Blockchain-based permission management method and device, and node in blockchain system
By deploying smart contracts in the blockchain system to record and transmit permission requests and decision information, the problem of permission management between the intranet environments of different participants is solved, and permission management across participants and normal authorization response of business systems are realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-14
- Publication Date
- 2026-03-31
AI Technical Summary
In blockchain systems, the data transfer between the internal networks of different participants is not possible, which prevents the direct transmission and response of permission requests and decision-making information, thus affecting the normal authorization management of business systems.
By deploying smart contracts in a blockchain system to record permission request information and decision information, a first computing device is allowed to send permission request information to a first node, and a second computing device sends permission decision information to a second node based on the permission request information. This adds permission decision information to the smart contract state, supporting the target business system's response to access requests.
It enables data flow of the authorization system between different participants, supports the target business system to respond to access requests corresponding to permission application information, and realizes cross-partner permission management.
Smart Images

Figure CN115664704B_ABST
Abstract
Description
Technical Field
[0001] The embodiments in this specification belong to the field of blockchain technology, and in particular relate to a blockchain-based permission management method, device, and node in a blockchain system. Background Technology
[0002] Blockchain is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and cryptographic algorithms. In a blockchain system, data blocks are sequentially linked together to form a chain-like data structure, and a distributed ledger is cryptographically guaranteed to be immutable and unforgeable. Due to its decentralized, immutable, and autonomous characteristics, blockchain has received increasing attention and application. Based on different application scenarios and user needs, blockchains can generally be divided into three main categories: public blockchains, private blockchains, and consortium blockchains. Summary of the Invention
[0003] The purpose of this invention is to provide a blockchain-based permission management method, device, and node in a blockchain system.
[0004] Firstly, a blockchain-based permission management method is provided, involving a first computing device and a second computing device belonging to different participants. The first computing device and the second computing device are respectively connected to a first node and a second node in a blockchain system. A smart contract is deployed in the blockchain system, and the first computing device is associated with a target business system. The method includes: the first computing device responding to a first message initiated by the target business system by sending a first transaction to the first node, wherein the first message and the first transaction include permission request information, causing the blockchain system to add the permission request information to the contract state of the smart contract; the second computing device obtaining the permission request information from the second node and sending a second transaction to the second node according to the permission request information, wherein the second transaction includes permission decision information corresponding to the permission request information, causing the blockchain system to add the permission decision information to the contract state of the smart contract.
[0005] In one possible implementation, the permission request information indicates a first account that wishes to register in the target business system, and the permission decision information indicates whether to allow the registration of the first account in the target business system.
[0006] In one possible implementation, the permission request information indicates a first account and a first service that it wishes to use, and the permission decision information indicates whether to allow the first account to use the first service.
[0007] In one possible implementation, the method further includes: the first computing device, in response to a second message initiated by the target business system, sending a third transaction to the first node, wherein the second message is initiated by the target business system after receiving an access request, and the second message and the third transaction include permission query information corresponding to the access request, causing the first node to return a permission query result, wherein when the contract state of the smart contract includes target permission application information corresponding to the permission query information, the permission query result includes target permission decision information corresponding to the target permission application information; the first computing device provides the permission query result to the target business system, causing the target business system to respond to the access request based on the permission query result.
[0008] In one possible implementation, the access request is used to request the registration of a second account in the target business system, or the access request is used to request the target business system to provide a second service to the second account.
[0009] In one possible implementation, the access request is used to request the registration of a second account in the target business system. When the contract state of the smart contract does not include the target permission application information corresponding to the permission query information, the permission query result indicates that the target business system prohibits the registration of the second account in the target business system.
[0010] In one possible implementation, the access request is used to request the target business system to provide a second service to the second account. When the contract state of the smart contract does not include the target permission application information corresponding to the permission query information, the permission query result instructs the target business system to prohibit the provision of the second service to the second account.
[0011] In one possible implementation, the second computing device obtains the permission request information from the second node, specifically by sending a fourth transaction to the second node, causing the second node to return the permission request information.
[0012] Secondly, a blockchain-based permission management method is provided, involving a first computing device and a second computing device belonging to different participants. The first computing device and the second computing device are respectively connected to a first node and a second node in a blockchain system. A smart contract is deployed in the blockchain system. The first computing device is associated with a target business system, and the method is executed by the first computing device. The method includes: obtaining a first message initiated by the target business system, the first message including permission request information; sending a first transaction including the permission request information to the first node, causing the blockchain system to add the permission request information to the contract state of the smart contract; and causing the blockchain system to add permission decision information corresponding to the permission request information to the contract state of the smart contract based on a second transaction from the second computing device.
[0013] In one possible implementation, the permission request information indicates a first account that wishes to register in the target business system, and the permission decision information indicates whether to allow the registration of the first account in the target business system.
[0014] In one possible implementation, the permission request information indicates a first account and a first service that it wishes to use, and the permission decision information indicates whether to allow the first account to use the first service.
[0015] In one possible implementation, the method further includes: responding to a second message initiated by the target business system, sending a third transaction to the first node, wherein the second message is initiated by the target business system after receiving an access request, and the second message and the third transaction include permission query information corresponding to the access request, causing the first node to return a permission query result, wherein when the contract state of the smart contract includes target permission application information corresponding to the permission query information, the permission query result includes target permission decision information corresponding to the target permission application information; providing the permission query result to the target business system, causing the target business system to respond to the access request based on the permission query result.
[0016] In one possible implementation, the access request is used to request the registration of a second account in the target business system, or the access request is used to request the target business system to provide a second service to the second account.
