of the terminal user, the change request including the changed electronic certificate; if the first terminal verifies that the changed electronic certificate is valid, the first terminal signs the changed electronic certificate using the private key of the first terminal to obtain the signature of the first terminal; the first terminal uploads the signature of the first terminal and the changed electronic certificate to the blockchain network.
[0015] Optionally, the method further includes: when the first terminal is in a connected state with the blockchain network, the first terminal obtains a newly added block from the blockchain network every second time period; and the first terminal caches the newly added block locally.
[0016] Optionally, the first terminal is connected to both the first sub-terminal and the second sub-terminal, the first sub-terminal has a local cache of the first sub-block to be selected, and the second sub-terminal has a local cache of the second sub-block to be selected; the first sub-block to be selected and the second sub-block to be selected both include an electronic certificate of the terminal user, and the method further includes: the first terminal obtains a first block height of the first sub-block to be selected and a second block height of the second sub-block to be selected; if the first block height is greater than the second block height, the first terminal obtains the first sub-block to be selected from the first sub-terminal, and adds the first sub-block to be selected to the set of blocks to be selected; if the first block height is less than the second block height, the first terminal obtains the second sub-block to be selected from the second sub-terminal, and adds the second sub-block to be selected to the set of blocks to be selected.
[0017] On the one hand, an embodiment of the present application provides a data verification device based on blockchain, including:
[0018] A first data processing module, configured to receive, when the first terminal is not connected to the blockchain network, a processing request for a target service from the second terminal;
[0019] A data reading module, used for reading a set of blocks to be selected from a local cache, wherein the blocks to be selected in the set of blocks to be selected all include the electronic certificate of the terminal user of the second terminal, and the blocks to be selected in the set of blocks to be selected are read from the blockchain network by the first terminal when the first terminal is in a connected state with the blockchain network;
[0020] A data verification module, used to obtain block information of a block to be selected in the set of blocks to be selected, determine an update time of the electronic certificate of the terminal user according to the block information of the block to be selected in the set of blocks to be selected, and verify the validity of the electronic certificate in the block to be selected in the set of blocks to be selected according to the update time;
[0021] The second data processing module is used to process the above-mentioned target business according to the valid electronic certificate.
[0022] Optionally, the block information includes a timestamp, and the data verification module is specifically used to obtain a first time corresponding to the timestamp of a selected block in the selected block set, and to obtain a system time of the first terminal as the second time; to obtain a time interval between the first time and the second time; to determine the selected block with the smallest time interval in the selected block set as the target block; and to determine the time corresponding to the timestamp of the target block as the update time of the electronic certificate of the terminal user.
[0023] Optionally, the block information includes a block height, and the data verification module is specifically used to obtain a candidate block with the largest block height from the candidate block set as a target block; and determine the time corresponding to the timestamp of the target block as the update time of the electronic certificate of the terminal user.
[0024] Optionally, the block information includes the signature of the first terminal, and the data verification module is specifically used to obtain the public key of the first terminal; use the public key of the first terminal to verify the signature of the first terminal; determine the selected block that passes the verification in the selected block set as the authentication block; determine the block with the highest block height in the authentication block as the target block; determine the time corresponding to the timestamp of the target block as the update time of the electronic certificate of the terminal user.
[0025] Optionally, the data verification module is specifically used to determine that the electronic certificate in the target block is valid if the update time is within a first time period.
[0026] Optionally, the above-mentioned device also includes: a data change module, which is used to receive a change request from the above-mentioned second terminal for the electronic certificate of the above-mentioned terminal user, and the above-mentioned change request includes the changed electronic certificate; if the above-mentioned changed electronic certificate is verified to be valid, the above-mentioned changed electronic certificate is signed with the private key of the above-mentioned first terminal to obtain the signature of the above-mentioned first terminal; the signature of the above-mentioned first terminal and the above-mentioned changed electronic certificate are uploaded to the above-mentioned blockchain network.
[0027] Optionally, the above-mentioned device also includes: a first data storage module, which is used to obtain newly added blocks from the above-mentioned blockchain network every second time when the above-mentioned first terminal is in a connected state with the blockchain network; and cache the above-mentioned newly added blocks locally.
[0028] Optionally, the first terminal is connected to both the first sub-terminal and the second sub-terminal, the first sub-terminal has a local cache of the first sub-block to be selected, and the second sub-terminal has a local cache of the second sub-block to be selected; the first sub-block to be selected and the second sub-block to be selected both include an electronic certificate of the terminal user, and the device further includes: a second data storage module, used to obtain a first block height of the first sub-block to be selected and a second block height of the second sub-block to be selected; if the first block height is greater than the second block height, the first sub-block to be selected is obtained from the first sub-terminal, and the first sub-block to be selected is added to the set of blocks to be selected; if the first block height is less than the second block height, the second sub-block to be selected is obtained from the second sub-terminal, and the second sub-block to be selected is added to the set of blocks to be selected.
[0029] On one hand, the present application provides a computer device, including: a processor, a memory, and a network interface;
[0030] The above-mentioned processor is connected to the memory and the network interface, wherein the network interface is used to provide data communication function, the above-mentioned memory is used to store computer programs, and the above-mentioned processor is used to call the above-mentioned computer program to execute the method in the above-mentioned aspect in the embodiment of the present application.
[0031] On the one hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. The computer program includes program instructions, which, when executed by a processor, enable the processor to execute the blockchain-based data verification method of the first aspect mentioned above.
[0032] In the embodiment of the present application, the first terminal pre-reads the to-be-selected blocks in the blockchain network to a local to-be-selected block set, and the to-be-selected blocks include the electronic certificate of the terminal user of the second terminal; therefore, when the first terminal is not connected to the blockchain network, and receives a business processing request from the second terminal, the to-be-selected block set can be read locally; this can effectively avoid the problem that the first terminal cannot read the electronic certificate of the terminal user of the second terminal due to the unconnected state between the first terminal and the blockchain network, resulting in the target business not being processed; it can ensure that the target business is processed normally and improve business processing efficiency. Furthermore, since different to-be-selected blocks in the to-be-selected block set record the electronic certificates of the terminal user at different times, that is, the to-be-selected blocks in the to-be-selected block set record the dynamic electronic certificates of the terminal user (that is, dynamic user information). Therefore, the first terminal can obtain the block information of the to-be-selected block in the to-be-selected block set, determine the update time of the terminal user's electronic certificate according to the block information of the to-be-selected block in the to-be-selected block set, and verify the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time, so as to effectively obtain the updated electronic certificate of the terminal user and ensure the accuracy of the electronic certificate. Therefore, in the case where the electronic certificate is valid, the first terminal processes the target business according to the valid electronic certificate, that is, by improving the accuracy and authenticity of the electronic certificate, it can ensure that the target business is accurately and effectively executed. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0034] Figure 1a It is a schematic diagram of the architecture of a data verification system provided by an embodiment of the present application;
[0035] Figure 1b This is a schematic diagram of a blockchain node system provided by an embodiment of the present application;
[0036] Figure 1c This is a schematic diagram of a blockchain provided by an embodiment of the present application;
[0037] Figure 2 This is a flowchart of a data verification method based on blockchain provided in an embodiment of the present application;
[0038] Figure 3 This is a schematic diagram of a process of uploading electronic certificate information to a chain provided by an embodiment of the present application;
[0039] Figure 4 This is a flowchart of a data verification method based on blockchain provided in an embodiment of the present application;
[0040] Figure 5 This is a flowchart of a data verification method based on blockchain provided in an embodiment of the present application;
[0041] Figure 6 This is a schematic diagram of the composition structure of a blockchain-based data verification device provided in an embodiment of the present application;
[0042] Figure 7 It is a schematic diagram of the composition structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0043] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0044] See also Figure 1a , Figure 1a It is a schematic diagram of the architecture of a data verification system provided by an embodiment of the present application. The schematic diagram of the system architecture includes a blockchain node system, a first terminal and a second terminal, wherein the first terminal may refer to a terminal corresponding to an institution to which the office belongs, and the second terminal may refer to a terminal held by a terminal user who needs to handle a target business in the office. The blockchain node system may be a terminal corresponding to an institution to which the national head office belongs, that is, the blockchain node system records the electronic certificates of terminal users across the country. The first terminal can be used to provide a variety of services, perform business processing, read the electronic certificates of the terminal user of the second terminal from the local cache, and so on; the business may include services that require identity authentication, such as bank card processing, identity card replacement, and marital status change. The process of business processing may refer to the need for a terminal user holding the second terminal to perform business processing, such as handling a bank card business, the first terminal reads the electronic certificate of the terminal user of the second terminal cached locally and verifies the electronic certificate, and after the first terminal verifies that the electronic certificate is valid, the first terminal processes the business of handling the bank card, that is, starts to handle the bank card for the terminal user of the second terminal. The electronic certificate of the terminal user may refer to an electronic certificate used to prove the identity of the terminal user, specifically an electronic ID card, an electronic passport, etc. The electronic certificate may include the user's identity information, such as name, gender, age, place of residence, years of holding the certificate, etc. The second terminal may be used to send a processing request for the target service to the first terminal.
