On-chain and off-chain collaboration methods, devices, terminal equipment, and media
By isolating and establishing global identity chain nodes in terminal devices and anchoring off-chain asset information summary, the problem of on-chain off-chain collaboration is solved, off-chain asset transfer and information interconnection are realized, blockchain value network is built, and data security and supervision efficiency are improved.
Patent Information
- Application Number
- CN202111197609.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-14
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2041-10-14
AI Technical Summary
In the prior art, the interconnection of on-chain information and off-chain information is difficult, resulting in serious data silos, high risk of data leakage, and the storage rights and application rights of traditional data centers are not distinguished, and a unified data usage strategy is lacking.
Isolate the first node to access the global identity chain in the terminal device, assign the on-chain identity, and anchor the off-chain asset information summary and the main account identity on the global identity chain through the first node, realizing the anchoring of off-chain assets and on-chain identity.
It has realized on-chain and off-chain collaboration, supported off-chain asset transfer and information interconnection, built a blockchain value network, and ensured data security and regulatory reliability.
Smart Images

Figure CN114020832B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of blockchain technology, and in particular relates to a method, apparatus, terminal device, and medium for collaboration between an on-chain and an off-chain. Background Art
[0002] In the current Web 2.0 era, data is monopolized by a single entity, leaving individuals unable to control the lifecycle of their private data. Much of the data held in traditional institutional data centers remains unavailable to the outside world. Data desensitization, secure transmission, and access paths remain undefined, leading to a significant data silo phenomenon. Furthermore, transaction data and account systems are monopolized by a single entity, making it difficult for regulators to intervene and exposing them to significant data leakage risks. Traditional data is stored unilaterally, making it susceptible to tampering and difficult to audit. Furthermore, traditional data centers do not distinguish between storage rights and application rights, leaving no fixed policy for the sharing of revenue from data use by data owners and external users. Furthermore, traditional networks monopolize the right to maintain the status of personal data and the right to persist transaction platforms and transaction data. To address the challenges of Web 2.0, building a Web 3.0 blockchain value network and achieving decentralized data storage and circulation is essential. However, the interconnection of on-chain and off-chain information presents a major obstacle to building a blockchain value network. Therefore, facilitating collaboration between on-chain and off-chain data is a pressing issue. Summary of the Invention
[0003] In view of this, the embodiments of the present application provide a method, apparatus, terminal device and medium for on-chain and off-chain collaboration to achieve interconnection and interoperability of on-chain information and off-chain information.
[0004] In a first aspect, an embodiment of the present application provides an on-chain and off-chain collaboration method, the collaboration method being applied to a terminal device, the collaboration method comprising:
[0005] Isolate and establish a first node for accessing a global identity chain in the terminal device, where the global identity chain is used to allocate an on-chain identity to the terminal device upon application by the first node;
[0006] Obtaining the primary account identity of the terminal device, where the primary account identity is the on-chain identity assigned to the terminal device in the global identity chain;
[0007] Generate a first off-chain asset information summary based on the off-chain assets of the terminal device;
[0008] Anchoring the first off-chain asset information summary and the primary account identity on the global identity chain through the first node.
[0009] In a second aspect, an embodiment of the present application provides an on-chain and off-chain collaboration device, the collaboration device being applied to a terminal device, the collaboration device comprising:
[0010] an on-chain identity maintenance module, configured to isolate and establish a first node in the terminal device for accessing a global identity chain, wherein the global identity chain is configured to allocate an on-chain identity to the terminal device upon application by the first node;
[0011] A primary account identity acquisition module, configured to acquire the primary account identity of the terminal device, wherein the primary account identity is the on-chain identity assigned to the terminal device in the global identity chain;
[0012] An off-chain asset management module, configured to generate a first off-chain asset information summary based on the off-chain assets of the terminal device;
[0013] An asset anchoring identity module, configured to anchor the first off-chain asset information summary and the primary account identity on the global identity chain through the first node.
[0014] In a third aspect, an embodiment of the present application provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor implements the collaboration method described in the first aspect when executing the computer program.
[0015] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the collaboration method as described in the first aspect is implemented.
[0016] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when executed on a terminal device, enables the terminal device to execute the collaboration method described in the first aspect above.
[0017] Compared with the prior art, the beneficial effects of the embodiments of the present application are as follows: the present application establishes a first node for accessing the global identity chain in isolation in the terminal device, uses the on-chain identity assigned to the terminal device in the global identity chain as the primary account identity, and generates a first off-chain asset information summary based on the off-chain assets of the terminal device. The first off-chain asset information summary and the primary account identity are anchored on the global identity chain through the first node, thereby realizing the anchoring of off-chain assets and on-chain identities, which can be used for on-chain and off-chain collaboration, and further can realize the off-chain asset transfer and information interconnection of terminal devices under on-chain and off-chain collaboration, and can be used to realize the construction of a blockchain value network. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0019] Figure 1 This is a flowchart of an on-chain and off-chain collaboration method provided in Example 1 of the present application;
[0020] Figure 2 This is a flowchart of an on-chain and off-chain collaboration method provided in Example 2 of the present application;
[0021] Figure 3 This is a schematic diagram of the structure of an on-chain and off-chain collaboration device provided in Example 3 of the present application;
[0022] Figure 4 This is a structural diagram of a terminal device provided in Example 4 of the present application. DETAILED DESCRIPTION
[0023] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.
