A permission control method, device, equipment and storage medium
Through the control nodes and witness nodes in the permission control chain, the problem that users cannot accurately control information permissions in centralized communication is solved, and the accurate sending and receiving of information is achieved.
Patent Information
- Application Number
- CN202211159440.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-22
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-09-22
AI Technical Summary
In the prior art, it is difficult for users to accurately control the sending and receiving permissions of information under centralized communication methods, resulting in receiving fraudulent information and spam information and being unable to accurately receive high-quality information.
The permission control chain is used to authenticate the identity through the control node and multiple witness nodes, and the user's permission is identified in a decentralized manner. Consensus verification is performed based on pre-set permission conditions to determine whether the identity information to be verified is qualified.
Accurate control over information sending permissions and receiving permissions, improve the accuracy of filtering out fraudulent information and spam information, and ensure that information is only sent to recipients who meet the conditions.
Smart Images

Figure CN115550013B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of permission management. Specifically, it relates to a permission control method, device, equipment, and storage medium. Background Art
[0002] With the development of network communication technology, email, text messages, etc. have become an irreplaceable network communication method.
[0003] However, in the actual use of the current centralized communication method, users often receive a lot of fraud information, junk information, etc., and cannot accurately receive only the information sent by high-quality users, bringing potential risks to users. In addition, in some scenarios, users hope that the information sent is only allowed to be received and viewed by specific users. Therefore, how to accurately control the sending and receiving permissions of information is a technical problem that needs to be solved urgently. Summary of the Invention
[0004] The purpose of this application is to provide a permission control method, device, equipment, and storage medium, which can accurately control the sending and receiving permissions of information, aiming at the above deficiencies in the prior art.
[0005] To achieve the above purpose, the technical solutions adopted in the embodiments of this application are as follows:
[0006] In the first aspect, the embodiments of this application provide a permission control method, which is applied to a permission control chain. The permission control chain includes a control node and multiple witness nodes. The method includes:
[0007] The control node broadcasts a verification identity instruction to each witness node according to the information of the target object received, where the target object is the object to be sent or the object to be received, and the verification identity instruction is used to indicate verifying the identity of the sender and / or the receiver of the target object;
[0008] Each witness node obtains the identity information to be verified from the business chain according to the verification identity instruction, and performs a consensus check on the identity information to be verified based on the pre-set permission conditions, and obtains a consensus check result. The identity information to be verified includes the identity of the sender and / or the receiver of the target object;
[0009] The control node determines whether the identity information to be verified is qualified according to the consensus check results of each witness node. If so, the target object is sent to the receiver of the target object through the business chain.
[0010] In the second aspect, the embodiments of this application also provide a permission control device, which is applied to a permission control chain. The permission control chain includes a control node and multiple witness nodes. The device includes:
[0011] A broadcast module, configured to broadcast an identity verification instruction to each of the witness nodes according to the information of the target object received, where the target object is a trigger condition for an object to be sent or an object to be received, and the identity verification instruction is used to indicate verifying the identity of the sender and / or the receiver of the target object;
[0012] A verification module, configured to obtain identity information to be verified from the business chain according to the identity verification instruction, and perform a consensus verification on the identity information to be verified based on a pre-set permission condition to obtain a consensus verification result, where the identity information to be verified includes the identity of the sender and / or the receiver of the target object;
[0013] A determination module, configured to determine whether the identity information to be verified is qualified according to the consensus verification results of each witness node, and if so, send the target object to the receiver of the target object through the business chain.
[0014] In a third aspect, an embodiment of the present application provides an electronic device, including: a processor, a storage medium, and a bus. The storage medium stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the storage medium through the bus, and the processor executes the machine-readable instructions to perform the steps of the permission control method in the first aspect above.
[0015] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it performs the steps of the permission control method in the first aspect above.
[0016] The beneficial effects of the present application are:
[0017] An embodiment of the present application provides a permission control method, device, device, and storage medium, which are applied to a permission control chain. The permission control chain includes control nodes and multiple witness nodes. The method includes: the control node broadcasts an identity verification instruction to each witness node according to the information of the target object received. The target object is an object to be sent or an object to be received. The identity verification instruction is used to indicate verifying the identity of the sender and / or the receiver of the target object; each witness node obtains identity information to be verified from the business chain according to the identity verification instruction, and performs a consensus verification on the identity information to be verified based on a pre-set permission condition to obtain a consensus verification result. The identity information to be verified includes the identity of the sender and / or the receiver of the target object; the control node determines whether the identity information to be verified is qualified according to the consensus verification results of each witness node, and if so, sends the target object to the receiver of the target object through the business chain.
[0018] By using the permission control method provided in the embodiments of the present application, the permissions of users can be identified through a permission control chain. Specifically, each witness node in the permission control chain can perform a consensus check on the identity information to be verified based on a preset permission condition to obtain the consensus check results of each witness node. The control node can determine whether the identity information to be verified is qualified by combining the consensus check results of each witness node. That is to say, the present application uses a decentralized method to identify the permissions of users, so as to accurately control the sending and receiving permissions of information. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can also be obtained based on these drawings without creative efforts.
[0020] Figure 1 A schematic diagram of the scenario of a permission control system provided by the embodiments of the present application;
[0021] Figure 2 A schematic flow chart of a permission control method provided by the embodiments of the present application;
[0022] Figure 3 A schematic diagram of the scenario of another permission control system provided by the embodiments of the present application;
[0023] Figure 4 A schematic flow chart of another permission control method provided by the embodiments of the present application;
[0024] Figure 5 A schematic diagram of the scenario of yet another permission control system provided by the embodiments of the present application;
[0025] Figure 6 A schematic flow chart of yet another permission control method provided by the embodiments of the present application;
[0026] Figure 7 A schematic flow chart of yet another permission control method provided by the embodiments of the present application;
[0027] Figure 8 A schematic diagram of the structure of a permission control device provided by the embodiments of the present application;
[0028] Figure 9 A schematic diagram of the structure of an electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are some but not all of the embodiments of this application. Components of the embodiments of this application usually described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.
