Time domain verification method and device
By determining the target path and trusted time domain in the blockchain database and verifying it, the lack of fast storage and verification of trusted time domains in the blockchain database is solved, and fast and efficient time domain verification is achieved.
Patent Information
- Application Number
- CN202111417517.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-25
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2041-11-25
AI Technical Summary
In blockchain database application scenarios, there is a lack of implementation solutions for fast storage and verification of trusted time domains.
By determining the target path in the preset path library, carrying the timestamp data set, determining the trusted time domain to be verified based on the time domain to be verified, and verifying it. In the case of successful verification, verify the target path to determine the validation success of the time domain to be verified.
A solution to quickly verify the time domain to be verified for any requirement is realized, which improves efficiency and ensures data reliability.
Smart Images

Figure CN114357064B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present specification relate to the field of information technology, and in particular to a time domain verification method and device. Background Art
[0002] When a centralized database service provider provides services to the outside world in a blockchain-style ledger, the ledger records the relevant data records that the relevant users need to save. How to quickly verify the trusted time transaction itself in a certain ledger or a certain section of the ledger is widely needed in the application scenarios of blockchain databases. At present, there is no similar implementation solution for fast storage and verification of trusted time domains on blockchain database ledgers. Summary of the invention
[0003] In view of this, the present specification provides a time domain verification method. One or more embodiments of the present specification also relate to a time domain verification device, a computing device, a computer readable storage medium, and a computer program to solve the technical defects existing in the prior art.
[0004] According to a first aspect of an embodiment of this specification, a time domain verification method is provided, including:
[0005] Determine a target path in a preset path library, wherein the target path carries a timestamp data set;
[0006] Determining a trusted time domain to be verified from the timestamp data set according to the time domain to be verified;
[0007] Verifying the trusted time domain to be verified;
[0008] If the trusted time domain to be verified is successfully verified, verifying the target path;
[0009] When the target path verification succeeds, it is determined that the time domain to be verified succeeds.
[0010] According to a second aspect of an embodiment of this specification, a time domain verification method is provided, including:
[0011] Determine the target hash value based on requirements;
[0012] Determine a timestamp data set according to the target hash value;
[0013] Determining a trusted time domain to be verified from the timestamp data set according to the time domain to be verified;
[0014] Verifying the trusted time domain to be verified;
[0015] Determining that the target hash value verification is successful when the trusted time domain to be verified is successful;
[0016] When the target hash value is successfully verified, it is determined that the time domain to be verified is successfully verified.
[0017] According to a third aspect of an embodiment of this specification, a time domain verification device is provided, including:
[0018] A path determination module is configured to determine a target path in a preset path library, wherein the target path carries a timestamp data set;
[0019] A trusted time domain determination module is configured to determine a trusted time domain to be verified from the timestamp data set according to the time domain to be verified;
[0020] A trusted time domain verification module, configured to verify the trusted time domain to be verified;
[0021] A path verification module, configured to verify the target path if the trusted time domain to be verified is successfully verified;
[0022] The verification result determination module is configured to determine that the verification of the time domain to be verified is successful if the verification of the target path is successful.
[0023] According to a fourth aspect of the embodiments of this specification, a time domain verification device is provided, including:
[0024] A requirement determination module is configured to determine a target hash value according to the requirement;
[0025] a data set determination module, configured to determine a timestamp data set according to the target hash value;
[0026] A trusted time domain determination module is configured to determine a trusted time domain to be verified from the timestamp data set according to the time domain to be verified;
[0027] A trusted time domain verification module, configured to verify the trusted time domain to be verified;
[0028] A target hash value verification module is configured to determine that the target hash value verification is successful if the trusted time domain to be verified is successfully verified;
[0029] The verification result determination module is configured to determine that the verification of the time domain to be verified is successful if the verification of the target hash value is successful.
[0030] According to a fifth aspect of an embodiment of this specification, a computing device is provided, including:
[0031] Memory and processor;
[0032] The memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions.
[0033] According to a sixth aspect of the embodiments of this specification, a computer-readable storage medium is provided, which stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, the steps of the time domain verification method are implemented.
[0034] According to a seventh aspect of the embodiments of this specification, a computer program is provided, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the time domain verification method described in the claims.
[0035] The time domain verification method provided in the embodiment of this specification includes determining a target path in a preset path library, wherein the target path carries a timestamp data set, determining a trusted time domain to be verified from the timestamp data set according to the time domain to be verified, verifying the trusted time domain to be verified, verifying the target path when the trusted time domain to be verified is successfully verified, and determining that the verification of the time domain to be verified is successful when the verification of the target path is successful. Determining the corresponding trusted time domain according to the time domain to be verified, verifying the trusted time domain, and determining that the verification of the time domain to be verified is successful when the verification of the trusted time domain is successful, can implement a solution for verifying any required time domain to be verified, and the verification speed is fast, which improves efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 is a flow chart of a time domain verification method provided by an embodiment of this specification;
[0037] Figure 2 It is an architectural diagram of a time domain verification method provided by an embodiment of this specification;
[0038] Figure 3 is another flow chart of a time domain verification method provided by an embodiment of this specification;
[0039] Figure 4 is a schematic diagram of a time domain verification device provided by an embodiment of this specification;
[0040] Figure 5 is a flow chart of another time domain verification method provided by an embodiment of this specification;
[0041] Figure 6 is a schematic diagram of another time domain verification device provided by an embodiment of this specification;
[0042] Figure 7It is a block diagram of a computing device provided by one embodiment of the present specification. DETAILED DESCRIPTION
[0043] Many specific details are described in the following description to facilitate a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the connotation of this specification, so this specification is not limited to the specific implementation disclosed below.