[0017] In one possible implementation, the access request is used to request the registration of a second account in the target business system. When the contract state of the smart contract does not include the target permission application information corresponding to the permission query information, the permission query result indicates that the target business system prohibits the registration of the second account in the target business system.
[0018] In one possible implementation, the access request is used to request the target business system to provide a second service to the second account. When the contract state of the smart contract does not include the target permission application information corresponding to the permission query information, the permission query result instructs the target business system to prohibit the provision of the second service to the second account.
[0019] Thirdly, a blockchain-based permission management method is provided, involving a first computing device and a second computing device belonging to different participants. The first computing device and the second computing device are respectively connected to a first node and a second node in a blockchain system. The first computing device is associated with a target business system. A smart contract is deployed in the blockchain system. The contract state of the smart contract includes permission request information added by the blockchain system based on a first transaction. The first transaction is sent by the first computing device after receiving a first message initiated by the target business system. The method is executed by the second computing device. The method includes: obtaining the permission request information from the second node; sending a second transaction to the second node based on the permission request information, the second transaction including permission decision information corresponding to the permission request information, so that the blockchain system adds the permission decision information to the contract state of the smart contract.
[0020] In one possible implementation, the permission request information indicates a first account that wishes to register in the target business system, and the permission decision information indicates whether to allow the registration of the first account in the target business system.
[0021] In one possible implementation, the permission request information indicates a first account and a first service that it wishes to use, and the permission decision information indicates whether to allow the first account to use the first service.
[0022] In one possible implementation, obtaining the permission request information from the second node specifically includes: sending a fourth transaction to the second node to cause the second node to return the permission request information; sending a second transaction to the second node based on the permission request information specifically includes: in response to the decision operation of the participant to which the second computing device belongs regarding the permission request information, sending a second transaction to the second node.
[0023] Fourthly, a first node is provided in a blockchain system, which also includes a second node. The first node and the second node are respectively connected to a first computing device and a second computing device belonging to different participants. A smart contract is deployed in the blockchain system, and the first computing device is associated with a target business system. The first node includes: a communication processing unit configured to acquire a first transaction, which is sent by the first computing device based on a first message initiated by the target business system. The first message and the first transaction include permission request information; and a transaction processing unit configured to add the permission request information to the contract state of the smart contract based on the first transaction.
[0024] In one possible implementation, the communication processing unit is further configured to acquire a third transaction, which is sent by the first computing device based on a second message initiated by the target business system. The second message is initiated by the target business system after receiving an access request. The second message and the third transaction include permission query information corresponding to the access request. The transaction processing unit is further configured to return a permission query result to the first computing device based on the third transaction. When the contract state of the smart contract includes target permission application information corresponding to the permission query information, the permission query result includes target permission decision information corresponding to the target permission application information, so that the target business system responds to the access request based on the permission query result.
[0025] Fifthly, a second node is provided in a blockchain system, which further includes a first node. The first node and the second node are respectively connected to a first computing device and a second computing device belonging to different participants. The first computing device is associated with a target business system. A smart contract is deployed in the blockchain system. The contract state of the smart contract includes permission request information added by the blockchain system based on a first transaction. The first transaction is sent by the first computing device after receiving a first message initiated by the target business system. The second node includes: a communication processing unit configured to send the permission request information to the second computing device; and to obtain a second transaction sent from the second computing device based on the permission request information, the second transaction including permission decision information corresponding to the permission request information; and a transaction processing unit configured to add the permission decision information to the contract state of the smart contract based on the second transaction.
[0026] Sixthly, a blockchain-based permission management device is provided, involving a first computing device and a second computing device belonging to different participants. The first computing device and the second computing device are respectively connected to a first node and a second node in a blockchain system. A smart contract is deployed in the blockchain system. The first computing device is associated with a target business system, and the device is deployed within the first computing device. The device includes: an information acquisition unit configured to acquire a first message initiated by the target business system, the first message including permission request information; and an information sending unit configured to send a first transaction including the permission request information to the first node, causing the blockchain system to add the permission request information to the contract state of the smart contract, and causing the blockchain system to add permission decision information corresponding to the permission request information to the contract state of the smart contract based on a second transaction from the second computing device.
[0027] Sixthly, a blockchain-based permission management device is provided, involving a first computing device and a second computing device belonging to different participants. The first computing device and the second computing device are respectively connected to a first node and a second node in a blockchain system. The first computing device is associated with a target business system. A smart contract is deployed in the blockchain system. The contract state of the smart contract includes permission request information added by the blockchain system based on a first transaction. The first transaction is sent by the first computing device after receiving a first message initiated by the target business system. The device is deployed in the second computing device. The device includes: an information acquisition unit configured to acquire the permission request information from the second node; and an information sending unit configured to send a second transaction to the second node based on the permission request information. The second transaction includes permission decision information corresponding to the permission request information, causing the blockchain system to add the permission decision information to the contract state of the smart contract.
[0028] In a seventh aspect, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed in a computing device, causes the computing device to perform the method described in any one of the second or third aspects.
[0029] Eighthly, a computing device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor, when executing the computer program, implements the method described in any one of the second or third aspects.