[0024] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.
[0025] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0026] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.
[0027] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0028] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0029] The on-chain and off-chain collaboration method provided in the embodiment of the present application can be applied to devices such as handheld computers, desktop computers, laptops, ultra-mobile personal computers (UMPCs), netbooks, cloud servers, and personal digital assistants (PDAs). The embodiment of the present application does not impose any restrictions on the specific type of terminal device.
[0030] It should be understood that the size of the serial numbers of the steps in the following embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0031] In order to illustrate the technical solution of the present application, specific embodiments are provided below.
[0032] See also Figure 1 , is a flowchart of a chain-chain collaboration method provided in Example 1 of the present application. The collaboration method is applied to a terminal device, such as Figure 1 As shown, the collaborative method may include the following steps:
[0033] Step S101: Isolate and establish a first node for accessing the global identity chain in a terminal device.
[0034] Among them, the global identity chain is used to allocate on-chain identities to terminal devices under the application of the first node.
[0035] The terminal devices corresponding to the on-chain identities assigned in the global identity chain can jointly form a blockchain value network. The terminal devices can transmit messages in a User Datagram Protocol (UDP)-like and Transmission Control Protocol (TCP)-like manner, thereby building corresponding application services. When assigning on-chain identities to terminal devices, the global identity chain can assign on-chain identities to terminal devices based on the distribution of terminal devices and their corresponding logical location topology, such as using a distributed hash table (DHT).
[0036] Isolation can be achieved by physically isolating namespaces through partitioning, thereby maintaining the identities of different nodes on different chains. A node representing the global identity chain, known as the first node, must be built on the terminal device. If nodes for other blockchains are required, separate nodes corresponding to the different roles participating in different blockchains should be established. For example, if redundant storage is required when participating in namespace-1 chain, a storage node for namespace-1 chain should be established and maintained on the terminal device. If only on-chain verification is required when participating in namespace-2 chain, a light node for namespace-2 chain should be established and maintained on the terminal device.
[0037] Terminal devices can be various types of devices, such as institutional, personal, and IoT devices. Institutional devices can include servers and databases, personal devices can include mobile phones and computers, and IoT devices can include smart homes, smart wearables, and vehicle controllers. This application does not limit the type of terminal device, and corresponding methods can be added to the terminal device as needed to implement corresponding functions.
[0038] Terminal devices can access Layer 1 and Layer 2. Layer 1 is a digital twin world composed of blockchain networks, that is, nodes are set up in terminal devices to connect to the above-mentioned other blockchains. Layer 2 is the physical real world composed of off-chain assets, that is, the off-chain assets of terminal devices. Layer 1 and Layer 2 networks share the value network composed of terminal devices in the global identity chain to route and forward messages.
[0039] Step S102: Obtain the primary account identity of the terminal device.
[0040] The primary account identity is the on-chain identity assigned to the terminal device in the global identity chain. The identity assigned to the terminal device by the global identity chain is the primary account identity of the terminal device, which uniquely identifies the terminal device in the global identity chain. This primary account identity can be an identity document (ID) or a hash value.
[0041] Optionally, the collaborative approach also includes:
[0042] When a transaction is initiated on a terminal device, the transaction is endorsed based on the identity of the primary account and a group signature is obtained;
[0043] A group signature is added to the transaction, and based on the transaction, a transaction request is initiated to the counterparty. The group signature is used to instruct the counterparty to verify the transaction request through the group public key.
[0044] The master account identity can be used for group signature authentication. The group signature is used to indicate to the counterparty that a transaction request initiated by an asset within the terminal device is endorsed by the master account identity and that the administrator of the group signature is the terminal device. For example, an IoT device belonging to an institution's terminal device periodically initiates a transaction request to a counterparty. The transaction request must include the group signature endorsed by the terminal device, and the counterparty can verify the transaction request using the corresponding group public key.
[0045] Step S103: Generate a first off-chain asset information summary based on the off-chain assets of the terminal device.
[0046] Among them, the off-chain assets of the terminal device can refer to assets such as equipment, platforms, databases, resources, etc. belonging to the terminal device, or assets such as funds, stocks, gold, etc. belonging to the owner of the terminal device. For example, the owner of the terminal device holds funds in a bank, which can be the off-chain assets of the terminal device. For example, the terminal device is an institutional server, and there are also devices distributed in the institution that use the services provided by the server. These devices can be the off-chain assets of the terminal device.