[0044] The terms used in one or more embodiments of this specification are only for the purpose of describing specific embodiments, and are not intended to limit one or more embodiments of this specification. The singular forms of "a", "said" and "the" used in one or more embodiments of this specification and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0045] It should be understood that although the terms first, second, etc. may be used to describe various information in one or more embodiments of this specification, this information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0046] First, the terms involved in one or more embodiments of this specification are explained.
[0047] The trusted ledger database (LedgerDB) is a centralized, fast and cryptographically verifiable ledger database service that provides strong audit capabilities (non-repudiation and non-tamperability) in natural time.
[0048] Timestamp is data generated using digital signature technology. The object of the signature includes information such as the original file information, signature parameters, and signature time. The timestamp system is used to generate and manage timestamps. It digitally signs the signature object to generate a timestamp to prove that the original file existed before the signature time.
[0049] A Merkle tree is a tree structure that can be a binary tree or a multi-branch tree. The value of a Merkle tree child node is the content of the data item or the hash value of the data item, and the value of a non-leaf node is based on the information of its child node.
[0050] The Merkle Patricia Tree combines the advantages of the dictionary tree and the Merkle tree. In the compressed dictionary tree, the root node is empty, while the Merkle Patricia Tree can save the hash checksum of the entire tree at the root node, and the checksum is generated in the same way as the Merkle tree.
[0051] Hash value, or HASH value, is a set of binary values obtained by encrypting the file content. It is mainly used for file verification or signing.
[0052] MD5 Message-Digest Algorithm, a widely used cryptographic hash function, can generate a 128-bit (16-byte) hash value to ensure the integrity and consistency of information transmission.
[0053] In this specification, a time domain verification method is provided. This specification also involves a time domain verification device, a computing device, a computer-readable storage medium and a computer program, which are described in detail one by one in the following embodiments.
[0054] Figure 1 A flow chart of a time domain verification method provided according to an embodiment of the present specification is shown, which specifically includes the following steps.
[0055] Step 102: Determine a target path in a preset path library, wherein the target path carries a timestamp data set.
[0056] Among them, the preset path library can be a pre-established path database, which includes paths of multiple types of data, and the corresponding data can be found through these paths. The path database can be in the form of a hash tree structure. The target path can be the path of the target data to be found. When searching for the target data, the target path of the target data is first obtained, and then the search is performed according to the target path. The timestamp data set can be a data set containing timestamps, and the data set can be in the form of a hash tree structure.
[0057] In actual applications, the trusted ledger database may include data such as the timestamp of the transaction, the type of transaction, the identification code of the trader, etc. Each type of data can be associated through the path library. When a certain type of data needs to be found, the path of the data of that type in the path library must first be obtained.
[0058] For example, if we need to verify the transaction time of a shopping website, we need to obtain data about the transaction time, that is, we need to obtain a timestamp dataset, obtain the identifier of the path of the timestamp dataset, and then find the path of the timestamp dataset in the path library according to the identifier.
[0059] In an achievable embodiment, when searching for a target path, it is determined based on an identification string, and the specific implementation is as follows:
[0060] Determining the target path in the preset path library includes:
[0061] Determine the identification string based on the required attributes;
[0062] The path nodes are determined level by level in the path library according to the order of the characters in the identification character string to form the target path.
[0063] The required attribute may be the type of data to be searched, the identification string may be a string generated by encrypting the name of the timestamp data set through an encryption algorithm, and the characters in the string may be identifiers of each level of the path.
[0064] In practical applications, see Figure 2 , Figure 2 is an architectural diagram of a time domain verification method provided by an embodiment of this specification, Figure 2 Tree 1 in is a Merkle compressed prefix tree. Tree 1 is the data structure corresponding to the path library. Figure 2 The tree 2 in is a Merkle tree, and the tree 2 is the data structure corresponding to the timestamp data set. The root node (Root) refers to the root node of the tree 1, and the nodes 1 to 7 (Node1-Node7) refer to the 7 child nodes of the tree 1. The path nodes are determined in the Merkle compression prefix tree according to the characters in the identification string.
[0065] For example, the path name of the timestamp dataset is "TSA_TIMESTAMP". The MD5 information digest algorithm is used to calculate "TSA_TIMESTAMP" to obtain the string: 3359fd16. The timestamp dataset can be obtained by searching down level by level through "3", "3", "5", and "9fd16" in the string.
[0066] It should be noted that when calculating the name of the timestamp data set to obtain the identification string, not only the MD5 information digest algorithm can be used, but also the SHA256 algorithm can be used. The embodiments of this specification do not limit this, and it is sufficient to calculate the name of the timestamp data set to obtain the identification string.
[0067] The embodiments of this specification use a pre-established path library, and search for a target path in the path library according to characters in an identification string, so that a timestamp data set can be quickly found, thereby improving search efficiency.
[0068] Step 104: Determine a trusted time domain to be verified from the timestamp data set according to the time domain to be verified.
[0069] The time domain to be verified may be a transaction time interval that needs to be verified, and the trusted time domain to be verified may be multiple trusted timestamps determined in the trusted account database according to the time domain to be verified.
[0070] In practical applications, to verify transactions in any period of time in the requirements, we must first find the corresponding trusted time domain that contains the time period in the requirements. The trusted time domain can be verified. The trusted time domain can be determined based on two trusted timestamps, so we must first find two timestamps that determine the trusted time domain.