[0030] Through the technical solutions provided in the embodiments of this specification, a smart contract is deployed in the blockchain system. The first node and the second node in the blockchain system are respectively connected to a first computing device and a second computing device belonging to different participants, and the first computing device is associated with a target business system. On this basis, the participant to which the first computing device belongs can trigger the target business system to initiate a first message according to its own needs, and then the first computing device sends a first transaction to the first node. The first message and the first transaction include permission request information, so that the blockchain system adds the aforementioned permission request information to the contract state of the smart contract. The second computing device can obtain the aforementioned permission request information from the second node. The participant to which the second computing device belongs can trigger the second computing device to send a second transaction to the second node according to the aforementioned permission request information. The second transaction includes permission decision information corresponding to the aforementioned permission request information, so that the blockchain system adds the aforementioned permission decision information to the contract state of the smart contract. The permission decision information can be used to support the target business system in responding to the access requests it receives corresponding to the permission request information. In this way, by recording permission request information from the first computing device and its corresponding permission decision information from the second computing device through smart contracts in the blockchain system, the authorization system data of the target business system can be transferred between computing devices belonging to different participants, thereby enabling the participant to the second computing device to manage the relevant permissions of the participant to the first computing device in using the target business system. Attached Figure Description
[0031] To more clearly illustrate the technical solutions of the embodiments in this specification, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 This is an example of the system architecture diagram of the blockchain system provided in the embodiments of this specification;
[0033] Figure 2 This is one of the schematic diagrams of a blockchain-based permission management method provided in the embodiments of this specification;
[0034] Figure 3 This is the second schematic diagram of a blockchain-based permission management method provided in the embodiments of this specification;
[0035] Figure 4 This is a schematic diagram of the first node in a blockchain system provided in the embodiments of this specification;
[0036] Figure 5This is a schematic diagram of a second node in a blockchain system provided in the embodiments of this specification;
[0037] Figure 6 This is one of the schematic diagrams of a blockchain-based access control device provided in the embodiments of this specification;
[0038] Figure 7 This is the second schematic diagram of a blockchain-based permission management device provided in the embodiments of this specification. Detailed Implementation
[0039] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0040] A blockchain system is a distributed network built from multiple nodes. Any two nodes within it communicate at the application layer through a peer-to-peer (P2P) network. See also... Figure 1 As shown, a blockchain system can, for example, contain nodes 1 to 4. Any two nodes from 1 to 4 can communicate at the application layer via a P2P network. The blockchain system utilizes a decentralized (or multi-centralized) distributed ledger constructed using a chain-like block structure, stored on each (or most) node in the distributed blockchain network. Therefore, the blockchain system needs to address the consistency and correctness of the ledger data across multiple decentralized (or multi-centralized) nodes. Each node in the blockchain system runs a blockchain program. Under certain fault-tolerance requirements, a consensus mechanism ensures that all loyal nodes have the same transactions, thereby guaranteeing consistent execution results for the same transactions. Multiple transactions arranged in sequence are packaged into a block, and the world state is updated based on the execution results of these transactions. The current mainstream consensus mechanisms may include, but are not limited to: Proof of Work (POW), Proof of Stake (POS), Practical Byzantine Fault Tolerance (PBFT) algorithm, and Honey Badger Byzantine Fault Tolerance (HoneyBadgerBFT) algorithm, etc.
[0041] A transaction in a blockchain system refers to a task unit executed and recorded within the blockchain system. A transaction typically includes a From field, a To field, and a Data field. Specifically, in the case of a transfer transaction, the From field represents the account address initiating the transaction (i.e., initiating a transfer task to another account), the To field represents the account address receiving the transaction (i.e., receiving the transfer), and the Data field includes the transfer amount. In the case of a transaction calling a smart contract in the blockchain system, the From field represents the account address initiating the transaction, the To field represents the account address of the contract called by the transaction, and the Data field includes the function name in the called contract and the parameters passed to that function, which is used to retrieve and execute the function's code from the blockchain system during transaction execution.
[0042] Smart contracts in a blockchain system are contracts that can be triggered and executed by transactions. Smart contracts can be defined in the form of code. For example, calling a smart contract in a consortium blockchain involves initiating a transaction pointing to the smart contract's address, causing each node in the consortium blockchain network to run the smart contract code in a distributed manner. It's important to note that besides users creating smart contracts, the system can also set smart contracts in the genesis block. These contracts are generally called genesis contracts. Typically, genesis contracts can set some data structures, parameters, attributes, and methods of the blockchain system. Furthermore, accounts with system administrator privileges can create or modify system-level contracts (referred to as system contracts).
[0043] In smart contract deployment scenarios, a transaction containing smart contract creation information (i.e., a transaction used to create a smart contract) can be sent to the blockchain system. The `from` field of this transaction is the account address of the transaction initiator, the `data` field includes the code of the smart contract to be created (such as bytecode or machine code), and the `to` field is empty to indicate that the transaction is used to deploy the contract. After nodes reach a consensus through the consensus mechanism, the contract address is determined, a contract account corresponding to the smart contract's contract address is added to the state database, state storage corresponding to the contract account is allocated, and the contract code is stored in the smart contract's state storage.
[0044] In scenarios involving contract invocation, a transaction for invoking a smart contract can be sent to the blockchain system. The `from` field of this transaction is the account address of the transaction initiator, the `to` field is the contract address of the smart contract being invoked, and the `data` field includes the method and parameters for invoking the smart contract. After consensus is reached on this transaction within the blockchain system, each node can execute the transaction, thereby executing the smart contract and updating the corresponding state database based on the execution of the smart contract.