[0047] Because off-chain assets are private information of the terminal device or its owner, it is necessary to obtain the corresponding information digest of the off-chain assets to prevent the leakage of private information. The information digest can refer to the encrypted data obtained by encrypting the data using a corresponding algorithm. For example, the corresponding data can be converted into a hash value using a hash function, or the off-chain assets of the terminal device can be encrypted using a message digest algorithm. The encryption process does not require a key, and the encrypted data cannot be decrypted.
[0048] The off-chain assets of terminal devices can be obtained through recording and statistics. Recording can mean that when an asset is allocated to a terminal device, the asset information and other data of the asset are recorded in the terminal device. Statistics can mean that the terminal device sends an information acquisition instruction to its subordinate devices, and its subordinate devices respond to the information acquisition instruction and feedback the corresponding information. The terminal device counts the corresponding information as its off-chain assets.
[0049] Optionally, the collaborative approach also includes:
[0050] Obtain asset information sent by the party that owns the target asset;
[0051] Based on the asset information, verify whether the target asset is already an off-chain asset of the on-chain identity assigned in the global identity chain;
[0052] If the target asset is not the off-chain asset of the target on-chain identity assigned in the global identity chain, the target asset will be used as the off-chain asset of the terminal device;
[0053] If the target asset is an off-chain asset of the target on-chain identity assigned in the global identity chain, the target asset will be allocated based on the negotiation between the target on-chain identity and the terminal device.
[0054] Assets that do not belong to the terminal device can be registered as off-chain assets of the terminal device. This registration can mean establishing a subordinate relationship between the terminal device and the asset. If the asset is a virtual asset, the virtual asset can be directly stored in the terminal device. If the asset is a physical asset, the physical asset information needs to be stored in the terminal device. If the target asset has been registered as an off-chain asset of another device, the target asset can be transferred or jointly held based on the negotiation between the other device and the terminal device to achieve the distribution of the target asset.
[0055] To register as a subordinate of a terminal device, the party that owns the target asset sends the asset information to the terminal device. The terminal device then verifies whether the target asset is already an off-chain asset of another device or another device owner that participates in the global identity chain and has an assigned on-chain identity. If the target asset is not an off-chain asset with an assigned on-chain identity in the global identity chain, meaning it does not have a subordinate relationship with another device, indicating that the target asset is a legitimate asset, the target asset can be used as an off-chain asset of the terminal device.
[0056] Optionally, the collaborative approach also includes:
[0057] When connecting to heterogeneous data sources through adapter interfaces, obtain standardized data corresponding to the data from the heterogeneous data sources;
[0058] Use standardized data as off-chain assets of terminal devices.
[0059] Among them, in order to connect to heterogeneous data sources and obtain heterogeneous data, it is necessary to adapt the heterogeneous data sources through the adaptation interface. In specific applications, the adaptation interface can also establish adaptation with interfaces in traditional financial and medical fields and adaptation with database views, thereby enhancing the scope of application.
[0060] This method contains a heterogeneous storage and computing grid, which can convert heterogeneous data sources into standardized data and store them. The stored standardized data serves as an off-chain asset of the terminal device.
[0061] Optionally, the collaborative approach also includes:
[0062] By penetrating the intranet proxy, heterogeneous storage and computing networks can access the external network to obtain the off-chain assets of terminal devices in the external network.
[0063] Among them, the intranet penetration agent uses technologies such as network proxy to enable heterogeneous storage and computing networks in the intranet to access the external network to obtain corresponding off-chain assets.
[0064] For different types of terminal devices, different components can be set to achieve corresponding functions. For example, for institutional type terminal devices, the terminal devices can also include non-perception docking components, data interconnection components and institutional business related components. The non-perception docking component includes the above-mentioned heterogeneous storage and computing grid and data adaptation middleware, which is used to connect to heterogeneous data sources, store standardized data, and establish interface adaptation in traditional financial and medical fields and interface adaptation of database views. The data interconnection component includes the above-mentioned intranet penetration agent, which is used to allow the heterogeneous storage and computing grid in the intranet to access the external network or be accessed by the external network. The institutional business related component may refer to the authentication middleware, which is used to perform identity authentication and permission control for external network access.
[0065] For personal and IoT terminal devices, privacy management components and other asset management components can be set up to implement privacy management, asset management and other functions.
[0066] Step S104: Anchor the first off-chain asset information summary and the primary account identity on the global identity chain through the first node.
[0067] Among them, the first node is a node of the global identity chain. The first node sends the above-obtained first off-chain asset information summary to the first node, and the first node associates and binds it with the corresponding master account identity and puts it on the chain. That is, the first off-chain asset information summary can be anchored to the master account identity on the global identity chain.
