Blockchain-based Data Processing Method, Device, Equipment and Storage Medium
The main proxy node obtains and synchronizes blockchain configuration information in the public network, and solves the problem of low efficiency in the configuration of business node clusters in the blockchain network, and realizes automated node deployment and efficient configuration.
Patent Information
- Application Number
- CN202111003289.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-30
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-08-30
AI Technical Summary
In the prior art, the configuration efficiency of the service node cluster in the blockchain network is low, and manual configuration is required, resulting in cumbersome operations.
The main agent node obtains the public network access information of the service node cluster, connects to the public network of the management node cluster, obtains node description information, and determines the blockchain configuration information based on the information, and automatically synchronizes it to the service processing node to realize the automated configuration of the node.
It improves the configuration efficiency of the business node cluster, realizes the automated deployment of blockchain nodes, reduces manual participation, and improves configuration efficiency.
Smart Images

Figure CN115730934B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of blockchain technology, and in particular, to a data processing method, apparatus, device, and storage medium based on blockchain. Background Art
[0002] A blockchain network refers to a system for data sharing between nodes. The blockchain network may include multiple business node clusters. When the nodes in each business node cluster are working properly, they can receive transaction data and maintain a blockchain based on the received transaction data. Here, the transaction data may include, but is not limited to: transaction records of banks (such as remittance records, loan records), medical treatment information of medical institutions, student enrollment information of educational institutions, and so on. In order to ensure communication between business node clusters in the blockchain network, there may be information connections between every two business node clusters in the blockchain network, and information transmission can be carried out between business node clusters through the above information connections. Currently, it is necessary to manually configure the nodes in the business node cluster as nodes in the blockchain network to achieve the information connection between every two business node clusters, and the operation process is relatively cumbersome, resulting in a relatively low configuration efficiency of the business node cluster. Summary of the Invention
[0003] The technical problem to be solved by the embodiments of this application is to provide a data processing method, apparatus, device, and storage medium based on blockchain, which can effectively improve the configuration efficiency of the business node cluster.
[0004] One aspect of the embodiments of this application provides a data processing method based on blockchain, including:
[0005] The main proxy node obtains a configuration request for the first business node cluster; the configuration request carries the public network access information of the first business proxy node in the first business node cluster, and the main proxy node belongs to the management node cluster of the blockchain network;
[0006] Connect the first business proxy node to the public network to which the management node cluster belongs according to the public network access information, and obtain the node description information of the first business processing node in the first business node cluster from the first business proxy node through the public network;
[0007] Determine blockchain configuration information matching the first service node cluster according to the node description information, and send the blockchain configuration information to the first service proxy node through the public network; the first service proxy node synchronizes the blockchain configuration information to the first service processing node through the first private network to which the first service node cluster belongs, and the blockchain configuration information is used to configure the first service processing node as a node in the blockchain network.
[0008] An embodiment of the present application provides a data processing device based on a blockchain, including:
[0009] An acquisition module, configured to acquire a configuration request for a first service node cluster; the configuration request carries public network access information of a first service proxy node in the first service node cluster, and the main proxy node belongs to a management node cluster of the blockchain network;
[0010] A connection module, configured to connect the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, and acquire node description information of a first service processing node in the first service node cluster from the first service proxy node through the public network;
[0011] A determination module, configured to determine blockchain configuration information matching the first service node cluster according to the node description information, and send the blockchain configuration information to the first service proxy node through the public network; the first service proxy node synchronizes the blockchain configuration information to the first service processing node through the first private network to which the first service node cluster belongs, and the blockchain configuration information is used to configure the first service processing node as a node in the blockchain network.
[0012] Optionally, the determination module determines blockchain configuration information matching the first service node cluster according to the node description information, including:
[0013] Determine a target block associated with the node description information from the blockchain in the blockchain network;
[0014] Acquire an image file of a blockchain application program from a database node of the management node cluster through a second private network to which the management node cluster belongs;
[0015] Determine the target block and the image file as blockchain configuration information matching the first service node cluster; the image file is used to generate a blockchain node container in the first service processing node, and the target block is used to generate a blockchain belonging to the first service node cluster in the blockchain node container.
[0016] Optionally, the node description information includes the service type to which the service processed by the first service processing node belongs; the determining module determines a target block associated with the node description information from the blockchain in the blockchain network, including:
[0017] Identifying the institution to which the service processing node belongs according to the service type to which the service processed by the first service processing node belongs;
[0018] Reading the block associated with the institution to which the first service processing node belongs from the blockchain in the blockchain network as the target block.
[0019] Optionally, the node description information includes the remaining storage capacity of the service processing node; the determining module determines a target block associated with the node description information from the blockchain in the blockchain network, including:
[0020] Obtaining the generation time of the block on the blockchain in the blockchain network;
[0021] Reading one or more target blocks from the blockchain in the blockchain network according to the generation time; the total amount of data in the one or more target blocks is less than the remaining storage capacity of the first service processing node.
[0022] Optionally, the public network access information includes the public network address of the first service proxy node; the connecting module connects the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, including:
[0023] Configuring an access interface for the first service proxy node to access the public network according to the public network address of the first service proxy node;
[0024] Establishing a network connection between the first service proxy node and the main proxy node based on the access interface and the public network address;
[0025] If the network connection between the first service proxy node and the main proxy node is successful, it is determined that the first service proxy node has been connected to the public network to which the management node cluster belongs.
[0026] Optionally, the determining module sends the blockchain configuration information to the first service proxy node through the public network, including:
[0027] Encrypting the blockchain configuration information with the public key of the first service processing node to obtain encrypted data;
[0028] Sign the encrypted data with the private key of the master proxy node to obtain encrypted data carrying the signature information of the master proxy node;
[0029] Encapsulate the encrypted data carrying the signature information of the master proxy node into the data body of the data packet;
[0030] Encapsulate the public network address of the first service proxy node into the packet header of the data packet;
[0031] Send the encrypted data carrying the signature information of the master proxy node and the data packet with the public network address of the first service proxy node to the first service proxy node through the public network.
[0032] Optionally, the device further includes:
[0033] An update module, configured to obtain a public network mapping table, where the public network mapping table is used to reflect the mapping relationship between proxy nodes in the blockchain network and public network addresses;
[0034] Update the public network mapping table with the public network address of the first service proxy node to obtain an updated public network mapping table;
[0035] Synchronize the updated public network mapping table to the first service proxy node through the public network;
[0036] Synchronize the public network address of the first service proxy node to service proxy nodes in the remaining service node clusters in the blockchain network; the remaining service node clusters are service node clusters in the blockchain network other than the first service node cluster, and service proxy nodes in the remaining service node clusters perform data transmission with the first service proxy node according to the public network address and the public network.
[0037] Optionally, the determination module is further configured to:
[0038] Obtain service attribute information of a target service to be processed;
[0039] Determine a second service node cluster matching the service attribute information from the blockchain network according to the service attribute information;
[0040] Send the target service to a second service proxy node of the second service node cluster through the public network; the second service proxy node synchronizes the target service to a second service processing node for processing the target service through a third private network to which the second service node cluster belongs, and the second service processing node belongs to the second service node cluster.
[0041] Optionally, the determining module determines, from the blockchain network, a second business node cluster that matches the service attribute information, including:
[0042] Obtain the cluster relationship tree of the blockchain network, where the parent node of the cluster relationship tree is the management node cluster, and the child nodes of the cluster relationship tree are the business node clusters in the blockchain network;
[0043] Traverse the business node clusters in the cluster relationship tree according to the node paths of the cluster relationship tree;
[0044] Determine, from the cluster relationship tree, a second business node cluster that matches the service attribute information of the target service.
[0045] Optionally, the service attribute information includes the service type of the target service; the determining module determines, from the cluster relationship tree, a second business node cluster that matches the service attribute information of the target service, including:
[0046] Determine the security level of the target service according to the service type of the target service;
[0047] Obtain the number of times of data anomalies that occur in the business node clusters in the cluster relationship tree during the historical time period;
[0048] Divide the security levels of the business node clusters in the cluster relationship tree according to the number of times;
[0049] Use the business node clusters in the cluster relationship tree whose security levels are higher than the security level of the target service as the second business node clusters that match the attribute information of the target service.
[0050] Optionally, the service attribute information includes the processing duration for processing the target service; the determining module determines, from the cluster relationship tree, a second business node cluster that matches the service attribute information of the target service, including:
[0051] Obtain the service volume corresponding to the services to be processed by the business node clusters in the cluster relationship tree; and count the waiting duration according to the service volume corresponding to the services to be processed;
[0052] Use the sum of the waiting duration and the processing duration as the processing delay;
[0053] Use the business node clusters in the cluster relationship tree with a processing delay less than the delay threshold as the second business node clusters that match the attribute information of the target service.
[0054] On the one hand, the present application provides a computer device, including: a processor and a memory;
[0055] Wherein, the above-mentioned memory is used to store a computer program, and the above-mentioned processor is used to call the above-mentioned computer program to execute the following steps:
[0056] Obtain a configuration request for the first service node cluster; the configuration request carries the public network access information of the first service proxy node in the first service node cluster, and the main proxy node belongs to the management node cluster of the blockchain network;
[0057] Connect the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, and obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network;
[0058] Determine the blockchain configuration information matching the first service node cluster according to the node description information, and send the blockchain configuration information to the first service proxy node through the public network; the first service proxy node synchronizes the blockchain configuration information to the first service processing node through the first private network to which the first service node cluster belongs, and the blockchain configuration information is used to configure the first service processing node as a node in the blockchain network. An embodiment of the present application provides a computer-readable storage medium on the one hand. The above-mentioned computer-readable storage medium stores a computer program. The above-mentioned computer program includes program instructions. When the above-mentioned program instructions are executed by a processor, the following steps are executed:
[0059] Obtain a configuration request for the first service node cluster; the configuration request carries the public network access information of the first service proxy node in the first service node cluster, and the main proxy node belongs to the management node cluster of the blockchain network;
[0060] Connect the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, and obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network;
[0061] Determine the blockchain configuration information matching the first service node cluster according to the node description information, and send the blockchain configuration information to the first service proxy node through the public network; the first service proxy node synchronizes the blockchain configuration information to the first service processing node through the first private network to which the first service node cluster belongs, and the blockchain configuration information is used to configure the first service processing node as a node in the blockchain network.
