A method, device, equipment and storage medium for collaboration in a blockchain
By sending and verifying target credentials in the blockchain, the problem of centralized management of DAO organization permission data is solved, achieving higher security and transparency.
Patent Information
- Application Number
- CN202211013948.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-23
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2042-08-23
AI Technical Summary
When existing DAO organizations use web2 permission tools, the centralized management of permission data makes them vulnerable to malicious attacks that could lead to large-scale leaks, making it difficult to guarantee security.
In a blockchain, by sending target credentials to target member terminals, receiving and verifying the credential description information in the collaboration request, determining collaboration permissions, and allowing eligible terminals to participate in collaboration according to the collaboration permission contract.
Decentralized management of access control data improves the security and transparency of access control data within the target organization.
Smart Images

Figure CN115442049B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of blockchain, in particular to a method and device for collaboration in a blockchain, equipment and a storage medium. BACKGROUND
[0002] DAO (Decentralized Autonomous Organization, a decentralized autonomous organization) is an organization form derived from the core concept of blockchain (collaborative behavior of co-creation, co-construction, co-governance and co-sharing by a group reaching a consensus). Specifically, DAO is also an organization form in which the management and operation rules of the organization are coded in the form of a smart contract on a blockchain, thereby running autonomously without centralized control or third-party intervention.
[0003] At present, although DAO organizations have the characteristics of decentralized management, most DAO organizations still use web2 permission tools to centrally manage and store permission data within the organization. At this time, since the web2 permission tool can only support centralized management and storage of permission data (i.e., the permission data is stored centrally in a fixed terminal within the organization, and is managed centrally by the fixed terminal), if the terminal within the organization that manages and stores the above permission data is maliciously attacked, it is easy to cause a large-scale leakage of permission data within the organization, so it can be seen that in the centralized management mode, the security of the permission data within the organization is difficult to guarantee. SUMMARY
[0004] Therefore, the purpose of the present application is to provide a method and device for collaboration in a blockchain, equipment and a storage medium, to effectively improve the security and transparency of the management of permission data within a target organization on the basis of realizing decentralized management of permission data.
[0005] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the following preferred embodiments are described in detail below, and the accompanying drawings are described as follows.
[0006] In a first aspect, the embodiments of the present application provide a method for collaboration in a blockchain, the method comprising:
[0007] sending a target credential to a target member terminal that meets the participation conditions of a target collaboration; wherein the target member terminal is determined from a plurality of member terminals that apply to participate in the target collaboration within a target organization; and the target credential is used to prove that the target member terminal has a collaboration permission to participate in the target collaboration;
[0008] receive a collaboration request of a first member terminal in the target organization for the target collaboration, and verify whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal;
[0009] when it is determined based on the collaboration permission verification result that the first member terminal has the collaboration permission to participate in the target collaboration, allow the first member terminal to participate in the target collaboration according to a collaboration participation strategy agreed in a collaboration permission contract.
[0010] In a second aspect, the embodiments of the present application provide a device for collaboration in a blockchain, and the device comprises:
[0011] a first response module configured to send a target credential to a target member terminal satisfying a participation condition of a target collaboration, wherein the target member terminal is determined from a plurality of member terminals in a target organization applying to participate in the target collaboration, and the target credential is used to prove that the target member terminal has a collaboration permission to participate in the target collaboration;
[0012] a first verification module configured to receive a collaboration request of a first member terminal in the target organization for the target collaboration, and verify whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal;
[0013] a first processing module configured to, when it is determined based on the collaboration permission verification result that the first member terminal has the collaboration permission to participate in the target collaboration, allow the first member terminal to participate in the target collaboration according to a collaboration participation strategy agreed in a collaboration permission contract.
[0014] In a third aspect, the embodiments of the present application provide a system for collaboration in a blockchain, and the system comprises a collaboration initiation terminal, a subject terminal of a target organization, a collaboration permission contract, and a plurality of member terminals in the target organization, wherein the subject terminal of the target organization is configured to:
[0015] send a target credential to a target member terminal satisfying a participation condition of a target collaboration, wherein the target member terminal is determined from a plurality of member terminals in a target organization applying to participate in the target collaboration, and the target credential is used to prove that the target member terminal has a collaboration permission to participate in the target collaboration;
[0016] The collaboration initiation terminal is configured to receive a collaboration request of a first member terminal in the target organization for the target collaboration, and verify whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal.
[0017] When it is determined based on the collaboration permission verification result that the first member terminal has the collaboration permission to participate in the target collaboration, the first member terminal is allowed to participate in the target collaboration according to a collaboration participation strategy agreed in the collaboration permission contract.
[0018] In a fourth aspect, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the method for collaboration in a block chain.
[0019] In a fifth aspect, an embodiment of the present application provides a computer readable storage medium, and the computer readable storage medium stores a computer program, and the computer program is executable on a processor to implement the steps of the method for collaboration in a block chain.
[0020] The technical scheme provided by the embodiment of the present application can include the following beneficial effects:
[0021] The method, device, equipment and storage medium for collaboration in a block chain provided by the embodiment of the present application send a target credential to a target member terminal that meets a participation condition of a target collaboration; receive a collaboration request of a first member terminal in a target organization for the target collaboration, and verify whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal; when it is determined based on the collaboration permission verification result that the first member terminal has the collaboration permission to participate in the target collaboration, the first member terminal is allowed to participate in the target collaboration according to a collaboration participation strategy agreed in the collaboration permission contract. In this way, on the basis of realizing the decentralized management of permission data, the present application can effectively improve the security and transparency of the management of permission data in the target organization. BRIEF DESCRIPTION OF DRAWINGS
[0022] In order to more clearly illustrate the technical scheme of the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0023] Figure 1 A flowchart of a method for collaboration in a blockchain is shown.
[0024] Figure 2 A flowchart of a method for sending a target credential is shown.
[0025] Figure 3 A flowchart of a first method for verifying whether a member terminal meets a participation condition of a target collaboration is shown.
[0026] Figure 4 A flowchart of a second method for verifying whether a member terminal meets a participation condition of a target collaboration is shown.
[0027] Figure 5 A flowchart of a method for verifying whether a verifiable credential held by a first member terminal belongs to a target credential is shown.
[0028] Figure 6 A flowchart of a method for internal collaboration in an organization using a collaboration permission contract is shown.
[0029] Figure 7 A structural diagram of a device for collaboration in a blockchain is shown.
[0030] Figure 8 A structural diagram of a system for collaboration in a blockchain is shown.
[0031] Figure 9 A structural diagram of an electronic device 900 provided by an embodiment of the present application is shown. DETAILED DESCRIPTION
[0032] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of illustrating and describing, and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn according to the actual proportions. The flowcharts in the present application show the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowcharts can not be implemented in sequence, and the steps without logical context relationship can be reversed in sequence or implemented simultaneously. In addition, one or more other operations can be added to the flowcharts or one or more operations can be removed from the flowcharts under the guidance of the content of the present application.
[0033] In addition, the described embodiments are only some embodiments of the present application, rather than all embodiments. The components of the embodiments of the present application described and shown in the accompanying drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0034] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the presence of the features declared thereafter, but does not exclude the addition of other features.
[0035] At present, although the DAO organization has the characteristics of decentralized management, most DAO organizations still use web2 permission tools to centrally manage and store the permission data within the organization. At this time, since the web2 permission tool can only support centralized management and storage of permission data (i.e., the permission data is stored centrally in a fixed terminal within the organization, and is centrally managed by the fixed terminal), once the terminal within the organization that manages and stores the above permission data is maliciously attacked, it is easy to cause a large-scale leakage of the permission data within the organization, so it can be seen that in the centralized management mode, the security of the permission data within the organization is difficult to guarantee.
[0036] Based on this, the embodiments of the present application provide a method, device, equipment and storage medium for collaboration in a blockchain, a target credential is sent to a target member terminal that meets a participation condition of a target collaboration; a collaboration request for the target collaboration is received from a first member terminal within a target organization, and whether a verifiable credential held by the first member terminal belongs to the target credential is verified according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal; when it is determined based on the collaboration permission verification result that the first member terminal has collaboration permission to participate in the target collaboration, the first member terminal is allowed to participate in the target collaboration according to a collaboration participation strategy agreed in a collaboration permission contract. In this way, the present application can effectively improve the security and transparency of the management of permission data within the target organization on the basis of realizing the decentralized management of permission data.
[0037] It should be noted that the embodiments of the present application provide a method, device, equipment and storage medium for collaboration in a blockchain; wherein the method for collaboration in a blockchain provided by the embodiments of the present application is applicable to a device for collaboration in a blockchain, which can be integrated in a computer equipment.
[0038] Specifically, the aforementioned computer equipment can be terminal devices, such as mobile phones, tablets, laptops, desktop computers, etc.; the aforementioned computer equipment can also be servers, which can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms, but are not limited to these.
[0039] To facilitate understanding of the embodiments of this application, the following provides a detailed description of a method, apparatus, device, and storage medium for collaboration in a blockchain.
[0040] Reference Figure 1 As shown, Figure 1 The diagram illustrates a flowchart of a method for collaboration in a blockchain according to an embodiment of this application. The method includes steps S101-S103; specifically:
[0041] S101, send the target credentials to the target member terminal that meets the participation conditions for the target collaboration.
[0042] S102, receive a collaboration request from a first member terminal within the target organization for the target collaboration, and verify whether the verifiable credential held by the first member terminal belongs to the target credential based on the credential description information contained in the collaboration request, and obtain the collaboration permission verification result of the first member terminal.
[0043] S103, when it is determined based on the collaboration permission verification result that the first member terminal has the collaboration permission to participate in the target collaboration, the first member terminal is allowed to participate in the target collaboration in accordance with the collaboration participation strategy agreed in the collaboration permission contract.
[0044] The method for cooperation in the blockchain provided in the embodiments of the present application sends target credentials to target member terminals that meet the participation conditions of target cooperation; receives a cooperation request of a first member terminal in a target organization for target cooperation, and verifies whether the verifiable credentials held by the first member terminal belong to the target credentials according to the credential description information contained in the cooperation request, to obtain a cooperation permission verification result of the first member terminal; when it is determined that the first member terminal has the cooperation permission to participate in the target cooperation based on the cooperation permission verification result, the first member terminal is allowed to participate in the target cooperation according to the cooperation participation strategy agreed in the cooperation permission contract. In this way, on the basis of realizing the decentralized management of permission data, the security and transparency of the management of permission data in the target organization can be effectively improved.
[0045] Specifically, in addition to the computer device described above, the method for cooperation in the blockchain provided in the embodiments of the present application can also be applied to the verifiable credential system corresponding to the target organization on the blockchain. At this time, in the verifiable credential system, there are multiple participants (i.e., multiple different types of user terminals in the target organization): the subject terminal of the target organization, the cooperation permission contract on the blockchain (associated with the target organization), and each member terminal in the target organization (including both the cooperation initiation terminal that initiates the target cooperation and the member terminal that applies to participate in the target cooperation); that is, each member terminal in the target organization, the subject terminal of the target organization, and the cooperation permission contract described above jointly constitute the verifiable credential system corresponding to the target organization on the blockchain.