[0071] For example, the data structure of the timestamp data set is a Merkle tree, the trusted timestamps in the timestamp data set can be arranged in sequence, the trusted timestamps corresponding to the time domain to be verified are searched in the Merkle tree of the timestamp data set, and the corresponding trusted timestamps are combined into a trusted time domain.
[0072] In an achievable embodiment, the trusted timestamps at both ends of the trusted time domain can be determined by the two endpoints of the time domain to be verified. The specific implementation method is as follows:
[0073] Determining the trusted time domain to be verified from the timestamp data set according to the time domain to be verified includes:
[0074] Determining a start trusted timestamp and an end trusted timestamp from the timestamp data set according to the time domain to be verified;
[0075] The trusted time domain to be verified is determined based on the start trusted timestamp and the end trusted timestamp.
[0076] The start trusted timestamp may be a trusted timestamp at the beginning of the trusted time domain, and the end trusted timestamp may be a trusted timestamp at the end of the trusted time domain.
[0077] Continuing with the above example, the time domain to be verified is TA-TB. In the Merkle tree, the starting trusted timestamp TA1 can be found based on TA, and the ending trusted timestamp TB1 can be found based on TB. The trusted time domain is from the starting trusted timestamp to the ending trusted timestamp, that is, the trusted time domain is: TA1-TB1.
[0078] In another implementation embodiment, the search for the start trusted timestamp and the end trusted timestamp is determined based on two anchor points of the timestamp to be verified, and the specific implementation method is as follows:
[0079] Determining a start trusted timestamp and an end trusted timestamp according to the time domain to be verified includes:
[0080] Obtaining the starting anchor point and the ending anchor point of the time domain to be verified;
[0081] Find a trusted timestamp before the time of the starting anchor point from the timestamp data set and determine it as the starting trusted timestamp;
[0082] A trusted timestamp after the time of the termination anchor point is found in the timestamp data set and determined as the termination trusted timestamp.
[0083] The starting anchor point may be the start time of the time domain to be verified, and the ending anchor point may be the end time of the time domain to be verified.
[0084] Using the above example, when searching for the starting trusted timestamp TA1, the trusted timestamp TA1 before TA is found in the timestamp data set. When searching for the trusted timestamp TB1, the trusted timestamp TB1 before TB is found in the timestamp data set. For example, when TA is 2:00 and TB is 3:00, the most recent trusted timestamp before 2:00 in the timestamp data set is 1:55, so 1:55 is determined as TA1, and the most recent trusted timestamp after 3:00 in the timestamp data set is 3:25, so 3:25 is determined as TB1.
[0085] The embodiment of the present specification arranges the trusted timestamps in sequence, and two trusted timestamps of the trusted time domain can be found based on the time domain to be verified in a short time, thereby improving the search speed of the trusted time domain.
[0086] Step 106: Verify the trusted time domain to be verified.
[0087] In practical applications, verifying the trusted time domain is to verify that the trusted time domain has not been tampered with. Verifying that the trusted time domain has not been tampered with is to verify that the trusted timestamp in the trusted time domain has not been tampered with.
[0088] In an achievable embodiment, the verification capability of the data structure may be used to verify the trusted time domain to be verified, and the specific implementation method is as follows:
[0089] The verifying the trusted time domain to be verified includes:
[0090] According to the hash tree, the trusted timestamp in the trusted time domain to be verified is verified.
[0091] For example, the hash tree is a Merkle tree, which includes 8 trusted timestamps in the trusted time domain. The verification capability of the Merkle tree is used to verify the 8 trusted timestamps respectively. When the 8 trusted timestamps are successfully verified, the trusted time domain to be verified is also determined to be successfully verified.
[0092] Furthermore, in an achievable embodiment, verification is performed in a hash tree according to a hash value of a trusted timestamp, and the specific implementation is as follows:
[0093] The verifying the trusted timestamp in the trusted time domain to be verified according to the hash tree includes:
[0094] Based on the verification rule of the hash tree, verification is performed according to the hash value of the trusted timestamp in the trusted time domain to be verified;
[0095] Wherein, the leaf node in the hash tree includes the recorded hash value of the trusted timestamp.
[0096] Continuing with the above example, the 8 leaf nodes of the Merkle tree map the hash values of the 8 trusted timestamps in the trusted time domain to be verified. The hash value of the trusted timestamp is calculated and calculated upward according to the structure of the Merkle tree until the root node of the Merkle tree. When the calculated value of the hash operation of the root node is the same as the recorded hash value of the root node in the Merkle tree, it is determined that the trusted time domain verification is successful.
[0097] In another achievable embodiment, the trusted timestamp is verified based on the verification capability of the Merkle tree, and the specific implementation method is as follows:
[0098] The verification rule based on the hash tree is verified according to the hash value of the trusted timestamp in the trusted time domain to be verified, including:
[0099] Performing a hash operation on the trusted timestamp to obtain a first verification hash value;
[0100] When the first verification hash value is the same as the record hash value of the leaf node, performing a hash operation on the first verification hash value and the record hash value of the brother node of the leaf node to generate a second verification hash value;
[0101] When the second verification hash value is the same as the record hash value of the first parent node, continue to perform hash operations based on the second verification hash value and the record hash values of the sibling nodes of the first parent node until a root verification hash value is obtained, wherein the first parent node is the parent node of the leaf node;
[0102] The trusted timestamp verification is determined to be successful when the record hash value of the root node of the hash tree is the same as the root verification hash value.