[0062] In this application, first, according to the public network access information of the first service proxy node, the first service proxy node is connected to the public network to which the management node cluster belongs. In this way, each node in the first service node cluster can communicate with other node clusters through the public network, realizing the interconnection and interoperability between cross-domain blockchain nodes. Then, the main proxy node can obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network, determine the blockchain configuration information matching the first service node cluster according to the node description information, and send the blockchain configuration information to the first service proxy node through the public network. By determining the blockchain configuration information matching the first service node cluster according to the node description information and sending the blockchain configuration information to the first service proxy node, it is beneficial to realize the personalized configuration of the service processing nodes in the first service node cluster, without the need for manual participation, improving the efficiency of configuring the first service node cluster. At the same time, the process of configuring the first service processing node is equivalent to adding a blockchain node to the blockchain network. That is to say, this application can realize the automatic deployment of blockchain nodes, improving the efficiency of deploying blockchain nodes. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0064] Figure 1 is a schematic diagram of the architecture of a blockchain-based data processing system provided by the present application;
[0065] Figure 2 is a schematic diagram of the structure of a blockchain provided by the present application;
[0066] Figure 3 is a schematic diagram of the process of generating a block on the blockchain provided by the present application;
[0067] Figure 4 is a schematic diagram of the structure of the functional components in each node device of a blockchain-based data processing system provided by the present application;
[0068] Figure 5 is a schematic diagram of the process of a blockchain-based data processing method provided by the present application;
[0069] Figure 6 is a schematic diagram of a scenario for updating the public network mapping table provided by the present application;
[0070] Figure 7 It is the process intention of a data processing method based on blockchain provided by this application;
[0071] Figure 8 It is the process intention of a data processing method based on blockchain provided by this application;
[0072] Figure 9 It is the process intention of a main proxy node automatically deploying blockchain nodes provided by this application;
[0073] Figure 10 It is the scenario intention of cross - domain communication between business node clusters provided by this application;
[0074] Figure 11 It is the structural schematic diagram of a data processing device based on blockchain provided by an embodiment of this application;
[0075] Figure 12 It is the structural schematic diagram of a computer device provided by an embodiment of this application. Detailed implementation manners
[0076] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the protection scope of this application.
[0077] First, a data processing system for implementing the data processing method based on blockchain of this application is introduced. As Figure 1 shown, the data processing system includes a management node cluster and one or more business node clusters. Figure 1 Taking two business node clusters as an example for illustration, the two business node clusters are respectively business node cluster 1 and business node cluster 2.
[0078] Among them, the management node cluster includes a main proxy node 101 and multiple business processing nodes. Figure 1 Taking the management node cluster including three business processing nodes as an example for illustration, the business processing nodes include business processing node 102, business processing node 103, and business processing node 104. Each node in the management node cluster can communicate through a private network 10. For example, when business processing node 102 needs to communicate with business processing node 103, business processing node 102 can directly send data to business processing node 103 through private network 10.
[0079] Among them, as Figure 1Among them, the service node cluster 1 includes a service proxy node 201 and multiple service processing nodes. Figure 1 Among them, taking the case where the service node cluster 1 includes three service processing nodes as an example for illustration, the service processing nodes include a service processing node 202, a service processing node 203, and a service processing node 204. Each node in the service node cluster 1 can communicate through a private network 20. For example, when the service proxy node 201 needs to communicate with the service processing node 202, the service proxy node 201 can directly send data to the service processing node 202 through the private network 20. Similarly, as Figure 1 Among them, the service node cluster 2 includes a service proxy node 301 and multiple service processing nodes. Figure 1 Among them, taking the case where the service node cluster 2 includes three service processing nodes as an example for illustration, the service processing nodes include a service processing node 302, a service processing node 303, and a service processing node 304. Each node in the service node cluster 2 can communicate through a private network 30. For example, when the service proxy node 301 needs to communicate with the service processing node 302, the service proxy node 301 can directly send data to the service processing node 302 through the private network 30.
[0080] It can be understood that, as Figure 1 Among them, the private network 10 can refer to the internal network of the management node cluster. Specifically, the private network 10 can refer to the private network (Virtual Private Cloud, VPC) of a cloud provider. This private network 10 only allows communication between each node within the management node cluster, that is, internal data isolation between the management node cluster and other node clusters can be achieved through the private network 10. The private network 20 can refer to the internal network of the service node cluster 1. Specifically, the private network 20 can refer to the private network of an organization such as an institution or a department. This private network 20 only allows communication between each node within the service node cluster 1, that is, internal data isolation between the service node cluster 1 and other node clusters can be achieved through the private network 20. Similarly, the private network 30 can refer to the internal network of the service node cluster 2. Specifically, the private network 30 can refer to the private network of an organization such as an institution or a department. This private network 30 only allows communication between each node within the service node cluster 2, that is, internal data isolation between the service node cluster 2 and other node clusters can be achieved through the private network 30.
[0081] It is understandable that the management node cluster, service node cluster 1, and service node cluster 2 can refer to the device sets of different departments of the same organization. For example, the management node cluster can be the device set of the management department of Organization A, service node cluster 1 belongs to the device set of Business Department 1 of Organization A, and service node cluster 2 belongs to the device set of Business Department 2 of Organization A. Or, the management node cluster, service node cluster 1, and service node cluster 2 can refer to the device sets of different organizations. For example, the management node cluster, service node cluster 1, and service node cluster 2 belong to the device sets of Organization A, Organization B, and Organization C respectively.
[0082] It is understandable that since private network 10, private network 20, and private network 30 belong to different private networks respectively, the communication between the management node cluster, service node cluster 1, and service node cluster 2 can be referred to as cross-domain communication. Cross-domain communication refers to network communication in different regions or different intranets, which requires connection through the external network (i.e., the Internet) or other gateways to communicate. Specifically, as Figure 1 shown, the management node cluster, service node cluster 1, and service node cluster 2 can communicate through the public network 40 (i.e., the external network). Specifically, the main proxy node 101 of the management node cluster, the service proxy node 201 of service node cluster 1, and the service proxy node 301 of service node cluster 2 are connected through the public network 40. When two node clusters need to communicate, information forwarding needs to be carried out through the proxy nodes within the node cluster. For example, when the service processing node 103 in the management node cluster needs to communicate with the service processing node 202 in service node cluster 1, first, the service processing node 103 can send data to the main proxy node 101 through the private network 10. The main proxy node 101 can send the data to the service proxy node 201 in service node cluster 1 through the public network 40, and the service proxy node 201 forwards the data to the service processing node 202.
[0083] It is understandable that the nodes in each service node cluster all belong to the nodes in the same blockchain network. When the nodes in each service node cluster are working normally, they can receive transaction data and maintain a blockchain based on the received transaction data. Here, the transaction data can include but is not limited to: transaction records of banks (such as remittance records, loan records), medical treatment information of medical institutions, student enrollment information of educational institutions, etc. A blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. A blockchain, essentially a decentralized database, is a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain consists of multiple blocks. SeeFigure 2 A blockchain consists of multiple blocks. The genesis block includes a block header and a block body. The block header stores the feature value of the input information, version number, timestamp, and difficulty value, and the block body stores the input information. The next block after the genesis block has the genesis block as its parent block. The next block also includes a block header and a block body. The block header stores the feature value of the input information of the current block, the feature value of the block header of the parent block, version number, timestamp, and difficulty value, and so on. This makes the block data stored in each block in the blockchain associated with the block data stored in the parent block, ensuring the security of the input information in the block.
[0084] When generating each block in the blockchain, refer to Figure 3 When the node where the blockchain is located receives the input information, it verifies the input information. After the verification is completed, it stores the input information in the memory pool and updates the hash tree used to record the input information. Then, it updates the timestamp to the time when the input information is received and tries different random numbers, performing eigenvalue calculations multiple times so that the calculated eigenvalue can satisfy the following formula:
[0085] SHA256(SHA256(version+prev_hash+merkle_root+ntime+nbits+x))<TARGET
[0086] Among them, SHA256 is the eigenvalue algorithm used to calculate the eigenvalue; version (version number) is the version information of the relevant block protocol in the blockchain; prev_hash is the feature value of the block header of the parent block of the current block; merkle_root is the feature value of the input information; ntime is the update time of the updated timestamp; nbits is the current difficulty, which is a fixed value within a certain period of time and is determined again after exceeding the fixed time period; x is a random number; TARGET is the eigenvalue threshold, and this eigenvalue threshold can be determined according to nbits.
[0087] In this way, when a random number that satisfies the above formula is calculated, the information can be stored correspondingly, generating a block header and a block body to obtain the current block. Subsequently, the node where the blockchain is located sends the newly generated block to other nodes in the data sharing system it belongs to according to the node identifiers of other nodes in the data sharing system. Other nodes verify the newly generated block and add the newly generated block to the blockchain they store after the verification is completed.
[0088] A blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer. The blockchain underlying platform can include processing modules such as user management, basic services, smart contracts, and operation monitoring. Among them, the user management module is responsible for managing the identity information of all blockchain participants, including maintaining the generation of public and private keys (account management), key management, and maintaining the correspondence between the real identity of users and blockchain addresses (permission management). And under authorized circumstances, it supervises and audits the transaction situations of certain real identities, and provides rule configuration for risk control (risk control audit); the basic service module is deployed on all blockchain node devices to verify the validity of business requests, and records the valid requests to storage after consensus. For a new business request, the basic service first performs interface adaptation parsing and authentication processing (interface adaptation), then encrypts the business information through a consensus algorithm (consensus management), transmits it to the shared ledger completely and consistently after encryption (network communication), and performs record storage; the smart contract module is responsible for the registration and issuance of contracts, contract triggering, and contract execution. Developers can define contract logic through a certain programming language, publish it to the blockchain (contract registration), trigger the execution by calling keys or other events according to the logic of contract terms, complete the contract logic, and at the same time provide functions for contract upgrade and cancellation; the operation monitoring module is mainly responsible for the deployment, configuration modification, contract setting, cloud adaptation during the product release process, and visual output of the real-time state during product operation, such as: alarm, monitoring network conditions, monitoring the health status of node devices, etc.