[0030] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of this application claimed, but merely represents selected embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of this application without creative efforts fall within the scope of protection of this application.
[0031] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0032] Before explaining the embodiments of this application in detail, the application scenarios of this application will be introduced first. The application scenario can specifically be a scenario for managing user permissions, such as which users can send emails, text messages, etc. to a target user, which users can view the emails, text messages, or status sent by the target user, etc. It should be noted that this application does not limit it. Figure 1 The following is a schematic diagram of the scenario of a permission control system provided for the embodiments of this application. As Figure 1 shown, the system may include a permission control chain 101 and a service chain 102. Among them, the permission control chain 101 is used to manage the permissions of users. The service chain 102 manages the identity information of users, such as gender, age, hobbies, etc. The service chain 102 can be understood as a web3 chain, and the web3 chain has an open user profile. The permission management chain 101 includes a control node and multiple witness nodes, such as witness node 1, witness node 2, witness node 3, and witness node 4. It should be noted that this application does not limit the number of witness nodes. The control node and witness nodes in the permission control chain 101 can judge the permissions of users in the following exemplary manner. Exemplarily, witness node 1, witness node 2, witness node 3, and witness node 4 can respectively obtain the identity information of the sender or the receiver of the target object from the service chain 102, and then perform a consensus check based on the identity information of the sender or the receiver of the target object and the pre-set permission conditions. The control node determines whether to send the target object to the receiver of the target object according to the consensus check results of each witness node. In one example, if it is determined to send the target object to the receiver of the target object, the control node can send the target object to the receiver of the target object through the service chain 102.
[0033] The permission control method mentioned in this application will be described by way of example in conjunction with the accompanying drawings as follows. Figure 2 It is a schematic flowchart of a permission control method provided by an embodiment of this application. The execution entity of this method is any node (management node, witness node) in the above-mentioned permission management chain, such as Figure 2 As shown, this method may include:
[0034] S201. The control node broadcasts an identity verification instruction to each witness node according to the information of the target object received.
[0035] Among them, the target object is the object to be sent or the object to be received, and the identity verification instruction is used to indicate verifying the identity of the sender or the receiver of the target object. Exemplarily, the object to be sent may be the content of an email, the content of a text message, etc., and the object to be received may include the status information published by the user and the trigger condition for wanting to view the status information published by the user, such as user 1 wanting to view the status information published by user 2. It should be noted that this application does not limit the specific content of the target object.
[0036] Exemplarily, if user F wants to send an email to user A's mailbox, then user F first sends the information of the target object containing the email content to the control node in the permission control chain. It can be understood that the information of the target object may also include the identifiers of the users, such as the identifier of user F and the identifier of user A. Of course, it may also include other information, which is not limited in this application. After obtaining the information of the target object, the control node can extract the identity of the sender of the target object and / or the identity of the receiver of the target object from the information of the target object, generate an identity verification instruction, and broadcast this identity verification instruction to each witness node.
[0037] It should be understood that the identity of the sender of the target object and the identity of the receiver of the target object have different meanings in different application scenarios. For example, in the application scenario of which users can send messages to the target user, the identity of the sender of the target object is the user who sends the message to the target user, and the identity of the receiver of the target object is the target user; for example, in the application scenario of which users can receive or view the messages sent by the target user, the identity of the sender of the target object is the target user, and the receiver of the target object is the user who receives or views the messages sent by the target user.
[0038] S202. Each witness node obtains the identity information to be verified from the business chain according to the identity verification instruction, and performs a consensus check on the identity information to be verified based on the pre-set permission conditions, and obtains a consensus check result.
[0039] Among them, the identity information to be verified includes the identity of the sender and / or the identity of the recipient of the target object. Exemplarily, after obtaining the identity verification instruction, each witness node can extract the identity of the sender and / or the identity of the recipient of the target object from the identity verification instruction. It can be understood that the situation of the user to be verified is different in different scenarios. For example, in the application scenario of which users can send messages to the target user mentioned above, the sender of the target object can be used as the user to be verified; for example, in the application scenario of which users can receive or view the messages sent by the target user mentioned above, the recipient of the target object can be used as the user to be verified. It should be noted that this application does not limit it.
[0040] Here, a witness node is used for illustration. Assuming that the sender of the target object is used as the user to be verified, then this witness node can obtain the identity information to be verified corresponding to the sender of the target object from the business chain, and then perform a consensus check on the identity information to be verified corresponding to the sender of the target object according to the pre-stored permission conditions, that is, determine whether the identity information to be verified corresponding to the sender of the target object meets the content in the permission conditions. The consensus check result corresponding to this witness node may be characterized as meeting this situation or may be characterized as not meeting this situation.
[0041] It should be understood that other witness nodes can refer to the above consensus check process, which will not be described here.
[0042] S203. The control node determines whether the identity information to be verified is qualified according to the consensus check results of each witness node. If so, the target object is sent to the recipient of the target object through the business chain.
[0043] The control node can receive the consensus check results corresponding to each witness node, and determine whether the identity information to be verified is qualified based on the consensus check results corresponding to each witness node and the preset conditions. Continuing the above example, the control node can combine the consensus check results corresponding to each witness node and the preset conditions to determine whether the sender of the target object is qualified, that is, whether the sender of the target object has the right to send a message to the recipient of the target object. If it is determined that the sender of the target object is qualified, the information generated by the sender of the target object (the target object, that is, the object to be sent) can be sent to the recipient of the target object through the business chain.
[0044] In summary, in the permission control method provided by this application, the permissions of users can be identified through a permission control chain. Specifically, each witness node in the permission control chain can perform a consensus check on the identity information to be verified based on a preset permission condition to obtain the consensus check results of each witness node. The control node can determine whether the identity information to be verified is qualified by combining the consensus check results of each witness node. That is to say, this application uses a decentralized method to identify the permissions of users, so as to accurately control the sending and receiving permissions of information.
