Electronic certificate storage method, device, equipment, medium and product
By distributing electronic certificates in a blockchain network and establishing mapping relationships, the problem of low security in the electronic certificate management system is solved, achieving highly reliable and tamper-proof electronic certificate storage.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA CONSTRUCTION BANK
- Filing Date
- 2023-01-04
- Publication Date
- 2026-08-04
AI Technical Summary
Existing electronic certificate management systems suffer from low security. Centralized servers are vulnerable to hacker attacks and operational errors that could lead to information leaks, and the usage records of certificate data are inconsistent.
Electronic certificates are stored on multiple nodes in a blockchain network, and the storage records are recorded in the blockchain network's ledger. A mapping relationship is established between certificate information and the information required for business requests, and automated management and storage are achieved through smart contracts.
It improves the security and reliability of electronic certificate storage, prevents tampering and leakage, and ensures the fairness, impartiality and consistency of information.
Smart Images

Figure CN116010361B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to an electronic certificate storage method, apparatus, device, medium and product. Background Technology
[0002] Paper-based certificates, licenses, and other documents are prone to loss or damage, while saving these documents electronically can effectively solve these problems. Electronic certificates are digital records of certificate information created by electronic devices according to relevant technical specifications, facilitating transmission, use, and management over the internet.
[0003] The existing electronic certificate management system stores personal certificate data and data usage records on centralized servers. If the server is attacked by hackers, information can easily be leaked. In addition, staff may also make mistakes and accidentally delete data. In other words, the current storage method of electronic certificates has low security. Summary of the Invention
[0004] This application provides an electronic certificate storage method, apparatus, device, medium, and product that can improve the reliability and security of electronic certificate storage.
[0005] In a first aspect, embodiments of this application provide an electronic certificate storage method, applied to a first device, the method comprising:
[0006] Obtain the first electronic certificate sent by the second device, the first electronic certificate including multiple certificate information;
[0007] Multiple certificate information is stored in multiple first nodes in the blockchain network. The multiple certificate information corresponds one-to-one with the multiple first nodes. The first node is a node in the blockchain network used for storage. The blockchain network includes the first blockchain node corresponding to the first device.
[0008] The storage records of the first electronic certificate across multiple first nodes are recorded in the general ledger of the blockchain network;
[0009] Based on multiple certificate information, a mapping relationship is constructed. In the mapping relationship, multiple certificate information and the certificate information required by multiple business requests correspond one-to-one. The certificate information required by the business requests is generated based on the certificate information stored in the blockchain network.
[0010] The mapping relationship is stored in the business processing nodes of the blockchain network.
[0011] Secondly, this application provides an electronic certificate storage device, applied to a first device, the device comprising:
[0012] The acquisition module is used to acquire the first electronic certificate sent by the second device. The first electronic certificate includes multiple certificate information.
[0013] The first storage module is used to store multiple certificate information in multiple first nodes in the blockchain network. The multiple certificate information corresponds one-to-one with the multiple first nodes. The first node is a node in the blockchain network used for storage. The blockchain network includes the first blockchain node corresponding to the first device.
[0014] The recording module is used to record the storage records of the first electronic certificate on multiple first nodes in the general ledger of the blockchain network;
[0015] The construction module is used to build a mapping relationship based on multiple certificate information. In the mapping relationship, multiple certificate information and the certificate information required by multiple business requests correspond one-to-one. The certificate information required by the business requests is generated based on the certificate information stored in the blockchain network.
[0016] The second storage module is used to store the mapping relationship in the business processing nodes of the blockchain network.
[0017] Thirdly, embodiments of this application provide an electronic device, which includes: a processor and a memory storing computer program instructions;
[0018] When the processor executes computer program instructions, it implements the electronic certificate storage method as described in any of the embodiments of the first aspect.
[0019] Fourthly, embodiments of this application provide a computer storage medium storing computer program instructions, which, when executed by a processor, implement the electronic certificate storage method as described in any of the embodiments of the first aspect.