[0045] Among them, the node device, the first terminal and the second terminal in the blockchain node system can be computer devices, including mobile phones, tablet computers, laptops, PDAs, smart speakers, mobile Internet devices (MID, mobile internet device), POS (Point Of Sales, point of sale) machines, wearable devices (such as smart watches, smart bracelets, etc.), etc.; it can also refer to an independent server, or a server cluster composed of several servers, or a cloud computing center.
[0046] Also, see Figure 1b , Figure 1b Schematic diagram of a blockchain node system provided by an embodiment of the present application. Figure 1b As shown, the blockchain node system may include multiple nodes, each of which can receive input information when performing normal operations, and maintain the verification information data in the blockchain node system based on the received input information. In order to ensure the information intercommunication within the blockchain node system, there can be an information connection between each node in the blockchain node system, and information can be transmitted between nodes through the above information connection. For example, when any node in the blockchain node system receives input information, other nodes in the blockchain node system obtain the input information according to the consensus algorithm, and store the input information as data in the transaction information data, so that the data stored on all nodes in the blockchain node system are consistent.
[0047] Each node in the blockchain node system has a corresponding node identifier, and each node in the blockchain node system can store the node identifiers of other nodes in the blockchain node system, so that the generated blocks can be broadcast to other nodes in the blockchain node system according to the node identifiers of other nodes. Each node can maintain a node identifier list as shown in the following table, and store the node name and node identifier in the node identifier list accordingly. Among them, the node identifier can be an IP (Internet Protocol, a protocol for interconnecting networks) address and any other information that can be used to identify the node. Table 1 only uses the IP address as an example for explanation.
[0048] Table 1
[0049]
[0050] Each node in the blockchain node system stores the same blockchain. The blockchain consists of multiple blocks, see Figure 1c , Figure 1c This is a schematic diagram of a blockchain provided by an embodiment of the present application, such as Figure 1cAs shown, the blockchain consists of multiple blocks. The genesis block includes a block header and a block body. The block header stores input information feature values, version numbers, timestamps, and difficulty values, and the block body stores input information. The next block of the genesis block uses the genesis block as its parent block. The next block also includes a block header and a block body. The block header stores input information feature values of the current block, feature values of the block header of the parent block, version numbers, timestamps, and difficulty values, and so on. This ensures that the block data stored in each block in the blockchain is associated with the block data stored in the parent block, thereby ensuring the security of the input information in the block.
[0051] The embodiment of the present application utilizes the smart contract in the blockchain technology and the tamper-proof characteristics of the blockchain to process the data, that is, a data verification method based on the blockchain is provided, wherein the smart contract, that is, a computerized protocol, can execute the terms of a certain contract, and is implemented by a code deployed on a shared account book for execution when certain conditions are met. According to actual business needs, the code is used to complete automated transactions. Of course, the smart contract is not limited to executing contracts for transactions, but can also execute contracts for processing received information. The so-called blockchain is a new application mode of computer technologies such as distributed data storage, point-to-point transmission (P2P transmission), consensus mechanism, encryption algorithm, etc. It is essentially a decentralized database; the blockchain can be composed of multiple serial transaction records (also known as blocks) that are connected and protected by cryptography. The distributed ledger connected by the blockchain allows multiple parties to effectively record transactions and can permanently check the transaction (cannot be tampered with). Among them, the consensus mechanism refers to a mathematical algorithm that realizes the establishment of trust and the acquisition of rights and interests between different nodes in the blockchain network; that is, the consensus mechanism is a mathematical algorithm recognized by all network nodes of the blockchain.
[0052] Furthermore, if Figure 1aAs shown, in the process of implementing the data verification method based on blockchain, for example, when the first terminal is connected to the blockchain network, the first terminal can read the block including the user's electronic certificate from the blockchain network and store the read block; this is conducive to reading the required electronic certificate from the local when the first terminal is not connected to the blockchain network, which is conducive to the normal execution of the business. For example, if the first terminal is not connected to the blockchain network, the first terminal receives a processing request for the target business from the second terminal, and the processing request indicates that the electronic certificate of the terminal user of the second terminal is required to process the target business. Therefore, the first terminal can read the block including the electronic certificate of the terminal user from the local cache as a block to be selected, and obtain the block information of the block to be selected. Furthermore, the update time of the electronic certificate of the terminal user is determined according to the block information, and the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set is verified according to the update time. If the electronic certificate is valid, it indicates that the electronic certificate in the to-be-selected block has not been tampered with, or the electronic certificate in the to-be-selected block is an updated electronic certificate, and the target business can be processed according to the electronic certificate in the to-be-selected block. If the electronic certificate is not valid, it indicates that the electronic certificate in the to-be-selected block has been tampered with, or the electronic certificate in the to-be-selected block is not an updated electronic certificate, and the block with the electronic certificate of the terminal user can be re-acquired, and the validity of the electronic certificate in the re-acquired block can be verified, until it is determined that the electronic certificate is valid, and the target business is processed according to the electronic certificate in the re-acquired block.
[0053] For example, when the first terminal corresponding to the Ministry of Civil Affairs Office is not connected to the blockchain network, the terminal user holding the second terminal needs to handle the marriage registration business at the second terminal. After the first terminal receives the processing request for the marriage registration business from the second terminal, the first terminal reads the block including the electronic certificate A of the terminal user of the second terminal from the local cache of the first terminal as the block to be selected, and obtains the block information of the block to be selected; further, the first terminal determines the update time of the electronic certificate A of the terminal user according to the block information, verifies the validity of the electronic certificate A in the block to be selected according to the update time, and if the update time of the electronic certificate A is within the first time period, it indicates that the electronic certificate A is valid, and the marriage registration business of the terminal user is processed according to the electronic certificate A. If the update time of the electronic certificate A is not within the first time period, it indicates that the electronic certificate A is not valid, indicating that the electronic certificate A has been tampered with, or the electronic certificate A is not an updated electronic certificate. For example, the name of the terminal user is Zhang Yi, but the terminal user changes the name to Zhang Er at the management department office, but the name on the electronic certificate A is still Zhang Yi, which indicates that the electronic certificate A is not the updated electronic certificate. The first terminal then reacquires the block with the electronic certificate of the terminal user, that is, obtains the electronic certificate B, the name in the electronic certificate B is Zhang Er, and verifies the validity of the electronic certificate B in the reacquired block. When it is determined that the electronic certificate B is valid, the marriage registration business of the terminal user is processed according to the electronic certificate B in the reacquired block. The management department has the authority to change the user's name.
[0054] For further information, see Figure 2 , Figure 2 : is a flowchart of a data verification method based on blockchain provided by an embodiment of the present application. As shown in the figure, the method includes:
[0055] S101, when the first terminal is not connected to the blockchain network, the first terminal receives a processing request for a target service from the second terminal.
[0056] Here, the unconnected state between the first terminal and the blockchain network may refer to: the network between the first terminal and the blockchain network is disconnected, or the node device in the blockchain network fails; at this time, the first terminal cannot obtain data through the blockchain network, etc. The first terminal may be a terminal corresponding to the institution to which the office belongs, such as a terminal corresponding to the Ministry of Civil Affairs, a terminal corresponding to the management department, a terminal corresponding to the bank, etc. The second terminal may refer to a terminal held by a terminal user who needs to handle the target business in the office, such as a terminal held by a terminal user who needs to handle a bank card, a terminal held by a terminal user who needs to handle a marriage registration, a terminal held by a terminal user who needs to handle a Hong Kong and Macao Pass, a terminal held by a terminal user who needs to handle a passport, etc. The target business is the business that the terminal user holding the second terminal needs to handle, such as a marriage registration business, a bank card handling business, a passport handling business, etc. The first terminal may be connected to the second terminal, such as a Bluetooth connection, a near field communication connection, or other connection methods. After the first terminal is connected to the second terminal, the second terminal may send a processing request for the target business to the first terminal, and the first terminal receives the processing request for the target business sent by the second terminal.