[0089] Among them, each node in the blockchain network (that is, the nodes in each node cluster) can be a server or a terminal device. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The terminal device can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto.
[0090] It is understandable that the management node cluster is used to store the node information and control data of the blockchain network, and is responsible for scheduling blockchain nodes and uniformly managing the lifecycle in the blockchain network. The management node cluster is the main node deployed in the cloud business factory or private network environment, and can also be called the BaaS main cluster. Here, BaaS refers to Blockchain as a Service, which provides one-stop, highly secure, and easy-to-use blockchain services, with functions such as integrated development, management, and operation and maintenance, and supports customers to quickly deploy blockchain networks. Specifically, as Figure 4 shown, different nodes in the management node cluster have different functional components to achieve different functions. For example, the main proxy node in the management node cluster has the following functional components 1-5:
[0091] 1. Console: It can be used to provide a visual interaction interface for the BaaS cluster (i.e., the business node cluster). Through this visual interaction interface, the administrator can implement the management and scheduling operations of blockchain network nodes, as well as the capability configuration operations of other BaaS platforms.
[0092] 2. Database: It can be a relational database, which is used to store the metadata of the blockchain network. The metadata of the blockchain network includes the mapping relationship between nodes and node clusters in the blockchain network, monitoring, and other control data, etc.
[0093] 3. Control service: It is a general term for the basic functions of the BaaS platform, which here represents the basic capabilities of the BaaS platform possessed by the management node cluster.
[0094] 4. Automatic deployment: It is used to schedule, create, and destroy blockchain nodes, and maintain the lifecycle of nodes in the blockchain network.
[0095] 5. Cross-domain proxy: It is used to forward the traffic of nodes in the blockchain network, that is, to forward the data in the management node cluster to other business node clusters, and is also used for the traffic of automatic deployment and other control services; the traffic here can refer to the transaction data interacted by each node in the blockchain network.
[0096] Among them, the business processing nodes in the management node cluster include the accounting nodes and consensus nodes in the blockchain network. The accounting nodes can refer to those used to package the data to be uploaded to the blockchain into blocks. After the consensus nodes perform consensus on the blocks, the blocks are stored on the blockchain in the blockchain network.
[0097] Similarly, the business node cluster includes the nodes in the blockchain network, which are used to maintain the blockchain ledger and are deployed in the private environment or non-main nodes. Specifically, as Figure 4As shown, different nodes in the service node cluster have different functional components to implement different functions. For example, the service proxy node in the service node cluster has the following functional components ac:
[0098] a. API server: API (Application Programming Interface) server, used to provide the management API interface of the business node cluster (i.e. the access interface for communicating with other node clusters).
[0099] b. Cross-domain control: used for component initialization, node monitoring and control services, and can be used as a lightweight local node management view.
[0100] c. Cross-domain proxy: Data traffic from different node clusters is forwarded through the cross-domain proxy (i.e., business proxy node). The cross-domain proxy only opens one port to the outside world, which serves the function of collecting service ports and facilitates the configuration of network policies in a private environment.
[0101] The business processing nodes in the business node cluster include multiple accounting nodes in the blockchain network. The accounting nodes can be used to package the data to be uploaded into blocks. After the consensus nodes reach consensus on the blocks, the blocks are stored on the blockchain in the blockchain network. It should be noted that Figure 4 As shown, the above data processing system may further include an image warehouse, which refers to a warehouse for storing image files of functional components in each node cluster, and is deployed on the public network as a public image warehouse, and can be accessed by each node cluster.
[0102] For further information, see Figure 5 , is a flowchart of a data processing method based on blockchain provided in an embodiment of the present application. Figure 5 As shown, this method can be Figure 1 The method may be performed by a master agent node in the system, wherein the method may at least include the following S101-S103:
[0103] S101. The master agent node obtains a configuration request for a first business node cluster; the configuration request carries the public network access information of the first business agent node in the first business node cluster, and the master agent node belongs to the management node cluster of the blockchain network.
[0104] In this application, when the first service node cluster needs to be added to the blockchain network, the first service proxy node in the first service node cluster can obtain public network access information, which can refer to the access information for accessing the public network of the blockchain network. The public network access information can include the public network address of the first service proxy node and the public network address of the first service proxy node, etc. Further, a configuration request carrying the public network access information of the first service proxy node is generated and sent to the main proxy node in the management node cluster.
[0105] S102. Connect the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, and obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network.
[0106] In this application, the first service node cluster may include one or more service processing nodes. For the convenience of distinction, the service processing nodes belonging to the first service node cluster may be referred to as the first service processing nodes. The main proxy node can verify the legitimacy of the first service proxy node according to the public network access information. If the first service proxy node is not legitimate, it can refuse to connect the first proxy service node to the public network to which the management node cluster belongs. When the first service proxy node is legitimate, the first service proxy node can be connected to the public network to which the management node cluster belongs, and the node description information of the first service processing node in the first service node cluster can be obtained from the first service proxy node through the public network. Here, the node description information of the first service processing node includes at least one of the location information of the first service processing node, the service type to which the service processed by the first service processing node belongs, and the remaining storage space of the first service processing node. By connecting the first service proxy node to the public network to which the management node cluster belongs, communication between the management service node cluster and the first service node cluster can be realized. It is not necessary for each node in the first service node cluster to be connected to the public network, which can effectively avoid the congestion problem of the public network. At the same time, by interacting data between the proxy nodes in the node cluster, it is not necessary for the service processing nodes in the node cluster to directly interact data, which can realize internal data isolation between different node clusters and improve data security.
[0107] It is understandable that the public network access information includes the public network address of the first service proxy node. The verification of the legality of the first service proxy node based on the public network access information includes: obtaining the address length of the public network address of the first service proxy node. If the address length is within the length range, it is determined that the first service proxy node is legal; if the address length is not within the length range, it is determined that the first service proxy node is illegal. Alternatively, verify whether the public network address of the first service proxy node belongs to the authorized address list. The authorized address list includes multiple public network addresses with the permission to connect to the public network. If the public network address of the first service proxy node belongs to the authorized address list, it is determined that the first service proxy node is legal; if the public network address of the first service proxy node does not belong to the authorized address list, it is determined that the first service proxy node is illegal. By verifying the legality of the first service proxy node, illegal nodes can be effectively prevented from connecting to the blockchain network, improving the security of the blockchain network.
[0108] Optionally, the public network access information includes the public network address of the first service proxy node. After the master proxy node executes step S102, the following steps s11 to s14 may be included:
[0109] s11. Obtain the public network mapping table, which is used to reflect the mapping relationship between the proxy nodes in the blockchain network and the public network addresses.
[0110] s12. Update the public network mapping table with the public network address of the first service proxy node to obtain the updated public network mapping table.
[0111] s13. Synchronize the updated public network mapping table to the first service proxy node through the public network.
[0112] s14. Synchronize the public network address of the first service proxy node to the service proxy nodes in the remaining service node cluster in the blockchain network; the remaining service node cluster is the service node cluster other than the first service node cluster in the blockchain network, and the service proxy nodes in the remaining service node cluster perform data transmission with the first service proxy node according to the public network address and the public network.
[0113] In steps s11 to s14, the master proxy node and the service proxy nodes in the remaining service node cluster may both include the public network mapping table, which is used to reflect the mapping relationship between the public network addresses of the proxy nodes in each node cluster and the proxy nodes. For example, Figure 6As shown, from the public network mapping table, the public network address of the main proxy node (i.e., the main node) is the main address, the public network address of service proxy node 1 (i.e., node 1) is address 1, and the public network address of service proxy node 2 (i.e., node 2) is address 2. Assume that the public network address of service proxy node 3 (node 3) is address 3. After service proxy node 3 connects to the public network, the main proxy node can update the public network mapping table with the address 3 of service proxy node 3 to obtain the updated public network mapping table. Further, the main proxy node can synchronize the updated public network mapping table to service proxy node 3 through the public network, and synchronize the address 3 of service proxy node 3 to service proxy node 1 and service proxy node 2. Service proxy node 1 and service proxy node 2 can update the local public network mapping table with the address 3 of service proxy node 3. After each proxy node obtains the updated public network mapping table, it can communicate with each node cluster through the public network mapping table. It should be noted that Figure 6 Service proxy node 1, service proxy node 2, and service proxy node 3 in
[0114] S103. Determine the blockchain configuration information matching the first service node cluster according to the node description information, and send the blockchain configuration information to the first service proxy node through the public network; the first service proxy node synchronizes the blockchain configuration information to the first service processing node through the first private network to which the first service node cluster belongs, and the blockchain configuration information is used to configure the first service processing node as a node in the blockchain network.
[0115] In this application, since the node description information of different service node clusters is inconsistent, the data synchronized from the blockchain network by different service node clusters is inconsistent. Therefore, the main proxy node can determine the blockchain configuration information matching the first service node cluster according to the node description information, and synchronize the blockchain configuration information to the first service proxy node through the public network. Here, the blockchain configuration information may include the mirror file of the blockchain application program and the blocks matching the node description information, etc. After receiving the blockchain configuration information, the first service proxy node can send the blockchain configuration information to the first service processing node of the first service node cluster through the first private network to which the first service node cluster belongs, and configure the first service processing node as a node in the blockchain network according to the blockchain configuration information. By sending the blockchain configuration information from the main proxy node to the first service proxy node, the configuration of the service processing nodes in the first service node cluster can be realized without manual participation, improving the efficiency of configuring the first service node cluster.