[0020] Fifthly, embodiments of this application provide a computer program product in which instructions are executed by the processor of an electronic device, causing the electronic device to perform the electronic certificate storage method as described in any of the embodiments of the first aspect above.
[0021] The electronic certificate storage method, apparatus, device, medium, and product in this application embodiment obtain a first electronic certificate sent by a second device. The first electronic certificate includes multiple certificate information. Then, the multiple certificate information is stored in multiple first nodes in a blockchain network, with each certificate information corresponding one-to-one with a first node. Each first node is a storage node in the blockchain network, and the blockchain network includes a first blockchain node corresponding to the first device. Next, the storage records of the first electronic certificate in the multiple first nodes are recorded in the general ledger of the blockchain network. Then, a mapping relationship is constructed based on the multiple certificate information, where each certificate information corresponds one-to-one with the certificate information required for multiple business requests. The certificate information required for the business requests is generated based on the certificate information stored in the blockchain network. Finally, the mapping relationship is stored in the business processing node of the blockchain network. By employing the above method, the electronic certificates uploaded by the second device are distributed and stored in a blockchain network, and each storage record is recorded in the blockchain network. This ensures that the user's electronic certificates cannot be tampered with, guarantees the fairness and impartiality of electronic certificate information storage, and effectively improves the security of electronic certificates while preventing their leakage, thereby enhancing the reliability and security of electronic certificate storage. Attached Figure Description
[0022] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a flowchart illustrating an embodiment of an electronic certificate storage method provided in this application;
[0024] Figure 2 This is a schematic diagram illustrating the storage of certificate information according to an embodiment of this application;
[0025] Figure 3 This is a schematic diagram of an identity authentication process provided in an embodiment of this application;
[0026] Figure 4 This is a schematic diagram of a business processing flow provided in an embodiment of this application;
[0027] Figure 5 This is a schematic diagram of another business processing procedure provided in an embodiment of this application;
[0028] Figure 6 This is a schematic diagram of the structure of an electronic certificate storage device provided in an embodiment of this application;
[0029] Figure 7 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0030] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.
[0031] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.
[0032] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the term "comprising" or any other variations thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.
[0033] Data has become a resource with irreplaceable economic functions, especially with the advent of the big data era, where data dimensions are increasing and its potential value is rising. Data information resource sharing and application play a crucial supporting role in cross-departmental business collaboration and service coordination. Big data sharing can effectively solve the phenomenon of "data silos," and data resources can be effectively integrated. However, how to use data for exchange and trading, and how to prevent data leakage without permission, remain pressing issues in data sharing. In the field of open data sharing, it is essential to address the security issues of data retention and transfer, ensuring the security and controllability of shared data throughout the entire process of collection, exchange, and sharing.
[0034] With the development of the internet and mobile internet, information technology, primarily based on computers, networks, and communications, is profoundly impacting social life and government operations. To innovate government work models and improve administrative efficiency and service levels, government agencies are widely implementing reforms such as electronic licenses and fully electronic registration management, promoting the online application of electronic licenses for administrative approvals, and encouraging all levels of government agencies to implement fully electronic and networked applications.
[0035] In current data sharing and exchange, electronic certificates are exchanged as structured data. During the exchange process, the business parties requesting data store the data in the form of databases and tables, and generate electronic certificate documents through the electronic certificate system to support government service operations. This achieves the goal of "reducing steps, time limits, materials, processes, and in-person visits" in government service-related operations, allowing users to complete tasks in one visit. However, trusted sharing using electronic certificates as data carriers mainly suffers from unclear responsibilities regarding usage rights, management rights, and ownership; or difficulty in identifying changes when information changes, leading to inconsistencies between the obtained and provided information.
[0036] To address the problems of the prior art, embodiments of this application provide an electronic certificate storage method, apparatus, device, medium, and product. The electronic certificate storage method provided in this application embodiment will be described first below.