[0068] The owner of the terminal device needs to record the balance sheet in real time and synchronize the information summary of the off-chain assets to the main account identity in real time to facilitate supervision and audit by regulators.
[0069] Optionally, if the terminal device is a supervisory device, the collaboration device further includes:
[0070] Node maintenance module, used to maintain redundant computing nodes and redundant storage nodes of supervisory equipment;
[0071] The monitoring module is used to monitor the transfer process of assets or information of all devices on the global identity chain based on the redundant computing nodes and redundant storage nodes of the supervisory equipment.
[0072] End devices with a regulatory structure must participate in the global identity chain and be configured with redundant computing and storage nodes to monitor asset changes in other end devices in real time. Regulatory agencies maintain on-chain and off-chain collaboration methods, participate in namespace-n (n is a natural number) chains, and oversee Layer 1. Regulatory agencies must participate in the namespace-0 global identity chain and maintain full nodes (redundant computing and redundant storage) to monitor sandbox asset hash changes and inter-chain collaboration information in real time. If regulatory agencies need to oversee namespace-n (n!=0) chains, they can maintain full nodes for the corresponding chains.
[0073] A value network is constructed based on the internet IP identity of the primary account for on-chain and off-chain collaboration. Regarding persistence (i.e., accounting), the application chain records transactions and collaboration information between terminal devices in real time. Accounting is performed in two ways: if the value transfer occurs within an application chain, it is recorded only in the storage node of that application chain. If the value transfer occurs between application chains, it is recorded in the witness module of the global identity chain and the storage nodes of the relevant application chains. Message transmission: This constructs a stateless blockchain value transmission method, where each transmission action is unconnected. When an application chain sends a request to multiple application chains or the global identity chain and then returns a receipt, the blockchains or cross-chain gateways involved do not need to record this transmission process, and message retransmissions are not recorded. The cross-chain gateway can be compared to a router in the information internet, similar to the way stateless HTTP uses stateful TCP under the hood. Furthermore, the stateless IP uniquely identifies the primary account identity for on-chain and off-chain collaboration.
[0074] The embodiment of the present application establishes a first node for accessing the global identity chain in isolation in the terminal device, uses the on-chain identity assigned to the terminal device in the global identity chain as the primary account identity, and generates a first off-chain asset information summary based on the off-chain assets of the terminal device. The first off-chain asset information summary and the primary account identity are anchored on the global identity chain through the first node, thereby realizing the anchoring of off-chain assets and on-chain identities. This can be used for on-chain and off-chain collaboration, and further, the off-chain asset transfer and information interconnection of the terminal device can be realized under the on-chain and off-chain collaboration, which can be used to realize the construction of a blockchain value network.
[0075] See also Figure 2 , is a flowchart of a chain-on-chain collaboration method provided in Example 2 of this application. The collaboration method can be used in terminal devices, such as Figure 2 As shown, the collaborative method may include the following steps:
[0076] Step S201: Isolate and establish a first node for accessing the global identity chain in a terminal device.
[0077] Step S202: Obtain the primary account identity of the terminal device.
[0078] Step S203: Generate a first off-chain asset information summary based on the off-chain assets of the terminal device.
[0079] Among them, the contents of step S201 and step S203 are the same as those of the above-mentioned step S101 and step S103. Please refer to the description of the above-mentioned step S101 and step S103, and no further details will be given here.
[0080] Step S204: Detect whether the terminal device includes the target node for accessing the target application chain established in isolation.
[0081] The target application chain can refer to any blockchain described in the first embodiment. If a terminal device wants to participate in the target application chain, it needs to establish a target node in isolation. The target node is used to access the target application chain for data exchange.
[0082] The above-mentioned target application chain records transactions and stores collaborative information in real time. If the transaction is a value transfer within the target application chain, it is only recorded in the storage node of the target application chain. If the transaction is a value transfer between two chains, it is recorded in the global identity chain (i.e., collaborative information storage) and the storage nodes of the two chains.
[0083] Step S205: If it is detected that the terminal device contains a target node for accessing the target application chain established in isolation, a summary of the asset information off the second chain is obtained.
[0084] The second off-chain asset information digest refers to the off-chain asset information digest of the target node. The target node is the node in the terminal device. The owner of the terminal device can configure the corresponding assets in the target node, which means that the target node also contains off-chain assets. To prevent the leakage of private information such as off-chain assets, it is necessary to convert the off-chain assets into an information digest using a corresponding algorithm. Please refer to the description of the first embodiment above and will not be repeated here.
[0085] Step S206: Anchor the first off-chain asset information summary, the second off-chain asset information summary, and the primary account identity on the global identity chain through the first node.
[0086] Among them, the off-chain assets of the target node are also the off-chain assets of the terminal device. Therefore, the first off-chain asset information summary and the second off-chain asset information summary obtained above are both sent to the first node. The first node associates and binds them with the corresponding master account identity and puts them on the chain. That is, the first off-chain asset information summary, the second off-chain asset information summary and the master account identity can be anchored on the global identity chain.