[0116] Optionally, the method may include the following steps s21 to s23:
[0117] S21. Obtain the business attribute information of the target business to be processed.
[0118] S22. Determine a second business node cluster matching the business attribute information from the blockchain network according to the business attribute information.
[0119] S23. Send the target business to the second business proxy node of the second business node cluster through the public network; the second business proxy node synchronizes the target business to the second business processing node for processing the target business through the third private network to which the second business node cluster belongs, and the second business processing node belongs to the second business node cluster.
[0120] In steps S21 - S23, the main proxy node can obtain the attribute information of the target business to be processed, and the attribute information of the target business may include the business type of the target business, the processing duration for processing the target business, the timeliness level of the target business, etc. Further, a second business node cluster matching the business attribute information can be determined from the blockchain network according to the business attribute information, that is, the second business node cluster is a node cluster good at processing the target business, or the second business node cluster is a node cluster associated with the target business. Then, the target business can be sent to the second business proxy node of the second business node cluster through the public network, and the second business proxy node synchronizes the target business to the second business processing node for processing the target business through the third private network to which the second business node cluster belongs, and the target business is processed by the second business processing node. The target business can be sent to the second business processing node through the main business proxy node, that is to say, the main business proxy node processes the target business by remotely scheduling the processing nodes in the business node cluster, improving the business processing efficiency. In addition, through the unified scheduling of the main proxy node, the utilization rate of the processing nodes in the business node cluster can be ensured.
[0121] Optionally, the main proxy node cluster can obtain the second business node cluster matching the business attribute information through the cluster relationship tree. Specifically, the above step S22 may include the following steps S31 - S33:
[0122] S31. Obtain the cluster relationship tree of the blockchain network, the parent node of the cluster relationship tree is the management node cluster, and the child nodes of the cluster relationship tree are the business node clusters in the blockchain network.
[0123] S32. Traverse the business node clusters in the cluster relationship tree according to the node paths of the cluster relationship tree.
[0124] S33. Determine a second business node cluster matching the business attribute information of the target business from the cluster relationship tree.
[0125] In steps S31 to S33, the master agent node may include a cluster relationship tree. The parent node of the cluster relationship tree is the management node cluster, and the child nodes of the cluster relationship tree are the service node clusters in the blockchain network. Each service node cluster can be arranged in the child nodes of the cluster relationship tree according to the service processing characteristics of the service node cluster. For example, the service processing characteristics may include the number of times the service node cluster processes services within a historical time period (such as the past week or the past month). That is, the more times the service node cluster corresponds to, the higher the probability that the service node cluster matches the service attribute information of the target service. Therefore, the service node cluster is arranged in the child node that is traversed first. On the contrary, the fewer times the service node cluster corresponds to, the lower the probability that the service node cluster matches the service attribute information of the target service. Therefore, the service node cluster is arranged in the child node that is traversed later. Optionally, the service processing characteristics may include the service importance level of the services processed by the service node cluster (or the security level of the service node cluster). That is, the higher the service importance level of the services processed by the service node cluster, the service node cluster is arranged in the child node that is traversed first, which can reduce the time for traversing the service node clusters and reduce the latency for processing high-importance-level services. On the contrary, the lower the service importance level of the services processed by the service node cluster, the service node cluster is arranged in the child node that is traversed later. The master agent node can obtain the second service node cluster that matches the service attribute information according to the service node relationship tree. Specifically, the master agent node can obtain the cluster relationship tree and traverse the child nodes of the cluster relationship tree according to the node path of the cluster relationship tree. The node path can refer to from left to right and from top to bottom of the cluster relationship tree. Further, the second service node cluster that matches the service attribute information of the target service can be determined from the cluster relationship tree. Determining the second service node cluster that matches the service attribute information through the cluster relationship tree can improve the efficiency of obtaining the second service node cluster, that is, improve the scheduling efficiency of the service node clusters.
[0126] Optionally, the service attribute information includes the service type of the target service; the above step S33 may include the following steps S41 to S44:
[0127] S41. Determine the security level of the target service according to the service type of the target service.
[0128] S42. Obtain the number of times of data anomalies of the service node clusters in the cluster relationship tree within a historical time period.
[0129] S43. Divide the security levels of the service node clusters in the cluster relationship tree according to the number of times.
[0130] S44. Use the business node clusters in the cluster relationship tree whose security level is greater than that of the target service as the second business node clusters that match the attribute information of the target service.
[0131] In steps S41 to S44, the master agent node can determine the security level of the target service according to the service type of the target service. For example, if the service type of the target service is tax settlement service, ID card application service, etc., the security level of the target service is relatively high; if the service type of the target service is web page loading, application update service, etc., the security level of the target service is relatively low. The master agent node can obtain the number of times of data anomalies of the business node clusters in the cluster relationship tree during the historical time period. Data anomalies can refer to situations such as data errors, data loss, data tampering, data leakage, etc. Further, the security levels of the business node clusters in the cluster relationship tree can be divided according to this number; the more the number of times, the lower the security level of the business node cluster, and vice versa, the fewer the number of times, the higher the security level of the business node cluster. Then, the business node clusters in the cluster relationship tree whose security level is greater than that of the target service can be used as the second business node clusters that match the attribute information of the target service. By determining the second business node cluster that matches the business attribute information through the service type of the target service data, it can ensure that the target service is processed safely and effectively.
[0132] Optionally, the service attribute information includes the processing duration for processing the target service; the above step S33 can include the following steps S51 to S53:
[0133] S51. Obtain the service volume corresponding to the business to be processed of the business node clusters in the cluster relationship tree; count the waiting duration according to the service volume corresponding to the business to be processed.
[0134] S52. Use the sum of the waiting duration and the processing duration as the processing delay.
[0135] S53. Use the business node clusters in the cluster relationship tree whose processing delay is less than the delay threshold as the second business node clusters that match the attribute information of the target service.
[0136] In steps S51 - S53, the master proxy node can obtain the traffic volume corresponding to the business to be processed in the business node cluster in the cluster relationship tree, and count the waiting duration according to the traffic volume corresponding to the business to be processed; that is, the more the traffic volume corresponding to the business to be processed, the longer the waiting duration, and the less the traffic volume corresponding to the business to be processed, the shorter the waiting duration. Further, the sum between the waiting duration and the processing duration can be calculated, and the sum between the waiting duration and the processing duration is used as the processing delay. Then, the business node cluster in the cluster relationship tree with a processing delay less than the delay threshold can be used as the second business node cluster that matches the attribute information of the target business; by determining the second business node cluster that matches the business attribute information according to the processing duration of the target business, the processing delay of processing the target business can be effectively reduced, and the efficiency of processing the target business can be improved.
[0137] In this application, first, according to the public network access information of the first business proxy node, the first business proxy node is connected to the public network to which the management node cluster belongs, so that each node in the first business node cluster can communicate with other node clusters through the public network. Then, the master proxy node can obtain the node description information of the first business processing node in the first business node cluster from the first business proxy node through the public network, determine the blockchain configuration information that matches the first business node cluster according to the node description information, and send the blockchain configuration information to the first business proxy node through the public network. By determining the blockchain configuration information that matches the first business node cluster according to the node description information and sending the blockchain configuration information to the first business proxy node, it is beneficial to realize the personalized configuration of the business processing nodes in the first business node cluster without manual participation, and improve the efficiency of configuring the first business node cluster. At the same time, the process of configuring the first business processing node is equivalent to adding a blockchain node to the blockchain network. That is to say, this application can realize the automatic deployment of blockchain nodes and improve the efficiency of deploying blockchain nodes.
[0138] Further, please refer to Figure 7 , which is a schematic flowchart of a data processing method based on blockchain provided by an embodiment of this application. As Figure 7 shown, this method can be executed by the master proxy node in Figure 1 , and at least includes the following S201 - S206:
[0139] S201. The master proxy node obtains a configuration request for the first business node cluster; the configuration request carries the public network access information of the first business proxy node in the first business node cluster, and the master proxy node belongs to the management node cluster of the blockchain network.
[0140] S202. Connect the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, and obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network.
[0141] Optionally, the public network access information includes the public network address of the first service proxy node; in step S202 above, connecting the first service proxy node to the public network to which the management node cluster belongs according to the public network access information includes the following steps s61 - s63:
[0142] s61. Configure an access interface for the first service proxy node to access the public network according to the public network address of the first service proxy node.
[0143] s62. Establish a network connection between the first service proxy node and the main proxy node based on the access interface and the public network address.
[0144] s63. If the network connection between the first service proxy node and the main proxy node is successful, determine that the first service proxy node has been connected to the public network to which the management node cluster belongs.
[0145] In steps s61 - s63, the main proxy node in the management node cluster can configure an access interface for the first service proxy node to access the public network according to the public network address of the first service proxy node. This access interface can refer to the interface provided by the above - mentioned API server; establish a network connection between the first service proxy node and the main proxy node based on this access interface and the public network address. If the network connection between the first service proxy node and the main proxy node fails, an access interface for the first service proxy node to access the public network can be re - configured, or the public address can be obtained from the first service proxy node. If the network connection between the first service proxy node and the main proxy node is successful, determine that the first service proxy node has been connected to the public network to which the management node cluster belongs. By connecting the first service proxy node to the public network, private cross - domain interconnection of blockchain nodes can be achieved; in addition, the steps of connecting the first service proxy node to the public network are all executed by the main proxy node in the management node cluster, which can achieve centralized and unified management of blockchain nodes.
[0146] S203. Determine the target block associated with the node description information from the blockchain in the blockchain network.