[0046] The cooperation initiation terminal belongs to the member terminal in the target organization (i.e., the cooperation initiation terminal can represent the member terminal in the target organization that initiates the target cooperation). The cooperation initiation terminal can initiate a target cooperation within the target organization (such as document cooperation to complete a specific document, task cooperation to complete a specific task, etc.). The specific terminal type of the cooperation initiation terminal and the specific cooperation type of the target cooperation initiated by the cooperation initiation terminal are not limited in the embodiments of the present application.
[0047] In the verifiable credential system described above, after initiating the target cooperation, the cooperation permission contract on the blockchain can first perform permission auditing on each member terminal that applies to participate in the target cooperation, to determine the target member terminal that meets the participation conditions of the target cooperation (equivalent to having the cooperation permission to participate in the target cooperation) from the multiple member terminals that apply to participate in the target cooperation, and issue participation permission for the target cooperation (such as the participation permission in the form of non-fungible token) to the determined target member terminal. The specific issuance form of the participation permission is not limited in the embodiments of the present application.
[0048] In the target organization, the subject terminal of the target organization has the right to issue and verify various VC (Verifiable Credential, verifiable credential) credentials within the target organization. Based on this, when the above-mentioned participation permission issuing event is monitored, the subject terminal of the target organization can issue a target credential (the target credential belongs to the verifiable credential that the subject terminal of the target organization can issue in the above-mentioned verifiable credential system) unique to each target member terminal determined for each target member terminal, so that the target member terminal can prove that it has the collaboration permission to participate in the target collaboration (that is, the target member terminal has the possession right of the target credential) through the possession of the target credential in the subsequent process of participating in the target collaboration.
[0049] Based on this, after obtaining the above-mentioned target credential, the target member terminal can send a collaboration request for the target collaboration to the collaboration initiating terminal and present the VP (Verifiable presentation, verifiable presentation) description information of the target credential to the collaboration initiating terminal in the collaboration request, so that the collaboration initiating terminal can verify whether the target member terminal has the collaboration permission to participate in the target collaboration according to the credential description information (that is, the above-mentioned VP description information) contained in the collaboration request (that is, in the above-mentioned verifiable credential system, the collaboration initiating terminal also has the verification right of the target credential), so that when it is determined that the target member terminal has the collaboration permission to participate in the target collaboration, the target member terminal is allowed to participate in the target collaboration according to the collaboration participation strategy agreed in the above-mentioned collaboration permission contract.
[0050] Next, taking the application to the above-mentioned verifiable credential system as an example, the steps in the method for collaboration in the blockchain provided by the embodiments of the present application are described in detail.
[0051] S101, send a target credential to a target member terminal that meets the participation condition of a target collaboration.
[0052] Here, within the target organization, the collaboration initiating terminal (which belongs to the member terminal within the target organization) can initiate the target collaboration, and other member terminals except the collaboration initiating terminal can apply to participate in the target collaboration; At this time, the above-mentioned target member terminal can be determined from the multiple member terminals that apply to participate in the target collaboration within the target organization (that is, the target member terminal is determined from the multiple member terminals that apply to participate in the target collaboration within the target organization).
[0053] It should be noted that when the collaboration initiation terminal initiates the target collaboration within the target organization (equivalent to initiating the target collaboration on the blockchain), the target collaboration can be initiated through the above-mentioned collaboration permission contract associated with the target organization, or can be directly initiated through the subject terminal of the target organization. For the specific initiation mode of the above-mentioned target collaboration, the embodiments of the present application do not make any limitation.
[0054] Specifically, taking the example of the collaboration initiation terminal initiating the target collaboration within the target organization through the above-mentioned collaboration permission contract associated with the target organization, when the collaboration initiation terminal initiates the target collaboration to the above-mentioned collaboration permission contract, the collaboration detail information submitted by the collaboration initiation terminal can include: the user identity information of the collaboration initiation terminal (equivalent to the specific collaboration initiator identity information of the target collaboration), the effective participation period of the target collaboration (such as the time range area between the collaboration initiation time and the collaboration termination time of the target collaboration, which is the above-mentioned effective participation period), the participation condition of the above-mentioned target collaboration (which can be one participation condition, or multiple participation conditions), and the specific collaboration content of the target collaboration, etc. For the specific information content and specific information format of the above-mentioned collaboration detail information, the embodiments of the present application do not make any limitation.
[0055] Here, the target credential is used to prove that the target member terminal has the collaboration permission to participate in the target collaboration; wherein when the method for collaboration in the blockchain provided by the embodiments of the present application runs on the above-mentioned computer device, the execution subject of step S101 (i.e. the sender of the target credential) can be the computer device; when the method for collaboration in the blockchain provided by the embodiments of the present application runs on the above-mentioned verifiable credential system, based on the subject terminal of the target organization having the issuing right of various types of VC credentials (i.e. verifiable credentials), at this time, whether the collaboration initiation terminal indirectly initiates the target collaboration within the target organization through the collaboration permission contract, or directly initiates the target collaboration within the target organization through the subject terminal of the target organization, the execution subject of step S101 (i.e. the sender of the target credential) is the subject terminal of the target organization.
[0056] It should be noted that the initiator of the target collaboration (i.e. the above-mentioned collaboration initiation terminal) can be a member terminal corresponding to any one organization member within the target organization. For the specific terminal type corresponding to the initiator of the target collaboration, the embodiments of the present application do not make any limitation.
[0057] It should be noted that the target collaboration can be a document collaboration for completing a certain specific document, or a task collaboration for completing a certain to-be-executed task. For the specific collaboration type of the target collaboration, the embodiments of the present application do not make any limitation.
[0058] For the target organization, it should be noted that the target organization represents an organization on the blockchain; wherein the organization type to which the target organization belongs at least includes a decentralized autonomous organization (i.e., DAO organization); that is, the target organization can be a DAO organization on the blockchain, or can be a group organization or team organization of other types on the blockchain, and the specific organization type of the target organization is not limited by the embodiments of the present application.
[0059] S102, receiving a collaboration request for the target collaboration from a first member terminal in the target organization, and verifying whether the verifiable credential held by the first member terminal belongs to the target credential according to the credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal. Here, in the verifiable credential system, the collaboration initiator terminal (i.e., the initiator of the target collaboration) has the verification right of the target credential, so in actual application, the collaboration initiator terminal can receive the collaboration request for the target collaboration sent by the first member terminal in the target organization, to verify whether the first member terminal holds the valid target credential according to the credential description information contained in the collaboration request, thereby realizing the decentralized management of the permission data in the target organization (i.e., no longer storing the collaboration permission information of all member terminals on a fixed terminal in the organization).
[0060] It should be noted that, similar to step S101, when the method for collaboration in the blockchain provided by the embodiments of the present application is running on the above-mentioned computer device, the execution subject of step S102 (i.e., the receiver of the collaboration request and the verifier of the above-mentioned credential description information) can also be the computer device; the repeated parts will not be described here.
[0061] It should be noted that the first member terminal is only used to represent the member terminal that actually sends the collaboration request to the collaboration initiator terminal, and whether the first member terminal belongs to the plurality of member terminals described in step S101 is not limited by the embodiments of the present application.
[0062] Specifically, the first member terminal can send a collaboration request to the collaboration initiation terminal for the target collaboration, and present the VP description information (i.e., the credential description information contained in the collaboration request) of the VC credential (i.e., the above-mentioned verifiable credential) held by the first member terminal to the collaboration initiation terminal, so that the collaboration initiation terminal can verify whether the VC credential held by the first member terminal belongs to the target credential in step S101 according to the VP description information contained in the collaboration request. When the VP description information contained in the collaboration request is consistent with the credential information recorded in the target credential in step S101, it is determined that the first member terminal belongs to the target member terminal (i.e., it is determined that the first member terminal has the collaboration right to participate in the target collaboration). When the VP description information contained in the collaboration request is inconsistent with the credential information recorded in the target credential in step S101, it is determined that the first member terminal does not belong to the target member terminal (i.e., it is determined that the first member terminal does not have the collaboration right to participate in the target collaboration). Thus, before each member terminal actually participates in the target collaboration, the collaboration initiation terminal can use the VP description information contained in the collaboration request and the credential information of the target credential previously issued by the subject terminal of the target organization to effectively verify whether each member terminal has the collaboration right to participate in the target collaboration.
[0063] Based on this, according to the implementation of steps S101-S102, the target organization does not need to store the right data (such as the list data of the target member terminals having the right to participate in the target collaboration) of the target collaboration in a fixed terminal. Instead, the participation right of each member terminal can be effectively verified by the above-mentioned method before each member terminal actually participates in the target collaboration. Thus, on the basis of realizing the decentralized management of the right data, the security and transparency of the management of the right data in the target organization are effectively improved.
[0064] S103, when it is determined that the first member terminal has the collaboration right to participate in the target collaboration based on the collaboration right verification result, allowing the first member terminal to participate in the target collaboration according to the collaboration participation strategy agreed in the collaboration right contract.
[0065] Here, based on the description of step S102, when it is determined that the first member terminal has the collaboration right to participate in the target collaboration in step S103, the collaboration initiation terminal can allow the first member terminal to participate in the target collaboration according to the collaboration participation strategy agreed in the collaboration right contract. When it is determined that the first member terminal does not have the collaboration right to participate in the target collaboration, the collaboration initiation terminal can refuse the first member terminal to participate in the target collaboration. Thus, the actual collaboration process of the target collaboration is only open to the target member terminal having the collaboration right to participate in the target collaboration, and the security and credibility of the collaboration in the target organization are effectively improved.
[0066] Here, for the target credential and the credential description information, it needs to be explained that: since the target credential belongs to the VC credential issued by the subject terminal of the target organization, and the credential description information belongs to the VP description information (i.e. verifiable expression) of the verifiable credential (wherein, when the first member terminal belongs to the target member terminal, the verifiable credential is the target credential), therefore, in the embodiment of the application, the target credential can be applied to the VC system (i.e. verifiable credential system), wherein the VC system includes four participants: issuer, an entity that owns user data and can issue verifiable credentials (i.e. VC credentials), such as banks, universities, and other institutions and organizations; holder, the holder is the user, the user requests, receives and holds the VC credential from the issuer, and presents the VC credential to the verifier, the issued VC credential can be self-saved for future use, for example, saved in the user's smart contract on the blockchain, and the user can also transfer one or more VC credentials to other users; verifier, receives and verifies the VC credential, and after verification, can provide a certain type of service to the user presenting the VC credential; identifier registration authority (verifiable data registry), maintains a database of distributed identity identifiers (DIDs), such as a certain blockchain, distributed ledger, etc. In the VC system, the verifier can verify the VC credential presented by the user, or verify the VP description information of the VC credential presented by the user, and after verification, the validity of the VC credential held by the user can be determined.