[0087] When anchoring the second off-chain asset information summary with the primary account identity, it is also necessary to specify the ownership, usage rights, lease rights, etc. of this part of the off-chain assets, and limit the methods of counterparty retrieval, trading, and collaboration. At the same time, it is also necessary to determine whether this part of the off-chain assets can be bound to multiple blockchains to participate in the profit sharing based on specific industry standards.
[0088] Optionally, when a second node connected to the first application chain and a third node connected to the second application chain are isolated and established in the terminal device, the collaboration method further includes:
[0089] Obtain the first application account identity and second application account identity of the terminal device, where the first application account identity is the on-chain identity allocated by the terminal device from the first application chain at the request of the second node, and the second application account identity is the on-chain identity allocated by the terminal device from the second application chain at the request of the third node;
[0090] When detecting a cross-chain asset or information transfer from the second node to the third node, if the primary account identity is associated with the second application account identity, the identity of the third node is confirmed to be authentic; or when detecting a cross-chain asset or information transfer from the third node to the second node, if the primary account identity is associated with the first application account identity, the identity of the second node is confirmed to be authentic.
[0091] The first application chain and the second application chain both belong to the target application chain, and the corresponding second and third nodes both belong to the target node. There are at least three nodes in the terminal device, namely the first node, the second node, and the third node. The second node and the third node belong to different application chains, which can realize cross-chain asset transfer and information transfer. When conducting cross-chain asset transfer or information transfer transactions, the first node is used to witness the transaction and simultaneously upload the transaction to the global identity chain to obtain a witness certificate, thereby enabling autonomous collaboration between chains.
[0092] The association between the master account identity and the application account identity can be used to confirm the authenticity of the destination party's identity during cross-chain asset or information transfers. It can also be used to verify the legitimacy and validity of assets and information during inter-chain asset and information interactions. It can also be used for collaboration and witnessing of inter-chain distributed transactions.
[0093] Optionally, when the terminal device establishes a fourth node for accessing the third application chain and the target device establishes a fifth node of the third application chain, the collaboration apparatus further includes:
[0094] A second application identity acquisition module is configured to acquire a third application account identity of the terminal device and a fourth application account identity of the target device, wherein the third application account identity is an on-chain identity allocated by the terminal device from the third application chain at the request of the fourth node, and the fourth application account identity is an on-chain identity allocated by the target device from the third application chain at the request of the fifth node;
[0095] The second identity authenticity confirmation module is used to determine the authenticity of the identities of the fourth node and the fifth node when detecting the transfer of assets or information between the fourth node of the terminal device and the fifth node of the target device, if the main account identity of the terminal device is associated with the third application account identity, and the main account identity of the target device is associated with the fourth application account identity.
[0096] The method of this application can be used to build a new e-commerce trading platform, where the off-chain assets of terminal device owners can be traded and evaluated on the chain. The method of this application can also be used to build a new social networking platform, where terminal device owners can transfer information and assets through the blockchain value network, and social information is stored locally on the terminal device as off-chain assets. The method of this application can also be used to build a new investment and financing long-term and short-term lending platform, where individual or institutional terminal devices can invest and finance with each other, and engage in long-term and short-term lending. The credit score of the terminal device owner is maintained by the global identity chain and related application chains.
[0097] The method of the present application can be used to build a new type of medical service platform. The data generated during the use of IoT devices such as medical devices, the data generated by personal medical treatment, the data generated by hospital diagnosis and treatment, and other private information generate an off-chain asset information summary, which is synchronized in real time to the asset hash field of the global identity chain. The private information is stored locally on the IoT device, individual or platform. Long-term care insurance and specific nursing services collaborate and store evidence in the blockchain value network, and the credit score of the doctor-patient interaction evaluation is synchronized in real time to the global identity chain or related application chain. Based on the long-term investment cooperation and R&D of medicine, medical devices, scientific researchers, suppliers, manufacturers, medical insurance institutions, and social capital, a medical investment bank is established. The medical investment bank can borrow from other financial institutions. As a bridge between the wholesale and retail ends, the medical investment bank helps the value flow of the new medical service platform.
[0098] Taking the blockchain value network composed of the terminal devices of this application in the investment, R&D, production and return of medical machinery in the medical field as an example, this paper explains the collaborative mode of real estate investment trusts (REITs) in the financing of light assets such as new medical infrastructure and medical equipment movables, and expounds on the new infrastructure and circulation mode of value circulation in the value network in the Web3.0 digital economy era.
[0099] Build terminal devices for relevant personnel, institutions, and the Internet of Things (IoT). All terminal devices apply for master account identities from the global identity chain. Terminal devices independently participate in relevant application chains and generate on-chain application account identities for these chains. Medical investment banks, medical insurance bureaus, suppliers, manufacturers, research centers, and hospitals establish institutional terminal devices, while social capital investors and medical device companies establish personal or IoT terminal devices.