[0147] In this application, the primary proxy node can synchronize all blocks on the blockchain in the blockchain network to the business processing nodes in each node cluster, or synchronize some of the blocks on the blockchain in the blockchain network to the business processing nodes in each node cluster. When the primary proxy node synchronizes some of the blocks on the blockchain in the blockchain network to the business processing nodes in each node cluster, it can determine the target blocks associated with the node description information from the blockchain in the blockchain network, so as to synchronize the target blocks to the first business processing node in the first business node cluster, which can save the storage space of the first business processing node.
[0148] It can be understood that when the primary proxy node synchronizes some of the blocks on the blockchain in the blockchain network to the business processing nodes in each node cluster, in order to ensure that the data in each node cluster is stored in the form of a blockchain, the primary proxy node can synchronize all the block headers on the blockchain of the blockchain network to the first business processing node, and synchronize the block body of the target block associated with the node description information on the blockchain in the blockchain network to the first business processing node, that is, it is not necessary to synchronize the block bodies corresponding to the blocks not associated with the node description information on the blockchain in the blockchain network to the first business processing node, which can save the storage space of the first business processing node.
[0149] Optionally, the node description information includes the business type to which the business processed by the first business processing node belongs; step S203 may include the following steps s71 to s72:
[0150] s71. Identify the institution to which the business processing node belongs according to the business type to which the business processed by the first business processing node belongs.
[0151] s72. Read the blocks associated with the institution to which the first business processing node belongs from the blockchain in the blockchain network as the target blocks.
[0152] In steps s71 to s72, for example, if the business type to which the business processed by the first business processing node belongs is a tax business, then the institution to which the first business processing node belongs is the tax bureau, and the blocks belonging to the tax bureau can be read from the blockchain in the blockchain network as the target blocks. For another example, if the business type to which the business processed by the first business processing node belongs is a marriage business, then the institution to which the first business processing node belongs is the civil affairs bureau, and the blocks belonging to the civil affairs bureau can be read from the blockchain in the blockchain network as the target blocks.
[0153] Optionally, the node description information includes the remaining storage capacity of the business processing node; step S203 may include the following steps s81 to s82:
[0154] S81. Obtain the generation time of the blocks on the blockchain in the blockchain network.
[0155] S82. Read one or more target blocks from the blockchain in the blockchain network according to the generation time; the total amount of data in the one or more target blocks is less than the remaining storage capacity of the first service processing node.
[0156] In steps S81 - S82, the master proxy node can obtain the generation time of the blocks on the blockchain in the blockchain network. The greater the time interval between the generation time of the block and the current time, the higher the probability that the data in the block becomes invalid; conversely, the smaller the time interval between the generation time of the block and the current time, the lower the probability that the data in the block becomes invalid. Therefore, the master proxy node can read one or more target blocks from the blockchain in the blockchain network according to the generation time, that is, read one or more target blocks whose generation time is within a time period (such as the recent week, the recent month) from the blockchain in the blockchain network, and the total amount of data in the one or more target blocks is less than the remaining storage capacity of the first service processing node. By obtaining the target blocks synchronized to the first service processing node according to the generation time of the blocks, it is possible to avoid the invalidation of the data synchronized to the first service processing node and improve the utilization rate of the first service processing node.
[0157] S204. Obtain the mirror file of the blockchain application program from the database node of the management node cluster through the second private network belonging to the management node cluster.
[0158] S205. Determine the target block and the mirror file as the blockchain configuration information matching the first service node cluster; the mirror file is used to generate a blockchain node container in the first service processing node, and the target block is used to generate a blockchain belonging to the first service node cluster in the blockchain node container.
[0159] In steps S204 - S205, the master proxy node can obtain the mirror file of the blockchain application program from the database node of the management node cluster through the second private network of the management node cluster. The mirror file includes the application program for generating the blockchain; further, determine the target block and the mirror file as the blockchain configuration information matching the first service node cluster. By the master proxy node obtaining the mirror file and the target block, it is beneficial to configure the first service processing nodes in the first service node cluster as blockchain nodes.
[0160] S206. Send the blockchain configuration information to the first service proxy node through the public network.
[0161] Optionally, step S206 may include the following steps S91 - S95:
[0162] S91. Encrypt the blockchain configuration information using the public key of the first service processing node to obtain encrypted data.
[0163] S92. Sign the encrypted data using the private key of the main proxy node to obtain encrypted data carrying the signature information of the main proxy node.
[0164] S93. Enclose the encrypted data carrying the signature information of the main proxy node in the data body of the data packet.
[0165] S94. Enclose the public network address of the first service proxy node in the packet header of the data packet.
[0166] S95. Send, through the public network, the data packet carrying the encrypted data with the signature information of the main proxy node and the public network address of the first service proxy node to the first service proxy node.
[0167] In steps S91 - S95, the main proxy node can obtain the public key of the first service proxy node. The public key of the first service proxy node can be reported by the first service proxy node to the main proxy node through the public network. Encrypt the blockchain configuration information using the public key of the first service proxy node to obtain encrypted data. Then, sign the encrypted data using the private key of the main proxy node to obtain encrypted data carrying the signature information of the main proxy node. Encrypting the blockchain configuration information can avoid information leakage and improve information security. At the same time, signing the encrypted data using the private key of the main proxy node can improve the credibility of the blockchain configuration information.
[0168] Furthermore, enclose the encrypted data carrying the signature information of the main proxy node in the data body of the data packet, enclose the public network address of the first service proxy node in the packet header of the data packet, and send, through the public network, the data packet carrying the encrypted data with the signature information of the main proxy node and the public network address of the first service proxy node to the first service proxy node. By adding the public network address of the first service proxy node to the packet header of the data packet, the forwarding of the data packet can be completed based on the packet header. That is to say, before the data packet is forwarded to the first service processing node, it is not necessary to decrypt the data in the data body of the data packet, which can improve the forwarding efficiency of the data packet and the security of data packet forwarding.
[0169] In this application, first, according to the public network access information of the first service proxy node, the first service proxy node is connected to the public network to which the management node cluster belongs, so that each node in the first service node cluster can communicate with other node clusters through the public network. Then, the main proxy node can obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network, determine the target block associated with the node description information from the blockchain in the blockchain network, and obtain the mirror file of the blockchain application program from the database node of the management node cluster through the second private network to which the management node cluster belongs. Further, the target block and the mirror file are determined as the blockchain configuration information matching the first service node cluster, and the blockchain configuration information is sent to the first service proxy node through the public network. By synchronizing the target block and the mirror file associated with the node description information to the first service processing node, it is beneficial to realize the personalized configuration of the service processing nodes in the first service node cluster, without manual participation, improving the efficiency of configuring the first service node cluster; nor is it necessary to synchronize all the blocks on the blockchain in the blockchain network to the first service processing node, which can save the storage space of the first service processing node. At the same time, the process of configuring the first service processing node is equivalent to adding a blockchain node to the blockchain network. That is to say, this application can realize the automatic deployment of blockchain nodes and improve the efficiency of deploying blockchain nodes.
[0170] In the embodiment of this application, taking the management node cluster as the BaaS cluster as an example, the data processing method based on the blockchain in this application is described. The goal of this application is that the administrator can automatically deploy and manage blockchain nodes in any region (private environment) through the console interface of the BaaS cluster. The BaaS cluster, as a centralized management platform, can be pre-deployed on the main node, and the service node clusters in each region can be deployed according to the application requirements of customers. After the service node cluster in a certain region is deployed to the blockchain network, the main proxy node of the BaaS cluster can schedule the blockchain nodes in that region. The flow of the data processing method based on the blockchain in this application is as Figure 8 shown, and the method may include the following steps 1-4:
[0171] (1) Environment Deployment. Deploy the cross - domain control service in the business proxy nodes of the business node cluster in the target region. The cross - domain control service is not limited to a single component and can be a local control service composed of multiple microservices, aiming to provide the BaaS service capabilities for the local private environment. These component functions include a - d: a. Initialization service: Collect the access authentication information of each node in the business node cluster so that the automatic deployment service of the BaaS cluster can pull the k8s api configuration to prepare for deploying blockchain nodes by calling the k8s api (i.e., the access interface of the business node cluster, which is the public network interface). Here, the access authentication information can include the node description of the business processing nodes in the business node cluster. b. Api interface (i.e., local interface): Provide an interface for accessing the blockchain network for the local private environment to dock with local blockchain applications. c. Console service: Provide a graphical interface to facilitate users to view and manage the blockchain network and local blockchain nodes. d. Monitoring service: Monitor the running information of the blockchain network and nodes, such as node health status, node traffic, etc.
[0172] (2) Node Deployment. The main proxy node receives a configuration request for the business processing nodes in the business node cluster. After receiving the configuration request, it triggers the automatic deployment process as shown in Figure 9 The automatic deployment process includes the following steps s1 - s3: s1. The automatic deployment component in the main proxy node obtains the API server configuration of the business proxy node, that is, obtains the access interface of the business proxy node according to the public network address of the business proxy node, and connects the business proxy node to the public network to which the management node cluster belongs based on this access interface and the public network address of the business proxy node. s2. The automatic deployment component in the main proxy node creates the mirror file of the blockchain application program and the target block, that is, obtains the mirror file of the blockchain application program from the database node in the management node cluster, and obtains the target block that matches the node description information of the business processing node from the blockchain in the blockchain network. Further, send the target block and the mirror file to the business proxy node, and the business proxy node synchronizes the target block and the mirror file to the business processing nodes in the business node cluster. The business processing nodes generate blockchain node containers according to the mirror file and add the target block to the blockchain node containers. s3. Create cross - domain configuration, that is, send traffic forwarding rules to the cross - domain proxy component of the business proxy node. The traffic forwarding rules can include a public network mapping table and the size of the traffic forwarded each time, etc.
[0173] It should be noted that to ensure the effectiveness of each business node cluster, each business node cluster may include multiple business processing nodes, and each business proxy node has the same traffic forwarding rule, which is obtained from the main proxy node. To ensure the synchronization of the traffic forwarding rules in each business proxy node, each business proxy node can monitor the traffic forwarding rules in the main proxy node. When it is detected that the traffic forwarding rules are updated, each business proxy node synchronizes the updated traffic forwarding rules to improve the effectiveness of the traffic forwarding rules.