[0037] Before providing a further detailed description of the embodiments of the present invention, the nouns and terms involved in the embodiments of the present invention will be explained, and the nouns and terms involved in the embodiments of the present invention shall be interpreted as follows.
[0038] 1) Transaction, equivalent to the computer term "transaction", includes operations that need to be submitted to the blockchain network for execution. It does not refer solely to transactions in a business context. Given that the term "transaction" is conventionally used in blockchain technology, this embodiment of the invention follows this convention.
[0039] For example, a Deploy transaction is used to install a specified smart contract on a node in the blockchain network and prepare it for invocation; an Invoke transaction is used to append a record of a transaction to the blockchain by invoking a smart contract and to operate on the blockchain's state database, including update operations (including adding, deleting, and modifying key-value pairs in the state database) and query operations (i.e., querying key-value pairs in the state database).
[0040] 2) Blockchain is an encrypted, chain-like storage structure for transactions formed by blocks.
[0041] For example, the header of each block can include the hash values of all transactions in the block, as well as the hash values of all transactions in the previous block, thereby preventing tampering and forgery of transactions in the block based on hash values; newly generated transactions are filled into the block and, after consensus among nodes in the blockchain network, are appended to the tail of the blockchain, thus forming a chain-like growth.
[0042] 3) A blockchain network is a collection of nodes that incorporate new blocks into a blockchain through consensus.
[0043] 4) Ledger is a collective term for the blockchain (also known as ledger data) and the state database synchronized with the blockchain.
[0044] In this context, the blockchain records transactions in the form of files in a file system; the state database records transactions in the blockchain in the form of key-value pairs of different types, which is used to support fast querying of transactions in the blockchain.
[0045] 5) Smart Contracts, also known as chaincode or application code, are programs deployed in nodes of a blockchain network. Nodes execute smart contracts called in received transactions to update or query key-value pairs in the ledger database.
[0046] 6) Consensus is a process in a blockchain network used to reach an agreement on transactions in a block among multiple involved nodes. A block that reaches an agreement will be appended to the end of the blockchain. Mechanisms for achieving consensus include Proof of Work (PoW), Proof of Stake (PoS), Delegated Proof-of-Stake (DPoS), and Proof of Elapsed Time (PoET).
[0047] 7) User, used to represent an individual, legal person or organization (such as multiple government, enterprise or organization departments, or possibly a combination of the above) who needs to submit relevant materials on the blockchain to handle a business that requires the participation of multiple government units, enterprises and organizations.
[0048] 8) Participating parties, used to represent government agencies, enterprises (such as banks, which users need to open bank accounts when they are starting a company), and organizations (such as participating accounting firms) that participate in the user's business.
[0049] Figure 1 A flowchart illustrating an embodiment of the electronic certificate storage method provided in this application is shown. Figure 1 As shown, this method is applied to the first device, and the method may specifically include the following steps:
[0050] S101, Obtain the first electronic certificate sent by the second device.
[0051] Optionally, the first device can be a terminal device that builds a blockchain network platform, and the second device can be a terminal device of a participant in the blockchain network. The second device can only perform business operations and realize the electronic certificate sharing service after it is registered in the blockchain network platform built by the first device and authorized and managed by the first device.
[0052] Optionally, the first device can be a computer device such as a laptop or desktop computer, or a server, which can be a standalone server or a server cluster composed of multiple servers. The first device can be a device of one party processing one or more business transactions based on blockchain, such as a terminal device of a government service platform (which may include a unified online service platform, a power operation platform, a government service website, etc.). This terminal device can provide various services and can handle business transactions corresponding to each service for users, such as education services, housing and construction services, civil affairs services, and professional qualification services.