[0100] The off-chain asset summary of all terminal devices is stored in the global identity chain in real time. Social capital investors, medical investment banks, research centers, manufacturers, hospitals and other investment and financing stakeholders make long-term and short-term loans through the investment application chain. The portfolio investment strategy and investment return rate are maintained by the application chain contract itself.
[0101] Scientific research centers, hospitals and other institutions maintain the R&D process of medical devices through the R&D application chain. R&D funds are transferred across the investment application chain. The global identity chain serves as a witness, and the specific fund transfer information is directly transmitted between the two application chains.
[0102] Suppliers, manufacturers, research centers, etc. maintain the supply chain and production process of medical devices through the production application chain.
[0103] Medical insurance bureaus, hospitals, medical devices, etc. maintain the use process of medical devices through the return application chain. The information on the use process of medical devices is uploaded to the terminal devices of the Internet of Things through the Internet of Things. The off-chain assets of the terminal devices of the Internet of Things are connected and interconnected with traditional data centers.
[0104] The embodiment of this application establishes a target node that accesses the target application chain and anchors the target node's off-chain assets to the master account identity, enabling management of all off-chain assets and a wider range of applications. The blockchain value network established based on the method of this application can be used to build new e-commerce, social networking, long-term and short-term lending, and medical service applications. While storing the private data of individuals, institutions, and IoT devices off-chain, on-chain transactions can be achieved, ensuring the security of the information.
[0105] The on-chain and off-chain collaboration method corresponding to the above embodiment is applied to the terminal device. Figure 3A structural block diagram of the on-chain and off-chain collaboration device provided in Example 3 of the present application is shown. The collaboration device is applied to a terminal device. For ease of explanation, only the parts related to the embodiment of the present application are shown.
[0106] See also Figure 3 , the collaboration device includes:
[0107] The on-chain identity maintenance module is used to isolate and establish a first node in the terminal device to access the global identity chain. The global identity chain is used to allocate an on-chain identity to the terminal device upon application by the first node.
[0108] The master account identity acquisition module is used to obtain the master account identity of the terminal device. The master account identity is the on-chain identity assigned to the terminal device in the global identity chain;
[0109] A first off-chain asset management module, configured to generate a first off-chain asset information summary based on the off-chain assets of the terminal device;
[0110] The first asset anchoring identity module is used to anchor the first off-chain asset information summary and the primary account identity on the global identity chain through the first node.
[0111] Optionally, the collaboration device further includes:
[0112] The asset information acquisition module is used to obtain the asset information sent by the party that owns the target asset;
[0113] The asset information verification module is used to verify whether the target asset is an off-chain asset of the on-chain identity assigned in the global identity chain based on the asset information;
[0114] The first asset statistics module is configured to treat the target asset as an off-chain asset of the terminal device if the target asset is not an off-chain asset of the on-chain identity assigned in the global identity chain;
[0115] If the target asset is an off-chain asset of the target on-chain identity assigned in the global identity chain, the target asset will be allocated based on the negotiation between the target on-chain identity and the terminal device.
[0116] Optionally, the collaboration device further includes:
[0117] The group signature module is used to endorse the transaction and obtain the group signature based on the identity of the primary account when the terminal device initiates the transaction;
[0118] The transaction initiation module is used to add a group signature to the transaction and initiate a transaction request to the counterparty based on the transaction. The group signature is used to instruct the counterparty to verify the transaction request through the group public key.
[0119] Optionally, the collaboration device further includes:
[0120] A node detection module is used to detect whether the terminal device contains a target node for accessing the target application chain established in isolation;
[0121] The second off-chain asset management module is configured to obtain a second off-chain asset information summary upon detecting that the terminal device includes a target node that is isolated and connected to the target application chain. The second off-chain asset information summary refers to the off-chain asset information summary of the target node;
[0122] The second asset anchoring identity module is used to anchor the off-chain asset information summary of the target node and the primary account identity on the global identity chain through the first node.
[0123] Optionally, when a second node connected to the first application chain and a third node connected to the second application chain are isolated and established in the terminal device, the collaboration apparatus further includes:
[0124] A first application identity acquisition module is configured to acquire a first application account identity and a second application account identity of a terminal device. The first application account identity is an on-chain identity allocated by the terminal device from the first application chain upon application by the second node. The second application account identity is an on-chain identity allocated by the terminal device from the second application chain upon application by the third node.
[0125] The first identity authenticity confirmation module is used to confirm the authenticity of the third node's identity when detecting a cross-chain asset or information transfer from the second node to the third node, if the master account identity is associated with the second application account identity; or to confirm the authenticity of the second node's identity when detecting a cross-chain asset or information transfer from the third node to the second node, if the master account identity is associated with the first application account identity.