[0045] The examples of this application mainly explain the permission control method from two dimensions. The first dimension is which users can send messages to the target user, and the second dimension is which users can receive or view the messages sent by the target user.
[0046] First, introduce an example of the first dimension. If the information of the target object is sent from the sender of the target object to the control node, the information of the target object includes: the target object, the identifier of the sender of the target object, and the identifier of the recipient of the target object. For example, user F wants to send an email to user A. Then user F is the sender of the target object. User F first sends the information of the target object to be sent to user A to the control node in the permission control chain. The information of the target object includes the email content, that is, the target object, which can be understood as the object to be sent, the identifier of user F, that is, the identifier of the sender of the target object, and the identifier of user A, that is, the identifier of the recipient of the target object.
[0047] Correspondingly, the above control node sends a verification identity instruction to each witness node according to the received information of the target object, including: the control node broadcasts a first verification identity instruction to each witness node according to the identifier of the sender of the target object and the identifier of the recipient of the target object. The first verification identity instruction includes the identifier of the sender of the target object and the identifier of the recipient of the target object.
[0048] Among them, after receiving the information of the target object sent by the sender of the target object, the control node can extract the identifier of the sender of the target object and the identifier of the recipient of the target object from the information of the target object, and broadcast a first verification identity instruction containing the identifier of the sender of the target object and the identifier of the recipient of the target object to each witness node. Continuing with the above example, the control node can broadcast a first verification identity instruction containing the identifier of user F and the identifier of user A to each witness node based on the identifier of user F and the identifier of user A. That is to say, the first verification identity instruction includes user F as the sender of the target object and user A as the recipient of the target object.
[0049] Furthermore, each witness node can know that user F wants to send a message to user A. Based on this, the following example introduces how each witness node obtains the identity information related to user F.
[0050] Optionally, each of the above witness nodes obtains the identity information to be verified from the business chain according to the identity verification instruction, including: each witness node obtains the identity of the sender of the target object from the business chain according to the identifier of the sender of the target object in the first identity verification instruction.
[0051] Among them, after each witness node obtains the first identity verification instruction, it can extract the identifier of the sender of the target object from the first identity verification instruction. Each witness node obtains the identity of the sender of the target object from the business chain based on the identifier of the sender of the target object. Continuing with the above example, each witness node can respectively obtain the identity of user F from the business chain, that is, the identity information related to user F, such as gender, age, hobbies, etc. It can be understood that the identity information related to other users such as user F and user A is stored on the business chain, and each witness node can obtain the identity information related to user F from the query node on the business chain.
[0052] Exemplarily, it should be understood that the permission conditions corresponding to the receiver of the target object can be pre-stored in each witness node, such as the permission conditions corresponding to user A. The permission conditions corresponding to user A include some restrictive conditions on identity attributes, such as gender restrictive conditions, age restrictive conditions, hobby restrictive conditions, etc. It should be noted that this application does not limit the permission conditions. Each witness node can obtain the identity information of user F from the business chain based on the content in the permission conditions corresponding to user A. Assuming that the permission conditions corresponding to user A only include age restriction content and hobby content, then each witness node only obtains the age information and hobby information of user F from the business chain.
[0053] It can be seen that each witness node can obtain all the identity information of the sender of the target object from the business chain, or only obtain the identity information corresponding to the permission conditions of the sender of the target object.
[0054] Optionally, before performing consensus verification on the identity information to be verified based on the pre-set permission conditions to obtain the consensus verification result, it further includes: the control node obtains the permission conditions corresponding to the receiver of the target object, and broadcasts the identifier of the receiver of the target object and the permission conditions corresponding to the receiver of the target object to each witness node.
[0055] Combined with Figure 3 for illustration, Figure 3 is a schematic diagram of another permission control system scenario provided by the embodiments of this application. As Figure 3As described above, user A corresponding to the recipient of the target object can set permission conditions to the control node on the permission management chain through the terminal. The permission conditions can filter the identity of the sender of the target object. The control node broadcasts the permission conditions corresponding to user A and the identifier of user A to each witness node. Witness node 1, witness node 2, witness node 3, and witness node 4 can store the permission conditions corresponding to user A and user A as the recipient in association. It can be understood that if there are multiple recipients, such as user B and user C, then each witness node can store the permission conditions corresponding to user B and user B as the recipient of the target object in association, and store the permission conditions corresponding to user C and user C as the recipient of the target object in association.
[0056] Figure 4 It is a schematic flowchart of another permission control method provided by an embodiment of this application. As Figure 4 shown, optionally, the above-mentioned consensus verification is performed on the identity information to be verified based on the pre-set permission conditions to obtain a consensus verification result, including:
[0057] S401. Each witness node obtains the permission conditions corresponding to the recipient of the target object according to the identifier of the recipient of the target object in the first identity verification instruction, and performs a consensus verification on the identity of the sender of the target object according to the permission conditions corresponding to the recipient of the target object to obtain a consensus verification result.
[0058] According to the above description, each witness node may include permission conditions corresponding to multiple recipients of the target object respectively. After each witness node obtains the identity information of the sender of the target object from the business chain, each witness node can determine the recipient of the target object corresponding to the sender of the target object based on the sender of the target object in the first identity verification instruction. Continuing with the above example, the first identity verification instruction includes user F as the sender and user A as the recipient. Then, after each witness node obtains the identity information of user F, it can obtain the permission conditions corresponding to user A based on user A, and then perform a consensus verification on user F according to the permission conditions corresponding to user A and the identity information of user F to obtain a consensus result.