[0045] It's important to note that contract accounts typically also possess some state. These states are defined by state variables within the smart contract and acquire new values during the smart contract's creation and execution. Contract accounts can be used to store the contract states related to the smart contract. Once an event triggers a clause in the smart contract (meeting the execution conditions), the code can be executed automatically. In a blockchain system, the contract state of a smart contract is stored in a storage trie. The hash value of the root node of this storage trie is stored in `storage_root`, thus locking all contract states of that contract under that contract account through hashing. The storage trie is an MPT tree structure that stores a key-value mapping from state addresses to state values. From the root node to the leaf node, each node stores the address of a state variable, and each leaf node stores the value of a state variable.
[0046] A blockchain system can involve multiple participants. Different nodes in the blockchain system may interface with different computing devices. Nodes and computing devices that interface with each other belong to the same participant, while different nodes / computing devices may belong to different participants. These participants can be institutions, organizations, or individuals. For example, a blockchain system can be a consortium blockchain with multiple participants: node 1 and computing device 10 belong to participant A; node 2 and computing device 20 belong to participant B; node 3 and computing device 30 belong to participant C; and node 4 and computing device 40 belong to participant D. The computing devices can process the data and transmit the results to the nodes they interface with through transactions. Different computing devices can establish communication connections through high-speed blockchain transmission networks (BTN).
[0047] Within one participant's intranet environment, a target business system developed and / or operated by another participant may be deployed. For example, business system P is operated by participant A; computing device 20 is located in participant B's intranet environment. Business system B may be deployed on computing device 20 or on other computing devices connected to computing device 20 within participant B's intranet environment. In this case, business system P is the business system associated with computing device 20. Business system P can adopt various software application models, including Software as a Service (SaaS), and business system P itself typically provides multiple services.
[0048] The intranet environments of two different participants may not be interconnected, and the authorization system data of the target business system cannot flow between the two participants' intranet environments. For example, permission request information initiated by participant B through business system P may not be directly transmitted to participant A, and participant B also cannot provide permission decision information corresponding to the permission request information initiated by business system P, so that business system P can use the aforementioned permission decision information to respond to the aforementioned access request when it receives an access request from a participant corresponding to the aforementioned permission request information; wherein the aforementioned access request may be used to request the registration of an account in business system P, or it may be used to request the provision of a certain service to an account already registered in business system P.
[0049] In view of the above problems, this specification provides at least one blockchain-based permission management method, device, and node in a blockchain system. The blockchain system deploys smart contracts. A first node and a second node in the blockchain system are respectively connected to a first computing device and a second computing device belonging to different participants. The first computing device is associated with a target business system. Based on this, the participant to which the first computing device belongs can trigger the target business system to initiate a first message according to its own needs. The first computing device then sends a first transaction to the first node. The first message and the first transaction include permission request information, causing the blockchain system to add the aforementioned permission request information to the contract state of the smart contract. The second computing device can obtain the aforementioned permission request information from the second node. The participant to which the second computing device belongs can trigger the second computing device to send a second transaction to the second node based on the aforementioned permission request information. The second transaction includes permission decision information corresponding to the aforementioned permission request information, causing the blockchain system to add the aforementioned permission decision information to the contract state of the smart contract. The permission decision information can be used to support the target business system in responding to access requests received corresponding to the permission request information. In this way, by recording permission request information from the first computing device and its corresponding permission decision information from the second computing device through smart contracts in the blockchain system, the authorization system data of the target business system can be transferred between computing devices belonging to different participants, thereby enabling the participant to the second computing device to manage the relevant permissions of the participant to the first computing device in using the target business system.
[0050] Figure 2This is one of the schematic diagrams illustrating a blockchain-based permission management method provided in the embodiments of this specification. It exemplarily describes the process by which participant B, belonging to computing device 20, requests permission related to business system P from participant A, belonging to computing device 10, through business system P. Industry application middleware 1 and industry application middleware 2 can be deployed in computing devices 10 and 20 respectively. Participant B may, in a browser or other client program, use an administrator account to initiate an access request Q1 to business system P, requesting participant A to grant the administrator account permission to register account d1 in business system P; or use the administrator account to initiate an access request Q2 to business system P, requesting permission to grant account d1, already registered in business system P, permission to use a service S1 provided by business system P. Both access requests Q1 and Q2 can trigger business system P to initiate a message M1 containing permission request information. See also... Figure 2 As shown, the process may include, but is not limited to, the following steps S21 to S26.
[0051] Step S21: The computing device 20 obtains message M1 initiated by the business system P.
[0052] The computing device 20 receives a message M1 initiated by the business system P, for example, through the industry application middleware 2. Regarding the permission request information included in the message M1: when the message M1 is initiated based on the aforementioned access request Q1, the permission request information may indicate the account d1 that wishes to register in the business system P, and may also indicate the administrator account that initiated the access request Q1; when the message M1 is initiated based on the aforementioned access request Q2, the permission request information may indicate the account d1 that is already registered in the business system P and a certain service S1 that it wishes to use and that is provided by the business system P.
[0053] In step S22, computing device 20 sends transaction Tx1 to node 2 in the blockchain system.
[0054] The computing device 20 sends a transaction Tx1 to the node 2, for example, through the industry application middleware 2. The transaction Tx1 requests to invoke the smart contract C1 deployed in the blockchain system. The transaction Tx1 includes, for example, permission request information located in message M1.
[0055] Step S23: The blockchain system adds permission application information to the contract state of smart contract C1 based on transaction Tx1.
[0056] In a blockchain system, nodes including node 1 and node 2 can execute transaction Tx1 to add permission request information located in transaction Tx1 to the contract state of smart contract C1.
[0057] Step S24: The computing device 10 obtains the permission request information added to the contract state of smart contract C1 by the blockchain system.