[0126] Optionally, when the terminal device establishes a fourth node for accessing the third application chain and the target device establishes a fifth node of the third application chain, the collaboration apparatus further includes:
[0127] A second application identity acquisition module is configured to acquire a third application account identity of the terminal device and a fourth application account identity of the target device, wherein the third application account identity is an on-chain identity allocated by the terminal device from the third application chain at the request of the fourth node, and the fourth application account identity is an on-chain identity allocated by the target device from the third application chain at the request of the fifth node;
[0128] The second identity authenticity confirmation module is used to determine the authenticity of the identities of the fourth node and the fifth node when detecting the transfer of assets or information between the fourth node of the terminal device and the fifth node of the target device, if the main account identity of the terminal device is associated with the third application account identity, and the main account identity of the target device is associated with the fourth application account identity.
[0129] Optionally, if the terminal device is a supervisory device, the collaboration device further includes:
[0130] Node maintenance module, used to maintain redundant computing nodes and redundant storage nodes of supervisory equipment;
[0131] The monitoring module is used to monitor the transfer process of assets or information of all devices on the global identity chain based on the redundant computing nodes and redundant storage nodes of the supervisory equipment.
[0132] It should be noted that the information interaction, execution process and other contents between the above modules are based on the same concept as the method embodiment of this application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0133] Figure 4 This is a schematic diagram of the structure of a terminal device provided in Example 4 of this application. Figure 4 As shown, the terminal device 4 of this embodiment includes: at least one processor 40 ( Figure 4 Only one is shown), a memory 41, and a computer program 42 stored in the memory 41 and executable on at least one processor 40. When the processor 40 executes the computer program 42, the steps in any of the above-mentioned on-chain and off-chain collaboration method embodiments are implemented.
[0134] The terminal device may include, but is not limited to, a processor 40 and a memory 41. Those skilled in the art will understand that Figure 4 It is only an example of the terminal device 4 and does not constitute a limitation on the terminal device 4. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include input and output devices, network access devices, etc.
[0135] The processor 40 may be a CPU, or other general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor may be a microprocessor or any conventional processor.
[0136] In some embodiments, the memory 41 may be an internal storage unit of the terminal device 4, such as a hard disk or memory of the terminal device 4. In other embodiments, the memory 41 may also be an external storage device of the terminal device 4, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash memory card, etc. equipped on the terminal device 4. Furthermore, the memory 41 may include both an internal storage unit of the terminal device 4 and an external storage device. The memory 41 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of a computer program. The memory 41 may also be used to temporarily store data that has been output or is about to be output.
[0137] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned device can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, it can implement the steps of the above-mentioned method embodiment. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include at least: any entity or device capable of carrying computer program code, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals and telecommunication signals.
[0138] The present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed through a computer program product. When the computer program product runs on a terminal device, the terminal device can implement the steps in the above-mentioned method embodiment when executing it.
[0139] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0140] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0141] In the embodiments provided in this application, it should be understood that the disclosed devices / terminal devices and methods can be implemented in other ways. For example, the device / terminal device embodiments described above are merely illustrative. For example, the division of modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0142] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0143] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. A method for collaboration between on-chain and off-chain, characterized in that: The collaboration method is applied to a terminal device, and the collaboration method includes: Isolate and establish a first node for accessing a global identity chain in the terminal device, where the global identity chain is used to allocate an on-chain identity to the terminal device upon application by the first node; Obtaining the primary account identity of the terminal device, where the primary account identity is the on-chain identity assigned to the terminal device in the global identity chain; Generate a first off-chain asset information summary based on the off-chain assets of the terminal device; Anchoring the first off-chain asset information summary and the primary account identity on the global identity chain through the first node; The collaborative method further comprises: Detecting whether the terminal device includes a target node for accessing the target application chain established in isolation; If it is detected that the terminal device includes the target node connected to the target application chain in isolation, obtaining a second off-chain asset information digest, where the second off-chain asset information digest refers to the off-chain asset information digest of the target node; The first node anchors the second off-chain asset information summary and the primary account identity on the global identity chain. When anchoring the second off-chain asset information summary and the primary account identity, the ownership, use rights, and lease rights of this off-chain asset are specified, and the methods for counterparty retrieval, trading, and collaboration are restricted. At the same time, according to specific industry standards, it is determined whether this off-chain asset should be bound to multiple blockchains to participate in profit sharing. In the case where the second node accessing the first application chain and the third node accessing the second application chain are isolated and established in the terminal device, the collaboration method further includes: Obtaining a first application account identity and a second application account identity of the terminal device, where the first application account identity is an on-chain identity allocated to the terminal device from the first application chain at the request of the second node, and the second application account identity is an on-chain identity allocated to the terminal device from the second application chain at the request of the third node; When detecting that the second node transfers cross-chain assets or information to the third node, if the master account identity is associated with the second application account identity, the identity of the third node is confirmed to be authentic; or when detecting that the third node transfers cross-chain assets or information to the second node, if the master account identity is associated with the first application account identity, the identity of the second node is confirmed to be authentic.