[0174] (3) Node communication. The business proxy node loads the cross-domain configuration and forwards the traffic of the blockchain node to the business proxy node in other business node clusters or the local blockchain node according to the traffic forwarding rule. As Figure 10 shown, Figure 10 taking the example of the business processing node 1 in business node cluster 1 sending data to the business processing node 3 in business node cluster 2, the cross-domain traffic forwarding process is described. As Figure 10 shown, business node cluster 1 includes business processing node 1, business processing node 2, and business proxy node A, and business node cluster 2 includes business processing node 3, business processing node 4, and business proxy node B. The remote node domain names of business processing node 3 and business processing node 4 are domain name 3 and domain name 4 respectively. The remote node domain name can refer to the node identifier of the business processing node. When a node in business node cluster 1 needs to forward traffic to a node in business node cluster 2, business proxy node A can map the remote node domain name belonging to business node cluster 2 to the local area to generate routing information. As Figure 10 shown, there is a mapping relationship between domain name 3, domain name 4 and business proxy node B respectively, indicating that when any node in business node cluster 1 needs to forward traffic to business processing node 3 or business processing node 4 in business node cluster 2, the traffic needs to be forwarded through business proxy node B. At the same time, business proxy node B needs to map the domain name of the local business processing node to the local area to generate routing information. As Figure 10 shown, there is a mapping relationship between domain name 3 and business processing node 3, indicating that the domain name of business processing node 3 is domain name 3, and there is a mapping relationship between domain name 4 and business processing node 4, indicating that the domain name of business processing node 4 is domain name 4.
[0175] Further, when the service processing node 1 needs to send target data to the service processing node 3, the service processing node 1 can send the target data to the service proxy node A through the private network of the service node cluster 1. The target data may carry the domain name 3, and the domain name 3 carried by the target data is used to indicate that the target data is to be sent to the service processing node 3. The service proxy node A can query the routing information corresponding to the domain name 3 locally. At this time, the routing information corresponding to the domain name 3 indicates that the target data is to be forwarded to the service proxy node B. Therefore, the service proxy node A can send the target data carrying the domain name 3 to the service proxy node B through the public network between the service node cluster 1 and the service node cluster 2. The service proxy node B can query the routing information corresponding to the domain name 3 locally. At this time, the routing information corresponding to the domain name 3 indicates that the target data is to be forwarded to the service processing node 3. Therefore, the service proxy node B can send the target data to the service processing node 3 through the private network of the service node cluster 2.
[0176] (4) Node control. Locally obtain data on the blockchain through cross-domain, and manage and maintain the blockchain network and local nodes, such as updating the version of the blockchain application program, controlling the life cycle of blockchain nodes, and so on.
[0177] In summary, through the public network access information of the service proxy node, the service proxy node is connected to the public network to which the management node cluster belongs, so that each node in the service node cluster can communicate with other node clusters through the public network. Then, the main proxy node can obtain the node description information of the service processing nodes in the service node cluster from the service proxy node through the public network, determine the blockchain configuration information matching the service node cluster according to the node description information, and send the blockchain configuration information to the service proxy node through the public network. By determining the blockchain configuration information matching the service node cluster according to the node description information and sending the blockchain configuration information to the service proxy node, it is beneficial to realize the personalized configuration of the service processing nodes in the service node cluster, without the need for manual participation, and improve the efficiency of configuring the service node cluster. At the same time, the process of configuring the service processing node is equivalent to adding a blockchain node to the blockchain network. That is to say, the present application can realize the automatic deployment of blockchain nodes and improve the efficiency of deploying blockchain nodes.
[0178] Please refer to Figure 11 , which is a schematic structural diagram of a blockchain-based data processing device 1 provided by an embodiment of the present application. The above-mentioned blockchain-based data processing device 1 may be a computer program (including program code) running in a computer device. For example, the blockchain-based data processing device 1 is an application software; the device may be used to execute the corresponding steps in the method provided by the embodiment of the present application. Such as Figure 11As shown in the figure, the blockchain-based data processing device 1 may include: an acquisition module 801, a connection module 802, a determination module 803, and an update module 804.
[0179] The acquisition module is used to acquire a configuration request for the first service node cluster; the configuration request carries the public network access information of the first service proxy node in the first service node cluster, and the main proxy node belongs to the management node cluster of the blockchain network;
[0180] The connection module is used to connect the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, and obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network;
[0181] The determination module is used to determine the blockchain configuration information matching the first service node cluster according to the node description information, and send the blockchain configuration information to the first service proxy node through the public network; the first service proxy node synchronizes the blockchain configuration information to the first service processing node through the first private network to which the first service node cluster belongs, and the blockchain configuration information is used to configure the first service processing node as a node in the blockchain network.
[0182] Optionally, the determination module determines the blockchain configuration information matching the first service node cluster according to the node description information, including:
[0183] Determine a target block associated with the node description information from the blockchain in the blockchain network;
[0184] Obtain the mirror file of the blockchain application program from the database node of the management node cluster through the second private network to which the management node cluster belongs;
[0185] Determine the target block and the mirror file as the blockchain configuration information matching the first service node cluster; the mirror file is used to generate a blockchain node container in the first service processing node, and the target block is used to generate a blockchain belonging to the first service node cluster in the blockchain node container.
[0186] Optionally, the node description information includes the service type to which the service processed by the first service processing node belongs; the determination module determines a target block associated with the node description information from the blockchain in the blockchain network, including:
[0187] Identify the institution to which the service processing node belongs according to the service type to which the service processed by the first service processing node belongs;
[0188] Read a block associated with the institution to which the first service processing node belongs from the blockchain in the blockchain network as a target block.
[0189] Optionally, the node description information includes the remaining storage capacity of the service processing node; the determining module determines a target block associated with the node description information from the blockchain in the blockchain network, including:
[0190] Obtain the generation time of the blocks on the blockchain in the blockchain network;
[0191] Read one or more target blocks from the blockchain in the blockchain network according to the generation time; the total amount of data in the one or more target blocks is less than the remaining storage capacity of the first service processing node.
[0192] Optionally, the public network access information includes the public network address of the first service proxy node; the connection module connects the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, including:
[0193] Configure an access interface for the first service proxy node to access the public network according to the public network address of the first service proxy node;
[0194] Establish a network connection between the first service proxy node and the main proxy node based on the access interface and the public network address;
[0195] If the network connection between the first service proxy node and the main proxy node is successful, it is determined that the first service proxy node has been connected to the public network to which the management node cluster belongs.
[0196] Optionally, the determining module sends the blockchain configuration information to the first service proxy node through the public network, including:
[0197] Encrypt the blockchain configuration information with the public key of the first service processing node to obtain encrypted data;
[0198] Sign the encrypted data with the private key of the main proxy node to obtain encrypted data carrying the signature information of the main proxy node;
[0199] Encapsulate the encrypted data carrying the signature information of the main proxy node into the data body of the data packet;
[0200] Encapsulate the public network address of the first service proxy node into the packet header of the data packet;
[0201] Send, through the public network, the encrypted data carrying the signature information of the main proxy node and the data packet of the public network address of the first service proxy node to the first service proxy node.
[0202] Optionally, the device further includes:
[0203] An update module, configured to obtain a public network mapping table, where the public network mapping table is used to reflect the mapping relationship between proxy nodes in the blockchain network and public network addresses;
[0204] Update the public network mapping table with the public network address of the first service proxy node to obtain an updated public network mapping table;
[0205] Synchronize the updated public network mapping table to the first service proxy node through the public network;
[0206] Synchronize the public network address of the first service proxy node to service proxy nodes in the remaining service node clusters in the blockchain network; the remaining service node clusters are service node clusters in the blockchain network other than the first service node cluster, and service proxy nodes in the remaining service node clusters perform data transmission with the first service proxy node according to the public network address and the public network.
[0207] Optionally, the determination module is further configured to:
[0208] Obtain service attribute information of a target service to be processed;
[0209] Determine a second service node cluster matching the service attribute information from the blockchain network according to the service attribute information;
[0210] Send the target service to a second service proxy node of the second service node cluster through the public network; the second service proxy node synchronizes the target service to a second service processing node for processing the target service through a third private network to which the second service node cluster belongs, and the second service processing node belongs to the second service node cluster.
[0211] Optionally, when the determination module determines a second service node cluster matching the service attribute information from the blockchain network according to the service attribute information, it includes:
[0212] Obtain a cluster relationship tree of the blockchain network, where the parent node of the cluster relationship tree is the management node cluster, and the child nodes of the cluster relationship tree are service node clusters in the blockchain network;
[0213] Traverse service node clusters in the cluster relationship tree according to the node path of the cluster relationship tree;
[0214] Determine a second business node cluster that matches the service attribute information of the target service from the cluster relationship tree.
[0215] Optionally, the service attribute information includes the service type of the target service; the determining module determines a second business node cluster that matches the service attribute information of the target service from the cluster relationship tree, including:
[0216] Determine the security level of the target service according to the service type of the target service;
[0217] Obtain the number of times of data anomalies occurred in the business node clusters in the cluster relationship tree during the historical time period;
[0218] Divide the security levels of the business node clusters in the cluster relationship tree according to the number of times;
[0219] Use the business node clusters in the cluster relationship tree whose security level is higher than that of the target service as the second business node clusters that match the attribute information of the target service.
[0220] Optionally, the service attribute information includes the processing duration for processing the target service; the determining to determine a second business node cluster that matches the service attribute information of the target service from the cluster relationship tree includes:
[0221] Obtain the service volume corresponding to the business to be processed in the business node clusters in the cluster relationship tree; count the waiting duration according to the service volume corresponding to the business to be processed;
[0222] Use the sum between the waiting duration and the processing duration as the processing delay;
[0223] Use the business node clusters in the cluster relationship tree with a processing delay less than the delay threshold as the second business node clusters that match the attribute information of the target service.