[0057] Optionally, before the first terminal receives the processing request of the second terminal for the target business, the first terminal may pre-establish a connection with the blockchain network. When the first terminal and the blockchain network are in a connected state, the first terminal obtains a newly added block from the blockchain network every second time period; the first terminal caches the newly added block locally, and the newly added block may refer to a newly written block in the blockchain network; or, the newly added block may refer to a newly written block in the blockchain network and related to the business processed by the first terminal.
[0058] Here, the second time can be 1 hour, one day, one week, or one month, and the second time is not limited in the embodiment of the present application. For example, if the second time is 1 hour, when the first terminal is connected to the blockchain network, the first terminal obtains the newly added blocks from the blockchain network every 1 hour and caches the newly added blocks locally. The block includes the electronic certificate of the terminal user, and the terminal user here can refer to any terminal user.
[0059] Optionally, before the first terminal obtains the newly added block from the blockchain network every second time, the blockchain node system can generate each block in the blockchain according to the electronic certificate of the terminal user uploaded by the third terminal. Here, the third terminal may include the first terminal, and the number of the third terminal may also be multiple. For example, the third terminal includes the terminal corresponding to the management department office and the terminal corresponding to the Ministry of Civil Affairs office. The third terminal may also include the terminal of the Ministry of Civil Affairs Office in Bao'an District, the terminal of the Ministry of Civil Affairs Office in Nanshan District, and the terminals of the Ministry of Civil Affairs Office in other regions, the terminal of the management department office in Bao'an District, the terminal of the management department office in Nanshan District, and the terminals of the management department offices in other regions. For example, the terminal corresponding to the Nanshan District Management Department Office uploads the electronic certificate C of the terminal user verified by the terminal corresponding to the Nanshan District Management Department Office, and uploads it to the blockchain network; when the marital status of the terminal user changes, the terminal corresponding to the Nanshan District Ministry of Civil Affairs Office verifies the identity status of the terminal user, generates the changed electronic certificate D, and uploads the electronic certificate D to the blockchain network. The first terminal may be, for example, the management department office in Futian District, and the first terminal obtains the newly added block from the blockchain network, and the newly added block includes the electronic certificate D. When generating each block in the blockchain, see Figure 3 , Figure 3 This is a schematic diagram of an electronic certificate information chain-up process provided by an embodiment of the present application. When the node where the blockchain is located receives the input information (electronic certificate information), it verifies the input information. After the verification is completed, the input information is stored in the memory pool, and the hash tree used to record the input information is updated; then, the update timestamp is updated to the time when the input information is received, and different random numbers are tried, and the characteristic value calculation is performed multiple times, so that the calculated characteristic value can satisfy the following formula:
[0060]
[0061] in SHA256 the eigenvalue algorithm used to compute the eigenvalues; version (version number) is the version information of the relevant block protocol in the blockchain; prev_hash It is the block header feature value of the parent block of the current block; merkle_root is the characteristic value of the input information; ntime The update time of the update timestamp; nbits The current difficulty is fixed for a period of time and is determined again after a fixed period of time. x is a random number; TARGET is the eigenvalue threshold, which can be calculated based on nbits Definitely got it.
[0062] In this way, when the random number that satisfies the above formula is calculated, the information can be stored accordingly, the block header and block body can be generated, and the current block can be obtained. Subsequently, the node where the blockchain is located sends the newly generated block to other nodes in the blockchain node system where it is located according to the node identification of other nodes in the blockchain node system. Other nodes verify the newly generated block and add the newly generated block to the blockchain stored in it after completing the verification.
[0063] After the blockchain node system generates each block in the blockchain according to the electronic certificate of the terminal user uploaded by the third terminal, the first terminal can cache the blocks in the blockchain node system locally, and obtain newly added blocks from the blockchain network at second intervals. When the first terminal subsequently verifies the electronic certificate of the terminal user of the second terminal, since the first terminal has pre-cached the blocks in the blockchain network locally, the first terminal can use them directly without having to connect to the Internet to obtain the blocks. Even in the absence of a network, the first terminal can perform business processing by obtaining locally cached blocks, which can improve business processing efficiency.
[0064] S102: The first terminal reads a set of blocks to be selected from a local cache.
[0065] Among them, the to-be-selected blocks in the to-be-selected block set all include the electronic certificate of the terminal user of the second terminal, and the to-be-selected blocks in the to-be-selected block set are read from the blockchain network when the first terminal is in a connected state with the blockchain network. The to-be-selected block set includes one or more to-be-selected blocks.
[0066] It is understandable that when the first terminal is in a connected state with the blockchain network, the first terminal reads at least one block to be selected that matches the user information of the terminal user from the blockchain network, obtains a set of blocks to be selected, and obtains newly added blocks from the blockchain network every second time, caches the newly added blocks locally, and caches the newly added blocks in the set of blocks to be selected. It can be seen that each block to be selected in the set of blocks to be selected contains the electronic certificate of the terminal user, and the electronic certificate in each block to be selected is the electronic certificate of the terminal user in different time periods. Among them, the processing request of the target service may include user information, and the user information may include the user's name, the user's face information, and the user's fingerprint information. For example, when the user information is the user's face information, when the terminal user's face is facing the face collection device of the first terminal, when the first terminal obtains the terminal user's face information, that is, the first terminal receives the processing request of the second terminal for the target service, then the block to be selected that matches the terminal user's face information is queried in the local cache.
[0067] When the first terminal queries multiple candidate blocks that match the terminal user, and each candidate block contains the terminal user's electronic certificate, it indicates that the terminal user has updated the electronic certificate at different time periods, for example, the terminal user applied for an electronic certificate when he was a minor, updated the electronic certificate when he became an adult, updated the electronic certificate when the terminal user's name changed, and updated the electronic certificate when the terminal user accepted a criminal punishment. That is, each electronic certificate corresponds to a state of the terminal user. By querying the candidate blocks that match the terminal user in the local cache, it is possible to avoid obtaining incomplete electronic certificates of the terminal user. For example, it is possible to avoid the terminal user only providing electronic certificates that are beneficial to him.
[0068] S103, the first terminal obtains block information of a block to be selected in the set of blocks to be selected, determines an update time of an electronic certificate of a terminal user according to the block information of the block to be selected in the set of blocks to be selected, and verifies the validity of the electronic certificate in the block to be selected in the set of blocks to be selected according to the update time.
[0069] Here, the update time of the electronic certificate is the most recent update time of the electronic certificate. For example, if the current system time is Thursday, March 5, 2020, and the electronic certificate has three update times, namely March 5, 2005, March 5, 2010, and March 5, 2019, then the update time of the electronic certificate is March 5, 2019, which is the most recent update time to the current system time. Block information may include timestamps, block heights, signatures of third terminals, etc. Timestamps may be character sequences that uniquely identify a certain moment in time. The block height can be used to identify the location of the block to be selected in the blockchain, and based on this, find all the basic attributes and transaction records related to the block to be selected. The larger the block height, the more recent the electronic certificate in the block is, that is, the electronic certificate in the block is an updated electronic certificate, that is, the higher the accuracy of the electronic certificate; the smaller the block height, the more recent the electronic certificate in the block is, that is, the electronic certificate in the block is not, that is, the electronic certificate in the block is before the update, that is, the lower the accuracy of the electronic certificate. The signature of the third terminal is used to indicate that the block to be selected has been verified by the third terminal and is valid after verification.
[0070] Optionally, verifying the validity of the electronic certificate may refer to: verifying whether the electronic certificate in the block to be selected is an updated electronic certificate, and if the electronic certificate is an updated electronic certificate, determining that the electronic certificate is valid; if the electronic certificate is not an updated electronic certificate, determining that the electronic certificate is not valid. For example, the update time of the electronic certificate in the block to be selected may be determined based on the time interval between the time corresponding to the timestamp of the block to be selected corresponding to the electronic certificate and the system time of the first terminal, thereby determining whether the electronic certificate in the block to be selected is an updated electronic certificate.