[0103] Using the above example, Figure 2 Take one of the eight trusted timestamps in tree 2 as an example, perform a hash operation on the trusted timestamp to obtain a hash value HASH1 of the trusted timestamp, compare the hash value HASH1 with the record hash value HASHa in leaf node 1, when HASH1 and HASHa are the same, obtain the record hash value HASHb of the brother node 2 of leaf node 1, hash HASHa and HASHb together to obtain HASH2, when HASH2 is the same as the verification hash value HASHc in node 21, obtain the verification hash value HASHd of node 22, hash HASHc and HASHd together to obtain the verification hash value HASH3, obtain the record hash value HASHe of node 32, hash HASH3 and HASHe to obtain the root verification hash value HASH4, compare HASH4 with the record hash value HASHf of root node 41, and when HASH4 is the same as the record hash value HASHf of root node 41, it is determined that the trusted timestamp verification is successful.
[0104] The embodiments of this specification use the data structure of the Merkle tree to verify the trusted timestamp in the trusted time domain, and use the verification capability of the Merkle tree to increase the speed of verification and improve the efficiency of verification.
[0105] Step 108: Verify the target path if the trusted time domain to be verified is successfully verified.
[0106] In practical applications, when the trusted time domain verification is successful, it is also necessary to ensure that the target path corresponding to the trusted time domain has not been tampered with. When the trusted time domain verification is successful and the target path verification is successful, it can be determined that the time domain to be verified has not been modified.
[0107] In an achievable embodiment, the verification capability of the data structure may be used to verify the target path, and the specific implementation method is as follows:
[0108] The verifying the target path includes:
[0109] The target path is verified according to the index tree and the hash tree.
[0110] The index tree may be a tree structure mapped by the path library.
[0111] Specifically, the target path is verified according to the index tree and the hash tree. It can be understood that the hash tree is verified first. When the hash tree verification is successful (such as the calculated value and the recorded value are the same), the index tree is verified through the root node of the hash tree. Since the index tree is a path library mapping, verifying the index tree is to verify the target path. Therefore, accurate verification of the target path can be achieved through the hash tree and the index tree.
[0112] In the specific implementation, the specific implementation method of verifying the target path according to the index tree and the hash tree is as follows:
[0113] The verifying the target path according to the index tree and the hash tree includes:
[0114] Based on the verification rules of the index tree, verifying the target path according to the recorded hash value of the root node of the hash tree;
[0115] The branch node of the index tree includes a common hash value of the root node and the current path identifier.
[0116] Specifically, the branch node is a node of the index tree that contains information of the hash tree, and the branch node has no child nodes, and the current path identifier is an identifier string of the path node corresponding to the root node of the hash tree.
[0117] For example, see Figure 2 The index tree is a Merkle compressed prefix tree. Node 6 of the index tree can store key-value pairs, where "9fd16" is the key and the root node of the hash tree is the value. The target path is verified according to the hash value of the key-value pair until the root node (Node1) is successfully verified.
[0118] In actual applications, based on the verification rules of the index tree, the target path is verified according to the recorded hash value of the root node of the hash tree. The specific implementation method is as follows:
[0119] The verification rule based on the index tree, performing verification according to the hash value of the root node of the hash tree, includes:
[0120] Performing a hash operation on the recorded hash value of the root node and the current path identifier to obtain a third verification hash value;
[0121] When the third verification hash value is the same as the common record hash value, a fourth verification hash value is generated by performing a hash operation based on the third verification hash value and the hash value of the brother node of the branch node;
[0122] When the fourth verification hash value is the same as the hash value of the second parent node, continue to perform hash operations based on the fourth verification hash value and the hash value of the brother node of the second parent node until a root verification hash value is obtained, wherein the second parent node is the parent node of the branch node;
[0123] The trusted timestamp verification is determined to be successful when the hash value of the root node of the hash tree is the same as the root verification hash value.
[0124] The principle of the verification method of the Merkle compressed prefix tree in the above embodiment is the same as that of the verification method of the Merkle tree, which will not be repeated here.
[0125] The embodiments of this specification use the data structure of the Merkle tree to verify the trusted timestamp in the trusted time domain to ensure that the trusted timestamp has not been changed. After the trusted time domain verification is successful, the Merkle compressed prefix tree is used for verification to ensure that the target path has not been changed. The verification capability of the Merkle tree is used to increase the speed of verification. At the same time, the use of two layers of verification ensures the reliability of the data.
[0126] Step 110: Determine that the verification of the time domain to be verified is successful if the target path verification is successful.
[0127] In practical applications, the trusted time domain to be verified is first determined based on the time domain to be verified. When the trusted time domain is successfully verified, it is also necessary to ensure that the target path corresponding to the trusted time domain has not been tampered with, that is, to verify the target path. When the target path is successfully verified, it can be determined that the trusted time domain and the path where the trusted time domain is located have not been modified. Because the trusted time domain covers the time domain to be verified, the time domain to be verified is also successfully verified.
[0128] The following combination Figure 3 Taking the application of the time domain verification method provided in this specification on a shopping website as an example, the time domain verification method is further described. Figure 3 This is another flow chart of a time domain verification method provided by an embodiment of this specification, which specifically includes the following steps.
[0129] Step 302: Determine an identification string according to the required attributes.
[0130] In actual applications, the requirements may be: the transaction time of a shopping website needs to be verified. The shopping website stores the transaction time through a trusted ledger database. Data about the transaction time needs to be obtained, that is, a timestamp data set needs to be obtained. First, the identification string of the path of the timestamp data set is obtained, and then the path of the timestamp data set is found in the path library according to the identification string. Then the requirement attribute may be: timestamp.