[0059] In an achievable embodiment, taking a witness node as an example for illustration, the witness node determines whether the identity information of user F meets the permission conditions corresponding to user A. For example, whether the age of user F meets the age limit in the permission conditions, and whether the hobbies of user F are within the scope of the hobbies in the permission conditions. If the identity information of user F meets the permission conditions corresponding to user A, the witness node signs user F successfully. If the identity information of user F does not meet the permission conditions corresponding to user A, the witness node signs user F as failed. That is to say, the consensus verification results include two types: successful signature and failed signature. The process for other witness nodes to determine the consensus verification results can refer to the above description and will not be elaborated here.
[0060] Optionally, the above process of sending the target object to the recipient of the target object through the business chain includes: the control node signs the target object as qualified and sends the qualified-signed target object to the business chain for consensus processing, and the business chain sends the target object after consensus processing to the recipient of the target object.
[0061] Combined with Figure 3 For illustration, after obtaining the consensus verification results (consensus verification result 1, consensus verification result 2, consensus verification result 3, and consensus verification result 4), witness node 1, witness node 2, witness node 3, and witness node 4 can respectively send the consensus verification results to the control node. The control node determines whether user F is qualified based on consensus verification result 1, consensus verification result 2, consensus verification result 3, and consensus verification result 4, that is, whether user F has the right to send an email to user A.
[0062] Exemplarily, the control node determines the number of witness nodes corresponding to the successful label according to the consensus verification results of each witness node, and compares the number of witness nodes corresponding to the successful label with a preset threshold. If the number of witness nodes corresponding to the successful label is greater than the preset threshold, the control node determines that user F is qualified. According to the above description, the information of the target object obtained by the control node also includes the email content sent by user F to user A. After determining that user F is qualified, the control node can sign the email content as qualified, that is, sign the target object as qualified.
[0063] In an achievable embodiment, the control node can send the qualified-signed email content to the business chain, and perform consensus processing on the signed email content through a pre-set consensus mechanism. If the consensus is successful, the email content after consensus processing is sent to the inbox of user F.
[0064] It can be seen that in this application, the witness nodes perform consensus verification on the identity of the sender of the target object, and control the write permission of the inbox of the recipient of the target object. In this way, only the information of high-quality users who meet the requirements of the recipient of the target object can be sent to the recipient, improving the accuracy of filtering out low-quality information such as fraudulent information and spam information.
[0065] Next, an example of the second dimension mentioned above is introduced. If the information of the target object is sent by the recipient of the target object to the control node, the information of the target object includes: the identifier of the sender of the target object and the identifier of the recipient of the target object. For example, if user E wants to view the status published by user D, then user E is the recipient of the target object and user D is the sender of the target object. For example, when user E wants to view the status published by user D, the information of the target object is first sent to the control node in the permission control chain. Among them, the information of the target object includes the trigger condition for user E to want to view the status published by user D, that is, the trigger condition of the object to be received mentioned above, the identifier of user E, which is the identifier of the recipient of the target object, and the identifier of user D, which is the identifier of the sender of the target object.
[0066] Correspondingly, the above-mentioned control node sends an identity verification instruction to each witness node according to the received information of the target object, including: the control node broadcasts a second identity verification instruction to each witness node according to the identifier of the recipient of the target object and the identifier of the sender of the target object, and the second identity verification instruction includes the identifier of the recipient of the target object and the identifier of the sender of the target object.
[0067] Among them, after receiving the information of the target object sent by the recipient of the target object, the control node can extract the identifier of the recipient of the target object and the identifier of the sender of the target object from the information of the target object, and broadcast a second identity verification instruction containing the identifier of the recipient of the target object and the identifier of the sender of the target object to each witness node. Continuing with the above example, the control node can broadcast a second identity verification instruction containing the identifier of user E and the identifier of user D to each witness node based on the identifier of user E and the identifier of user D, that is, the second identity verification instruction includes user E as the recipient of the target object and user D as the recipient of the target object.
[0068] Furthermore, each witness node knows that user E wants to view the status published by user D. Based on this, the following example introduces how each witness node obtains the identity information related to user E.
[0069] Optionally, each of the above witness nodes obtains the identity information to be verified from the business chain according to the identity verification instruction, including: each witness node obtains the identity of the recipient of the target object from the business chain according to the identifier of the recipient of the target object in the second identity verification instruction.
[0070] Among them, after each witness node obtains the second identity verification instruction, the identifier of the recipient of the target object can be extracted from the second identity verification instruction, and each witness node obtains the identity of the recipient of the target object from the business chain based on the identifier of the recipient of the target object. Continuing with the above example, each witness node can obtain the identity of User E from the business chain respectively, that is, the identity information related to User E, such as whether they are enthusiastic about public welfare and whether they have studied abroad. It can be understood that the identity information of other users such as User E and User D is stored on the business chain, and each witness node can obtain the identity information related to User E from the query node on the business chain.
[0071] Exemplarily, it should be understood that the permission conditions corresponding to the sender of the target object can be pre-stored in each witness node, such as the permission conditions corresponding to User D. The permission conditions corresponding to User D include some conditions of identity attributes, such as being enthusiastic about public welfare and studying abroad. It should be noted that the content of the permission conditions is not limited in this application. Each witness node can obtain the identity information of User E from the business chain based on the content in the permission conditions corresponding to User D. Assuming that the permission conditions corresponding to User D only include the identity attribute of studying abroad, then each witness node only obtains the identity information of whether User E has studied abroad from the business chain.
[0072] Optionally, before performing the consensus verification on the identity information to be verified based on the pre-set permission conditions to obtain the consensus verification result, it further includes: the control node obtains the permission conditions corresponding to the sender of the target object, and broadcasts the identifier of the sender of the target object and the permission conditions corresponding to the sender of the target object to each witness node.