[0224] According to an embodiment of the present application, Figure 5 The steps involved in the data processing method based on blockchain shown can be Figure 11 executed by each module in the data processing device based on blockchain shown. For example, Figure 5 The step S101 shown in can be Figure 11 executed by the obtaining module 801 in Figure 5 The step S102 shown in can be Figure 11 executed by the connection module 802 in; Figure 5 The step S103 shown in can be Figure 11 executed by the determining module 803 in.
[0225] Similarly, according to an embodiment of the present application, Figure 7 the steps involved in the blockchain-based data processing method shown can be performed by Figure 11 each module in the blockchain-based data processing device shown. For example, Figure 7 the step S201 shown in Figure 11 can be performed by the obtaining module 801 in Figure 7 the step S202 shown in Figure 11 can be performed by the connection module 802 in Figure 7 the steps S203 - S206 shown in Figure 11 can be performed by the determination module 803 in
[0226] According to an embodiment of the present application, Figure 11 each module in the blockchain-based data processing device shown can be separately or all combined into one or several units to form, or a certain one (or some) of the units can be further split into multiple smaller sub-units in terms of function, and the same operations can be achieved without affecting the realization of the technical effects of the embodiments of the present application. The above modules are divided based on logical functions. In practical applications, the function of one module can also be realized by multiple units, or the functions of multiple modules can be realized by one unit. In other embodiments of the present application, the blockchain-based data processing device can also include other units. In practical applications, these functions can also be assisted by other units and can be realized by the cooperation of multiple units.
[0227] According to an embodiment of the present application, it can be achieved by running a computer program (including program code) capable of executing the respective steps involved in the corresponding method shown in Figure 5 on a general computer device such as a computer including processing elements and storage elements such as a central processing unit (CPU), a random access storage medium (RAM), and a read-only storage medium (ROM), to construct the blockchain-based data processing device shown in Figure 11 and to implement the blockchain-based data processing method of the embodiments of the present application. The above computer program can be recorded on, for example, a computer-readable recording medium, and be loaded into the above computing device through the computer-readable recording medium and run therein.
[0228] In this application, first, according to the public network access information of the first service proxy node, the first service proxy node is connected to the public network to which the management node cluster belongs, so that each node in the first service node cluster can communicate with other node clusters through the public network. Then, the main proxy node can obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network, determine the blockchain configuration information matching the first service node cluster according to the node description information, and send the blockchain configuration information to the first service proxy node through the public network. By determining the blockchain configuration information matching the first service node cluster according to the node description information and sending the blockchain configuration information to the first service proxy node, it is beneficial to realize the personalized configuration of the service processing nodes in the first service node cluster, without the need for manual participation, and improve the efficiency of configuring the first service node cluster. At the same time, the process of configuring the first service processing node is equivalent to adding a blockchain node to the blockchain network. That is to say, this application can realize the automatic deployment of blockchain nodes and improve the efficiency of deploying blockchain nodes.
[0229] Please refer to Figure 12 , which is a schematic structural diagram of a computer device provided by an embodiment of this application. As Figure 12 shown, the above computer device 1000 may include: a processor 1001, a network interface 1004, and a memory 1005. In addition, the above computer device 1000 may further include: a user interface 1003 and at least one communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. Among them, the user interface 1003 may include a display screen (Display) and a keyboard (Keyboard). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. Optionally, the memory 1005 may further be at least one storage device located far from the aforementioned processor 1001. As Figure 12 shown, the memory 1005, as a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a device control application program.
[0230] In Figure 12 the computer device 1000 shown, the network interface 1004 can provide network communication functions; while the user interface 1003 is mainly used to provide an input interface for users; and the processor 1001 can be used to call the device control application program stored in the memory 1005 to implement:
[0231] Obtain a configuration request for the first business node cluster; the configuration request carries the public network access information of the first business proxy node in the first business node cluster, and the main proxy node belongs to the management node cluster of the blockchain network;
[0232] Connect the first business proxy node to the public network to which the management node cluster belongs according to the public network access information, and obtain the node description information of the first business processing node in the first business node cluster from the first business proxy node through the public network;
[0233] Determine the blockchain configuration information matching the first business node cluster according to the node description information, and send the blockchain configuration information to the first business proxy node through the public network; the first business proxy node synchronizes the blockchain configuration information to the first business processing node through the first private network to which the first business node cluster belongs, and the blockchain configuration information is used to configure the first business processing node as a node in the blockchain network.
[0234] Optionally, the processor 1001 may be used to call the device control application program stored in the memory 1005 to implement determining the blockchain configuration information matching the first business node cluster according to the node description information, including:
[0235] Determine a target block associated with the node description information from the blockchain in the blockchain network;
[0236] Obtain the mirror file of the blockchain application program from the database node of the management node cluster through the second private network to which the management node cluster belongs;
[0237] Determine the target block and the mirror file as the blockchain configuration information matching the first business node cluster; the mirror file is used to generate a blockchain node container in the first business processing node, and the target block is used to generate a blockchain belonging to the first business node cluster in the blockchain node container.
[0238] Optionally, the node description information includes the business type to which the business processed by the first business processing node belongs; the processor 1001 may be used to call the device control application program stored in the memory 1005 to implement determining a target block associated with the node description information from the blockchain in the blockchain network, including:
[0239] Identify the institution to which the business processing node belongs according to the business type to which the business processed by the first business processing node belongs;
[0240] Read the block associated with the institution to which the first service processing node belongs from the blockchain in the blockchain network as the target block.
[0241] Optionally, the node description information includes the remaining storage capacity of the service processing node; optionally, the processor 1001 may be used to call the device control application program stored in the memory 1005 to determine the target block associated with the node description information from the blockchain in the blockchain network, including:
[0242] Obtain the generation time of the block on the blockchain in the blockchain network;
[0243] Read one or more target blocks from the blockchain in the blockchain network according to the generation time; the total amount of data in the one or more target blocks is less than the remaining storage capacity of the first service processing node.
[0244] Optionally, the public network access information includes the public network address of the first service proxy node; the processor 1001 may be used to call the device control application program stored in the memory 1005 to connect the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, including:
[0245] Configure an access interface for the first service proxy node to access the public network according to the public network address of the first service proxy node;
[0246] Establish a network connection between the first service proxy node and the main proxy node based on the access interface and the public network address;
[0247] If the network connection between the first service proxy node and the main proxy node is successful, it is determined that the first service proxy node has been connected to the public network to which the management node cluster belongs.
[0248] Optionally, the processor 1001 may be used to call the device control application program stored in the memory 1005 to send the blockchain configuration information to the first service proxy node through the public network, including:
[0249] Encrypt the blockchain configuration information with the public key of the first service processing node to obtain encrypted data;
[0250] Sign the encrypted data with the private key of the main proxy node to obtain the encrypted data carrying the signature information of the main proxy node;
[0251] Encapsulate the encrypted data carrying the signature information of the main proxy node into the data body of the data packet;
[0252] Encapsulate the public network address of the first service proxy node into the message header of the data message;
[0253] Send, through the public network, the encrypted data carrying the signature information of the master proxy node and the data message with the public network address of the first service proxy node to the first service proxy node.
[0254] Optionally, the processor 1001 may be used to call the device control application program stored in the memory 1005 to obtain a public network mapping table, where the public network mapping table is used to reflect the mapping relationship between the proxy nodes in the blockchain network and the public network addresses;
[0255] Update the public network mapping table with the public network address of the first service proxy node to obtain an updated public network mapping table;
[0256] Synchronize the updated public network mapping table to the first service proxy node through the public network;
[0257] Synchronize the public network address of the first service proxy node to the service proxy nodes in the remaining service node clusters in the blockchain network; the remaining service node clusters are the service node clusters in the blockchain network other than the first service node cluster, and the service proxy nodes in the remaining service node clusters perform data transmission with the first service proxy node according to the public network address and the public network.
[0258] Optionally, the processor 1001 may be used to call the device control application program stored in the memory 1005 to obtain the service attribute information of the target service to be processed;
[0259] Determine, from the blockchain network, a second service node cluster that matches the service attribute information according to the service attribute information;
[0260] Send the target service to the second service proxy node of the second service node cluster through the public network; the second service proxy node synchronizes the target service to the second service processing node for processing the target service through the third private network to which the second service node cluster belongs, and the second service processing node belongs to the second service node cluster.
[0261] Optionally, the processor 1001 may be used to call the device control application program stored in the memory 1005 to determine, from the blockchain network, a second service node cluster that matches the service attribute information according to the service attribute information, including:
[0262] Obtain the cluster relationship tree of the blockchain network, where the parent node of the cluster relationship tree is the management node cluster, and the child nodes of the cluster relationship tree are the business node clusters in the blockchain network;
[0263] Traverse the business node clusters in the cluster relationship tree according to the node paths of the cluster relationship tree;
[0264] Determine a second business node cluster that matches the business attribute information of the target business from the cluster relationship tree.
[0265] Optionally, the business attribute information includes the business type of the target business; the processor 1001 can be used to call the device control application program stored in the memory 1005 to implement determining a second business node cluster that matches the business attribute information of the target business from the cluster relationship tree, including:
[0266] Determine the security level of the target business according to the business type of the target business;
[0267] Obtain the number of times of data anomalies occurred in the business node clusters in the cluster relationship tree during the historical time period;
[0268] Divide the security levels of the business node clusters in the cluster relationship tree according to the number of times;
[0269] Use the business node clusters in the cluster relationship tree whose security levels are higher than the security level of the target business as the second business node clusters that match the attribute information of the target business.
[0270] Optionally, the business attribute information includes the processing duration for processing the target business; the processor 1001 can be used to call the device control application program stored in the memory 1005 to implement determining a second business node cluster that matches the business attribute information of the target business from the cluster relationship tree, including:
[0271] Obtain the business volume corresponding to the business to be processed of the business node clusters in the cluster relationship tree; count the waiting duration according to the business volume corresponding to the business to be processed;
[0272] Use the sum of the waiting duration and the processing duration as the processing delay;
[0273] Use the business node clusters in the cluster relationship tree with a processing delay less than the delay threshold as the second business node clusters that match the attribute information of the target business.