[0053] Optionally, electronic certificates are digital certificates that comply with relevant technical specifications. They are records of certificate information generated, processed, transmitted, and stored by electronic devices such as computers. Electronic certificates are not merely electronic versions of traditional paper certificates; their inherent electronic data characteristics necessitate the use of reliable technical measures to ensure their authenticity and validity, thereby achieving trustworthy issuance and application management of electronic certificates.
[0054] In some alternative implementations, electronic certificates may include electronic ID cards, electronic social security certificates, electronic marriage certificates, electronic housing provident fund certificates, electronic driver's licenses, electronic vehicle registration certificates, and electronic passports, etc.
[0055] S102, based on the certificate information of the first electronic certificate, the first electronic certificate is stored in multiple first nodes in the blockchain network. The first node is a node used for storage in the blockchain network, and the blockchain network includes the first blockchain node corresponding to the first device.
[0056] Optionally, in this embodiment, blockchain technology is a distributed ledger system that uses asymmetric encryption to digitally sign transactions, achieves consensus among multiple nodes through a consensus mechanism, and organizes and stores data in the form of chained blocks. Blockchain technology inherently possesses the characteristics of immutability, traceability, trustlessness, and distributed autonomy. It features novel application models of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. In this embodiment, a blockchain node refers to a hardware server that deploys blockchain software.
[0057] Optionally, the certificate information may include the issuance information of the electronic certificate, the version information of the electronic certificate, the catalog information of the electronic certificate, and the identity information of the holder of the electronic certificate.
[0058] The first node can store electronic certificates in different first nodes according to different types of certificate information.
[0059] Specifically, certificate information can be divided into general ledger information, transaction information, catalog information, and identity information. General ledger information may include: issuance information of electronic certificates, fingerprint data of electronic certificates, storage path of electronic certificates, version information of electronic certificates, and catalog summary of electronic certificates. Transaction information may include: verification application information of electronic certificates, verification authorization fingerprint of electronic certificates, and authorization information signature of electronic certificates. Catalog information may include: certificate catalog information of electronic certificates, catalog information fingerprint of electronic certificates, catalog information signature of electronic certificates, and catalog version information of electronic certificates. Identity information may include: user identity information of electronic certificates, identity information fingerprint of electronic certificates, identity information signature of electronic certificates, and identity version information of electronic certificates.
[0060] Optionally, the first node can be divided into ledger nodes, transaction nodes, directory nodes, and identity nodes based on the different types of electronic certificate information. This allows each first node to create blocks to store the certificate information corresponding to the electronic certificate and the node name. For example, blocks in the ledger node store the ledger information from the certificate information; blocks in the transaction node store the transaction information from the certificate information. Subsequently, the blockchain network is used to connect all the first nodes to form a chain of electronic certificate information.
[0061] like Figure 2 As shown, alternatively, in another possible implementation of this application, different types of certificate information can be stored in different blocks, thereby forming different blockchains. For example, the general ledger information in the certificate information can be stored in blocks in the general ledger chain; the transaction information in the certificate information can be stored in blocks in the transaction chain, and so on for directory information and node information, which will not be elaborated here. It should be noted that when a block in the blockchain is full, a new block is added to its respective chain to continue storing, thereby forming different cross-chains corresponding to the certificate information. These blockchains are then recorded in the blockchain node corresponding to the first device in the form of a ledger. Each block has its own block data, such as transaction list data, parent block hash value, transaction hash value, ledger hash value, receipt hash value, block number, timestamp, etc., making the electronic certificate usage process traceable and the certificate information tamper-proof.
[0062] Alternatively, in one possible implementation, operations such as classifying, uploading, storing, and adding electronic certificate information can be uniformly designed as smart contracts and executed on the blockchain.
[0063] Smart contracts are a technical term in blockchain technology architecture, referring to contracts that use computer language instead of legal language to record terms; they are generally implemented using Java or Go.