[0073] Combined with Figure 5 for illustration, Figure 5 is a schematic diagram of another scenario of the permission control system provided by the embodiment of the present application. As Figure 5As described above, user D corresponding to the sender of the target object can set permission conditions to the control node on the permission management chain through the terminal, and the permission conditions can filter the identity of the recipient of the target object. The control node broadcasts the permission conditions corresponding to user D and the identifier of user D to each witness node. Witness node 1, witness node 2, witness node 3, and witness node 4 can store the permission conditions corresponding to user D and user D as the sender of the target object in an associated manner. It can be understood that if there are multiple senders, such as user 1 and user 2, then each witness node can store the permission conditions corresponding to user 1 and user 1 as the sender of the target object in an associated manner, and store the permission conditions corresponding to user 2 and user 2 as the sender of the target object in an associated manner.
[0074] Figure 6 It is a schematic flowchart of another permission control method provided by an embodiment of this application. As Figure 6 shown, optionally, the above-mentioned consensus verification of the identity information to be verified based on the preset permission conditions to obtain a consensus verification result includes:
[0075] S601. Each witness node obtains the permission conditions corresponding to the sender of the target object according to the identifier of the sender of the target object in the second identity verification instruction, and performs a consensus verification on the identity of the recipient of the target object according to the permission conditions corresponding to the sender of the target object to obtain a consensus verification result.
[0076] According to the above description, each witness node may include permission conditions corresponding to multiple senders of the target object respectively. After each witness node obtains the identity information of the recipient of the target object from the business chain, then each witness node can determine the sender of the target object corresponding to the recipient of the target object based on the recipient of the target object in the second identity verification instruction. Continuing with the above example, the second identity verification instruction includes user E as the recipient of the target object and user D as the sender of the target object. Then, after each witness node obtains the identity information of user E, it can obtain the permission conditions corresponding to user D based on user D corresponding to user E, and then perform a consensus verification on user E according to the permission conditions corresponding to user D and the identity information of user E to obtain a consensus result.
[0077] In an implementable embodiment, taking a witness node as an example for illustration, the witness node determines whether the identity information of user E meets the permission conditions corresponding to user D. For example, whether user E has traveled abroad as defined in the permission conditions. If the identity information of user F has traveled abroad, it proves that the permission conditions corresponding to user D are met, and then the witness node successfully signs user E. If user E has no record of traveling abroad, it proves that the permission conditions corresponding to user D are not met, and then the witness node fails to sign user E. That is to say, the consensus verification result includes two results: successful signature and failed signature. The process for other witness nodes to determine the consensus verification result can refer to the above description and will not be elaborated here.
[0078] Figure 7 It is a schematic flowchart of another permission control method provided by the embodiment of the present application. As Figure 7 shown, optionally, before the control node sends a verification identity instruction to each witness node according to the information of the target object received, the method may further include:
[0079] S701: The control node obtains the target object sent by the sender of the target object and broadcasts the target object to each witness node.
[0080] S702: Each witness node encrypts the target object and sends the encrypted target object and the identifier of the sender of the target object to the business chain.
[0081] Continuing with the above example, user D first sends the published status information to the control node in the permission control chain, and the control node broadcasts the status information to each witness node. Exemplarily, the control node can pre-broadcast the encryption method corresponding to user D to each witness node, and then each witness node encrypts the status information corresponding to user D based on the encryption method corresponding to user D to obtain the encrypted status information. Each witness node respectively sends the encrypted status information and the identifier of user D to the smart contract of the business chain.
[0082] Optionally, sending the target object to the receiver of the target object through the business chain includes: The control node instructs each witness node to obtain the encrypted target object from the business chain to decrypt and obtain the target object, and send the target object to the receiver of the target object.
[0083] Combined with Figure 5It is described that after witness node 1, witness node 2, witness node 3, and witness node 4 obtain the consensus verification results (consensus verification result 1, consensus verification result 2, consensus verification result 3, consensus verification result 4), they can respectively send the consensus verification results to the control node. The control node determines whether user E is qualified based on consensus verification result 1, consensus verification result 2, consensus verification result 3, and consensus verification result 4, that is, whether user E has the right to view the status published by user D.
[0084] Exemplarily, the control node determines the number of witness nodes corresponding to the success label according to the consensus verification results corresponding to each witness node, compares the number of witness nodes corresponding to the success label with a preset threshold. If the number of witness nodes corresponding to the success label is greater than the preset threshold, the control node determines that user E is qualified. Furthermore, the control node sends an instruction indicating that user E is qualified to each witness node. Each witness node determines the identifier of user D corresponding to user E based on the instruction containing that user E is qualified, and then extracts the encrypted status information corresponding to the identifier of user D from the business chain. It can be understood that each witness node pre-stores a decryption method corresponding to the encryption method. Each witness node can decrypt the encrypted status information based on the decryption method to obtain the decrypted status information. The witness node sends the decrypted status information to the control node, and then the control node sends the decrypted status information to user E, that is, user E can view the status information published by user D.
[0085] It can be seen that in this application, the witness nodes perform consensus verification on the identity of the recipient of the target object, and control the permission to view the status published by the sender of the target object, so that only users who meet the requirements of the sender of the target object can view the status of the sender of the target object.
[0086] Figure 8 The figure is a schematic structural diagram of a permission control device provided by an embodiment of this application, which is applied to a permission control chain. The permission control chain includes a control node and multiple witness nodes. As Figure 8 shown, the device includes:
[0087] A broadcast module 801, configured to broadcast an identity verification instruction to each witness node according to the received information of the target object. The target object is the triggering condition of the object to be sent or the object to be received. The identity verification instruction is used to instruct to verify the identity of the sender and / or recipient of the target object;
[0088] A verification module 802, configured to obtain the identity information to be verified from the business chain according to the identity verification instruction, and perform consensus verification on the identity information to be verified based on the pre-set permission conditions to obtain a consensus verification result. The identity information to be verified includes the identity of the sender and / or recipient of the target object;
[0089] A determination module 803, configured to determine whether the identity information to be verified is qualified according to the consensus verification results of each witness node. If so, the target object is sent to the recipient of the target object through the service chain.
[0090] Optionally, if the information of the target object is sent by the sender of the target object to the control node, the information of the target object includes: the target object, the identifier of the sender of the target object, and the identifier of the recipient of the target object.