[0067] Based on this, it needs to be explained that when the collaboration method shown in steps S101-S103 is executed in the above verifiable credential system (i.e. not when the above process is run on the computer device as a whole), the member terminal in the target organization in the first member terminal / target member terminal / collaboration initiation terminal of the embodiment of the application can represent the holder in the above VC system; the subject terminal of the target organization can represent the issuer in the above VC system (i.e. has the right to issue the target credential); wherein, when the collaboration initiation terminal verifies whether the verifiable credential held by the first member terminal belongs to the target credential (i.e. when the collaboration initiation terminal executes step S102), the collaboration initiation terminal can also represent the verifier in the above VC system (i.e. the collaboration initiation terminal also has the right to verify the target credential).
[0068] The specific implementation process of each step in the embodiment of the application will be described in detail as follows:
[0069] For the specific implementation process of the above step S101, in combination with the above analysis content, in an optional implementation manner, when the collaboration method shown in the above steps S101-S103 belongs to a set of process methods that can be run on a computer device as a whole, then when step S101 is executed, the computer device can directly send target credentials to target member terminals that meet the participation conditions of the target collaboration, from the multiple member terminals that apply to participate in the target collaboration within the target organization, in response to the initiation of the target collaboration (such as receiving a collaboration initiation request for the target collaboration).
[0070] In another optional implementation manner, when the collaboration method shown in the above steps S101-S103 is applied to the above verifiable credential system (that is, the VC system composed of the collaboration initiation terminal, the subject terminal of the target organization, the collaboration permission contract on the block chain, and the multiple member terminals within the target organization), then the above step S101 can also be completed by the above collaboration permission contract and the above subject terminal of the target organization respectively. At this time, when the above step S101 is executed, the collaboration permission contract can first perform permission auditing on each member terminal that applies to participate in the target collaboration, to determine target member terminals that meet the participation conditions of the target collaboration (equivalent to having collaboration permissions to participate in the target collaboration) from the multiple member terminals that apply to participate in the target collaboration, and issue participation permissions for the target collaboration (such as the above participation permissions that can exist in the form of non-fungible tokens) to the determined target member terminals. Then, in the VC system, when the issuance event of the above participation permission is monitored, the subject terminal of the target organization can issue target credentials unique to each target member terminal for each target member terminal determined, so that the target member terminal can prove that it has collaboration permissions to participate in the target collaboration by holding the target credentials in the subsequent process of participating in the target collaboration.
[0071] Based on this, still taking application to the above verifiable credential system as an example, referring to Figure 2 Figure 2 Fig. 1 shows a flow diagram of a method for sending target credentials provided by an embodiment of the present application, which includes steps S201-S202; specifically:
[0072] S201, within the effective participation period corresponding to the target collaboration, for each member terminal, verifying whether the member terminal meets the participation conditions of the target collaboration according to the user data of the member terminal on the block chain, to obtain the participation permission verification result of the member terminal.
[0073] Here, taking the example that the collaboration initiation terminal initiates the target collaboration in the target organization through the above-mentioned collaboration permission contract, the collaboration permission contract responds to the initiation of the target collaboration and receives the participation request of each member terminal for the target collaboration within the effective participation period corresponding to the target collaboration.
[0074] Specifically, when initiating the target collaboration, the collaboration initiation terminal can submit the collaboration initiation time of the target collaboration and the collaboration termination time of the target collaboration in the initiation request, so that the collaboration permission contract can determine the time range area between the collaboration initiation time and the collaboration termination time as the effective participation period corresponding to the target collaboration according to the received initiation request.
[0075] It should be noted that in addition to the above-mentioned collaboration initiation time and the above-mentioned collaboration termination time, the collaboration initiation terminal can also submit the participation condition of the target collaboration in the initiation request of the target collaboration, so that the collaboration permission contract can filter out the target member terminal meeting the participation condition from the plurality of member terminals applying for participating in the target collaboration according to the participation condition of the target collaboration submitted by the collaboration initiation terminal.
[0076] Here, the participation condition of the target collaboration can be set according to the actual needs of the collaboration initiation terminal, based on which, the participation condition of the target collaboration can be the user qualification audit of the member terminal under a single dimension / single item evaluation index (for example, judging whether the contribution degree of the member terminal to the target organization / personal reputation of the member terminal in the target organization and other single item evaluation indexes meet the participation condition based on the user data of the member terminal on the blockchain); or the comprehensive audit of the member terminal under multiple dimensions / multiple item evaluation indexes (for example, in addition to the above-mentioned contribution degree, personal reputation and other evaluation indexes, the comprehensive audit can also be performed on the digital assets such as the document copyright, the article collection right and the article transaction right held by the member terminal); the specific condition content of the participation condition of the target collaboration is not limited in the embodiments of the present application.
[0077] Specifically, for each member terminal sending a participation request, if the collaboration permission contract determines that the member terminal meets the participation condition of the target collaboration (equivalent to determining that the member terminal has the collaboration permission to participate in the target collaboration), the collaboration permission contract can issue the participation permission for the target collaboration to the member terminal meeting the participation condition. The specific form of the participation permission can be an NFT (non-fungible Token) token, indicating that the collaboration permission contract determines that the member terminal has the collaboration permission to participate in the target collaboration based on the user data of the member terminal on the blockchain (such as historical interaction data of historical contributions to the target organization, document copyright, item collection right, item transaction right, and other digital asset data), so that the member terminal can prove its permission and membership to the subject terminal of the target organization by holding the NFT token.
[0078] It should be noted that the blockchain address of each member terminal on the blockchain is unique, and based on this, the collaboration permission contract can send an NFT token with a unique ID (Identity document) code to each member terminal meeting the participation condition, to reduce the abuse of NFT tokens and improve the security and transparency of the management of permission data in the target organization.
[0079] S202, when it is determined based on the participation permission verification result that the member terminal meets the participation condition of the target collaboration, it is determined that the member terminal belongs to the target member terminal, and the target credential is sent to the member terminal.
[0080] Here, in combination with the above step S201, the collaboration permission contract can send an NFT token with a unique ID code to each member terminal meeting the participation condition; for example, an NFT token with a token ID of 1 can be sent to the first member terminal meeting the participation condition, and an NFT token with a token ID of 2 can be sent to the second member terminal meeting the participation condition.
[0081] Based on this, when the subject terminal of the target organization sends a target credential to each member terminal meeting the participation condition, by adding the token ID of the NFT token held by each member terminal in the sent target credential, the subject terminal of the target organization can also issue a target credential unique to each member terminal (equivalent to being able to uniquely identify the identity of each target member terminal) to each member terminal meeting the participation condition, so that the target member terminal (i.e., the member terminal meeting the participation condition) can prove its collaboration permission to participate in the target collaboration by holding the target credential in the subsequent process of participating in the target collaboration.
[0082] As to the specific credential content of the above-mentioned "target credential", in the embodiment of the present application, when the subject terminal of the target organization issues the VC credential (i.e. the above-mentioned target credential) for the target member terminal, the VC credential contains: the valid time limit of the VC credential (i.e. the issuance time of the VC credential and the effective cutoff time of the VC credential), the token ID of the NFT token, the collaboration index corresponding to the target collaboration (equivalent to the collaboration code corresponding to the currently initiated target collaboration), the specific permission type of the target member terminal, and the signature information of the issuer (i.e. the signature information of the subject terminal of the target organization), and other information; as to the specific credential content of the above-mentioned target credential, the embodiment of the present application does not make any limitation.
[0083] It should be noted that when the collaboration condition of the target collaboration only includes one permission type of participation condition (for example, the participation condition stipulates that as long as the x condition is met, the collaboration permission of the target collaboration is obtained), at this time, it can be determined that the above-mentioned specific permission type recorded in the different target credentials held by different target member terminals is the same (for example, if "1" represents the collaboration permission of the target collaboration, then the above-mentioned specific permission type recorded in the target credential a held by the target member terminal A is "1", and the above-mentioned specific permission type recorded in the target credential b held by the target member terminal B is also "1"); when the collaboration condition of the target collaboration includes multiple permission types of participation conditions (for example, taking that the target collaboration belongs to a document collaboration as an example, the participation condition stipulates that the x1 condition is met, which means that the viewing permission in the document collaboration process is obtained, and the x2 condition is met, which means that the editing permission in the document collaboration process is obtained), at this time, the above-mentioned specific permission type recorded in the different target credentials held by different target member terminals may be different (for example, if "0" represents the viewing permission in the document collaboration process, and "1" represents the editing permission in the document collaboration process; when the target member terminal A has the above-mentioned editing permission, the above-mentioned specific permission type recorded in the target credential a held by the target member terminal A is "1"; when the target member terminal A has the above-mentioned viewing permission, the above-mentioned specific permission type recorded in the target credential a held by the target member terminal A is "0"). As to the specific determination method of the specific permission type recorded in the above-mentioned target credential, the embodiment of the present application does not make any limitation.
[0084] Based on this, taking that the target collaboration belongs to a document collaboration, the above-mentioned specific permission type includes: the viewing permission in the document collaboration process and the editing permission in the document collaboration process, and the target organization belongs to a DAO organization as an example, then the specific credential format of the target credential is as follows:
[0085]
[0086]
[0087] The first "id" in the target credential is used to represent the did identity information of the target member terminal A (i.e., the holder of the target credential); "type" is used to represent the credential type of the target credential: VerifiableCredential for identity / collaboration permission in cooperation; "issuanceDate" is used to represent the issuance time of the target credential; "expirationDate" is used to represent the effective cutoff time of the target credential;
[0088] The "issuer" in the target credential is used to represent the relevant information of the credential issuer (i.e., the target organization) of the target credential, wherein the "id" in the "issuer" information is used to represent the did identity information of the target organization, "version" is used to represent the organization type of the target organization (for example, the specific value "1" in the above is used to represent that the target organization belongs to the DAO organization), "created" is used to represent the creation time of the target credential, and "updated" is used to represent the update time of the target credential.
[0089] The "credentialSubject" in the target credential is used to represent the credential subject content of the target credential, specifically, the "id" in the "credentialSubject" information is also used to represent the did identity information of the target member terminal A (i.e., the holder of the target credential); "nftCorpPermistokenId" is used to represent the token ID of the NFT token held by the target member terminal A (for example, "2" can be used to represent that the token code of the NFT token held by the target member terminal A is 2); "cooperationIndex" is used to represent the cooperation index corresponding to the target cooperation (for example, "2" can be used to represent that the cooperation code corresponding to the target cooperation currently initiated is 2, so as to distinguish from other collaborations in cooperation); "permissionType" is used to represent the specific permission type of the target member terminal A in the target cooperation (for example, "1" can represent that the target member terminal A has the editing permission of the document in the target cooperation process); "signer" is used to represent the issuer information of the target credential (consistent with the did identity information of the target organization); and the "signatureValue" in the "proof" is used to represent the signature information of the target organization subject terminal (i.e., the issuer of the target credential) for the target credential.