[0071] Optionally, verifying the validity of the electronic certificate may refer to: verifying the block to be selected with the largest block height among the blocks to be selected, and determining the time corresponding to the timestamp of the block to be selected with the largest block height as the update time of the electronic certificate of the terminal user. If the time corresponding to the timestamp of the block to be selected is within the first time period, it is determined that the electronic certificate in the block to be selected is an updated electronic certificate, and the electronic certificate is valid; if the time corresponding to the timestamp of the block to be selected is not within the first time period, it is determined that the electronic certificate in the block to be selected is not an updated electronic certificate, and the electronic certificate is not valid.
[0072] Optionally, verifying the validity of the electronic certificate may refer to: verifying whether the signature of the block to be selected is the signature of the third terminal. If the signature of the block to be selected is the signature of the third terminal, that is, the electronic certificate in the block to be selected is verified by the third terminal, that is, the electronic certificate is authentic, that is, the electronic certificate has not been tampered with, and determining the time corresponding to the timestamp of the block to be selected with the highest block height as the update time of the terminal user's electronic certificate, and comparing the update time of the electronic certificate with the first time period to determine the validity of the electronic certificate. If the signature of the block to be selected is not the signature of the third terminal, that is, the electronic certificate in the block to be selected is not verified by the third terminal, that is, the electronic certificate is not authentic, that is, the electronic certificate has been tampered with, then it is determined that the electronic certificate in the block to be selected is not valid.
[0073] In the embodiment of the present application, any one of the following methods or a combination of the following methods can be used to determine the update time of the electronic certificate of the terminal user according to the block information of the to-be-selected block in the to-be-selected block set, and verify the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time;
[0074] In the first way, the first terminal can obtain the first time corresponding to the timestamp of the to-be-selected block in the to-be-selected block set, and obtain the system time of the first terminal as the second time; the first terminal obtains the time interval between the first time and the second time; the first terminal determines the to-be-selected block with the smallest time interval in the to-be-selected block set as the target block; the first terminal determines the time corresponding to the timestamp of the target block as the update time of the terminal user's electronic certificate. Optionally, the first terminal can determine the to-be-selected block corresponding to the timestamp corresponding to the first time with the smallest time interval between the first time and the second time as the target block.
[0075] For example, the first time corresponding to the timestamp of the selected block A in the selected block set is 17:00 on January 22, 2020, the first time corresponding to the timestamp of the selected block B in the selected block set is 10:00 on February 22, 2020, the system time of the first terminal is 17:00 on February 22, 2020, the time interval between the selected block A and the second time is 1 month, and the time interval between the selected block B and the second time is 7 hours. It can be seen that 7 hours is less than 1 month, so the selected block B is determined as the target block, and the time corresponding to the timestamp of the selected block B is determined as the update time of the terminal user's electronic certificate. If the time interval between the first time and the second time corresponding to the timestamp of the candidate block A in the candidate block set is greater than the time interval between the first time and the second time corresponding to the timestamp of the candidate block B in the candidate block set, it means that the candidate block A is not in an updated state, that is, the electronic certificate in the candidate block A is not an updated electronic certificate. For example, the status of the electronic certificate of the terminal user in the candidate block A has changed, such as the user's name, marital status, etc., but it has not been synchronized to the blockchain network.
[0076] In the second method, the first terminal obtains a candidate block with the largest block height from the candidate block set as a target block; the first terminal determines the time corresponding to the timestamp of the target block as the update time of the terminal user's electronic certificate.
[0077] For example, the block with the largest block height in the set of blocks to be selected is block C, and the target block is block C. The first terminal determines the time corresponding to the timestamp of block C as the update time of the terminal user's electronic certificate.
[0078] In a third method, the first terminal obtains the public key of the third terminal; the first terminal uses the public key of the third terminal to verify the signature of the third terminal; the first terminal determines the selected block that passes the verification in the selected block set as the authentication block; the first terminal determines the block with the highest block height in the authentication block as the target block; the first terminal determines the time corresponding to the timestamp of the target block as the update time of the terminal user's electronic certificate.
[0079] Here, the number of authentication blocks can be greater than or equal to one, the number of target blocks is one, and the target block is the block with the largest block height in at least one authentication block. It can be understood that the authentication block is a block that has passed the signature verification in the set of blocks to be selected, that is, the authentication block is a block that is confirmed by the third terminal and then uploaded to the blockchain network, and the authentication block includes the signature of the third terminal. It can be seen that the target block also includes the signature of the third terminal. The third terminal can refer to a terminal belonging to an authoritative agency, such as a terminal belonging to an administrative department, the Ministry of Civil Affairs, and other institutions.
[0080] In a specific implementation, the electronic certificate carries the signature of the third terminal. Before the first terminal obtains the public key of the third terminal, the third terminal can perform a hash operation on the electronic certificate to obtain a hash value of the electronic certificate, and use the private key of the third terminal to encrypt the hash value of the electronic certificate to obtain the electronic certificate carrying the signature of the third terminal. The electronic certificate carrying the signature of the third terminal and the electronic certificate (i.e., the original text) are broadcast to each node device in the blockchain node system, and each node device records the electronic certificate carrying the signature of the third terminal and the electronic certificate (i.e., the original text) in a block in the blockchain network.
[0081] The first terminal obtains the electronic certificate and the block of the electronic certificate signed by the third terminal in the blockchain network as the block to be selected. The first terminal can obtain the public key of the third terminal, use the public key of the third terminal to perform a hash operation on the electronic certificate, and obtain a first hash value; use the public key of the third terminal to decrypt the signature of the third terminal to obtain a second hash value. If the first hash value is the same as the second hash value, it is determined that the signature in the block to be selected has been verified, and it is determined that the electronic certificate in the block to be selected has not been tampered with, and the electronic certificate is uploaded by the third terminal, that is, the electronic certificate is verified by an authoritative organization; therefore, the block to be selected is used as the target block; it is determined that the target block is valid; if the first hash value is different from the second hash value, it is determined that the signature in the block to be selected has not been verified, and it is determined that the electronic certificate in the block to be selected has been tampered with, and the electronic certificate is not uploaded by the third terminal; therefore, the block to be selected is determined to be an invalid block. Optionally, the signatures carried in the multiple candidate blocks are all verified, and the candidate block with the highest block height is used as the target block.
[0082] Optionally, after determining the update time of the terminal user's electronic certificate based on the block information of the selected blocks in the selected block set through any one of the above three methods or a combination of the following methods, if the update time of the terminal user's electronic certificate is within the first time period, the first terminal determines that the electronic certificate in the target block is valid.
[0083] Here, the first time period is the validity period of the electronic certificate. For example, the validity period of the identity card includes 5 years, 10 years, 20 years, etc., and the validity period of the Hong Kong and Macao Pass includes 5 years, 10 years, etc. The validity period is calculated from the date of applying for the electronic certificate. If the update time of the electronic certificate determined by the above method is within the first time period, that is, the electronic certificate is still within the validity period, then the electronic certificate in the target block is determined to be valid, and the electronic certificates in the selected blocks other than the target block in the selected blockchain set are not valid; if the update time of the electronic certificate is not within the first time period, that is, the electronic certificate is not within the validity period, that is, the electronic certificate has expired, then the electronic certificate in the target block is determined to be not valid, and the electronic certificates in the selected blocks other than the target block in the selected blockchain set are also not valid.
[0084] By verifying the time interval between the time corresponding to the timestamp of the block to be selected and the system time of the first terminal and the block height of the block to be selected, it can be determined whether the state of the block to be selected is the updated state in the set of blocks to be selected, that is, whether the electronic certificate in the block to be selected is the latest electronic certificate in the local cache. By verifying the signature of the third terminal of the block to be selected, it can be determined whether the block to be selected has been verified by the third terminal, that is, the authenticity of the block to be selected can be determined.
[0085] S104: The first terminal processes the target service according to the valid electronic certificate.