[0091] Correspondingly, the broadcast module 801 is specifically configured to broadcast a first identity verification instruction to each witness node according to the identifier of the sender of the target object and the identifier of the recipient of the target object. The first identity verification instruction includes the identifier of the sender of the target object and the identifier of the recipient of the target object.
[0092] Optionally, the verification module 802 is specifically configured to obtain the identity of the sender of the target object from the service chain according to the identifier of the sender of the target object in the first identity verification instruction.
[0093] Optionally, the broadcast module 801 is further configured to obtain the permission condition corresponding to the recipient of the target object, and broadcast the identifier of the recipient of the target object and the permission condition corresponding to the recipient of the target object to each witness node.
[0094] Correspondingly, the verification module 802 is specifically configured to obtain the permission condition corresponding to the recipient of the target object according to the identifier of the recipient of the target object in the first identity verification instruction, and perform a consensus verification on the identity of the sender of the target object according to the permission condition corresponding to the recipient of the target object, so as to obtain a consensus verification result.
[0095] Optionally, the determination module 803 is specifically configured to perform a qualified signature on the target object by the control node, and send the target object after the qualified signature to the service chain for consensus processing, and the service chain sends the target object after the consensus processing to the recipient of the target object.
[0096] Optionally, if the information of the target object is sent by the recipient of the target object to the control node, the information of the target object includes: the identifier of the sender of the target object and the identifier of the recipient of the target object.
[0097] Correspondingly, the broadcast module 801 is specifically configured to broadcast a second identity verification instruction to each witness node according to the identifier of the recipient of the target object and the identifier of the sender of the target object. The second identity verification instruction includes the identifier of the recipient of the target object and the identifier of the sender of the target object.
[0098] Optionally, the verification module 802 is specifically configured to obtain the identity of the recipient of the target object from the service chain according to the identifier of the recipient of the target object in the second identity verification instruction.
[0099] Optionally, the broadcast module 801 is further configured to obtain the permission condition corresponding to the sender of the target object, and broadcast the identifier of the sender of the target object and the permission condition corresponding to the sender of the target object to each witness node;
[0100] Correspondingly, the verification module 802 is specifically configured to obtain the permission condition corresponding to the sender of the target object according to the identifier of the sender of the target object in the second identity verification instruction, and perform a consensus verification on the identity of the recipient of the target object according to the permission condition corresponding to the sender of the target object, so as to obtain a consensus verification result.
[0101] Optionally, the broadcast module 801 is further configured to obtain the target object sent by the sender of the target object, and broadcast the target object to each witness node; each witness node encrypts the target object, and sends the encrypted target object and the identifier of the sender of the target object to the service chain.
[0102] Optionally, the determination module 802 is further specifically configured to instruct each witness node to obtain the encrypted target object from the service chain to decrypt to obtain the target object, and send the target object to the recipient of the target object.
[0103] The above device is used to execute the method provided in the foregoing embodiment, and its implementation principle and technical effects are similar, and will not be elaborated here.
[0104] The above modules may be one or more integrated circuits configured to implement the above method, for example: one or more application specific integrated circuits (ASICs), or, one or more microprocessors (Digital Signal Processor, DSP for short), or, one or more field programmable gate arrays (Field Programmable Gate Array, FPGA for short), etc. Again, when the above certain module is implemented in the form of a processing element dispatching program code, the processing element may be a general-purpose processor, such as a central processing unit (Central Processing Unit, CPU for short) or other processors that can call program code. Again, these modules may be integrated together and implemented in the form of a system-on-a-chip (SOC for short).
[0105] Figure 9 The structural schematic diagram of an electronic device provided in an embodiment of the present application is asFigure 9 As shown, the electronic device may include: a processor 901, a storage medium 902, and a bus 903. The storage medium 902 stores machine-readable instructions executable by the processor 901. When the electronic device runs, the processor 901 communicates with the storage medium 902 through the bus 903. The processor 901 executes the machine-readable instructions to perform the following steps:
[0106] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically used for: applying to a permission control chain, where the permission control chain includes a control node and multiple witness nodes; the control node broadcasts a verification identity instruction to each witness node according to the information of the target object received. The target object is an object to be sent or an object to be received. The verification identity instruction is used to indicate verifying the identity of the sender and / or the receiver of the target object; each witness node obtains the identity information to be verified from the business chain according to the verification identity instruction, and performs a consensus check on the identity information to be verified based on the pre-set permission conditions to obtain a consensus check result. The identity information to be verified includes the identity of the sender and / or the receiver of the target object; the control node determines whether the identity information to be verified is qualified according to the consensus check results of each witness node. If so, the target object is sent to the receiver of the target object through the business chain.
[0107] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically used for: if the information of the target object is sent from the sender of the target object to the control node, the information of the target object includes: the target object, the identifier of the sender of the target object, and the identifier of the receiver of the target object; the control node sends a verification identity instruction to each witness node according to the received information of the target object, including: the control node broadcasts a first verification identity instruction to each witness node according to the identifier of the sender of the target object and the identifier of the receiver of the target object. The first verification identity instruction includes the identifier of the sender of the target object and the identifier of the receiver of the target object.
[0108] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically used for: each witness node obtains the identity of the sender of the target object from the business chain according to the identifier of the sender of the target object in the first verification identity instruction.
[0109] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically used for: the control node obtains the permission conditions corresponding to the receiver of the target object, and broadcasts the identifier of the receiver of the target object and the permission conditions corresponding to the receiver of the target object to each witness node.
[0110] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically configured to: each witness node obtains the permission conditions corresponding to the recipient of the target object according to the identifier of the recipient of the target object in the first authentication identity instruction, and performs a consensus verification on the identity of the sender of the target object according to the permission conditions corresponding to the recipient of the target object, and obtains a consensus verification result.