[0090] Regarding the specific implementation process of step S101 above, and based on the above analysis, it can be seen that when executing step S201, the participation conditions for target collaboration can be user qualification verification of member terminals under a single dimension / single assessment indicator; or it can be a comprehensive verification of member terminals under multiple dimensions / multiple assessment indicators. Based on this, this application embodiment also provides the following two optional implementation methods for executing step S201:
[0091] 1. When the participation condition for the target collaboration is based on a single dimension / single assessment indicator, and the user qualification verification is conducted on the member's terminal:
[0092] In one alternative implementation, refer to Figure 3 As shown, Figure 3 This illustration shows a flowchart of a first method for verifying whether a member terminal meets the participation conditions of a target collaboration, as provided in an embodiment of this application. The method includes steps S301-S303; specifically:
[0093] S301, Based on the user data of the member terminal on the blockchain, determine the historical contribution of the member terminal to the target organization.
[0094] It should be noted that the aforementioned user data may include: historical transaction data, historical collaboration data, and other historical interaction data of the member terminal on the blockchain, as well as various digital asset data such as document copyrights, item collection rights, and item trading rights of the member terminal. This application embodiment does not limit the specific data content of the aforementioned user data.
[0095] S302, in response to the historical contribution being greater than or equal to the target contribution threshold, determine that the member terminal meets the participation conditions for the target collaboration.
[0096] Here, the aforementioned target contribution threshold is determined based on the participation conditions of the target collaboration. That is, the specific value of the aforementioned target contribution threshold can be set by the collaboration initiating terminal itself; this embodiment of the application does not impose any limitations on this.
[0097] For example, taking a target contribution threshold of 60 as an example of the participation conditions for the target collaboration, if member terminal C's historical contribution to the target organization is 80, then based on the fact that member terminal C's historical contribution to the target organization is greater than the target contribution threshold set by the collaboration initiating terminal, it can be determined that member terminal C belongs to the target member terminal that meets the participation conditions for the target collaboration. At this time, according to the implementation method described in steps S201-S202 above, an NFT token for proving that member terminal C has the participation rights for the target collaboration can be issued to member terminal C through a collaboration permission contract. When the main terminal of the target organization detects the issuance of the NFT token, it will automatically send the target certificate to member terminal C to prove that member terminal C belongs to the target member terminal that meets the participation conditions for the target collaboration.
[0098] S303, in response to the historical contribution being less than the target contribution threshold, it is determined that the member terminal does not meet the participation conditions of the target collaboration.
[0099] For example, taking the target contribution threshold of 60 as an example of participation conditions in the target collaboration, if member terminal C's historical contribution to the target organization is 50, then based on the fact that member terminal C's historical contribution to the target organization is less than the target contribution threshold set by the collaboration initiating terminal, it is determined that member terminal C does not have the collaboration permission to participate in the target collaboration. The subsequent specific collaboration process of the target collaboration will not be open to member terminal C, so as to improve the security of collaboration permission data management within the target organization.
[0100] 2. When the participation conditions for the target collaboration are based on a comprehensive review of the member's terminal under multiple dimensions / multiple assessment indicators:
[0101] In another alternative implementation, refer to Figure 4 As shown, Figure 4 This illustration shows a flowchart of a second method for verifying whether a member terminal meets the participation conditions of a target collaboration, as provided in an embodiment of this application. The method includes steps S401-S403; specifically:
[0102] S401, based on the multiple assessment indicators included in the participation conditions of the target collaboration, obtain the valid user data associated with each assessment indicator from the user data of the member terminal on the blockchain.
[0103] Here, similar to the target contribution threshold mentioned above, the specific indicator type of the above assessment indicators can still be determined according to the participation conditions of the target collaboration. That is, the specific indicator type of the above assessment indicators can be set by the collaboration initiating terminal itself.
[0104] Exemplarily, taking the document collaboration as an example, the collaboration initiating terminal can take the number of document copyrights held by the member terminal, the number of participation in the document collaboration, the literature reference value of the historical document written by the member terminal, and the like as a plurality of evaluation indexes for evaluating whether the member terminal can participate in the target collaboration.
[0105] S402, according to the effective user data associated with each of the evaluation indexes and the index weight of each of the evaluation indexes, determine the comprehensive evaluation result of the member terminal.
[0106] Here, considering that the user data of the member terminal on the blockchain is massive, when verifying whether the member terminal meets the reference condition of the target collaboration, only the effective user data associated with each evaluation index is obtained from the massive user data according to the specific index type of each evaluation index, and the evaluation index value of the member terminal can be determined.
[0107] Here, according to the effective user data associated with each of the evaluation indexes, the index value of each of the evaluation indexes corresponding to the member terminal can be determined, and thus the comprehensive evaluation result of the member terminal can be obtained by weighted summation.
[0108] Exemplarily, taking the number of document copyrights as an example, the number of document copyrights held by the member terminal can be obtained from the digital assets of the member terminal, and if the member terminal holds the document copyrights of 10 different documents, the index value of the evaluation index p1 corresponding to the member terminal can be determined as 10.
[0109] S403, in response to the comprehensive evaluation result being greater than or equal to the target evaluation threshold, determine that the member terminal meets the participation condition of the target collaboration.
[0110] Here, the target evaluation threshold can also be determined according to the participation condition of the target collaboration.
[0111] Exemplarily, taking the target evaluation threshold included in the participation condition of the target collaboration as 70 as an example, if the comprehensive evaluation result of the member terminal C is 80, based on the comprehensive evaluation result of the member terminal C being greater than the target evaluation threshold set by the collaboration initiating terminal, it can be determined that the member terminal C belongs to the target member terminal that meets the participation condition of the target collaboration, at this time, the NFT token for proving that the member terminal C has the participation right of the target collaboration can be issued to the member terminal C according to the implementation manner described in steps S201-S202, when the subject terminal of the target organization monitors the issuance of the NFT token, the target voucher will be automatically sent to the member terminal C to prove that the member terminal C belongs to the target member terminal that meets the participation condition of the target collaboration.
[0112] For the specific implementation process of the above step S101, in combination with the above analysis content, it can be known that when the collaboration condition of the target collaboration includes multiple permission type participation conditions (for example, taking the case that the target collaboration belongs to a document collaboration, the participation condition stipulates that the x1 condition is met, that is, the viewing permission in the document collaboration process is met, and the x2 condition is met, that is, the editing permission in the document collaboration process is met), at this time, the specific permission type recorded in the different target credentials held by different target member terminals may be different. Based on this, in an optional implementation manner, the subject terminal of the target organization can determine the specific permission type required to be recorded in the target credential sent (that is, determine the specific value of "permissionType" in the above target credential) according to the implementation manner shown in steps a1-a2, and the specific implementation is as follows:
[0113] Step a1, in response to the user data of the member terminal on the blockchain satisfying the participation condition of the first permission type, it is determined that the member terminal belongs to the target member terminal, and the first target credential is sent to the member terminal.
[0114] Here, the first target credential is used to prove that the member terminal can participate in the target collaboration according to the participation permission stipulated by the first permission type.
[0115] Step a2, in response to the user data of the member terminal on the blockchain satisfying the participation condition of the second permission type, it is determined that the member terminal belongs to the target member terminal, and the second target credential is sent to the member terminal.
[0116] Here, the second target credential is used to prove that the member terminal can participate in the target collaboration according to the participation permission stipulated by the second permission type; wherein the participation condition of the second permission type is different from the participation condition of the first permission type.
[0117] For example, taking the case that the target collaboration belongs to a document collaboration, the first permission type can be the viewing permission in the document collaboration process, and the second permission type can be the editing permission in the document collaboration process. When it is determined that the member terminal C satisfies the participation condition of the first permission type, the target credential with the specific value of "permissionType" being "0" is sent to the member terminal C; when it is determined that the member terminal C satisfies the participation condition of the second permission type, the target credential with the specific value of "permissionType" being "1" is sent to the member terminal C; wherein "0" indicates that the member terminal C has the viewing permission of the document in the target collaboration process; "1" indicates that the member terminal C has the editing permission of the document in the target collaboration process.
[0118] For the specific implementation process of the above step S102, the specific information content and specific information format of the "credential description information" appearing in the above step S102 are described in detail as follows:
[0119] Here, the function based on the VP information is to verify the validity of the VC credential. In the embodiments of the present application, as an optional embodiment, the first member terminal can present the VP information containing all information of the VC credential as the above credential description information; as another optional embodiment, the first member terminal can also present the partial key information in the VC credential (such as expirationDate in the above target credential, "id", "nftCorpPermistokenId", "cooperationIndex", "permissionType" and "signatureValue" signature information appearing in "credentialSubject" information, "proof") as the credential description information of the VC credential. The specific information content of the above credential description information is not limited in the embodiments of the present application.
[0120] Specifically, taking the VC credential held by the first member terminal as the target credential in the above example as an example, the specific information format of the credential description information (i.e. VP information) presented by the first member terminal is as follows:
[0121]
[0122]
[0123] The first "signatureValue" (specific value: AdXfPXrnoGIxXw588MGEs5kGp3Hx86pk03Nf5doVW+sEX7wQQeOQMnBcFJba2muk / YJzzfRlm / yF862SZ2WSbxw=) appearing in the above credential description information is used to represent the signature information of the subject terminal of the target organization (i.e. the issuer of the VC credential) for the VC credential held by the first member terminal;
[0124] The second "signatureValue" (specific value: mmeMzjLepb5BcXpe9Li54D9OCqIa4runcmHHggxyME5WfzVP874Lgd8VovevsnliIJJzyMdqiuvs2kpffuwcYxs=) appearing in the above credential description information is used to represent the signature information of the first member terminal (i.e. the holder of the VC credential);
[0125] Here, the specific explanation of other characters in the above-mentioned credential description information can refer to the above-mentioned interpretation of the character part repeated in the target credential in the above-mentioned examples, and the repeated part will not be described here.
[0126] In combination with the above-mentioned examples related to the target credential and the credential description information, for the specific verification process of the above-mentioned step S102, refer to Figure 5 Figure 5 A flowchart of a method for verifying whether the verifiable credential held by the first member terminal belongs to the target credential is shown, and the method comprises steps S501-S502; specifically:
[0127] S501, according to the holder signature information recorded in the credential description information, verifying whether the first member terminal belongs to the holder of the target credential, obtaining the identity verification result of the first member terminal.
[0128] Here, after receiving the cooperation request sent by the first member terminal, the cooperation initiator terminal can verify the validity of the above-mentioned credential description information based on whether the "holder signature information" recorded in the above-mentioned credential description information (i.e. the specific value of the second "signatureValue" in the above-mentioned credential description information) is consistent with the holder signature information of the target credential (i.e. to verify whether the first member terminal is the holder of the target credential).
[0129] S502, when determining that the first member terminal belongs to the holder of the target credential based on the identity verification result, verifying whether the verifiable credential belongs to the valid target credential according to the issuer signature information recorded in the credential description information and the credential validity period of the verifiable credential, obtaining the cooperation permission verification result of the first member terminal.