[0086] Here, the above steps can verify whether the electronic certificate in the selected block is valid. If the electronic certificate in the selected block is valid, the first terminal processes the target business. For example, if the target business is marriage registration, the first terminal processes the marriage registration business. If the electronic certificate in the selected block is not valid, the first terminal will no longer process the target business.
[0087] Optionally, after processing the target business, the first terminal may also generate a block according to the target business, upload it to the blockchain network, and save the block corresponding to the target business to the set of blocks to be selected in the local cache. For example, if the target business is marriage registration, the first terminal may generate a block according to the electronic certificate in the block to be selected and the target business after processing the marriage registration business. For example, if the marital status of the terminal user in the electronic certificate in the block to be selected is single, the marital status of the terminal user in the block generated according to the electronic certificate in the block to be selected and the target business is married.
[0088] In the embodiment of the present application, the first terminal pre-reads the to-be-selected blocks in the blockchain network to a local to-be-selected block set, and the to-be-selected blocks include the electronic certificate of the terminal user of the second terminal; therefore, when the first terminal is not connected to the blockchain network, and receives a business processing request from the second terminal, the to-be-selected block set can be read locally; this can effectively avoid the problem that the first terminal cannot read the electronic certificate of the terminal user of the second terminal due to the unconnected state between the first terminal and the blockchain network, resulting in the target business not being processed; it can ensure that the target business is processed normally and improve business processing efficiency. Furthermore, since different to-be-selected blocks in the to-be-selected block set record the electronic certificates of the terminal user at different times, that is, the to-be-selected blocks in the to-be-selected block set record the dynamic electronic certificates of the terminal user (that is, dynamic user information). Therefore, the first terminal can obtain the block information of the to-be-selected block in the to-be-selected block set, determine the update time of the terminal user's electronic certificate according to the block information of the to-be-selected block in the to-be-selected block set, and verify the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time, so as to effectively obtain the updated electronic certificate of the terminal user and ensure the accuracy of the electronic certificate. Therefore, in the case where the electronic certificate is valid, the first terminal processes the target business according to the valid electronic certificate, that is, by improving the accuracy and authenticity of the electronic certificate, it can ensure that the target business is accurately and effectively executed.
[0089] Optionally, the first terminal can change the electronic certificate of the terminal user and upload the changed information to the blockchain network. For specific methods, please refer to Figure 4 , Figure 4 : is a flowchart of a data verification method based on blockchain provided by an embodiment of the present application. As shown in the figure, the method includes:
[0090] S201, when the first terminal is in an unconnected state with the blockchain network, the first terminal receives a processing request for a target service from the second terminal.
[0091] S202: The first terminal reads a set of blocks to be selected from a local cache.
[0092] S203, the first terminal obtains block information of a to-be-selected block in the to-be-selected block set, determines an update time of the electronic certificate of the terminal user according to the block information of the to-be-selected block in the to-be-selected block set, and verifies the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time.
[0093] S204: The first terminal processes the target service according to the valid electronic certificate.
[0094] Here, the specific implementation of steps S201 to S204 can be referred to Figure 2 The description of steps S101 to S104 in the corresponding embodiment will not be repeated here.
[0095] S205: The first terminal receives a request from the second terminal to change the electronic certificate of the terminal user.
[0096] The change request includes the changed electronic certificate. When the status of the electronic certificate of the terminal user holding the second terminal changes, the second terminal can send a change request for the electronic certificate of the terminal user, and the first terminal receives the change request for the electronic certificate of the terminal user from the second terminal. For example, when the name of the terminal user holding the second terminal changes, the second terminal sends the changed name to the first terminal, and the first terminal receives the changed name sent by the second terminal.
[0097] S206: If the first terminal verifies that the changed electronic certificate is valid, the first terminal signs the changed electronic certificate using the private key of the first terminal to obtain the signature of the first terminal.
[0098] Here, the specific signature verification process can refer to the process in which the first terminal uses the public key of the third terminal to verify the signature of the third terminal in step S103, which will not be repeated here. Optionally, the first terminal verifies that the changed electronic certificate is valid, which can refer to the first terminal verifying whether the changed electronic certificate sent by the second terminal is valid. Here, the validity of the changed electronic certificate can refer to whether the changed electronic certificate complies with relevant regulations. For example, the name of the terminal user in the electronic certificate before the change is two characters, but the number of characters in the name of the terminal user in the changed electronic certificate exceeds the prescribed number of characters, then the first terminal verifies that the changed electronic certificate is not valid. Alternatively, the marital status of the terminal user in the electronic certificate before the change is married, and the terminal user in the changed electronic certificate adds a new spouse. Since it does not comply with the regulations, the first terminal verifies that the changed electronic certificate is not valid.
[0099] If the first terminal verifies that the changed electronic certificate is valid, it indicates that the changed electronic certificate complies with relevant regulations, and the first terminal signs the changed electronic certificate using the private key of the first terminal to obtain the signature of the first terminal. The first terminal signs the changed electronic certificate using the private key of the first terminal to indicate that the changed electronic certificate is confirmed by the office where the first terminal is located to comply with relevant regulations. Since the changed electronic certificate has the signature of the first terminal, when other terminals read the signature of the first terminal, it can be indicated that the changed electronic certificate is authentic and legal.
[0100] S207, the first terminal uploads the signature of the first terminal and the changed electronic certificate to the blockchain network.
[0101] Here, after the first terminal uploads the signature of the first terminal and the changed electronic certificate to the blockchain network, in the subsequent business processing process, any terminal can determine that the changed electronic certificate is authentic and legal by reading the signature of the first terminal, and that the electronic certificate has not been tampered with by an illegal terminal.
[0102] In the embodiment of the present application, the first terminal verifies the changed electronic certificate by using the signature of the first terminal. If the verification is successful, the changed electronic certificate is uploaded to the blockchain network. All office terminals connected to the blockchain network can share the changed electronic certificate, which can avoid business processing errors caused by the office terminal failing to obtain the changed electronic certificate when the identity status of the terminal user changes.
[0103] Optionally, the first terminal can also add blocks from other terminals to the first terminal. For specific block adding methods, see Figure 5 , Figure 5 : is a flowchart of a data verification method based on blockchain provided by an embodiment of the present application. As shown in the figure, the method includes:
[0104] S301: The first terminal obtains a first block height of a first sub-block to be selected and a second block height of a second sub-block to be selected.
[0105] Among them, the first terminal is connected to the first sub-terminal and the second sub-terminal. The local cache of the first sub-terminal contains the first sub-block to be selected, and the local cache of the second sub-terminal contains the second sub-block to be selected. Both the first sub-block to be selected and the second sub-block to be selected include the electronic certificate of the terminal user.
[0106] Here, the first terminal may be a terminal corresponding to the office, the first sub-terminal may be a terminal corresponding to the clerk of the office, and the second sub-terminal may also be a terminal corresponding to the clerk of the office. For example, the first terminal may be a terminal at a bank's manual window, the first sub-terminal may be an ATM or a bank's self-service business processing machine, and the second sub-terminal may be an ATM or a bank's self-service business processing machine. The first sub-terminal may be a terminal that the clerk holds when he goes out to handle business, and the second sub-terminal may be a terminal that the clerk holds when he goes out to handle business. The connection status between the first terminal and the first sub-terminal and the second sub-terminal may include a wired connection or a short-range wireless communication connection. The wired connection may include a data line connection; the short-range wireless communication connection may include a Near Field Communication (NFC) connection, a Bluetooth connection, a ZigBee connection, a Wireless Local Area Network (WLAN) connection, an Infrared Data Association (IrDA) connection, a Radio Frequency Identification (RFID) connection, an Ultra Wide Band (UWB) connection, and the like.
[0107] In a specific implementation, when the first sub-terminal and the second sub-terminal are respectively connected to the blockchain network, the first sub-terminal and the second sub-terminal can cache the first sub-block to be selected and the second sub-block to be selected from the blockchain network respectively. Due to factors such as network signals or terminal devices, there may be differences between the first sub-block to be selected and the second sub-block to be selected.
[0108] S302: If the first block height is greater than the second block height, the first terminal obtains a first sub-block to be selected from the first sub-terminal, and adds the first sub-block to be selected to a set of blocks to be selected.
[0109] S303: If the first block height is less than the second block height, the first terminal obtains the second sub-block to be selected from the second sub-terminal, and adds the second sub-block to be selected to the set of blocks to be selected.