[0131] For example, if a transaction time of a shopping website needs to be verified, the name of the path of the timestamp data set of the transaction website is obtained from the database: "TSA_TIMESTAMP".
[0132] The embodiments of this specification can directly obtain a preset identification string, thereby improving search efficiency.
[0133] Step 304: Determine the path nodes in the path library step by step according to the order of the characters in the identification string to form the target path, wherein the target path carries a timestamp data set.
[0134] In actual applications, the path library is stored in the data structure of the Merkle compressed prefix tree, and the timestamp data set is stored in the data structure of the Merkle tree. When searching for the target path, the node is determined level by level in the Merkle compressed prefix tree according to the identification character.
[0135] Specifically, the trusted ledger database includes multiple types of data, and a name is assigned to the path of each type of data. The name of the path of the timestamp data set is "TSA_TIMESTAMP". The MD5 information digest algorithm is used to calculate "TSA_TIMESTAMP" to obtain the string: 3359fd16. The string has been pre-associated with the path of the timestamp data set. By searching down level by level in the Merkel compression prefix tree for "3", "3", "5", and "9fd16" in the string, a pair of key values can be obtained, where the value is the hash value of the root node of the Merkel tree corresponding to the timestamp data set.
[0136] The embodiments of this specification use a pre-established path library, and search for a target path in the path library according to characters in an identification string, so that a timestamp data set can be quickly found, thereby improving search efficiency.
[0137] Step 306: Determine a start trusted timestamp and an end trusted timestamp from the timestamp data set according to the time domain to be verified.
[0138] Step 308: Determine the trusted time domain to be verified based on the start trusted timestamp and the end trusted timestamp.
[0139] In practical applications, to verify transactions in any period of time on a shopping website, we first need to find a trusted time domain that contains the time period in the timestamp data set according to the time period of the transaction, where the trusted time domain can be verified for credibility. In addition, the trusted time domain can be determined based on two trusted timestamps, so the premise for determining the trusted time domain through two trusted timestamps is to find two timestamps that determine the trusted time domain.
[0140] Specifically, the time domain to be verified of the shopping website is TA-TB. In the Merkle tree, the starting trusted timestamp TA1 can be found according to TA, and the ending trusted timestamp TB1 can be found according to TB. The trusted time domain is from the starting trusted timestamp to the ending trusted timestamp, that is, the trusted time domain is: TA1-TB1. When searching for the starting trusted timestamp TA1, the trusted timestamp TA1 before TA is found in the timestamp data set. When searching for the trusted timestamp TB1, the trusted timestamp TB1 before TB is found in the timestamp data set. For example, when TA is 2:00 and TB is 3:00, the most recent trusted timestamp before 2:00 in the timestamp data set is 1:55, then 1:55 is determined as TA1, and the most recent trusted timestamp after 3:00 in the timestamp data set is 3:25, then 3:25 is determined as TB1.
[0141] The embodiment of the present specification arranges the trusted timestamps in sequence, and two trusted timestamps of the trusted time domain can be found based on the time domain to be verified in a short time, thereby improving the search speed of the trusted time domain.
[0142] Step 310: Based on the verification rule of the hash tree, verification is performed according to the hash value of the trusted timestamp in the trusted time domain to be verified.
[0143] In practical applications, verifying the trusted time domain is to verify that the trusted time domain has not been tampered with. Verifying that the trusted time domain has not been tampered with is to verify that the trusted timestamp in the trusted time domain has not been tampered with.
[0144] Specifically, the hash tree is the Merkle tree corresponding to the timestamp data set, which includes 4 trusted timestamps in the trusted time domain TA1-TB1. The Merkle tree verification capability is used to verify the trusted timestamps at both ends of the 4 trusted timestamps. When the trusted timestamps at both ends are successfully verified, the trusted time domain to be verified is also determined to be successfully verified. Take one of the 4 trusted timestamps as an example, see Figure 2, perform a hash operation on the trusted timestamp to obtain a hash value HASH1 of the trusted timestamp, compare the hash value HASH1 with the record hash value HASHa in the leaf node 1, when HASH1 and HASHa are the same, obtain the record hash value HASHb of the brother node 2 of the leaf node 1, hash HASHa and HASHb together to obtain HASH2, when HASH2 and the verification hash value HASHc in the node 21 are the same, obtain the verification hash value HASHd of the node 22, hash HASHc and HASHd together to obtain the verification hash value HASH3, obtain the record hash value HASHe of the node 32, hash HASH3 and HASHe to obtain the root verification hash value HASH4, compare HASH4 with the record hash value HASHf of the root node 41, and when HASH4 and the record hash value HASHf of the root node 41 are the same, it is determined that the trusted timestamp verification is successful. The above method can be used to calculate hash values only for leaf node 1 and leaf node 4 to reduce the amount of calculation and improve calculation efficiency, because leaf node 2 is the brother node of leaf node 1, and the hash value of leaf node 2 is needed when leaf node 1 is verified; leaf node 3 is the brother node of leaf node 4, and the hash value of leaf node 3 is needed when leaf node 4 is verified. When leaf node 1 and leaf node 4 are successfully verified, it is proved that leaf node 2 and leaf node 3 are trustworthy, that is, when both trusted timestamps are successfully verified, it is determined that the trusted time domain TA1-TB1 is successfully verified, that is, the trusted time domain TA1-TB1 has not been tampered with.
[0145] The embodiments of this specification use the data structure of the Merkle tree to verify the trusted timestamp in the trusted time domain, and use the verification capability of the Merkle tree to increase the speed of verification and improve the efficiency of verification.