[0130] Here, the cooperation initiator terminal can also verify the validity of the issuer of the target credential based on whether the issuer signature information recorded in the above-mentioned credential description information (the specific value of the first "signatureValue" in the above-mentioned credential description information) is consistent with the issuer signature information of the target credential (i.e. the specific value of "signatureValue" in the "proof" of the above-mentioned target credential).
[0131] Here, the cooperation initiator terminal can also verify the validity of the time limit of the target credential based on whether the "issuance time of the target credential" and "validity deadline of the target credential" in the above-mentioned credential description information are consistent with the above-mentioned credential validity period of the target credential.
[0132] For the specific implementation process of step S103, in a feasible implementation, when it is determined that the first member terminal has the collaboration right to participate in the target collaboration, the first member terminal can participate in the target collaboration according to the encryption transmission mode as shown in Figure 6 Specifically,
[0133] Referring to Figure 6 , Figure 6 Fig. 1 shows a flow diagram of a method for internal collaboration of an organization using a collaboration right contract according to an embodiment of the present application, which includes steps S601-S604; specifically,
[0134] S601, in response to the first member terminal having the collaboration right to participate in the target collaboration, encrypting the collaboration access token of the target collaboration according to the public key of the first member terminal to obtain a first encryption result of the collaboration access token.
[0135] Here, the public key of the first member terminal can be determined based on the blockchain address of the first member terminal on the blockchain.
[0136] Specifically, in the present embodiment, as an optional embodiment, the above-mentioned collaboration access token can include an access token access Token and an access random number access Random; at this time, the collaboration initiator terminal can encrypt the above-mentioned collaboration access token using the public key of the first member terminal, and the first encryption result of the collaboration access token is: the ciphertext access token access Token and the access random number access Random.
[0137] It should be noted that the specific token format of the above-mentioned collaboration access token and the specific form of the first encryption result of the collaboration access token are not limited in the present embodiment.
[0138] S602, send the first encryption result of the collaboration access token to the first member terminal, and upload the second encryption result of the collaboration access token to the collaboration right contract on the blockchain.
[0139] Here, the first member terminal can use its own user private key to decrypt the received first encryption result of the above-mentioned collaboration access token to obtain the decryption result of the collaboration access token.
[0140] Specifically, the second encryption result is obtained by a different encryption manner than the first encryption result; that is, the collaboration initiation terminal encrypts the collaboration access token by using the public key of the first member terminal, and sends the obtained first encryption result to the first member terminal; the collaboration initiation terminal encrypts the collaboration access token by using another encryption manner (i.e., a manner of not encrypting the collaboration access token by using the public key of the first member terminal), to obtain the ciphertext collaboration access token (i.e., the second encryption result), and upload the ciphertext collaboration access token to the collaboration permission contract on the blockchain, so that the collaboration permission contract can verify the decryption result of the collaboration access token sent by the different member terminals based on the ciphertext collaboration access token.
[0141] It should be noted that the ciphertext collaboration access token (i.e., the second encryption result) uploaded to the collaboration permission contract can be obtained by the collaboration initiation terminal based on an encryption algorithm different from the public key encryption manner (i.e., the encryption manner corresponding to the first encryption result), and the specific encryption algorithm corresponding to the ciphertext collaboration access token is not limited in the embodiments of the present application.
[0142] S603, receiving the decryption result of the collaboration access token fed back by the first member terminal, and verifying the decryption result on the blockchain based on the decryption result and the second encryption result of the collaboration access token uploaded to the collaboration permission contract.
[0143] Specifically, as an optional embodiment, the collaboration permission contract can receive the decryption result of the collaboration access token sent by different first member terminals (wherein, since the first encryption result is encrypted based on the public key of the first member terminal, the first member terminal can decrypt the received first encryption result based on the private key held by itself to obtain the decryption result), and then re-encrypt the decryption result on the blockchain according to the second encryption result of the collaboration access token by using the same encryption manner as the second encryption result (for example, if the second encryption result is obtained based on the keccak256 encryption algorithm, the decryption result can also be re-encrypted by using the keccak256 encryption algorithm), so as to determine that the decryption result sent by the current first member terminal passes the verification when it is determined that the re-encrypted result is the same as the second encryption result of the collaboration access token uploaded by the collaboration initiation terminal.
[0144] Specifically, as another optional embodiment, the collaboration permission contract can also decrypt the second encryption result of the collaboration access token on the blockchain according to the second encryption result of the collaboration access token, by a decryption method corresponding to the second encryption result, and verify the decryption result of the collaboration access token fed back by the first member terminal according to the collaboration access token obtained after decryption. When the two decryption results are consistent, it can be determined that the decryption result sent by the first member terminal passes the verification.
[0145] It should be noted that the specific verification method based on the above two optional embodiments is not limited by the embodiments of the present application for the specific verification method of the decryption result fed back by the first member terminal in step S603.
[0146] S604, when the decryption result passes the verification, allowing the first member terminal to participate in the target collaboration.
[0147] Here, when it is determined that the decryption result of the collaboration access token fed back by the first member terminal is correct, the first member terminal is allowed to participate in the target collaboration; wherein the first member terminal needs to comply with the specific permission type recorded in the target credential held by the first member terminal in the process of participating in the target collaboration, for example, if the specific permission type recorded in the target credential held by the first member terminal is: the viewing permission of the document in the target collaboration process, then the first member terminal can only view the document in the collaboration when participating in the target collaboration, and cannot edit the document in the collaboration.
[0148] The above-mentioned method for collaboration in the blockchain provided by the embodiments of the present application sends a target credential to a target member terminal that meets the participation condition of the target collaboration; receives a collaboration request of a first member terminal in a target organization for the target collaboration, and verifies whether the verifiable credential held by the first member terminal belongs to the target credential according to the credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal; when it is determined that the first member terminal has the collaboration permission to participate in the target collaboration based on the collaboration permission verification result, the first member terminal is allowed to participate in the target collaboration according to the collaboration participation strategy agreed in the collaboration permission contract. In this way, on the basis of realizing the decentralized management of permission data, the present application can effectively improve the security and transparency of the management of permission data in the target organization.
[0149] Based on the same inventive concept, the application further provides a device for collaboration in a blockchain corresponding to the above-mentioned method for collaboration in a blockchain. Since the device for collaboration in a blockchain in the embodiments of the application solves the problem in a similar principle to the above-mentioned method for collaboration in a blockchain in the embodiments of the application, the implementation of the device for collaboration in a blockchain can be referred to the implementation of the above-mentioned method for collaboration in a blockchain, and the repeated parts will not be described here.
[0150] With reference to Figure 7 , it is shown that the device for collaboration in a blockchain provided by the embodiments of the application comprises: Figure 7 The device for collaboration in a blockchain provided by the embodiments of the application comprises:
[0151] The first response module 701 is configured to send a target credential to a target member terminal satisfying a participation condition of a target collaboration; wherein the target member terminal is determined from a plurality of member terminals in a target organization applying for participating in the target collaboration; and the target credential is used to prove that the target member terminal has a collaboration permission for participating in the target collaboration.
[0152] The first verification module 702 is configured to receive a collaboration request of a first member terminal in the target organization for the target collaboration, and verify whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal.
[0153] The first processing module 703 is configured to allow the first member terminal to participate in the target collaboration according to a collaboration participation strategy agreed in a collaboration permission contract when it is determined that the first member terminal has a collaboration permission for participating in the target collaboration based on the collaboration permission verification result.
[0154] In an optional implementation, the target organization represents an organization located on the blockchain; and the organization type to which the target organization belongs at least includes a decentralized autonomous organization.
[0155] In an optional implementation, each member terminal in the target organization, a subject terminal of the target organization, and the collaboration permission contract jointly constitute a verifiable credential system corresponding to the target organization on the blockchain; wherein in the verifiable credential system:
[0156] The collaboration permission contract is configured to determine a target member terminal satisfying a participation condition of the target collaboration from the plurality of member terminals;
[0157] The subject terminal of the target organization has an issuing right of a verifiable credential, and is configured to send the target credential to the target member terminal; and the target credential belongs to the verifiable credential.
[0158] the target member terminal has the possession right of the target credential;
[0159] the collaboration initiation terminal of the target collaboration has the verification right of the target credential; the collaboration initiation terminal belongs to the member terminals in the target organization.
[0160] In an optional implementation, the first response module 701 is specifically configured to:
[0161] during the valid participation period corresponding to the target collaboration, for each of the member terminals, verifying whether the member terminal meets the participation condition of the target collaboration according to user data of the member terminal on the blockchain, to obtain a participation permission verification result of the member terminal;
[0162] when it is determined based on the participation permission verification result that the member terminal meets the participation condition of the target collaboration, determining that the member terminal belongs to the target member terminal, and sending the target credential to the member terminal.
[0163] In an optional implementation, when the first response module 701 verifies whether the member terminal meets the participation condition of the target collaboration according to the user data of the member terminal on the blockchain, the first response module 701 is configured to:
[0164] determining, according to the user data of the member terminal on the blockchain, a historical contribution of the member terminal to the target organization;
[0165] in response to the historical contribution being greater than or equal to a target contribution threshold, determining that the member terminal meets the participation condition of the target collaboration; wherein the target contribution threshold is determined according to the participation condition of the target collaboration;
[0166] in response to the historical contribution being less than the target contribution threshold, determining that the member terminal does not meet the participation condition of the target collaboration.
[0167] In an optional implementation, when the first response module 701 verifies whether the member terminal meets the participation condition of the target collaboration according to the user data of the member terminal on the blockchain, to obtain the participation permission verification result of the member terminal, the first response module 701 is further configured to:
[0168] according to a plurality of evaluation indexes included in the participation condition of the target collaboration, obtaining, from the user data of the member terminal on the blockchain, valid user data associated with each of the evaluation indexes;
[0169] determining a comprehensive evaluation result of the member terminal according to the valid user data associated with each of the evaluation indexes and an index weight of each of the evaluation indexes.
[0170] determining that the member terminal satisfies the participation condition of the target collaboration in response to the comprehensive evaluation result being greater than or equal to a target evaluation threshold; wherein the target evaluation threshold and the index weight of each evaluation index are determined according to the participation condition of the target collaboration.
[0171] In an optional implementation, when the participation condition of the target collaboration includes participation conditions of multiple different permission types, in the process of determining that the member terminal satisfies the participation condition of the target collaboration based on the participation permission verification result, determining that the member terminal belongs to the target member terminal, and sending the target credential to the member terminal, the first response module 701 is configured to:
[0172] determining that the member terminal belongs to the target member terminal and sending a first target credential to the member terminal in response to the user data of the member terminal on the blockchain satisfying a participation condition of a first permission type; wherein the first target credential is used to prove that the member terminal can participate in the target collaboration according to the participation permission of the first permission type;
[0173] or,
[0174] determining that the member terminal belongs to the target member terminal and sending a second target credential to the member terminal in response to the user data of the member terminal on the blockchain satisfying a participation condition of a second permission type; wherein the second target credential is used to prove that the member terminal can participate in the target collaboration according to the participation permission of the second permission type; the participation condition of the second permission type is different from the participation condition of the first permission type.