[0111] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically configured to: the control node performs a qualified signature on the target object, and sends the target object after the qualified signature to the business chain for consensus processing, and the business chain sends the target object after the consensus processing to the recipient of the target object.
[0112] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically configured to: if the information of the target object is sent by the recipient of the target object to the control node, the information of the target object includes: the identifier of the sender of the target object and the identifier of the recipient of the target object; the control node broadcasts a second authentication identity instruction to each witness node according to the identifier of the recipient of the target object and the identifier of the sender of the target object, and the second authentication identity instruction includes the identifier of the recipient of the target object and the identifier of the sender of the target object.
[0113] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically configured to: each witness node obtains the identity of the recipient of the target object from the business chain according to the identifier of the recipient of the target object in the second authentication identity instruction.
[0114] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically configured to: the control node obtains the permission conditions corresponding to the sender of the target object, and broadcasts the identifier of the sender of the target object and the permission conditions corresponding to the sender of the target object to each witness node.
[0115] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically configured to: each witness node obtains the permission conditions corresponding to the sender of the target object according to the identifier of the sender of the target object in the second authentication identity instruction, and performs a consensus verification on the identity of the recipient of the target object according to the permission conditions corresponding to the sender of the target object, and obtains a consensus verification result.
[0116] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically configured to: the control node obtains the target object sent by the sender of the target object, and broadcasts the target object to each witness node; each witness node encrypts the target object, and sends the encrypted target object and the identifier of the sender of the target object to the business chain.
[0117] In a feasible implementation, when the processor 901 executes the permission control method, it is specifically configured to: control the control node to instruct each witness node to obtain the encrypted target object from the service chain to decrypt the target object, and send the target object to the recipient of the target object.
[0118] Optionally, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps of the above method embodiment.
[0119] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: be applied to a permission control chain, which includes a control node and multiple witness nodes; the control node broadcasts a verification identity instruction to each witness node according to the received information of the target object, where the target object is an object to be sent or an object to be received, and the verification identity instruction is used to instruct to verify the identity of the sender and / or the recipient of the target object; each witness node obtains the information to be verified for identity from the service chain according to the verification identity instruction, and performs a consensus check on the information to be verified for identity based on the preset permission conditions to obtain a consensus check result, where the information to be verified for identity includes the identity of the sender and / or the recipient of the target object; the control node determines whether the information to be verified for identity is qualified according to the consensus check results of each witness node. If so, the target object is sent to the recipient of the target object through the service chain.
[0120] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: if the information of the target object is sent by the sender of the target object to the control node, the information of the target object includes: the target object, the identifier of the sender of the target object, and the identifier of the recipient of the target object; the control node sends a verification identity instruction to each witness node according to the received information of the target object, including: the control node broadcasts a first verification identity instruction to each witness node according to the identifier of the sender of the target object and the identifier of the recipient of the target object, and the first verification identity instruction includes the identifier of the sender of the target object and the identifier of the recipient of the target object.
[0121] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: each witness node obtains the identity of the sender of the target object from the service chain according to the identifier of the sender of the target object in the first verification identity instruction.
[0122] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: the control node obtains the permission conditions corresponding to the recipient of the target object, and broadcasts the identifier of the recipient of the target object and the permission conditions corresponding to the recipient of the target object to each witness node.
[0123] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: each witness node obtains the permission conditions corresponding to the recipient of the target object according to the identifier of the recipient of the target object in the first identity verification instruction, and performs a consensus verification on the identity of the sender of the target object according to the permission conditions corresponding to the recipient of the target object, and obtains a consensus verification result.
[0124] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: the control node performs a qualified signature on the target object, and sends the target object after the qualified signature to the business chain for consensus processing, and the business chain sends the target object after the consensus processing to the recipient of the target object.
[0125] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: if the information of the target object is sent by the recipient of the target object to the control node, the information of the target object includes: the identifier of the sender of the target object and the identifier of the recipient of the target object; the control node broadcasts a second identity verification instruction to each witness node according to the identifier of the recipient of the target object and the identifier of the sender of the target object, and the second identity verification instruction includes the identifier of the recipient of the target object and the identifier of the sender of the target object.
[0126] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: each witness node obtains the identity of the recipient of the target object from the business chain according to the identifier of the recipient of the target object in the second identity verification instruction.
[0127] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: the control node obtains the permission conditions corresponding to the sender of the target object, and broadcasts the identifier of the sender of the target object and the permission conditions corresponding to the sender of the target object to each witness node.
[0128] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: each witness node obtains the permission conditions corresponding to the sender of the target object according to the identifier of the sender of the target object in the second identity verification instruction, and performs a consensus verification on the identity of the recipient of the target object according to the permission conditions corresponding to the sender of the target object, and obtains a consensus verification result.
[0129] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: the control node obtains the target object sent by the sender of the target object, and broadcasts the target object to each witness node; each witness node encrypts the target object, and sends the encrypted target object and the identifier of the sender of the target object to the business chain.
[0130] In a feasible implementation, when the processor executes the permission control method, it is specifically configured to: control the node to instruct each witness node to obtain the encrypted target object from the service chain, decrypt the target object, and send the target object to the recipient of the target object.
[0131] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.
[0132] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0133] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0134] The above-mentioned integrated units implemented in the form of software functional units can be stored in a computer-readable storage medium. The above-mentioned software functional units stored in a storage medium include several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (English: processor) to execute some steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (English: Read-Only Memory, abbreviated as: ROM), random access memories (English: Random Access Memory, abbreviated as: RAM), magnetic disks or optical discs that can store program codes.
[0135] It should be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising said element.