[0110] Here, in steps S302~S303, the block height of the block can be used to indicate the status of the block to be selected. The larger the block height, the newer the block information in the block to be selected corresponding to the block, that is, the newer the electronic certificate in the block to be selected, that is, the more accurate the status of the terminal user in the electronic certificate.
[0111] Specifically, the first block height is greater than the second block height, that is, the block information in the first sub-block to be selected cached by the first sub-terminal is newer than the block information in the second sub-block to be selected cached by the second sub-terminal. The first terminal can make the blocks to be selected in the set of blocks to be selected of the first terminal more accurate by acquiring the sub-block to be selected corresponding to the terminal with a larger block height and adding it to the set of blocks to be selected, so that the status of the electronic certificate of the terminal user included in the block to be selected is more accurate. It can be seen that the larger the block height, the more accurate the electronic certificate information of the terminal user of the second terminal included in the block to be selected.
[0112] For example, the terminal user's electronic certificate has three changes, the first change is to change the unmarried status to divorced, the second change is to change the divorced status to married, and the third change is to change the married status to widowed, and the first block height is greater than the second block height, then the marital status of the terminal user in the to-be-selected block cached by the first terminal may be divorced, the marital status of the terminal user in the electronic certificate of the terminal user in the first sub-to-be-selected block cached by the first sub-terminal may be widowed, and the marital status of the terminal user in the electronic certificate of the terminal user in the second sub-to-be-selected block cached by the second sub-terminal may be married.
[0113] If the first block height is less than the second block height, the marital status of the terminal user in the electronic certificate of the terminal user in the first sub-block to be selected cached by the first sub-terminal may be married, while the marital status of the terminal user in the electronic certificate of the terminal user in the second sub-block to be selected cached by the second sub-terminal may be widowed. The first terminal then adds the sub-block to be selected corresponding to the terminal to be selected with a larger block height to the set of blocks to be selected, that is, adds the marital status of the terminal user "widowed" to the set of blocks to be selected of the first terminal.
[0114] Optionally, if the block height of the block to be selected of the first terminal is greater than the first block height and the second block height, the block to be selected may be added to the local cache of the first sub-terminal and the local cache of the second sub-terminal. Alternatively, if the first block height is greater than the second block height, the first sub-block to be selected may be added to the local cache of the second sub-terminal; if the first block height is less than the second block height, the second sub-block to be selected may be added to the local cache of the first sub-terminal. By comparing the block heights of the blocks in the first terminal, the first sub-terminal, and the second sub-terminal, the blocks in the terminal with the highest block height may be added to the terminal with the lower block height to achieve data update between terminals, thereby improving the accuracy of subsequent business processing.
[0115] S304: When the first terminal is not connected to the blockchain network, the first terminal receives a processing request from the second terminal for a target service.
[0116] S305: The first terminal reads a set of blocks to be selected from a local cache.
[0117] S306, the first terminal obtains block information of a block to be selected in the set of blocks to be selected, determines an update time of the electronic certificate of the terminal user according to the block information of the block to be selected in the set of blocks to be selected, and verifies the validity of the electronic certificate in the block to be selected in the set of blocks to be selected according to the update time.
[0118] S307: The first terminal processes the target service according to the valid electronic certificate.
[0119] Here, the specific implementation of steps S304 to S307 can be referred to Figure 2 The description of steps S101 to S104 in the corresponding embodiment will not be repeated here.
[0120] In an embodiment of the present application, the first terminal determines the block status of the sub-selected blocks of each sub-terminal by comparing the block heights of multiple sub-terminals, and adds the sub-selected blocks of the sub-terminal with the highest block height to the set of selected blocks of the first terminal. This can make the electronic certificate status of the terminal user in the selected block of the first terminal be updated, thereby improving the accuracy of subsequent business processing.
[0121] The method of the embodiment of the present application is introduced above, and the device of the embodiment of the present application is introduced below.
[0122] See also Figure 6 , Figure 6 60 is a schematic diagram of the composition structure of a data verification device based on blockchain provided in an embodiment of the present application. The data verification device based on blockchain can be a computer program (including program code) running on a computer device. For example, the data verification device based on blockchain is an application software; the device can be used to execute the corresponding steps in the method provided in an embodiment of the present application. The device 60 includes:
[0123] The first data processing module 601 is used to receive a processing request for a target service from a second terminal when the first terminal is not connected to the blockchain network;
[0124] The data reading module 602 is used to read a set of blocks to be selected from a local cache, wherein the blocks to be selected in the set of blocks to be selected all include the electronic certificate of the terminal user of the second terminal, and the blocks to be selected in the set of blocks to be selected are read from the blockchain network by the first terminal when the first terminal is in a connected state with the blockchain network;
[0125] The data verification module 603 is used to obtain the block information of the to-be-selected block in the to-be-selected block set, determine the update time of the electronic certificate of the terminal user according to the block information of the to-be-selected block in the to-be-selected block set, and verify the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time;
[0126] The second data processing module 604 is used to process the above target business according to the valid electronic certificate.
[0127] Optionally, the block information includes a timestamp, and the data verification module 603 is specifically used to:
[0128] Acquire a first time corresponding to a timestamp of a block to be selected in the set of blocks to be selected, and acquire a system time of the first terminal as a second time;
[0129] Obtaining the time interval between the first time and the second time;
[0130] Determine the candidate block with the smallest time interval in the candidate block set as the target block;
[0131] The time corresponding to the timestamp of the target block is determined as the update time of the electronic certificate of the terminal user.
[0132] Optionally, the block information includes a block height, and the data verification module 603 is specifically used to:
[0133] Obtain the candidate block with the largest block height from the above candidate block set as the target block;
[0134] The time corresponding to the timestamp of the target block is determined as the update time of the electronic certificate of the terminal user.
[0135] Optionally, the block information includes a signature of the third terminal, and the data verification module 603 is specifically used to:
[0136] Obtaining the public key of the third terminal;
[0137] Verifying the signature of the third terminal using the public key of the third terminal;
[0138] The block that has passed the signature verification in the above-mentioned set of blocks to be selected is determined as the authentication block; the block with the highest block height in the above-mentioned authentication blocks is determined as the target block;
[0139] The time corresponding to the timestamp of the target block is determined as the update time of the electronic certificate of the terminal user.
[0140] Optionally, the data verification module 603 is specifically used to: if the update time is within the first time period, determine that the electronic certificate in the target block is valid.
[0141] Optionally, the device 60 further includes:
[0142] The data change module 605 is used to receive a change request from the second terminal for the electronic certificate of the terminal user, wherein the change request includes the changed electronic certificate;
[0143] The data changing module 605 is used to sign the changed electronic certificate using the private key of the first terminal to obtain the signature of the first terminal if the changed electronic certificate is verified to be valid;
[0144] The signature of the first terminal and the changed electronic certificate are uploaded to the blockchain network.
[0145] Optionally, the device 60 further includes:
[0146] A first data storage module 606, configured to obtain a newly added block from the blockchain network at a second time interval when the first terminal is connected to the blockchain network;
[0147] The first data storage module 606 is used to cache the newly added blocks locally.
[0148] Optionally, the first terminal is connected to the first sub-terminal and the second sub-terminal, the first sub-terminal has a first sub-block to be selected in a local cache, and the second sub-terminal has a second sub-block to be selected in a local cache; the first sub-block to be selected and the second sub-block to be selected both include an electronic certificate of the terminal user, and the device 60 further includes:
[0149] The second data storage module 607 is used to obtain the first block height of the first sub-block to be selected and the second block height of the second sub-block to be selected;
[0150] The second data storage module 607 is configured to obtain the first sub-block to be selected from the first sub-terminal if the first block height is greater than the second block height, and add the first sub-block to be selected to the set of blocks to be selected;
[0151] The second data storage module 607 is used to obtain the second sub-block to be selected from the second sub-terminal if the height of the first block is less than the height of the second block, and add the second sub-block to be selected to the set of blocks to be selected.
[0152] It should be noted that Figure 6For the contents not mentioned in the corresponding embodiments, please refer to the description of the method embodiments, which will not be repeated here.