[0058] Computing device 10, for example, sends transaction Tx2 to node 1 in the blockchain system via industry application middleware 1. Transaction Tx2 requests to invoke smart contract C1 to poll the contract state of smart contract C1 for any newly added permission request information. When the contract state of smart contract C1 contains such information, node 1 returns this information to industry application middleware 1 in computing device 20. Furthermore, the information returned by node 1 to computing device 20 based on transaction Tx2 may also include the hash value of the newly added permission request information in the contract state of smart contract C1.
[0059] Computing device 10 may present permission request information obtained from the blockchain system to participant A, for example, through industry application middleware 1, or through other applications. Correspondingly, participant A can initiate a decision operation based on the presented permission request information, causing computing device 10 to execute step S25 based on the decision operation initiated by participant A.
[0060] In step S25, computing device 10 sends transaction Tx3 to node 1 in the blockchain system according to the permission request information.
[0061] Computing device 10, for example, responds to a decision-making operation initiated by participant A regarding permission request information via industry application middleware 1, sending transaction Tx3 to node 1. Transaction Tx3 requests a call to smart contract C1, and includes permission decision information corresponding to the permission request information. Specifically, when the permission request information indicates an account d1 desired to be registered in business system P, the permission decision information indicates whether registration of account d1 in business system P is permitted; when the permission request information indicates account d1 and its desired service S1, the permission decision information indicates whether service S1 is permitted. Furthermore, transaction Tx3 may also include, for example, the hash value of the permission request information corresponding to the permission decision information. As mentioned earlier, this hash value can be returned by node 1 in the blockchain system to industry application middleware 1 in computing device 20 based on transaction Tx2.
[0062] Step S26: The blockchain system adds permission decision information to the contract state of the smart contract based on transaction Tx3.
[0063] In a blockchain system, nodes including Node 1 and Node 2 can execute transaction Tx3 to add permission decision information from transaction Tx3 to the contract state of smart contract C1. Corresponding permission request information and permission decision information can be recorded together in the contract state of smart contract C1. For example, when node 1 executes transaction Tx3, it can retrieve the corresponding permission request information from the contract state of smart contract C1 based on the hash value of the permission request information corresponding to the permission decision information in transaction Tx3, and then store the corresponding permission request information and permission decision information as a complete permission request record in the contract state of smart contract C1.
[0064] It is understandable that if steps S21 to S26 are executed multiple times, multiple sets of corresponding permission request information and permission decision information may be recorded in the contract state of smart contract C1. The sets of corresponding permission request information and permission decision information recorded in the contract state of smart contract C1 can support the business system in responding to the access requests it receives.
[0065] Figure 3 This is the second schematic diagram of a blockchain-based permission management method provided in the embodiments of this specification. It exemplarily describes the process by which business system P responds to access requests received by business system P using the corresponding sets of permission request information and permission decision information recorded in the contract state of smart contract C1. See also... Figure 3 As shown, the process may include, but is not limited to, the following steps S31 to S36.
[0066] Step S31: The business system P receives the access request.
[0067] Participant B can, for example, use an administrator account in a browser or other client program to initiate an access request Q3 to the business system P, requesting that account d2 be registered in the business system; or use account d2 already registered in the business system P to initiate an access request Q4 to the business system P, requesting that the business system P provide a certain service S2 to account d2. The access request received by the business system P in step S31 can be either access request Q3 or access request Q4 as described above.
[0068] Step S32: The computing device 20 obtains message M2 initiated by the target business system.
[0069] The computing device 20 receives a message M2 initiated by the business system P, for example, through the industry application middleware 2. Message M2 may include permission query information corresponding to the access request received by the business system P in step 31. Specifically, when message M2 is initiated based on the aforementioned access request Q3, the permission query information may indicate the account d2 expected to be registered in the business system P, and may also indicate the administrator account that initiated access request Q3. When message M2 is initiated based on the aforementioned access request Q4, the permission query information may indicate the account d2 that initiated access request Q4 and the service S2 that the business system P is expected to provide to account d2.
[0070] In step S33, computing device 20 sends transaction Tx4 to node 2 in the blockchain system.
[0071] Computing device 20 sends transaction Tx4 to node 2, for example, through industry application middleware 2. Transaction Tx4 requests to invoke smart contract C1. Transaction Tx4 includes permission query information located in message M2.
[0072] In step S34, node 2 in the blockchain system returns the permission query result to computing device 20 based on transaction Tx4.
[0073] Node 2 can execute transaction Tx4 and return the permission query result to the industry application middleware 2 in computing device 20 based on the execution result of transaction Tx4. When the contract state of smart contract C1 includes target permission request information corresponding to the permission query information (e.g., when there is target permission request information identical to the permission query information), the permission query result includes target permission decision information corresponding to the target permission request information. Furthermore, when the contract state of the smart contract does not include target permission request information corresponding to the permission query information (e.g., when there is no target permission request information identical to the permission query information), the permission query result instructs business system P to prohibit the registration of account d2 requested by access request Q3 in business system P, or instructs business system P to prohibit providing service S2 to account d2 registered in the business system according to access request Q4.
[0074] In step S35, computing device 20 provides the permission query results to business system P.
[0075] Computing device 20 provides the permission query results returned by node 2 to business system P, for example, through industry application middleware 2.
[0076] Step S36: The business system P responds to the access request based on the permission query results.