[0146] Step 312: Based on the verification rule of the index tree, the target path is verified according to the recorded hash value of the root node of the hash tree.
[0147] Step 314: Determine that the verification of the time domain to be verified is successful if the target path verification is successful.
[0148] In practical applications, when the trusted time domain verification is successful, it is also necessary to ensure that the target path corresponding to the trusted time domain has not been tampered with. When the trusted time domain verification is successful and the target path verification is successful, it can be determined that the time domain to be verified has not been modified.
[0149] Specifically, see Figure 2, the index tree is the Merkle compressed prefix tree corresponding to the path library. The key-value pair stored in the Node6 node of the index tree is: "9fd16" and the root node of the hash tree. The target path is verified according to the hash value of the key-value pair until the root node Node1 is successfully verified. The verification method of the Merkle compressed prefix tree is the same as the verification method of the Merkle tree, which will not be repeated here. When the trusted time domain and the target path corresponding to the trusted time domain are both successfully verified, it proves that the time domain to be verified has not been tampered with, that is, the transactions that occurred on the shopping website during the time domain to be verified are credible.
[0150] The embodiments of this specification use the data structure of the Merkle tree to verify the trusted timestamp in the trusted time domain to ensure that the trusted timestamp has not been changed. After the trusted time domain verification is successful, the Merkle compressed prefix tree is used for verification to ensure that the target path has not been changed. The verification capability of the Merkle tree is used to increase the speed of verification. At the same time, the use of two layers of verification ensures the reliability of the data.
[0151] It should be noted that the data in the timestamp data set can not only be a trusted timestamp, but also an array including a trusted timestamp. The array can be in the form of [timestamp, time log sequence number], where the time log sequence number is the label of the log record that records the trusted timestamp in the trusted ledger database. In actual applications, after the time domain to be verified is successfully verified using the time domain verification method of the embodiment of this specification, the time log in the trusted ledger database can be found through the time log sequence number corresponding to TA1 and TB1, and the time log can be verified through a third-party timestamp system to verify that the real timestamp and the trusted timestamp signature are authentic and valid, further ensuring that the time domain to be verified has not been modified.
[0152] The embodiments of this specification use the data structure of the Merkle tree to verify the trusted timestamp in the trusted time domain to ensure that the trusted timestamp has not been changed. After the trusted time domain verification is successful, the Merkle compressed prefix tree is used for verification to ensure that the target path has not been changed. The verification capability of the Merkle tree is used to increase the speed of verification. At the same time, the use of two layers of verification ensures the reliability of the data.
[0153] Corresponding to the above method embodiment, this specification also provides a time domain verification device embodiment, Figure 4 FIG. 1 is a schematic diagram of a time domain verification device provided by an embodiment of the present specification. Figure 4 As shown, the device comprises:
[0154] The path determination module 402 is configured to determine a target path in a preset path library, wherein the target path carries a timestamp data set;
[0155] A trusted time domain determination module 404 is configured to determine a trusted time domain to be verified from the timestamp data set according to the time domain to be verified;
[0156] A trusted time domain verification module 406 is configured to verify the trusted time domain to be verified;
[0157] A path verification module 408 is configured to verify the target path if the trusted time domain to be verified is successfully verified;
[0158] The verification result determination module 410 is configured to determine that the verification of the time domain to be verified is successful if the verification of the target path is successful.
[0159] Optionally, the path determination module 402 is further configured to:
[0160] Determine the identification string based on the required attributes;
[0161] The path nodes are determined level by level in the path library according to the order of the characters in the identification character string to form the target path.
[0162] Optionally, the trusted time domain determination module 404 is further configured to:
[0163] Determining a start trusted timestamp and an end trusted timestamp from the timestamp data set according to the time domain to be verified;
[0164] The trusted time domain to be verified is determined based on the start trusted timestamp and the end trusted timestamp.
[0165] Optionally, the trusted time domain determination module 404 is further configured to:
[0166] Obtaining the starting anchor point and the ending anchor point of the time domain to be verified;
[0167] Find a trusted timestamp before the time of the starting anchor point from the timestamp data set and determine it as the starting trusted timestamp;
[0168] A trusted timestamp after the time of the termination anchor point is found in the timestamp data set and determined as the termination trusted timestamp.
[0169] Optionally, the trusted time domain verification module 406 is configured to:
[0170] According to the hash tree, the trusted timestamp in the trusted time domain to be verified is verified.
[0171] Optionally, the trusted time domain verification module 406 is configured to:
[0172] Based on the verification rule of the hash tree, verification is performed according to the hash value of the trusted timestamp in the trusted time domain to be verified;
[0173] Wherein, the leaf node in the hash tree includes the recorded hash value of the trusted timestamp.
[0174] Optionally, the trusted time domain verification module 406 is configured to:
[0175] Performing a hash operation on the trusted timestamp to obtain a first verification hash value;
[0176] When the first verification hash value is the same as the record hash value of the leaf node, performing a hash operation on the first verification hash value and the record hash value of the brother node of the leaf node to generate a second verification hash value;
[0177] When the second verification hash value is the same as the record hash value of the first parent node, continue to perform hash operations based on the second verification hash value and the record hash values of the sibling nodes of the first parent node until a root verification hash value is obtained, wherein the first parent node is the parent node of the leaf node;
[0178] The trusted timestamp verification is determined to be successful when the record hash value of the root node of the hash tree is the same as the root verification hash value.
[0179] Optionally, the path verification module 408 is configured to:
[0180] The target path is verified according to the index tree and the hash tree.