[0153] According to one embodiment of the present application, Figure 2 The steps involved in the blockchain-based data verification method shown can be represented by Figure 6 The various modules in the blockchain-based data verification device shown are executed. For example, Figure 2 The step S101 shown in FIG. 1 can be performed by Figure 6 The first data processing 601 is performed, Figure 2 The step S102 shown in FIG. 1 can be performed by Figure 6 The data reading module 602 is used to execute; Figure 2 The step S103 shown in FIG. 1 can be performed by Figure 6 The data verification module 603 is used to execute; Figure 2 The step S104 shown in FIG. 1 can be performed by Figure 6 According to one embodiment of the present application, Figure 6 The various modules in the data verification device shown can be combined into one or several units separately or in whole, or one (some) of the units can be further divided into multiple functionally smaller sub-units, which can achieve the same operation without affecting the realization of the technical effects of the embodiments of the present application. The above modules are divided based on logical functions. In practical applications, the functions of one module can also be implemented by multiple units, or the functions of multiple modules can be implemented by one unit. In other embodiments of the present application, the blockchain-based data processing device may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented by the collaboration of multiple units.
[0154] According to another embodiment of the present application, the program can be executed by running on a general-purpose computer device such as a computer including a central processing unit (CPU), a random access memory medium (RAM), a read-only memory medium (ROM), and other processing elements and storage elements. Figure 2 A computer program (including program code) for each step involved in the corresponding method shown in Figure 6 The data verification device based on blockchain shown in the embodiment of the present application is implemented to realize the data verification method based on blockchain. The above computer program can be recorded on, for example, a computer-readable recording medium, and loaded into the above computing device through the computer-readable recording medium, and run therein.
[0155] In the embodiment of the present application, the first terminal pre-reads the to-be-selected blocks in the blockchain network to a local to-be-selected block set, and the to-be-selected blocks include the electronic certificate of the terminal user of the second terminal; therefore, when the first terminal is not connected to the blockchain network, and receives a business processing request from the second terminal, the to-be-selected block set can be read locally; this can effectively avoid the problem that the first terminal cannot read the electronic certificate of the terminal user of the second terminal due to the unconnected state between the first terminal and the blockchain network, resulting in the target business not being processed; it can ensure that the target business is processed normally and improve business processing efficiency. Furthermore, since different to-be-selected blocks in the to-be-selected block set record the electronic certificates of the terminal user at different times, that is, the to-be-selected blocks in the to-be-selected block set record the dynamic electronic certificates of the terminal user (that is, dynamic user information). Therefore, the first terminal can obtain the block information of the to-be-selected block in the to-be-selected block set, determine the update time of the terminal user's electronic certificate according to the block information of the to-be-selected block in the to-be-selected block set, and verify the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time, so as to effectively obtain the updated electronic certificate of the terminal user and ensure the accuracy of the electronic certificate. Therefore, in the case where the electronic certificate is valid, the first terminal processes the target business according to the valid electronic certificate, that is, by improving the accuracy and authenticity of the electronic certificate, it can ensure that the target business is accurately and effectively executed.
[0156] See also Figure 7 , Figure 7 Schematic diagram of the structure of a computer device provided in an embodiment of the present application. Figure 7 As shown, the above-mentioned computer device 70 may include: a processor 701, a network interface 704 and a memory 705. In addition, the above-mentioned computer device 70 may also include: a user interface 703, and at least one communication bus 702. Among them, the communication bus 702 is used to realize the connection and communication between these components. Among them, the user interface 703 may include a display screen (Display), a keyboard (Keyboard), and the user interface 703 may optionally include a standard wired interface and a wireless interface. The network interface 704 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 705 may be a high-speed RAM memory, or it may be a non-volatile memory (non-volatile memory), such as at least one disk storage. The memory 705 may optionally also be at least one storage device located away from the aforementioned processor 701. As Figure 7 As shown, the memory 705 as a computer-readable storage medium may include an operating system, a network communication module, a user interface module, and a device control application program.
[0157] exist Figure 7 In the computer device 70 shown, the network interface 704 can provide a network communication function; the user interface 703 is mainly used to provide an input interface for the user; and the processor 701 can be used to call the device control application stored in the memory 705 to achieve:
[0158] When the first terminal is not connected to the blockchain network, receiving a processing request for a target service from the second terminal;
[0159] Reading a set of blocks to be selected from a local cache, wherein the blocks to be selected in the set of blocks to be selected all include the electronic certificate of the terminal user of the second terminal, and the blocks to be selected in the set of blocks to be selected are read from the blockchain network by the first terminal when the first terminal is in a connected state with the blockchain network;
[0160] Obtaining block information of the to-be-selected block in the to-be-selected block set, determining an update time of the electronic certificate of the terminal user according to the block information of the to-be-selected block in the to-be-selected block set, and verifying the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time;
[0161] The above target business is processed based on valid electronic certificates.
[0162] In one embodiment, the block information includes a timestamp, and the processor 701 determines the update time of the electronic certificate of the terminal user according to the block information of the selected block in the set of selected blocks, including:
[0163] Acquire a first time corresponding to a timestamp of a block to be selected in the set of blocks to be selected, and acquire a system time of the first terminal as a second time;
[0164] Obtaining the time interval between the first time and the second time;
[0165] Determine the candidate block with the smallest time interval in the candidate block set as the target block;
[0166] The time corresponding to the timestamp of the target block is determined as the update time of the electronic certificate of the terminal user.
[0167] In one embodiment, the block information includes a block height; the processor 701 determines the update time of the electronic certificate of the terminal user according to the block information of the selected block in the selected block set, including:
[0168] Obtain the candidate block with the largest block height from the above candidate block set as the target block;
[0169] The time corresponding to the timestamp of the target block is determined as the update time of the electronic certificate of the terminal user.
[0170] In one embodiment, the block information includes a signature of the third terminal, and the processor 701 determines the update time of the electronic certificate of the terminal user according to the block information of the selected block in the set of selected blocks, including:
[0171] Obtaining the public key of the third terminal;
[0172] Verifying the signature of the third terminal using the public key of the third terminal;
[0173] The candidate block that has passed the signature verification in the above candidate block set is determined as the authentication block;
[0174] Determine the block with the highest block height among the above authentication blocks as the target block;
[0175] The time corresponding to the timestamp of the target block is determined as the update time of the electronic certificate of the terminal user.
[0176] In one embodiment, the processor 701 executes the verification of the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time, including:
[0177] If the update time is within the first time period, the first terminal determines that the electronic certificate in the target block is valid.
[0178] In one embodiment, the processor 701 may call the program code to perform the following operations:
[0179] receiving a request from the second terminal to change the electronic certificate of the terminal user, wherein the request to change includes the changed electronic certificate;
[0180] If the changed electronic certificate is verified to be valid, the changed electronic certificate is signed using the private key of the first terminal to obtain the signature of the first terminal;
[0181] The signature of the first terminal and the changed electronic certificate are uploaded to the blockchain network.
[0182] In one embodiment, the processor 701 may call the program code to perform the following operations:
[0183] When the first terminal is connected to the blockchain network, a newly added block is obtained from the blockchain network at a second interval;
[0184] Cache the newly added blocks locally.
[0185] In one embodiment, the first terminal is connected to the first sub-terminal and the second sub-terminal, the first sub-terminal has a first sub-block to be selected in a local cache, the second sub-terminal has a second sub-block to be selected in a local cache, and the first sub-block to be selected and the second sub-block to be selected both include an electronic certificate of the terminal user, and the processor 701 may call the program code to perform the following operations:
[0186] Obtaining a first block height of the first sub-block to be selected and a second block height of the second sub-block to be selected;
[0187] If the height of the first block is greater than the height of the second block, obtaining the first sub-block to be selected from the first sub-terminal, and adding the first sub-block to be selected to the set of blocks to be selected;
[0188] If the height of the first block is less than the height of the second block, the second sub-block to be selected is obtained from the second sub-terminal, and the second sub-block to be selected is added to the set of blocks to be selected.
[0189] It should be understood that the computer device 70 described in the embodiment of the present application can execute the above Figure 2 , Figure 4 as well as Figure 5 The description of the above-mentioned blockchain-based data verification method in the corresponding embodiment can also be performed as described above. Figure 6 The description of the data verification device based on the main blockchain in the corresponding embodiment will not be repeated here. In addition, the description of the beneficial effects of the same method will not be repeated here.