2. The collaboration method according to claim 1, characterized in that: The collaborative method further comprises: Obtain asset information sent by the party that owns the target asset; Verify, based on the asset information, whether the target asset is an off-chain asset of the on-chain identity assigned in the global identity chain; If the target asset is not an off-chain asset of the target on-chain identity allocated in the global identity chain, the target asset is used as an off-chain asset of the terminal device; If the target asset is an off-chain asset of the target on-chain identity allocated in the global identity chain, the target asset is allocated according to the negotiation between the target on-chain identity and the terminal device.
3. The collaboration method according to claim 1, characterized in that: The collaborative method further comprises: When the terminal device initiates a transaction, the transaction is endorsed according to the identity of the primary account to obtain a group signature; The group signature is added to the transaction, and a transaction request is initiated to the transaction counterparty based on the transaction. The group signature is used to instruct the transaction counterparty to verify the transaction request through the group public key.
4. The collaboration method according to any one of claims 1 to 3, characterized in that: In the case where the terminal device establishes a fourth node for accessing the third application chain and the target device establishes a fifth node of the third application chain, the collaboration method further includes: Obtaining a third application account identity of the terminal device and a fourth application account identity of the target device, where the third application account identity is an on-chain identity allocated to the terminal device from the third application chain at the request of the fourth node, and the fourth application account identity is an on-chain identity allocated to the target device from the third application chain at the request of the fifth node; When the transfer of assets or information between the fourth node of the terminal device and the fifth node of the target device is detected, if the main account identity of the terminal device is associated with the third application account identity, and the main account identity of the target device is associated with the fourth application account identity, then the identities of the fourth node and the fifth node are determined to be authentic.
5. The collaboration method according to any one of claims 1 to 3, characterized in that: If the terminal device is a supervisory device, the collaboration method further includes: Maintaining redundant computing nodes and redundant storage nodes of the supervisory device; Based on the redundant computing nodes and redundant storage nodes of the supervisory device, the transfer process of assets or information of all devices on the global identity chain is monitored.
6. A collaborative device between an on-chain and an off-chain, characterized in that: The collaboration device is applied to a terminal device, and the collaboration device includes: an on-chain identity maintenance module, configured to isolate and establish a first node in the terminal device for accessing a global identity chain, wherein the global identity chain is configured to allocate an on-chain identity to the terminal device upon application by the first node; A primary account identity acquisition module, configured to acquire the primary account identity of the terminal device, wherein the primary account identity is the on-chain identity assigned to the terminal device in the global identity chain; A first off-chain asset management module, configured to generate a first off-chain asset information summary based on the off-chain assets of the terminal device; A first asset anchoring identity module, configured to anchor the first off-chain asset information digest and the primary account identity on the global identity chain through the first node; Collaboration devices also include: A node detection module is used to detect whether the terminal device contains a target node for accessing the target application chain established in isolation; The second off-chain asset management module is configured to obtain a second off-chain asset information summary upon detecting that the terminal device includes a target node that is isolated and connected to the target application chain. The second off-chain asset information summary refers to the off-chain asset information summary of the target node; The second asset anchoring identity module is used to anchor the target node's off-chain asset information summary and the master account identity on the global identity chain through the first node. When anchoring the second off-chain asset information summary and the master account identity, the ownership, use rights, and lease rights of this part of the off-chain asset are specified, and the methods of retrieval, trading, and collaboration by counterparties are restricted. At the same time, according to specific industry standards, it is determined whether this part of the off-chain asset should be bound to multiple blockchains to participate in the profit sharing. In the case where the second node accessing the first application chain and the third node accessing the second application chain are isolated and established in the terminal device, the collaboration apparatus further includes: A first application identity acquisition module is configured to acquire a first application account identity and a second application account identity of a terminal device. The first application account identity is an on-chain identity allocated by the terminal device from the first application chain upon application by the second node. The second application account identity is an on-chain identity allocated by the terminal device from the second application chain upon application by the third node. The first identity authenticity confirmation module is used to confirm the authenticity of the third node's identity when detecting a cross-chain asset or information transfer from the second node to the third node, if the master account identity is associated with the second application account identity; or to confirm the authenticity of the second node's identity when detecting a cross-chain asset or information transfer from the third node to the second node, if the master account identity is associated with the first application account identity.
7. A terminal device, characterized in that: The terminal device includes a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the collaboration method according to any one of claims 1 to 5 is implemented.
8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the collaboration method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
A data security protection and sharing method based on block chain, a system and an application thereof
CN109040012A
Code chain construction method and device based on unified identifier
CN112291305A