[0136] The above are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not require further definition and explanation in subsequent drawings. The above are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
Claims
1. A permission control method, characterized in that, Applied to a permission control chain, the permission control chain includes control nodes and multiple witness nodes, and the method includes: The control node broadcasts a verification identity instruction to each witness node according to the information of the target object received, where the target object is an object to be sent or an object to be received, and the verification identity instruction is used to indicate verifying the identity of the sender and / or the identity of the receiver of the target object; Each witness node obtains the identity information to be verified from the business chain according to the verification identity instruction, and performs a consensus verification on the identity information to be verified based on the pre-set permission conditions to obtain a consensus verification result, where the identity information to be verified includes the identity of the sender and / or the identity of the receiver of the target object; The control node determines whether the identity information to be verified is qualified according to the consensus verification results of each witness node. If so, the target object is sent to the receiver of the target object through the business chain; If the information of the target object is sent from the sender of the target object to the control node, the information of the target object includes: the target object, the identifier of the sender of the target object, and the identifier of the receiver of the target object; The control node sends a verification identity instruction to each witness node according to the information of the target object received, including: The control node broadcasts a first verification identity instruction to each witness node according to the identifier of the sender of the target object and the identifier of the receiver of the target object, and the first verification identity instruction includes the identifier of the sender of the target object and the identifier of the receiver of the target object.
2. The method according to claim 1, wherein Each witness node obtains the identity information to be verified from the business chain according to the verification identity instruction, including: Each witness node obtains the identity of the sender of the target object from the business chain according to the identifier of the sender of the target object in the first verification identity instruction.
3. The method according to claim 1 or 2, characterized in that, Before performing the consensus verification on the identity information to be verified based on the pre-set permission conditions to obtain a consensus verification result, it further includes: The control node obtains the permission conditions corresponding to the receiver of the target object, and broadcasts the identifier of the receiver of the target object and the permission conditions corresponding to the receiver of the target object to each witness node; Performing the consensus verification on the identity information to be verified based on the pre-set permission conditions to obtain a consensus verification result, including: Each witness node obtains the permission conditions corresponding to the receiver of the target object according to the identifier of the receiver of the target object in the first verification identity instruction, and performs a consensus verification on the identity of the sender of the target object according to the permission conditions corresponding to the receiver of the target object to obtain a consensus verification result.
4. The method according to claim 3, wherein Sending the target object to the receiver of the target object through the business chain, including: The control node performs a qualified signature on the target object, and sends the target object after the qualified signature to the business chain for consensus processing, and the business chain sends the target object after the consensus processing to the receiver of the target object.
5. The method according to claim 1, wherein If the information of the target object is sent by the recipient of the target object to the control node, the information of the target object includes: the identifier of the sender of the target object and the identifier of the recipient of the target object; The control node sends an identity verification instruction to each of the witness nodes according to the received information of the target object, including: The control node broadcasts a second identity verification instruction to each of the witness nodes according to the identifier of the recipient of the target object and the identifier of the sender of the target object, and the second identity verification instruction includes the identifier of the recipient of the target object and the identifier of the sender of the target object.
6. The method according to claim 5, wherein Each of the witness nodes obtains the identity information to be verified from the business chain according to the identity verification instruction, including: Each of the witness nodes obtains the identity of the recipient of the target object from the business chain according to the identifier of the recipient of the target object in the second identity verification instruction.
7. The method according to claim 5 or 6, characterized in that, Before performing a consensus check on the identity information to be verified based on preset permission conditions to obtain a consensus check result, it further includes: The control node obtains the permission conditions corresponding to the sender of the target object, and broadcasts the identifier of the sender of the target object and the permission conditions corresponding to the sender of the target object to each of the witness nodes; Performing a consensus check on the identity information to be verified based on preset permission conditions to obtain a consensus check result, including: Each of the witness nodes obtains the permission conditions corresponding to the sender of the target object according to the identifier of the sender of the target object in the second identity verification instruction, and performs a consensus check on the identity of the recipient of the target object according to the permission conditions corresponding to the sender of the target object to obtain a consensus check result.
8. The method according to claim 5, characterized in that, Before the control node sends an identity verification instruction to each of the witness nodes according to the received information of the target object, it further includes: The control node obtains the target object sent by the sender of the target object, and broadcasts the target object to each of the witness nodes; Each of the witness nodes encrypts the target object, and sends the encrypted target object and the identifier of the sender of the target object to the business chain.
9. The method according to claim 8, wherein Sending the target object to the recipient of the target object through the business chain, including: The control node instructs each of the witness nodes to obtain the encrypted target object from the business chain to decrypt to obtain the target object, and sends the target object to the recipient of the target object.
10. A permission control device, characterized in that Applied to a permission control chain, the permission control chain includes a control node and a plurality of witness nodes, and the device includes: A broadcast module, configured to broadcast an identity verification instruction to each of the witness nodes according to the received information of the target object, where the target object is a trigger condition of an object to be sent or an object to be received, and the identity verification instruction is used to instruct to verify the identity of the sender and / or recipient of the target object; The verification module is used to obtain the identity information to be verified from the business chain according to the identity verification instruction, and perform a consensus verification on the identity information to be verified based on the pre-set permission conditions to obtain a consensus verification result. The identity information to be verified includes the identity of the sender and / or the receiver of the target object; The determination module is used to determine whether the identity information to be verified is qualified according to the consensus verification results of each witness node. If so, the target object is sent to the receiver of the target object through the business chain; If the information of the target object is sent from the sender of the target object to the control node, the information of the target object includes: the target object, the identifier of the sender of the target object, and the identifier of the receiver of the target object; The broadcast module is specifically used for the control node to broadcast a first identity verification instruction to each witness node according to the identifier of the sender of the target object and the identifier of the receiver of the target object. The first identity verification instruction includes the identifier of the sender of the target object and the identifier of the receiver of the target object.
11. An electronic device, characterized in that, including: A processor, a storage medium, and a bus. The storage medium stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the storage medium through the bus. The processor executes the machine-readable instructions to perform the steps of the permission control method according to any one of claims 1-9.
12. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is run by the processor, it performs the steps of the permission control method according to any one of claims 1-9.
Citation Information
Patent Citations
Data processing method, device and equipment based on block chain and storage medium
CN112738253A