[0064] In these alternative embodiments, smart contracts are used to automatically execute protocols, avoiding human intervention and eliminating reliance on authoritative centralized nodes. Each node can execute smart contracts, automatically triggering storage. The stored records and electronic certificates are tamper-proof, effectively improving the security of electronic certificates, preventing their leakage, and enhancing the reliability and security of electronic certificate storage.
[0065] Optionally, the first blockchain node corresponds to the first device, that is, the first blockchain node is the terminal device for building the blockchain network platform, and the first blockchain node can record the transaction information of all first nodes in the above-mentioned certificate information chain, that is, all storage records.
[0066] S103 records the storage records of the first electronic certificate on multiple first nodes in the general ledger of the blockchain network.
[0067] Optionally, the type of blockchain network is flexible and diverse, and can be any of the following: public blockchain, private blockchain, or consortium blockchain. Taking a public blockchain as an example, any business entity's electronic devices, such as user terminals and servers, can access the blockchain network without authorization. Taking a consortium blockchain as an example, after obtaining authorization, the electronic devices (e.g., terminals / servers) under a business entity can access the blockchain network, thus becoming a special type of node in the blockchain network. In this embodiment, a consortium blockchain is used as an example for illustration.
[0068] The general ledger is the storage record of all certificate information in the first blockchain node corresponding to the first device, and it performs unified accounting management, authorization management, etc.
[0069] In these optional embodiments, the second device connects to the blockchain platform and stores the certificate information of the electronic certificates issued by this device through a smart contract, recording the storage record in the general ledger of the first blockchain node. Storing electronic certificates based on blockchain technology solves core issues such as the authenticity and security of electronic certificates, improving the reliability of electronic certificate storage.
[0070] S104. Based on the certificate information, construct a mapping relationship. The mapping relationship includes a one-to-one correspondence between multiple certificate information and the certificate information required for multiple business requests. The selection rules for the certificate information required for business requests are generated based on the certificate information stored in the blockchain network.
[0071] S105 stores the mapping relationship in the business processing node of the blockchain network.
[0072] Optionally, an electronic certificate service request can be a transaction request generated at any point in the process of applying for, using, or canceling an electronic certificate. Taking the requirement to upload the applicant's information during the electronic certificate application process as an example, an organization's staff can log into the system using their electronic certificate issuance system account and enter the certificate information provided by the applicant. The blockchain node maps the entered certificate information to the certificate information required for the service request, constructs a mapping relationship, and stores this mapping relationship in the business processing nodes of the blockchain network. Thus, when a user makes a service request, the business processing node can list the required certificate information based on the user's request, thereby retrieving the required certificate information from the first node, quickly completing the user's service processing, and improving the efficiency of service processing. The construction of the mapping relationship can be implemented using smart contracts or data tables; this embodiment does not impose a specific limitation.
[0073] Optionally, the certificate information requested in the business request can be adapted based on the attribute fields and identifier fields of the electronic certificate information. For example, a list of required certificate information can be constructed, listing the attribute information and identifier information of the required certificate information. Among them, the identifier information is used to store the unique identifier code of the electronic certificate; the attribute information is used to store the basic information of the electronic certificate, such as certificate number, certificate name, type, holder information, issuing authority, etc.
[0074] It's easy to understand that certificate information can also include business data information, ancillary document information, and digital signature information. The digital signature stored in the digital signature information can be used to verify the validity of electronic certificates; business data information can be information corresponding to any data that can be queried in the electronic certificate data, and is related to the specific electronic certificate business type; ancillary document information can be used to store any type of file related to the electronic certificate, such as documents, images, or scanned copies, to increase the completeness of the electronic certificate information. In one possible implementation of this application, different services may have different requirements, and these different requirements may require different electronic document information from the user. The terminal device can pre-set a correspondence between different services and electronic documents. The terminal device can search for the electronic document corresponding to the user's pending service from the above correspondence based on the user's pending service, and can determine the found electronic document as the user's electronic document required for the pending service. Alternatively, the relevant information of the user's pending service can be input into a predetermined model (such as a classification model) for analysis to output the corresponding result (i.e., electronic document). For example, if the user's pending service requires the use of the user's ID card information, the electronic document corresponding to the pending service can be determined to be the ID card information based on the predetermined classification model. As another example, if the user's pending service requires the use of the user's social security card information, the electronic document corresponding to the pending service can be determined to be the social security card, etc., based on the predetermined classification model.