[0077] When the access request received in step 31 is the aforementioned access request Q3, business system P can decide whether to register account d2 in business system P based on access request Q3 according to the permission query. When the access request received in step 31 is the aforementioned access request Q4, business system P can decide whether to provide service S2 to account d2 according to access request Q4 according to the permission query. When business system P adopts the software application model SaaS, business system P can return the page corresponding to service S2 to the browser or client program that initiated access request Q4 according to access request Q4, so that service S2 can be provided to account d2 through this page.
[0078] It should be noted that when the permission query result indicates that business system P prohibits the registration of account d2 requested by access request Q3 in business system P, or indicates that business system P prohibits providing service S2 to account d2 registered in business system according to access request Q4, business system P can trigger a process similar to the aforementioned steps S21 to S26 based on the corresponding administrator account, requesting participant A to grant the administrator account permission to register account d2 in business system P, or requesting to grant account d2 already registered in business system P permission to use a certain service S2 provided by business system P.
[0079] Based on the same concept as the aforementioned method embodiments, this specification also provides a first node in a blockchain system, which further includes a second node. The first node and the second node are respectively connected to a first computing device and a second computing device belonging to different participants. A smart contract is deployed in the blockchain system, and the first computing device is associated with a target business system. For example... Figure 4 As shown, the first node includes: a communication processing unit 41, configured to acquire a first transaction, the first transaction being sent by the first computing device according to a first message initiated by the target business system, the first message and the first transaction including permission request information; and a transaction processing unit 43, configured to add the permission request information to the contract state of the smart contract according to the first transaction.
[0080] In one possible implementation, the communication processing unit 41 is further configured to acquire a third transaction, wherein the third transaction is sent by the first computing device based on a second message initiated by the target business system, the second message being initiated by the target business system after receiving an access request, and the second message and the third transaction including permission query information corresponding to the access request; the transaction processing unit 43 is further configured to return a permission query result to the first computing device based on the third transaction, wherein when the contract state of the smart contract includes target permission application information corresponding to the permission query information, the permission query result includes target permission decision information corresponding to the target permission application information, so that the target business system responds to the access request based on the permission query result.
[0081] Based on the same concept as the aforementioned method embodiments, this specification also provides a second node in a blockchain system. The blockchain system further includes a first node. The first node and the second node are respectively connected to a first computing device and a second computing device belonging to different participants. The first computing device is associated with a target business system. A smart contract is deployed in the blockchain system. The contract state of the smart contract includes permission request information added by the blockchain system based on a first transaction. The first transaction is sent by the first computing device after receiving a first message initiated by the target business system. Figure 5 As shown, the second node includes: a communication processing unit 51, configured to send the permission request information to the second computing device; and to obtain a second transaction sent from the second computing device according to the permission request information, wherein the second transaction includes permission decision information corresponding to the permission request information; and a transaction processing unit 53, configured to add the permission decision information to the contract state of the smart contract according to the second transaction.
[0082] Based on the same concept as the aforementioned method embodiments, this specification also provides a blockchain-based permission management device, involving a first computing device and a second computing device belonging to different participants. The first computing device and the second computing device are respectively connected to a first node and a second node in a blockchain system. The blockchain system deploys smart contracts. The first computing device is associated with a target business system, and the device is deployed within the first computing device. Figure 6As shown, the device includes: an information acquisition unit 61, configured to acquire a first message initiated by the target business system, the first message including permission request information; and an information sending unit 63, configured to send a first transaction including the permission request information to the first node, causing the blockchain system to add the permission request information to the contract state of the smart contract, and causing the blockchain system to add permission decision information corresponding to the permission request information to the contract state of the smart contract based on a second transaction from the second computing device.
[0083] Based on the same concept as the aforementioned method embodiments, this specification also provides a blockchain-based permission management device, involving a first computing device and a second computing device belonging to different participants. The first computing device and the second computing device are respectively connected to a first node and a second node in a blockchain system. The first computing device is associated with a target business system. A smart contract is deployed in the blockchain system. The contract state of the smart contract includes permission request information added by the blockchain system according to a first transaction. The first transaction is sent by the first computing device after receiving a first message initiated by the target business system. The device is deployed in the second computing device. Figure 7 As shown, the device includes: an information acquisition unit 71 configured to acquire the permission application information from the second node; and an information sending unit 73 configured to send a second transaction to the second node according to the permission application information, wherein the second transaction includes permission decision information corresponding to the permission application information, so that the blockchain system adds the permission decision information to the contract state of the smart contract.
[0084] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0085] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0086] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or physical entities, or by products with certain functions. A typical implementation device is a server system. Of course, this application does not exclude the possibility that, with the future development of computer technology, the computer implementing the functions of the above embodiments can be, for example, a personal computer, a laptop computer, an in-vehicle human-machine interaction device, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0087] While one or more embodiments of this specification provide the operational steps of the methods described in the embodiments or flowcharts, more or fewer operational steps may be included based on conventional or non-inventive means. The order of steps listed in the embodiments is merely one possible order of execution among many steps and does not represent the only possible order. In actual device or end product execution, the methods shown in the embodiments or drawings may be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment, or even a distributed data processing environment). The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, product, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, product, or apparatus. Without further limitations, the presence of other identical or equivalent elements in the process, method, product, or apparatus that includes the elements is not excluded. For example, the use of terms such as "first," "second," etc., is to denote names and does not indicate any particular order.
[0088] For ease of description, the above devices are described in terms of function, divided into various modules. Of course, when implementing one or more of these specifications, the functions of each module can be implemented in one or more software and / or hardware components, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between devices or units, and may be electrical, mechanical, or other forms.