[0175] In an optional implementation, the first verification module 702 is specifically configured to:
[0176] verifying whether the first member terminal belongs to the holder of the target credential according to the holder signature information recorded in the credential description information, to obtain an identity verification result of the first member terminal;
[0177] when it is determined based on the identity verification result that the first member terminal belongs to the holder of the target credential, verifying whether the verifiable credential is a valid target credential according to the issuer signature information recorded in the credential description information and the credential validity period of the verifiable credential, to obtain a collaboration permission verification result of the first member terminal.
[0178] In an optional implementation, the first processing module 703 is specifically configured to:
[0179] in response to the first member terminal having the collaboration permission to participate in the target collaboration, encrypting, according to a public key of the first member terminal, a collaboration access token of the target collaboration to obtain a first encryption result of the collaboration access token;
[0180] sending the first member terminal the first encryption result of the collaboration access token and uploading the second encryption result of the collaboration access token to the collaboration permission contract on the blockchain; wherein the second encryption result and the first encryption result are obtained through different encryption manners;
[0181] receiving a decryption result of the collaboration access token fed back by the first member terminal, and verifying the decryption result on the blockchain based on the decryption result and the second encryption result of the collaboration access token uploaded to the collaboration permission contract;
[0182] when the decryption result passes the verification, allowing the first member terminal to participate in the target collaboration.
[0183] The above-mentioned collaboration device in the blockchain provided by the embodiments of the present application sends a target credential to a target member terminal that meets the participation condition of a target collaboration; receives a collaboration request of a first member terminal in a target organization for a target collaboration, and verifies whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal; when it is determined based on the collaboration permission verification result that the first member terminal has the collaboration permission to participate in the target collaboration, the first member terminal is allowed to participate in the target collaboration according to a collaboration participation strategy agreed in the collaboration permission contract. In this way, on the basis of realizing the decentralized management of permission data, the present application can effectively improve the security and transparency of permission data management in the target organization.
[0184] Based on the same inventive concept, the present application also provides a system corresponding to the above-mentioned method of collaboration in the blockchain. Since the system in the embodiments of the present application solves the problem in the same way as the above-mentioned method of collaboration in the blockchain, the implementation of the system can be referred to the implementation of the above-mentioned method, and the repeated parts will not be described here.
[0185] Referring to Figure 8 Figure 8 Fig. 1 shows a structural schematic diagram of a system for collaboration in the blockchain provided by the embodiments of the present application, which comprises a collaboration initiation terminal 800 (i.e. a member terminal initiating a target collaboration), a collaboration permission contract 801, a subject terminal 802 of a target organization and a plurality of member terminals 803 in the target organization; wherein the subject terminal 802 of the target organization is configured to:
[0186] sending a target credential to a target member terminal satisfying a participation condition of a target collaboration; wherein the target member terminal is determined from a plurality of member terminals in a target organization applying for participation in the target collaboration; the target credential is used to prove that the target member terminal has a collaboration permission of participating in the target collaboration;
[0187] The collaboration initiation terminal 800 is configured to receive a collaboration request of a first member terminal in the target organization for the target collaboration, and verify whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal.
[0188] When it is determined that the first member terminal has the collaboration permission of participating in the target collaboration based on the collaboration permission verification result, the first member terminal is allowed to participate in the target collaboration according to a collaboration participation strategy agreed in the collaboration permission contract 801; wherein the collaboration initiation terminal 800 is further configured to feed back the obtained collaboration permission verification result to a subject terminal 802 of the target organization.
[0189] In an optional implementation, the target organization represents an organization located on the blockchain; and the organization type to which the target organization belongs at least includes a decentralized autonomous organization.
[0190] In an optional implementation, each member terminal 803 in the target organization, the subject terminal 802 of the target organization, and the collaboration permission contract 801 collectively constitute a corresponding verifiable credential system of the target organization on the blockchain; wherein in the verifiable credential system:
[0191] The collaboration permission contract 801 is configured to determine a target member terminal satisfying a participation condition of the target collaboration from a plurality of member terminals 803.
[0192] The subject terminal 802 of the target organization has an issuing right of a verifiable credential, and is configured to send the target credential to the target member terminal; the target credential belongs to the verifiable credential.
[0193] The target member terminal has a holding right of the target credential.
[0194] The collaboration initiation terminal 800 of the target collaboration has a verification right of the target credential; and the collaboration initiation terminal 800 belongs to a member terminal in the target organization.
[0195] In an optional implementation, when the target credential is sent to the target member terminal satisfying the participation condition of the target collaboration, the collaboration permission contract 801 is configured to:
[0196] In the valid participation period of the target collaboration corresponding to the target organization, for each member terminal, according to user data of the member terminal on the blockchain, it is verified whether the member terminal meets the participation condition of the target collaboration, and a participation permission verification result of the member terminal is obtained;
[0197] The subject terminal 802 of the target organization is configured to:
[0198] When it is determined based on the participation permission verification result that the member terminal meets the participation condition of the target collaboration, it is determined that the member terminal belongs to the target member terminal, and the target credential is sent to the member terminal.
[0199] In an optional implementation, when it is verified whether the member terminal meets the participation condition of the target collaboration according to the user data of the member terminal on the blockchain, the collaboration permission contract 801 is configured to:
[0200] According to the user data of the member terminal on the blockchain, a historical contribution of the member terminal to the target organization is determined;
[0201] In response to the historical contribution being greater than or equal to a target contribution threshold, it is determined that the member terminal meets the participation condition of the target collaboration; wherein the target contribution threshold is determined according to the participation condition of the target collaboration;
[0202] In response to the historical contribution being less than the target contribution threshold, it is determined that the member terminal does not meet the participation condition of the target collaboration.
[0203] In an optional implementation, when it is verified whether the member terminal meets the participation condition of the target collaboration according to the user data of the member terminal on the blockchain, the collaboration permission contract 801 is further configured to:
[0204] According to a plurality of evaluation indexes included in the participation condition of the target collaboration, effective user data associated with each evaluation index is obtained from the user data of the member terminal on the blockchain;
[0205] According to the effective user data associated with each evaluation index and an index weight of each evaluation index, a comprehensive evaluation result of the member terminal is determined;
[0206] In response to the comprehensive evaluation result being greater than or equal to a target evaluation threshold, it is determined that the member terminal meets the participation condition of the target collaboration; wherein the target evaluation threshold and the index weight of each evaluation index are determined according to the participation condition of the target collaboration.
[0207] In an optional implementation, when the participation condition of the target collaboration includes participation conditions of multiple different permission types, when it is determined that the member terminal belongs to the target member terminal and the target credential is sent to the member terminal based on the participation permission verification result, the subject terminal 802 of the target organization is configured to:
[0208] determine that the member terminal belongs to the target member terminal and send a first target credential to the member terminal in response to the user data of the member terminal on the blockchain satisfying the participation condition of the first permission type; wherein the first target credential is used to prove that the member terminal can participate in the target collaboration according to the participation permission of the first permission type;
[0209] or,
[0210] determine that the member terminal belongs to the target member terminal and send a second target credential to the member terminal in response to the user data of the member terminal on the blockchain satisfying the participation condition of the second permission type; wherein the second target credential is used to prove that the member terminal can participate in the target collaboration according to the participation permission of the second permission type; the participation condition of the second permission type is different from the participation condition of the first permission type.
[0211] In an optional implementation, when the collaboration permission verification result of the first member terminal is obtained by verifying whether the verifiable credential held by the first member terminal belongs to the target credential according to the credential description information contained in the collaboration request, the collaboration initiation terminal 800 is configured to:
[0212] verify whether the first member terminal belongs to the holder of the target credential according to the holder signature information recorded in the credential description information, and obtain an identity verification result of the first member terminal;
[0213] when it is determined that the first member terminal belongs to the holder of the target credential based on the identity verification result, verify whether the verifiable credential belongs to a valid target credential according to the issuer signature information recorded in the credential description information and the credential validity period of the verifiable credential, and obtain the collaboration permission verification result of the first member terminal.
[0214] In an optional implementation, when the first member terminal is allowed to participate in the target collaboration according to the collaboration participation strategy agreed in the collaboration permission contract 801 based on the collaboration permission verification result of the first member terminal, the collaboration initiation terminal 800 is configured to:
[0215] In response to the first member terminal having the collaboration right to participate in the target collaboration, encrypt the collaboration access token of the target collaboration according to the public key of the first member terminal to obtain a first encryption result of the collaboration access token;
[0216] send the first encryption result of the collaboration access token to the first member terminal and upload the second encryption result of the collaboration access token to the collaboration right contract 801 on the blockchain; the second encryption result and the first encryption result are obtained through different encryption methods;
[0217] receive the decryption result of the collaboration access token fed back by the first member terminal, and verify the decryption result on the blockchain based on the decryption result and the second encryption result of the collaboration access token uploaded to the collaboration right contract 801;
[0218] When the decryption result passes the verification, allow the first member terminal to participate in the target collaboration; wherein the collaboration initiation terminal 800 is further configured to feed back the verification result of the collaboration access token to the first member terminal, so that the first member terminal can determine whether to participate in the target collaboration according to the received verification result.
[0219] The above-mentioned system for collaboration in the blockchain provided by the embodiments of the present application sends target credentials to target member terminals that meet the participation conditions of the target collaboration; receives a collaboration request for the target collaboration from a first member terminal in a target organization, and verifies whether the verifiable credentials held by the first member terminal belong to the target credentials according to the credential description information contained in the collaboration request, to obtain a collaboration right verification result of the first member terminal; when it is determined that the first member terminal has the collaboration right to participate in the target collaboration based on the collaboration right verification result, the first member terminal is allowed to participate in the target collaboration according to the collaboration participation strategy agreed in the collaboration right contract. In this way, the present application can effectively improve the security and transparency of the management of the right data in the target organization on the basis of realizing the decentralized management of the right data.
[0220] based on the same inventive concept, Figure 9 A structural schematic diagram of an electronic device 900 provided by the embodiments of the present application includes a processor 901, a memory 902 and a bus 903. The memory 902 stores machine-readable instructions executable by the processor 901. When the electronic device runs a method for collaboration in the blockchain as in the embodiments, the processor 901 communicates with the memory 902 through the bus 903. The processor 901 executes the machine-readable instructions, wherein the processor 901 executes the machine-readable instructions to implement the following steps, specifically:
[0221] sending a target credential to a target member terminal meeting a participation condition of a target collaboration; wherein the target member terminal is determined from a plurality of member terminals in a target organization applying for participating in the target collaboration; the target credential is used to prove that the target member terminal has a collaboration permission of participating in the target collaboration;
[0222] receiving a collaboration request of a first member terminal in the target organization for the target collaboration, and verifying whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal;
[0223] when it is determined that the first member terminal has the collaboration permission of participating in the target collaboration based on the collaboration permission verification result, allowing the first member terminal to participate in the target collaboration according to a collaboration participation strategy agreed in a collaboration permission contract.