[0190] In the embodiment of the present application, the first terminal pre-reads the to-be-selected blocks in the blockchain network to a local to-be-selected block set, and the to-be-selected blocks include the electronic certificate of the terminal user of the second terminal; therefore, when the first terminal is not connected to the blockchain network, and receives a business processing request from the second terminal, the to-be-selected block set can be read locally; this can effectively avoid the problem that the first terminal cannot read the electronic certificate of the terminal user of the second terminal due to the unconnected state between the first terminal and the blockchain network, resulting in the target business not being processed; it can ensure that the target business is processed normally and improve business processing efficiency. Furthermore, since different to-be-selected blocks in the to-be-selected block set record the electronic certificates of the terminal user at different times, that is, the to-be-selected blocks in the to-be-selected block set record the dynamic electronic certificates of the terminal user (that is, dynamic user information). Therefore, the first terminal can obtain the block information of the to-be-selected block in the to-be-selected block set, determine the update time of the terminal user's electronic certificate according to the block information of the to-be-selected block in the to-be-selected block set, and verify the validity of the electronic certificate in the to-be-selected block in the to-be-selected block set according to the update time, so as to effectively obtain the updated electronic certificate of the terminal user and ensure the accuracy of the electronic certificate. Therefore, in the case where the electronic certificate is valid, the first terminal processes the target business according to the valid electronic certificate, that is, by improving the accuracy and authenticity of the electronic certificate, it can ensure that the target business is accurately and effectively executed.
[0191] The embodiment of the present application also provides a computer-readable storage medium, which stores a computer program, which includes program instructions, which, when executed by a computer, causes the computer to perform the method of the aforementioned embodiment, and the computer may be part of the computer device mentioned above. For example, the processor 701 mentioned above. As an example, the program instructions may be deployed on a computer device for execution, or deployed on multiple computer devices located at one location for execution, or, executed on multiple computer devices distributed at multiple locations and interconnected by a communication network, and multiple computer devices distributed at multiple locations and interconnected by a communication network may constitute a blockchain network.
[0192] The terms "first", "second", "third" and "fourth" etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units inherent to these processes, methods, products or devices.
[0193] In the present application, "A and / or B" refers to one of the following: A, B, A and B. "At least one of..." refers to any combination of the listed items or any number of the listed items. For example, "at least one of A, B and C" refers to one of the following: A, B, C, A and B, B and C, A and C, A, B and C.
[0194] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing related hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc.
[0195] The method and related device provided by the embodiment of the present application are described with reference to the method flow chart and / or structural diagram provided by the embodiment of the present application, and can be specifically implemented by computer program instructions for each process and / or box of the method flow chart and / or structural diagram, and the combination of the process and / or box in the flow chart and / or block diagram. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for realizing the function specified in one process or multiple processes of the flow chart and / or one box or multiple boxes of the structural diagram. These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device, which implements the function specified in one process or multiple processes of the flow chart and / or one box or multiple boxes of the structural diagram. These computer program instructions may also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the structure diagram.
[0196] The above disclosure is only the preferred embodiment of the present application, which certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.
Claims
1. A data verification method based on blockchain, It is characterized in that include: When the first terminal is not connected to the blockchain network, the first terminal receives a processing request for a target service from the second terminal; The first terminal reads a set of blocks to be selected from a local cache, wherein the blocks to be selected in the set of blocks to be selected all include the electronic certificate of the terminal user of the second terminal, and the blocks to be selected in the set of blocks to be selected are read from the blockchain network by the first terminal when the first terminal is in a connected state with the blockchain network; The first terminal obtains block information of a block to be selected in the set of blocks to be selected, determines an update time of the electronic certificate of the terminal user according to the block information of the block to be selected in the set of blocks to be selected, and verifies the validity of the electronic certificate in the block to be selected in the set of blocks to be selected according to the update time; The first terminal processes the target service according to the valid electronic certificate.
2. The method according to claim 1, It is characterized in that The block information includes a timestamp, and determining the update time of the electronic certificate of the terminal user according to the block information of the to-be-selected block in the to-be-selected block set includes: The first terminal obtains a first time corresponding to a timestamp of a block to be selected in the set of blocks to be selected, and obtains a system time of the first terminal as a second time; The first terminal obtains the time interval between the first time and the second time; The first terminal determines the to-be-selected block with the smallest time interval in the set of to-be-selected blocks as the target block; The first terminal determines the time corresponding to the timestamp of the target block as the update time of the electronic certificate of the terminal user.
3. The method according to claim 1, It is characterized in that The block information includes a block height, and determining the update time of the electronic certificate of the terminal user according to the block information of the selected block in the set of selected blocks includes: The first terminal obtains a candidate block with the highest block height from the candidate block set as a target block; The first terminal determines the time corresponding to the timestamp of the target block as the update time of the electronic certificate of the terminal user.
4. The method according to claim 1, It is characterized in that The block information includes a signature of a third terminal, and determining the update time of the electronic certificate of the terminal user according to the block information of the to-be-selected block in the to-be-selected block set includes: The first terminal obtains a public key of the third terminal; The first terminal verifies the signature of the third terminal using the public key of the third terminal; The first terminal determines the candidate block in the candidate block set that has passed the signature verification as the authentication block; The first terminal determines the block with the highest block height in the authentication block as the target block; The first terminal determines the time corresponding to the timestamp of the target block as the update time of the electronic certificate of the terminal user.
5. The method according to any one of claims 2 to 4, wherein the validity of the electronic certificate in the candidate block in the candidate block set is verified according to the update time, include: If the update time is within the first time period, the first terminal determines that the electronic certificate in the target block is valid.
6. The method according to any one of claims 1 to 4, It is characterized in that The method further comprises: The first terminal receives a request from the second terminal to change the electronic certificate of the terminal user, wherein the change request includes the changed electronic certificate; If the first terminal verifies that the changed electronic certificate is valid, the first terminal signs the changed electronic certificate using the private key of the first terminal to obtain the signature of the first terminal; The first terminal uploads the signature of the first terminal and the changed electronic certificate to the blockchain network.
7. The method according to claim 6, It is characterized in that The method further comprises: When the first terminal is connected to the blockchain network, the first terminal obtains a newly added block from the blockchain network at a second time interval; The first terminal caches the newly added block locally.
8. The method according to claim 1, It is characterized in that The first terminal is connected to the first sub-terminal and the second sub-terminal, the first sub-terminal has a first sub-block to be selected in a local cache, the second sub-terminal has a second sub-block to be selected in a local cache, the first sub-block to be selected and the second sub-block to be selected both include an electronic certificate of the terminal user, and the method further includes: The first terminal obtains a first block height of the first sub-block to be selected and a second block height of the second sub-block to be selected; If the first block height is greater than the second block height, the first terminal obtains the first sub-block to be selected from the first sub-terminal, and adds the first sub-block to be selected to the set of blocks to be selected; If the first block height is less than the second block height, the first terminal obtains the second sub-block to be selected from the second sub-terminal, and adds the second sub-block to be selected to the set of blocks to be selected.
9. A data verification device based on blockchain, It is characterized in that include: A first data processing module, configured to receive a processing request for a target service from a second terminal when the first terminal is not connected to the blockchain network; A data reading module, configured to read a set of blocks to be selected from a local cache, wherein the blocks to be selected in the set of blocks to be selected all include the electronic certificate of the terminal user of the second terminal, and the blocks to be selected in the set of blocks to be selected are read from the blockchain network by the first terminal when the first terminal is in a connected state with the blockchain network; A data verification module, used to obtain block information of a block to be selected in the set of blocks to be selected, determine an update time of the electronic certificate of the terminal user according to the block information of the block to be selected in the set of blocks to be selected, and verify the validity of the electronic certificate in the block to be selected in the set of blocks to be selected according to the update time; The second data processing module is used to process the target business according to the valid electronic certificate.
10. A computer device, It is characterized in that include: Processor, memory, and network interface; The processor is connected to a memory and a network interface, wherein the network interface is used to provide a data communication function, the memory is used to store program codes, and the processor is used to call the program codes to execute the method according to any one of claims 1 to 8.
11. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor is caused to perform the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Electronic certificate management method and related equipment
CN107231351A
Information processing method and device based on block chain and computer readable storage medium
CN110598463A