[0075] In the electronic certificate storage method of this application embodiment, a first electronic certificate sent by a second device is obtained. The first electronic certificate includes multiple certificate information. Then, the multiple certificate information is stored in multiple first nodes in a blockchain network, with each certificate information corresponding one-to-one with a first node. Each first node is a storage node in the blockchain network, and the blockchain network includes a first blockchain node corresponding to the first device. Next, the storage records of the first electronic certificate in the multiple first nodes are recorded in the general ledger of the blockchain network. Then, a mapping relationship is constructed based on the multiple certificate information, where each certificate information corresponds one-to-one with the certificate information required for multiple business requests. The certificate information required for the business requests is generated based on the certificate information stored in the blockchain network. Finally, the mapping relationship is stored in the business processing node of the blockchain network. Through this method, the electronic certificates uploaded by the second device are distributed and stored in a blockchain network, and each storage record is recorded in the blockchain network. This ensures that the user's electronic certificates cannot be tampered with, guarantees the fairness and impartiality of electronic certificate information storage, and effectively improves the security of electronic certificates while preventing leakage, thus enhancing the reliability and security of electronic certificate storage.
[0076] In one embodiment, step 102 above may specifically be performed as follows:
[0077] S1021, encrypt the private information of the first electronic certificate to obtain encrypted information, wherein the certificate information includes the private information.
[0078] Optionally, the private information may be the identity information of the holder of the electronic certificate, or other certificate information that is designed to protect user privacy, such as the identity information in the certificate information described in step 102 above, such as the holder's fingerprint information, facial information, etc., which will not be elaborated here.
[0079] Optionally, the encryption method can be based on an asymmetric cryptographic algorithm, such as the Chinese national standard SM2. For specific encryption methods, refer to the encryption methods of existing technologies, which will not be elaborated here.
[0080] S1022, the encrypted information is stored in a target node, where the target node is one of the plurality of first nodes used to store the private information.
[0081] Optionally, the target node can be the identity node in step 102 above, used to store the private information of the electronic certificate.
[0082] Alternatively, the privacy information can be authorized and managed through smart contracts via a blockchain network platform, so that only authorized terminal devices are qualified to query the privacy information.
[0083] In these alternative embodiments, by encrypting the private information of electronic certificates, the security of the user's electronic certificate information being obtained or used can be protected, further improving the security and reliability of electronic certificate storage.
[0084] In one embodiment, after step S1022 described above, the method further includes:
[0085] S1023, Obtain the query request from the first user to query the second electronic certificate;
[0086] S1024, if the user to which the second electronic certificate belongs is the first user, the encrypted information of the second electronic certificate is decrypted according to the identity information of the first user to obtain the private information of the second electronic certificate.
[0087] S1025, if the user who owns the second electronic certificate is not the first user, send authentication information to the user who owns the second electronic certificate. If the authentication information is successful, decrypt the encrypted information of the second electronic certificate to obtain the private information of the second electronic certificate.
[0088] In one possible implementation, for the holder of the electronic certificate, the electronic certificate information includes the holder's personal privacy data. In order to prevent any user from arbitrarily obtaining other users' electronic certificate information, separate rules can be set for obtaining different electronic certificate information. For example, when other users obtain a user's electronic certificate information, they need to obtain the user's authorization, thereby ensuring the security of the user's electronic certificate information being obtained or used.