[0274] In this application, first, according to the public network access information of the first service proxy node, the first service proxy node is connected to the public network to which the management node cluster belongs, so that each node in the first service node cluster can communicate with other node clusters through the public network. Then, the main proxy node can obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network, determine the blockchain configuration information matching the first service node cluster according to the node description information, and send the blockchain configuration information to the first service proxy node through the public network. By determining the blockchain configuration information matching the first service node cluster according to the node description information and sending the blockchain configuration information to the first service proxy node, it is beneficial to realize the personalized configuration of the service processing nodes in the first service node cluster, without manual participation, and improve the efficiency of configuring the first service node cluster. At the same time, the process of configuring the first service processing node is equivalent to adding a blockchain node to the blockchain network. That is to say, this application can realize the automatic deployment of blockchain nodes and improve the efficiency of deploying blockchain nodes.
[0275] It should be understood that the computer device 1000 described in the embodiments of this application can execute the foregoing Figure 5 and the foregoing Figure 7 description of the above-mentioned blockchain-based data processing method in the corresponding embodiments, and can also execute the foregoing Figure 11 description of the above-mentioned blockchain-based data processing device in the corresponding embodiments, which will not be elaborated here. In addition, the description of the beneficial effects of adopting the same method will not be elaborated either.
[0276] In addition, it should be pointed out here that: the embodiments of this application also provide a computer-readable storage medium, and the above-mentioned computer-readable storage medium stores the computer program executed by the above-mentioned blockchain-based data processing device, and the above-mentioned computer program includes program instructions. When the above-mentioned processor executes the above-mentioned program instructions, it can execute the foregoing Figure 5 and Figure 7 description of the above-mentioned blockchain-based data processing method in the corresponding embodiments. Therefore, it will not be elaborated here. In addition, the description of the beneficial effects of adopting the same method will not be elaborated either. For the technical details not disclosed in the embodiments of the computer-readable storage medium involved in this application, please refer to the description of the method embodiments of this application.
[0277] As an example, the above-mentioned program instructions can be deployed to be executed on a computer device, or deployed to be executed on multiple computer devices located at one place. Or, they can be executed on multiple computer devices distributed at multiple locations and interconnected through a communication network. The multiple computer devices distributed at multiple locations and interconnected through a communication network can form a blockchain network.
[0278] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The above program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above various methods. Among them, the above storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0279] The above-disclosed are only the preferred embodiments of the present application. Of course, the scope of rights of the present application cannot be limited thereby. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.
Claims
1. A data processing method based on blockchain, characterized in that, Including: The main proxy node obtains a configuration request for the first service node cluster; The configuration request carries the public network access information of the first service proxy node in the first service node cluster, and the main proxy node belongs to the management node cluster of the blockchain network; Connect the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, and obtain the node description information of the first service processing node in the first service node cluster from the first service proxy node through the public network; Determine the target block associated with the node description information from the blockchain in the blockchain network, and read the block headers of all blocks on the blockchain; obtain the mirror file of the blockchain application program from the database node of the management node cluster through the second private network to which the management node cluster belongs; Determine the target block and the mirror file as the blockchain configuration information matching the first service node cluster; The mirror file is used to generate a blockchain node container in the first service processing node, and the target block and the block headers of all blocks are used to generate a blockchain belonging to the first service node cluster in the blockchain node container. Send the blockchain configuration information and all block headers to the first service proxy node through the public network; the first service proxy node synchronizes the blockchain configuration information and all block headers to the first service processing node through the first private network to which the first service node cluster belongs.
2. The method according to claim 1, wherein The node description information includes the service type to which the service processed by the first service processing node belongs; The determining the target block associated with the node description information from the blockchain in the blockchain network includes: Identify the organization to which the service processing node belongs according to the service type to which the service processed by the first service processing node belongs; Read the block associated with the organization to which the first service processing node belongs from the blockchain in the blockchain network as the target block.
3. The method according to claim 1, characterized in that, The node description information includes the remaining storage capacity of the service processing node; The determining the target block associated with the node description information from the blockchain in the blockchain network includes: Obtain the generation time of the blocks on the blockchain in the blockchain network; Read one or more target blocks from the blockchain in the blockchain network according to the generation time; the total amount of data in the one or more target blocks is less than the remaining storage capacity of the first service processing node.
4. The method according to claim 1, wherein The public network access information includes the public network address of the first service proxy node; The connecting the first service proxy node to the public network to which the management node cluster belongs according to the public network access information includes: Configure an access interface for the first service proxy node to access the public network according to the public network address of the first service proxy node; Establish a network connection between the first service proxy node and the main proxy node based on the access interface and the public network address. If the network connection between the first service proxy node and the master proxy node is successful, it is determined that the first service proxy node is connected to the public network to which the management node cluster belongs.
5. The method according to claim 4, characterized in that, The step of sending the blockchain configuration information and the block headers of all blocks to the first service proxy node through the public network includes: encrypting the blockchain configuration information with the public key of the first service processing node to obtain encrypted data; signing the encrypted data with the private key of the master proxy node to obtain encrypted data carrying the signature information of the master proxy node; encapsulating the encrypted data carrying the signature information of the master proxy node into the data body of the data packet; encapsulating the public network address of the first service proxy node into the packet header of the data packet; sending, through the public network, the encrypted data carrying the signature information of the master proxy node, the data packet with the public network address of the first service proxy node, and the block headers of all blocks to the first service proxy node.
6. The method according to claim 4, wherein The method further includes: obtaining a public network mapping table, which is used to reflect the mapping relationship between the proxy nodes in the blockchain network and the public network addresses; updating the public network mapping table with the public network address of the first service proxy node to obtain an updated public network mapping table; synchronizing the updated public network mapping table to the first service proxy node through the public network; synchronizing the public network address of the first service proxy node to the service proxy nodes in the remaining service node clusters in the blockchain network; the remaining service node clusters are the service node clusters in the blockchain network other than the first service node cluster, and the service proxy nodes in the remaining service node clusters perform data transmission with the first service proxy node according to the public network address and the public network.
7. The method according to claim 1, wherein The method further includes: obtaining the service attribute information of the target service to be processed; determining, from the blockchain network, a second service node cluster that matches the service attribute information according to the service attribute information; sending the target service to the second service proxy node of the second service node cluster through the public network; the second service proxy node synchronizes the target service to the second service processing node for processing the target service through the third private network to which the second service node cluster belongs, and the second service processing node belongs to the second service node cluster.
8. The method according to claim 7, characterized in that, The step of determining, from the blockchain network, a second service node cluster that matches the service attribute information according to the service attribute information includes: obtaining the cluster relationship tree of the blockchain network, where the parent node of the cluster relationship tree is the management node cluster, and the child nodes of the cluster relationship tree are the service node clusters in the blockchain network; traversing the service node clusters in the cluster relationship tree according to the node path of the cluster relationship tree; determining, from the cluster relationship tree, a second service node cluster that matches the service attribute information of the target service.
9. The method according to claim 8, wherein The service attribute information includes the service type of the target service; determining, from the cluster relationship tree, a second service node cluster that matches the service attribute information of the target service includes: Determining the security level of the target service according to the service type of the target service; Obtaining the number of times of data anomalies that occurred in the service node clusters in the cluster relationship tree during a historical time period; Dividing the security levels of the service node clusters in the cluster relationship tree according to the number of times; Taking the service node clusters in the cluster relationship tree whose security levels are higher than the security level of the target service as the second service node clusters that match the attribute information of the target service.
10. The method according to claim 8, wherein The service attribute information includes the processing duration for processing the target service; Determining, from the cluster relationship tree, a second service node cluster that matches the service attribute information of the target service includes: Obtaining the service volume corresponding to the service to be processed in the service node clusters in the cluster relationship tree; counting the waiting duration according to the service volume corresponding to the service to be processed; Taking the sum between the waiting duration and the processing duration as the processing delay; Taking the service node clusters in the cluster relationship tree with a processing delay less than the delay threshold as the second service node clusters that match the attribute information of the target service.
11. A data processing device based on blockchain, characterized in that, The data processing device belongs to the main proxy node, and the data processing device includes: An obtaining module, configured to obtain a configuration request for a first service node cluster; the configuration request carries the public network access information of a first service proxy node in the first service node cluster, and the main proxy node belongs to the management node cluster of the blockchain network; A connection module, configured to connect the first service proxy node to the public network to which the management node cluster belongs according to the public network access information, and obtain the node description information of a first service processing node in the first service node cluster from the first service proxy node through the public network; A determining module, configured to determine a target block associated with the node description information from the blockchain in the blockchain network, and read the block headers of all blocks on the blockchain; obtain the mirror file of the blockchain application program from the database node of the management node cluster through the second private network to which the management node cluster belongs; determine the target block and the mirror file as the blockchain configuration information that matches the first service node cluster; the mirror file is used to generate a blockchain node container in the first service processing node, and the target block and the block headers of all blocks are used to generate a blockchain belonging to the first service node cluster in the blockchain node container, and send the blockchain configuration information and all block headers to the first service proxy node through the public network; the first service proxy node synchronizes the blockchain configuration information and all block headers to the first service processing node through the first private network to which the first service node cluster belongs.
12. A computer device, characterized in that, Including: A processor and a memory; The processor is connected to the memory, wherein the memory is used to store program code, and the processor is used to call the program code to execute the method according to any one of claims 1-10.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program includes program instructions, and the program instructions, when executed by a processor, cause the processor to execute the method according to any one of claims 1-10.
Citation Information
Patent Citations
Method for configuring cross-network communication in block chain, equipment and computer storage medium
CN107911421A
Data processing method, device and equipment based on block chain
CN111708844A