[0224] In an optional implementation, the target organization represents an organization located on the blockchain; and the organization type to which the target organization belongs at least includes a decentralized autonomous organization.
[0225] In an optional implementation, each member terminal in the target organization, a subject terminal of the target organization, and the collaboration permission contract together constitute a verifiable credential system corresponding to the target organization on the blockchain; wherein in the verifiable credential system:
[0226] the collaboration permission contract is used to determine a target member terminal meeting a participation condition of the target collaboration from the plurality of member terminals;
[0227] the subject terminal of the target organization has an issuing right of a verifiable credential, and is used to send the target credential to the target member terminal; and the target credential belongs to the verifiable credential;
[0228] the target member terminal has a holding right of the target credential;
[0229] a collaboration initiation terminal of the target collaboration has a verification right of the target credential; and the collaboration initiation terminal belongs to a member terminal in the target organization.
[0230] In an optional implementation, when the target credential is sent to the target member terminal meeting the participation condition of the target collaboration, the processor 901 is configured to:
[0231] verify, for each of the member terminals, whether the member terminal satisfies the participation condition of the target collaboration according to user data of the member terminal on the blockchain, to obtain a participation permission verification result of the member terminal;
[0232] determine that the member terminal belongs to the target member terminal and send the target credential to the member terminal when it is determined that the member terminal satisfies the participation condition of the target collaboration based on the participation permission verification result.
[0233] In an optional implementation, when verifying whether the member terminal satisfies the participation condition of the target collaboration according to the user data of the member terminal on the blockchain, the processor 901 is configured to:
[0234] determine the historical contribution of the member terminal to the target organization according to the user data of the member terminal on the blockchain;
[0235] determine that the member terminal satisfies the participation condition of the target collaboration in response to the historical contribution being greater than or equal to a target contribution threshold value, wherein the target contribution threshold value is determined according to the participation condition of the target collaboration;
[0236] determine that the member terminal does not satisfy the participation condition of the target collaboration in response to the historical contribution being less than the target contribution threshold value.
[0237] In an optional implementation, when verifying whether the member terminal satisfies the participation condition of the target collaboration according to the user data of the member terminal on the blockchain to obtain the participation permission verification result of the member terminal, the processor 901 is further configured to:
[0238] obtain, from the user data of the member terminal on the blockchain, effective user data associated with each of a plurality of evaluation indexes included in the participation condition of the target collaboration;
[0239] determine a comprehensive evaluation result of the member terminal according to the effective user data associated with each of the evaluation indexes and an index weight of each of the evaluation indexes;
[0240] determine that the member terminal satisfies the participation condition of the target collaboration in response to the comprehensive evaluation result being greater than or equal to a target evaluation threshold value, wherein the target evaluation threshold value and the index weight of each of the evaluation indexes are determined according to the participation condition of the target collaboration.
[0241] In an optional implementation, when the participation condition of the target collaboration includes participation conditions of multiple different permission types, when the processor 901 determines that the member terminal belongs to the target member terminal and sends the target credential to the member terminal, in a manner that:
[0242] determines that the member terminal belongs to the target member terminal and sends a first target credential to the member terminal, in a manner that the user data of the member terminal on the blockchain satisfies the participation condition of the first permission type; and the first target credential is used to prove that the member terminal can participate in the target collaboration according to the participation permission of the first permission type;
[0243] or,
[0244] determines that the member terminal belongs to the target member terminal and sends a second target credential to the member terminal, in a manner that the user data of the member terminal on the blockchain satisfies the participation condition of the second permission type; and the second target credential is used to prove that the member terminal can participate in the target collaboration according to the participation permission of the second permission type; and the participation condition of the second permission type is different from the participation condition of the first permission type.
[0245] In an optional implementation, when the processor 901 verifies whether the verifiable credential held by the first member terminal belongs to the target credential according to the credential description information contained in the collaboration request, and obtains the collaboration permission verification result of the first member terminal, in a manner that:
[0246] verifies whether the first member terminal belongs to the holder of the target credential according to the holder signature information recorded in the credential description information, and obtains the identity verification result of the first member terminal;
[0247] when it is determined that the first member terminal belongs to the holder of the target credential based on the identity verification result, verifies whether the verifiable credential belongs to a valid target credential according to the issuer signature information recorded in the credential description information and the credential validity period of the verifiable credential, and obtains the collaboration permission verification result of the first member terminal.
[0248] In an optional implementation, when the processor 901 determines that the first member terminal has the collaboration permission to participate in the target collaboration based on the collaboration permission verification result, and allows the first member terminal to participate in the target collaboration according to the collaboration participation strategy agreed in the collaboration permission contract, in a manner that:
[0249] in response to the first member terminal having the collaboration permission to participate in the target collaboration, encrypting, according to a public key of the first member terminal, a collaboration access token of the target collaboration to obtain a first encryption result of the collaboration access token;
[0250] sending the first encryption result of the collaboration access token to the first member terminal and uploading the second encryption result of the collaboration access token to the collaboration permission contract on the blockchain; wherein the second encryption result and the first encryption result are obtained through different encryption manners;
[0251] receiving a decryption result of the collaboration access token fed back by the first member terminal, and verifying the decryption result on the blockchain based on the decryption result and the second encryption result of the collaboration access token uploaded to the collaboration permission contract;
[0252] when the decryption result passes the verification, allowing the first member terminal to participate in the target collaboration.
[0253] The electronic device provided in the embodiments of the present application sends a target credential to a target member terminal that meets a participation condition of a target collaboration; receives a collaboration request of a first member terminal in a target organization for a target collaboration, and verifies whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal; when it is determined based on the collaboration permission verification result that the first member terminal has the collaboration permission to participate in the target collaboration, the first member terminal is allowed to participate in the target collaboration according to a collaboration participation strategy agreed in a collaboration permission contract. In this way, the present application can effectively improve the security and transparency of permission data management in a target organization on the basis of realizing the decentralized management of permission data.
[0254] Based on the same inventive concept, the embodiments of the present application also provide a computer readable storage medium having a computer program stored thereon, the computer program being executed when a processor runs, and the processor executes the following steps:
[0255] sending a target credential to a target member terminal that meets a participation condition of a target collaboration; wherein the target member terminal is determined from a plurality of member terminals in a target organization that apply to participate in the target collaboration; and the target credential is used to prove that the target member terminal has a collaboration permission to participate in the target collaboration;
[0256] receive a collaboration request of a first member terminal in the target organization for the target collaboration, and verify whether a verifiable credential held by the first member terminal belongs to the target credential according to credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal;
[0257] when it is determined based on the collaboration permission verification result that the first member terminal has the collaboration permission to participate in the target collaboration, allow the first member terminal to participate in the target collaboration according to a collaboration participation strategy agreed in the collaboration permission contract.
[0258] In an optional implementation, the target organization represents an organization located on the blockchain; and the organization type to which the target organization belongs at least includes a decentralized autonomous organization.
[0259] In an optional implementation, each member terminal in the target organization, a subject terminal of the target organization, and the collaboration permission contract together constitute a verifiable credential system of the target organization corresponding to the blockchain; and in the verifiable credential system:
[0260] the collaboration permission contract is configured to determine a target member terminal that satisfies a participation condition of the target collaboration from the plurality of member terminals;
[0261] the subject terminal of the target organization has an issuing right of a verifiable credential, and is configured to send the target credential to the target member terminal; and the target credential belongs to the verifiable credential;
[0262] the target member terminal has a holding right of the target credential;
[0263] a collaboration initiation terminal of the target collaboration has a verification right of the target credential; and the collaboration initiation terminal belongs to a member terminal in the target organization.
[0264] In an optional implementation, when the target credential is sent to the target member terminal that satisfies the participation condition of the target collaboration, the processor is configured to:
[0265] in an effective participation period corresponding to the target collaboration, verify, for each member terminal, whether the member terminal satisfies the participation condition of the target collaboration according to user data of the member terminal on the blockchain, to obtain a participation permission verification result of the member terminal;
[0266] when it is determined based on the participation permission verification result that the member terminal satisfies the participation condition of the target collaboration, determine that the member terminal belongs to the target member terminal, and send the target credential to the member terminal.
[0267] In an optional implementation, when verifying whether the member terminal satisfies the participation condition of the target collaboration according to the user data of the member terminal on the blockchain, the processor is configured to:
[0268] determine the historical contribution of the member terminal to the target organization according to the user data of the member terminal on the blockchain;
[0269] determine that the member terminal satisfies the participation condition of the target collaboration in response to the historical contribution being greater than or equal to a target contribution threshold value, wherein the target contribution threshold value is determined according to the participation condition of the target collaboration;
[0270] determine that the member terminal does not satisfy the participation condition of the target collaboration in response to the historical contribution being less than the target contribution threshold value.
[0271] In an optional implementation, when verifying whether the member terminal satisfies the participation condition of the target collaboration according to the user data of the member terminal on the blockchain, the processor is further configured to:
[0272] obtain, from the user data of the member terminal on the blockchain, valid user data associated with each evaluation index included in the participation condition of the target collaboration;
[0273] determine a comprehensive evaluation result of the member terminal according to the valid user data associated with each evaluation index and an index weight of each evaluation index;
[0274] determine that the member terminal satisfies the participation condition of the target collaboration in response to the comprehensive evaluation result being greater than or equal to a target evaluation threshold value, wherein the target evaluation threshold value and the index weight of each evaluation index are determined according to the participation condition of the target collaboration.
[0275] In an optional implementation, when the participation condition of the target collaboration includes participation conditions of multiple different permission types, when determining that the member terminal satisfies the participation condition of the target collaboration based on the participation permission verification result, and sending the target credential to the member terminal, the processor is configured to:
[0276] determine that the member terminal belongs to the target member terminal and send a first target credential to the member terminal in response to the user data of the member terminal on the blockchain satisfying a participation condition of a first permission type, wherein the first target credential is used to prove that the member terminal can participate in the target collaboration according to a participation permission of the first permission type;
[0277] or,
[0278] in response to the user data of the member terminal on the blockchain satisfying the participation condition of the second permission type, determining that the member terminal belongs to the target member terminal, and sending a second target credential to the member terminal; wherein the second target credential is used to prove that the member terminal can participate in the target collaboration according to the participation permission of the second permission type; the participation condition of the second permission type is different from the participation condition of the first permission type.
[0279] In an optional implementation, when the processor is configured to verify whether the verifiable credential held by the first member terminal belongs to the target credential according to the credential description information contained in the collaboration request, and obtain the collaboration permission verification result of the first member terminal,
[0280] verify whether the first member terminal belongs to the holder of the target credential according to the holder signature information recorded in the credential description information, and obtain the identity verification result of the first member terminal;
[0281] When it is determined based on the identity verification result that the first member terminal belongs to the holder of the target credential, verify whether the verifiable credential is a valid target credential according to the issuer signature information recorded in the credential description information and the credential validity period of the verifiable credential, and obtain the collaboration permission verification result of the first member terminal.