[0181] Optionally, the path verification module 408 is configured to:
[0182] Based on the verification rules of the index tree, verifying the target path according to the recorded hash value of the root node of the hash tree;
[0183] The branch node of the index tree includes a common hash value of the root node and the current path identifier.
[0184] Optionally, the path verification module 408 is configured to:
[0185] Performing a hash operation on the recorded hash value of the root node and the current path identifier to obtain a third verification hash value;
[0186] When the third verification hash value is the same as the common record hash value, a fourth verification hash value is generated by performing a hash operation based on the third verification hash value and the hash value of the brother node of the branch node;
[0187] When the fourth verification hash value is the same as the hash value of the second parent node, continue to perform hash operations based on the fourth verification hash value and the hash value of the brother node of the second parent node until a root verification hash value is obtained, wherein the second parent node is the parent node of the branch node;
[0188] The trusted timestamp verification is determined to be successful when the hash value of the root node of the hash tree is the same as the root verification hash value.
[0189] The time domain verification device provided in the embodiments of this specification includes a path determination module, which is configured to determine a target path in a preset path library, wherein the target path carries a timestamp data set, a trusted time domain determination module, which is configured to determine a trusted time domain to be verified from the timestamp data set according to the time domain to be verified, a trusted time domain verification module, which is configured to verify the trusted time domain to be verified, a path verification module, which is configured to verify the target path if the trusted time domain to be verified is successfully verified, and a verification result determination module, which is configured to determine that the verification of the time domain to be verified is successful if the verification of the target path is successful. Determine the corresponding trusted time domain according to the time domain to be verified, verify the trusted time domain, and determine that the verification of the time domain to be verified is successful when the trusted time domain verification is successful. This can implement a solution for verifying any required time domain to be verified, and the verification speed is fast, thereby improving efficiency.
[0190] See also Figure 5 , Figure 5 is a flow chart of another time domain verification method provided by an embodiment of this specification. This specification also provides another time domain verification method, including:
[0191] Step 502, determine the target hash value according to the requirements;
[0192] Step 504, determining a timestamp data set according to the target hash value;
[0193] Step 506, determining a trusted time domain to be verified from the timestamp data set according to the time domain to be verified;
[0194] Step 508, verifying the trusted time domain to be verified;
[0195] Step 510, determining that the target hash value verification is successful if the trusted time domain to be verified is successful;
[0196] Step 512, when the target hash value is verified successfully, determine that the time domain to be verified is verified successfully.
[0197] The embodiments of this specification can also verify data without a path library, and only use the data structure of the Merkle tree to verify the time domain to be verified. The verification capability of the Merkle tree is used to increase the speed of verification and improve the efficiency of verification.
[0198] See also Figure 6 , Figure 6 is a schematic diagram of another time domain verification device provided by an embodiment of the present specification, the time domain verification device comprising:
[0199] The requirement determination module 602 determines the target hash value according to the requirement;
[0200] A data set determination module 604 determines a timestamp data set according to the target hash value;
[0201] A trusted time domain determination module 606 is configured to determine a trusted time domain to be verified from the timestamp data set according to the time domain to be verified;
[0202] A trusted time domain verification module 608 is configured to verify the trusted time domain to be verified;
[0203] The target hash value verification module 610 is configured to determine that the target hash value verification is successful if the trusted time domain to be verified is successfully verified;
[0204] The verification result determination module 612 is configured to determine that the verification of the to-be-verified time domain is successful if the verification of the target hash value is successful.
[0205] Figure 7 A block diagram of a computing device 700 provided according to an embodiment of the present specification is shown. The components of the computing device 700 include but are not limited to a memory 710 and a processor 720. The processor 720 is connected to the memory 710 via a bus 730, and a database 750 is used to store data.
[0206] The computing device 700 also includes an access device 740 that enables the computing device 700 to communicate via one or more networks 760. Examples of these networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 740 may include one or more of any type of network interface (e.g., a network interface card (NIC)) whether wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a World Wide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a universal serial bus (USB) interface, a cellular network interface, a Bluetooth interface, a near field communication (NFC) interface, and the like.
[0207] In one embodiment of the present specification, the above components of the computing device 700 and Figure 7 Other components not shown in the figure may also be connected to each other, for example, via a bus. It should be understood that Figure 7 The computing device block diagram shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art may add or replace other components as needed.
[0208] The computing device 700 may be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smart phone), a wearable computing device (e.g., a smart watch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or PC. The computing device 700 may also be a mobile or stationary server.
[0209] The processor 720 is used to execute the following computer executable instructions, which, when executed by the processor, implement the steps of the above-mentioned time domain verification method.
[0210] The above is a schematic scheme of a computing device of this embodiment. It should be noted that the technical scheme of the computing device and the technical scheme of the above-mentioned time domain verification method belong to the same concept, and the details not described in detail in the technical scheme of the computing device can be referred to the description of the technical scheme of the above-mentioned time domain verification method.
[0211] An embodiment of the present specification also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the above-mentioned time domain verification method.
[0212] The above is a schematic scheme of a computer-readable storage medium of this embodiment. It should be noted that the technical scheme of the storage medium and the technical scheme of the above-mentioned time domain verification method belong to the same concept, and the details not described in detail in the technical scheme of the storage medium can be referred to the description of the technical scheme of the above-mentioned time domain verification method.
[0213] An embodiment of the present specification further provides a computer program, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the above-mentioned time domain verification method.
[0214] The above is a schematic scheme of a computer program of this embodiment. It should be noted that the technical scheme of the computer program and the technical scheme of the above-mentioned time domain verification method belong to the same concept, and the details not described in detail in the technical scheme of the computer program can be referred to the description of the technical scheme of the above-mentioned time domain verification method.