[0089] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0090] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0091] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0092] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0093] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0094] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage, graphene storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0095] Those skilled in the art will understand that one or more embodiments of this specification can be provided as a method, system, or computer program product. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0096] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0097] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, system embodiments are basically similar to method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments. In the description of this specification, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this specification. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described can be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0098] The above description is merely an embodiment of one or more embodiments of this specification and is not intended to limit the scope of these embodiments. Various modifications and variations can be made to these embodiments by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims.
Claims
1. A permission management method based on a blockchain, involving a first computing device and a second computing device belonging to different participants, the first computing device and the second computing device being connected to a first node and a second node in a blockchain system respectively, the blockchain system having a smart contract deployed therein, the first computing device being associated with a target business system developed or operated by a second participant, the first computing device being located in an intranet environment of a first participant, the second computing device being located in an intranet environment of the second participant, the intranet environment of the first participant and the intranet environment of the second participant not being network-interconnected, the method comprising: the first computing device sending, in response to a first message initiated by the target business system, a first transaction to the first node, the first message and the first transaction including permission application information, causing the blockchain system to add the permission application information in a contract state of the smart contract; the second computing device obtaining the permission application information from the second node, and sending, according to the permission application information, a second transaction to the second node, the second transaction including permission decision information corresponding to the permission application information, causing the blockchain system to add the permission decision information in the contract state of the smart contract. 2.The method of claim 1, wherein the permission application information indicates a first account expected to be registered in the target business system, and the permission decision information indicates whether the first account is allowed to be registered in the target business system; or the permission application information indicates a first account and a first service expected to be used by the first account, and the permission decision information indicates whether the first account is allowed to use the first service. 3.The method of claim 1, further comprising: the first computing device sending, in response to a second message initiated by the target business system, a third transaction to the first node, the second message being initiated by the target business system after receiving an access request, the second message and the third transaction including permission query information corresponding to the access request, causing the first node to return a permission query result, wherein when the contract state of the smart contract includes target permission application information corresponding to the permission query information, the permission query result includes target permission decision information corresponding to the target permission application information; the first computing device providing the permission query result to the target business system, causing the target business system to respond to the access request according to the permission query result. 4.The method of claim 3, wherein the access request is used to request a second account to be registered in the target business system, or the access request is used to request the target business system to provide a second service to the second account. 5. The method of claim 3, wherein the access request is for requesting registration of a second account in the target business system, and when the target permission application information corresponding to the permission query information is not included in the contract state of the smart contract, the permission query result indicates that the target business system prohibits registration of the second account in the target business system. Alternatively, the access request is for requesting the target business system to provide a second service to a second account, and when the target permission application information corresponding to the permission query information is not included in the contract state of the smart contract, the permission query result indicates that the target business system prohibits the second account from using the second service.
6. The method of any one of claims 1-5, wherein the second computing device obtains the permission application information from the second node, specifically comprising: The second computing device sends a fourth transaction to the second node, so that the second node returns the permission application information.
7. A permission management method based on a blockchain, involving a first computing device and a second computing device belonging to different participants, the first computing device and the second computing device are connected to a first node and a second node in a blockchain system respectively, a smart contract is deployed in the blockchain system, the first computing device is associated with a target business system developed and / or operated by a second participant, the first computing device is located in an intranet environment of a first participant, the second computing device is located in an intranet environment of a second participant, the intranet environment of the first participant and the intranet environment of the second participant do not realize network interconnection, the method is executed by the first computing device, and the method comprises: obtaining a first message initiated by the target business system, wherein the first message comprises permission application information; sending a first transaction comprising the permission application information to the first node, so that the blockchain system adds the permission application information in the contract state of the smart contract, and so that the blockchain system adds permission decision information corresponding to the permission application information in the contract state of the smart contract according to a second transaction from the second computing device.
8. The method of claim 7, wherein the permission application information indicates a first account expected to be registered in the target business system, and the permission decision information indicates whether the first account is allowed to be registered in the target business system. Alternatively, the permission application information indicates a first account and a first service expected to be used by the first account, and the permission decision information indicates whether the first account is allowed to use the first service.
9. The method of claim 7, further comprising: in response to a second message initiated by the target business system, sending a third transaction to the first node, the second message being initiated by the target business system after receiving an access request, the second message and the third transaction comprising permission query information corresponding to the access request, so that the first node returns a permission query result, wherein when the target permission application information corresponding to the permission query information is included in the contract state of the smart contract, the permission query result comprises target permission decision information corresponding to the target permission application information. The permission query result is provided to the target business system, so that the target business system responds to the access request according to the permission query result.
10. The method of claim 9, wherein the access request is for requesting registration of a second account in the target business system, or the access request is for requesting the target business system to provide a second service to a second account.
11. The method of claim 9, wherein the access request is for requesting registration of a second account in the target business system, and when the target permission application information corresponding to the permission query information is not included in the contract state of the smart contract, the permission query result indicates that the target business system prohibits registration of the second account in the target business system. Alternatively, the access request is for requesting the target business system to provide a second service to a second account, and when the target permission application information corresponding to the permission query information is not included in the contract state of the smart contract, the permission query result indicates that the target business system prohibits the second service to the second account.