[0282] In an optional implementation, when the processor is configured to allow the first member terminal to participate in the target collaboration according to the collaboration participation strategy agreed in the collaboration permission contract when it is determined based on the collaboration permission verification result that the first member terminal has the collaboration permission to participate in the target collaboration,
[0283] in response to the first member terminal having the collaboration permission to participate in the target collaboration, encrypt the collaboration access token of the target collaboration according to the public key of the first member terminal, to obtain a first encryption result of the collaboration access token;
[0284] send the first encryption result of the collaboration access token to the first member terminal, and upload the second encryption result of the collaboration access token to the collaboration permission contract on the blockchain; wherein the second encryption result and the first encryption result are obtained by different encryption methods;
[0285] receive the decryption result of the collaboration access token fed back by the first member terminal, and verify the decryption result on the blockchain based on the decryption result and the second encryption result of the collaboration access token uploaded to the collaboration permission contract.
[0286] When the decryption result is verified, the first member terminal is allowed to participate in the target collaboration.
[0287] The computer readable storage medium provided in the embodiments of the present application sends target credentials to target member terminals that meet the participation conditions of target collaboration; receives a collaboration request of a first member terminal in a target organization for target collaboration, and verifies whether the verifiable credentials held by the first member terminal belong to the target credentials according to the credential description information contained in the collaboration request, to obtain a collaboration permission verification result of the first member terminal; when it is determined that the first member terminal has the collaboration permission to participate in the target collaboration based on the collaboration permission verification result, the first member terminal is allowed to participate in the target collaboration according to the collaboration participation strategy agreed in the collaboration permission contract. In this way, on the basis of realizing the decentralized management of permission data, the security and transparency of permission data management in the target organization can be effectively improved.
[0288] In the embodiments of the present application, the computer program can also execute other machine readable instructions when run by the processor to perform the method of collaboration in the blockchain as described in other embodiments. For specific method steps and principles, refer to the description of the embodiments, which will not be described in detail here.
[0289] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division, and there can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some communication interfaces, and can be electrical, mechanical or other forms.
[0290] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment.
[0291] In addition, each functional unit in the embodiments provided in the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.
[0292] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0293] It should be noted that similar reference numbers and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. In addition, the terms "first", "second", "third" and the like are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0294] Finally, it should be noted that the above-described embodiments are only specific implementations of the present application, which are used to illustrate the technical solutions of the present application, but not to limit them. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can make modifications or easily think of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed by the present application, or make equivalent replacements to some technical features. These modifications, changes or replacements do not cause the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application. They should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for collaboration in a blockchain, characterized in that, The method includes: Send a target credential to the target member terminal that meets the participation conditions of the target collaboration; wherein, the target member terminal is determined from multiple member terminals within the target organization that have applied to participate in the target collaboration; the target credential is used to prove that the target member terminal has the collaboration authority to participate in the target collaboration; The system receives a collaboration request from a first member terminal within the target organization for the target collaboration, and verifies whether the verifiable credentials held by the first member terminal belong to the target credentials based on the credential description information contained in the collaboration request, thereby obtaining the collaboration permission verification result of the first member terminal. When it is determined, based on the collaboration permission verification result, that the first member terminal has the collaboration permission to participate in the target collaboration, the first member terminal is allowed to participate in the target collaboration in accordance with the collaboration participation strategy agreed in the collaboration permission contract.
2. The method according to claim 1, characterized in that, The target organization represents the organization located on the blockchain; The target organization belongs to at least the following organizational types: decentralized autonomous organizations.
3. The method according to claim 1, characterized in that, Each member terminal within the target organization, the main terminal of the target organization, and the collaboration permission contract together constitute the verifiable credential system corresponding to the target organization on the blockchain; wherein, in the verifiable credential system: The collaboration permission contract is used to determine, from the plurality of member terminals, the target member terminal that meets the participation conditions of the target collaboration; The target organization's main terminal has the right to issue verifiable credentials and is used to send the target credentials to the target member terminals; The target member terminal has the right to hold the target credential; The collaboration initiating terminal of the target collaboration has the verification right of the target credential; the collaboration initiating terminal belongs to a member terminal within the target organization.
4. The method according to claim 1, characterized in that, Sending target credentials to target member terminals that meet the participation conditions for target collaboration includes: Within the effective participation period corresponding to the target collaboration, for each member terminal, based on the user data of the member terminal on the blockchain, it is verified whether the member terminal meets the participation conditions of the target collaboration, and the participation permission verification result of the member terminal is obtained. When it is determined, based on the participation permission verification result, that the member terminal meets the participation conditions of the target collaboration, the member terminal is determined to belong to the target member terminal, and the target credential is sent to the member terminal.
5. The method according to claim 4, characterized in that, The step of verifying whether a member terminal meets the participation conditions for the target collaboration based on its user data on the blockchain includes: Based on the user data of the member terminal on the blockchain, determine the member terminal's historical contributions to the target organization; In response to the historical contribution being greater than or equal to the target contribution threshold, it is determined that the member terminal meets the participation conditions for the target collaboration; wherein, the target contribution threshold is determined based on the participation conditions for the target collaboration; In response to the historical contribution being less than the target contribution threshold, it is determined that the member terminal does not meet the participation conditions for the target collaboration.
6. The method according to claim 4, characterized in that, The step of verifying whether the member terminal meets the participation conditions of the target collaboration based on the member terminal's user data on the blockchain, and obtaining the member terminal's participation permission verification result, further includes: Based on the multiple assessment indicators included in the participation conditions of the target collaboration, obtain the valid user data associated with each assessment indicator from the user data of the member terminal on the blockchain; The comprehensive assessment result of the member terminal is determined based on the valid user data associated with each assessment indicator and the indicator weight of each assessment indicator. In response to the comprehensive assessment result being greater than or equal to the target assessment threshold, it is determined that the member terminal meets the participation conditions for the target collaboration; wherein, the target assessment threshold and the indicator weight of each assessment indicator are determined according to the participation conditions for the target collaboration.
7. The method according to claim 4, characterized in that, When the participation conditions for the target collaboration include multiple participation conditions with different permission types, the step of determining that the member terminal belongs to the target member terminal and sending the target credential to the member terminal when it is determined that the member terminal meets the participation conditions for the target collaboration based on the participation permission verification result includes: In response to the fact that the user data of the member terminal on the blockchain meets the participation conditions of the first permission type, it is determined that the member terminal belongs to the target member terminal, and a first target credential is sent to the member terminal; wherein, the first target credential is used to prove that the member terminal can participate in the target collaboration in accordance with the participation permissions specified by the first permission type; or, In response to the fact that the user data of the member terminal on the blockchain meets the participation conditions of the second permission type, it is determined that the member terminal belongs to the target member terminal, and a second target credential is sent to the member terminal; wherein, the second target credential is used to prove that the member terminal can participate in the target collaboration in accordance with the participation permissions specified by the second permission type; the participation conditions of the second permission type are different from the participation conditions of the first permission type.
8. The method according to claim 1, characterized in that, The step of verifying whether the verifiable credential held by the first member terminal belongs to the target credential based on the credential description information contained in the collaboration request, and obtaining the collaboration permission verification result of the first member terminal, includes: Based on the holder's signature information recorded in the credential description information, the system verifies whether the first member terminal belongs to the holder of the target credential, and obtains the identity verification result of the first member terminal. When it is determined that the first member terminal belongs to the holder of the target credential based on the identity verification result, the issuer signature information recorded in the credential description information and the validity period of the verifiable credential are used to verify whether the verifiable credential is a valid target credential, so as to obtain the collaboration permission verification result of the first member terminal.
9. The method according to claim 1, characterized in that, When it is determined, based on the collaboration permission verification result, that the first member terminal has the collaboration permission to participate in the target collaboration, allowing the first member terminal to participate in the target collaboration according to the collaboration participation strategy agreed in the collaboration permission contract includes: In response to the first member terminal having the collaboration permission to participate in the target collaboration, the collaboration access token of the target collaboration is encrypted according to the public key of the first member terminal to obtain the first encryption result of the collaboration access token; The first encrypted result of the collaboration access token is sent to the first member terminal, and the second encrypted result of the collaboration access token is uploaded to the collaboration permission contract on the blockchain; wherein the second encrypted result and the first encrypted result are obtained through different encryption methods; The system receives the decryption result of the collaboration access token from the first member terminal, and verifies the decryption result on the blockchain based on the decryption result and the second encryption result of the collaboration access token uploaded to the collaboration permission contract. When the decryption result passes verification, the first member terminal is allowed to participate in the target collaboration.
10. A device for collaboration in a blockchain, characterized in that, The device includes: The first response module is used to send a target credential to a target member terminal that meets the participation conditions of the target collaboration; wherein, the target member terminal is determined from multiple member terminals within the target organization that have applied to participate in the target collaboration; the target credential is used to prove that the target member terminal has the collaboration authority to participate in the target collaboration; The first verification module is used to receive a collaboration request from a first member terminal within the target organization for the target collaboration, and to verify whether the verifiable credential held by the first member terminal belongs to the target credential based on the credential description information contained in the collaboration request, so as to obtain the collaboration permission verification result of the first member terminal. The first processing module is configured to, when determining, based on the collaboration permission verification result, that the first member terminal has the collaboration permission to participate in the target collaboration, allow the first member terminal to participate in the target collaboration in accordance with the collaboration participation strategy agreed in the collaboration permission contract.
11. A system for collaboration in a blockchain, characterized in that, The system includes: a collaboration initiation terminal, a main terminal of the target organization, a collaboration permission contract, and multiple member terminals within the target organization; wherein, the main terminal of the target organization is used for: Send a target credential to the target member terminal that meets the participation conditions of the target collaboration; wherein, the target member terminal is determined from multiple member terminals within the target organization that have applied to participate in the target collaboration; the target credential is used to prove that the target member terminal has the collaboration authority to participate in the target collaboration; The collaboration initiating terminal is used to receive a collaboration request from a first member terminal within the target organization for the target collaboration, and to verify whether the verifiable credential held by the first member terminal belongs to the target credential based on the credential description information contained in the collaboration request, so as to obtain the collaboration permission verification result of the first member terminal. When it is determined, based on the collaboration permission verification result, that the first member terminal has the collaboration permission to participate in the target collaboration, the first member terminal is allowed to participate in the target collaboration in accordance with the collaboration participation strategy agreed in the collaboration permission contract.
12. An electronic device, characterized in that, include: The device includes a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and the processor communicates with the memory via the bus when the electronic device is running, and the machine-readable instructions, when executed by the processor, perform the steps of the method for collaboration in a blockchain as described in any one of claims 1 to 9.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the steps of the method for collaboration in a blockchain as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Internet of Things system, equipment cooperation method, corresponding equipment, platform and node
CN110177107A
Digital certificate using method and device, computer equipment and storage medium
CN113746640A