[0215] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0216] The computer instructions include computer program codes, which may be in source code form, object code form, executable files or some intermediate forms, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer-readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.
[0217] It should be noted that, for the convenience of description, the aforementioned method embodiments are all described as a series of action combinations, but those skilled in the art should be aware that the embodiments of this specification are not limited by the order of the actions described, because according to the embodiments of this specification, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the embodiments of this specification.
[0218] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0219] The preferred embodiments of this specification disclosed above are only used to help explain this specification. The optional embodiments do not describe all the details in detail, nor do they limit the invention to only the specific implementation methods described. Obviously, many modifications and changes can be made according to the content of the embodiments of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of this specification, so that technicians in the relevant technical field can well understand and use this specification. This specification is only limited by the claims and their full scope and equivalents.
Claims
1. A time domain verification method, comprising: Determine a target path in a preset path library, wherein the target path carries a timestamp data set; Determining a trusted time domain to be verified from the timestamp data set according to the time domain to be verified; Verifying the trusted time domain to be verified; If the trusted time domain to be verified is successfully verified, verifying the target path; When the target path verification succeeds, it is determined that the time domain to be verified succeeds.
2. According to the method of claim 1, determining the target path in the preset path library comprises: Determine the identification string based on the required attributes; The path nodes are determined level by level in the path library according to the order of the characters in the identification character string to form the target path.
3. The method according to claim 1, wherein determining the trusted time domain to be verified from the timestamp data set according to the time domain to be verified comprises: Determine a start trusted timestamp and an end trusted timestamp from the timestamp data set according to the time domain to be verified; The trusted time domain to be verified is determined based on the start trusted timestamp and the end trusted timestamp.
4. The method according to claim 3, wherein determining the start trusted timestamp and the end trusted timestamp according to the time domain to be verified from the timestamp data set comprises: Obtaining the starting anchor point and the ending anchor point of the time domain to be verified; Find a trusted timestamp before the time of the starting anchor point from the timestamp data set and determine it as the starting trusted timestamp; A trusted timestamp after the time of the termination anchor point is found in the timestamp data set and determined as the termination trusted timestamp.
5. The method according to claim 1, wherein the verifying the trusted time domain to be verified comprises: According to the hash tree, the trusted timestamp in the trusted time domain to be verified is verified.
6. The method according to claim 5, wherein the verifying the trusted timestamp in the trusted time domain to be verified according to the hash tree comprises: Based on the verification rule of the hash tree, verification is performed according to the hash value of the trusted timestamp in the trusted time domain to be verified; Wherein, the leaf node in the hash tree includes the recorded hash value of the trusted timestamp.
7. The method according to claim 6, wherein the verification rule based on the hash tree is verified according to the hash value of the trusted timestamp in the trusted time domain to be verified, comprising: Performing a hash operation on the trusted timestamp to obtain a first verification hash value; When the first verification hash value is the same as the record hash value of the leaf node, performing a hash operation on the first verification hash value and the record hash value of the brother node of the leaf node to generate a second verification hash value; When the second verification hash value is the same as the record hash value of the first parent node, continue to perform hash operations based on the second verification hash value and the record hash values of the sibling nodes of the first parent node until a root verification hash value is obtained, wherein the first parent node is the parent node of the leaf node; The trusted timestamp verification is determined to be successful when the record hash value of the root node of the hash tree is the same as the root verification hash value.
8. The method according to claim 7, wherein the verifying the target path comprises: The target path is verified according to the index tree and the hash tree.
9. The method according to claim 8, wherein the verifying the target path according to the index tree and the hash tree comprises: Based on the verification rules of the index tree, verifying the target path according to the recorded hash value of the root node of the hash tree; The branch nodes of the index tree include the common hash value of the root node and the current path identifier.
10. The method according to claim 9, wherein the verification rule based on the index tree verifies the target path according to the recorded hash value of the root node of the hash tree, comprising: Performing a hash operation on the recorded hash value of the root node and the current path identifier to obtain a third verification hash value; When the third verification hash value is the same as the common hash value, performing a hash operation based on the third verification hash value and the hash value of the brother node of the branch node to generate a fourth verification hash value; When the fourth verification hash value is the same as the hash value of the second parent node, continue to perform hash operations based on the fourth verification hash value and the hash value of the brother node of the second parent node until a root verification hash value is obtained, wherein the second parent node is the parent node of the branch node; The target path verification is determined to be successful when the hash value of the root node of the hash tree is the same as the root verification hash value.
11. A time domain verification method, comprising: Determine the target hash value based on requirements; Determine a timestamp data set according to the target hash value; Determining a trusted time domain to be verified from the timestamp data set according to the time domain to be verified; Verifying the trusted time domain to be verified; Determining that the target hash value verification is successful when the trusted time domain to be verified is successful; When the target hash value is successfully verified, it is determined that the time domain to be verified is successfully verified.
12. A time domain verification device, comprising: A path determination module is configured to determine a target path in a preset path library, wherein the target path carries a timestamp data set; A trusted time domain determination module is configured to determine a trusted time domain to be verified from the timestamp data set according to the time domain to be verified; A trusted time domain verification module, configured to verify the trusted time domain to be verified; A path verification module, configured to verify the target path if the trusted time domain to be verified is successfully verified; The verification result determination module is configured to determine that the verification of the time domain to be verified is successful if the verification of the target path is successful.
13. A computing device comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the time domain verification method described in any one of claims 1 to 10 are implemented.
14. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the time domain verification method according to any one of claims 1 to 10.