12. A permission management method based on a block chain, involving a first computing device and a second computing device belonging to different participants, the first computing device and the second computing device are respectively connected to a first node and a second node in a block chain system, the first computing device is associated with a target business system developed or operated by a second participant, the first computing device is located in an intranet environment of a first participant, the second computing device is located in an intranet environment of a second participant, the intranet environment of the first participant and the intranet environment of the second participant do not realize network interconnection, a smart contract is deployed in the block chain system, and the contract state of the smart contract includes permission application information added by the block chain system according to a first transaction, the first transaction is provided by the first computing device after obtaining a first message initiated by the target business system, the method is executed by the second computing device, and the method comprises: Obtaining the permission application information from the second node; According to the permission application information, a second transaction is sent to the second node, the second transaction includes permission decision information corresponding to the permission application information, so that the block chain system adds the permission decision information in the contract state of the smart contract.
13. The method of claim 12, wherein the permission application information indicates a first account expected to be registered in the target business system, and the permission decision information indicates whether the first account is allowed to be registered in the target business system. Alternatively, the permission application information indicates a first account and a first service expected to be used by the first account, and the permission decision information indicates whether the first account is allowed to use the first service.
14. The method of claim 12 or 13, wherein the obtaining the permission application information from the second node comprises: A fourth transaction is sent to the second node, so that the second node returns the permission application information. The second transaction is sent to the second node according to the permission application information, and specifically includes: in response to a decision operation of a participant to which the second computing device belongs on the permission application information, the second transaction is sent to the second node.
15. A first node in a blockchain system, the blockchain system further comprising a second node, the first node and the second node being respectively connected to a first computing device and a second computing device belonging to different participants, the blockchain system deploying a smart contract, the first computing device being associated with a target business system developed or operated by a second participant, the first computing device being located in an intranet environment of a first participant, the second computing device being located in an intranet environment of a second participant, the intranet environment of the first participant and the intranet environment of the second participant not realizing network intercommunication, the first node comprising: a communication processing unit configured to obtain a first transaction, the first transaction being sent by the first computing device according to a first message initiated by the target business system, the first message and the first transaction comprising permission application information; a transaction processing unit configured to add the permission application information in a contract state of the smart contract according to the first transaction.
16. The first node of claim 15, wherein the communication processing unit is further configured to obtain a third transaction, the third transaction being sent by the first computing device according to a second message initiated by the target business system, the second message being initiated by the target business system after receiving an access request, the second message and the third transaction comprising permission query information corresponding to the access request; the transaction processing unit is further configured to return a permission query result to the first computing device according to the third transaction, wherein when the contract state of the smart contract comprises target permission application information corresponding to the permission query information, the permission query result comprises target permission decision information corresponding to the target permission application information, so that the target business system responds to the access request according to the permission query result.
17. A second node in a blockchain system, the blockchain system further comprising a first node, the first node and the second node being respectively connected to a first computing device and a second computing device belonging to different participants, the first computing device being associated with a target business system developed or operated by a second participant, the first computing device being located in an intranet environment of a first participant, the second computing device being located in an intranet environment of a second participant, the intranet environment of the first participant and the intranet environment of the second participant not realizing network intercommunication, the blockchain system deploying a smart contract, the contract state of the smart contract comprising permission application information added by the blockchain system according to a first transaction, the first transaction being sent by the first computing device after obtaining a first message initiated by the target business system, the second node comprising: a communication processing unit configured to send the permission application information to the second computing device; and obtaining a second transaction sent by the second computing device according to the permission application information, the second transaction including permission decision information corresponding to the permission application information; a transaction processing unit, configured to add the permission decision information in the contract state of the smart contract according to the second transaction. 18.A permission management apparatus based on a blockchain, involving a first computing device and a second computing device belonging to different participants, the first computing device and the second computing device being connected to a first node and a second node in a blockchain system respectively, the blockchain system having a smart contract deployed therein, the first computing device being associated with a target business system developed or operated by a second participant, the first computing device being located in an intranet environment of a first participant, the second computing device being located in an intranet environment of the second participant, the intranet environment of the first participant and the intranet environment of the second participant not being network-interconnected, the apparatus being deployed in the first computing device, and the apparatus comprising: an information obtaining unit, configured to obtain a first message initiated by the target business system, the first message including permission application information; an information sending unit, configured to send a first transaction including the permission application information to the first node, to cause the blockchain system to add the permission application information in the contract state of the smart contract, and to cause the blockchain system to add permission decision information corresponding to the permission application information in the contract state of the smart contract according to a second transaction from the second computing device. 19.A permission management apparatus based on a blockchain, involving a first computing device and a second computing device belonging to different participants, the first computing device and the second computing device being connected to a first node and a second node in a blockchain system respectively, the first computing device being associated with a target business system developed or operated by a second participant, the first computing device being located in an intranet environment of a first participant, the second computing device being located in an intranet environment of the second participant, the intranet environment of the first participant and the intranet environment of the second participant not being network-interconnected, the blockchain system having a smart contract deployed therein, the contract state of the smart contract including permission application information added in the contract state of the smart contract by the blockchain system according to a first transaction, the first transaction being sent by the first computing device after obtaining a first message initiated by the target business system, the apparatus being deployed in the second computing device, and the apparatus comprising: an information obtaining unit, configured to obtain the permission application information from the second node; an information sending unit, configured to send a second transaction to the second node according to the permission application information, the second transaction including permission decision information corresponding to the permission application information, to cause the blockchain system to add the permission decision information in the contract state of the smart contract. 20.A computer-readable storage medium having a computer program stored thereon, the computer program, when executed in a computing device, causing the computing device to perform the method of any one of claims 7-14.
21. A computing device comprising a memory having stored therein a computer program and a processor, wherein the processor, when executing the computer program, implements the method of any one of claims 7-14.
Citation Information
Patent Citations
Account permission management method and system based on blockchain
CN111641586A