[0089] After the terminal device of the business processing party (i.e., the second device) determines the electronic document information of the holder of the required electronic certificate, it can display a prompt message indicating that the electronic document information is required to the second device. The business processing party can explain to the holder of the electronic certificate that the holder's electronic document information is required, or the business processing party can provide the aforementioned prompt message to the holder of the electronic certificate. The holder of an electronic certificate can obtain the authorization information for that electronic certificate through their terminal device. Specifically, the holder's terminal device may have pre-stored authorization information for different electronic certificates. In this case, the holder can obtain the authorization information for the specific electronic certificate from the pre-stored authorization information and provide it to the business processing party. Alternatively, the holder's terminal device may have an application installed to generate authorization information for different electronic certificates. In this case, the holder can launch the application through their terminal device and generate the authorization information for the specific electronic certificate. The holder can then provide the generated authorization information to the business processing party.
[0090] The terminal device of the business processing party may include a mechanism or device for obtaining the authorization information of the electronic certificate holder. For example, if the authorization information of the electronic certificate holder is presented in the form of an image code, the terminal device of the business processing party may include an image code scanning device. In this way, the business processing party can scan the authorization information of the electronic certificate holder using the image code scanning device to obtain the authorization information. If the authorization information of the electronic certificate holder is presented in the form of a notification message, the terminal device of the business processing party may be equipped with a notification message processing mechanism. In this way, the business processing party can receive notification messages carrying the authorization information of the electronic certificate holder, thereby obtaining the authorization information and thus being qualified to view the private information of the electronic certificate holder.
[0091] In these alternative embodiments, by encrypting the private information of electronic certificates, the security of the user's electronic certificate information being obtained or used can be protected, further improving the security and reliability of electronic certificate storage.
[0092] In one embodiment, prior to step 101 above, the method may further perform the following steps:
[0093] S201, A second blockchain node is added to the blockchain network, and the second device corresponds to the second blockchain node.
[0094] S202, based on the user information of the participating parties, determine the permission information of the second device to query the general ledger, wherein the participating parties include users using the second device.
[0095] Optionally, the participants are government agencies, enterprises (such as banks, which users need to open bank accounts when they are starting a company), and organizations (such as participating accounting firms) that participate in the user's business transactions.
[0096] Optionally, the second blockchain node may only support users in initiating transactions (e.g., for storing data on-chain or querying on-chain data). For the functions of the first blockchain node in the blockchain network, such as the ledger recording function mentioned above, the second blockchain node may selectively implement them (e.g., depending on the specific business needs of the business entity). This allows for the maximum migration of user data and business processing logic to the blockchain network, achieving trustworthiness and traceability of data and business processing through the blockchain network.
[0097] Participants can only conduct business operations and access electronic certificate inquiry services after registering on the blockchain network and being authorized and managed by the platform. Registration, update, and deletion operations for participants are all uniformly designed as smart contracts, executed on the blockchain network platform, and recorded in the blockchain ledger. Platform administrators perform maintenance operations on participants through the portal, including registration, updates, and deletions. The first blockchain node executes the on-chain code (i.e., smart contracts) to maintain departmental data.
[0098] Optionally, the first blockchain node and the second blockchain node form a consortium blockchain, with each participant participating in the consortium blockchain, and each participant typically deploying more than one node; in the consortium blockchain, each participant is equal and autonomous.
[0099] S203, Receive the ledger query request from the second device.
[0100] S204, Verify the permission information of the second device according to the ledger query request.
[0101] As described above, different devices can be authorized and managed, granting different secondary devices different query permissions. When a secondary device needs to query ledger information, its query permissions can be verified to determine if it has the necessary authorization. This strictly controls the permissions of secondary devices and further enhances the security of electronic certificate data storage.
[0102] S205, if the permission information is verified, obtain the ledger information in the general ledger corresponding to the ledger query request.
[0103] Optionally, the query permissions of the second device are verified. When the query permissions of the second device match the ledger permission information to be queried, the ledger information to be queried is retrieved from the main ledger. The second device has the permission to inspect and modify the electronic certificates to be queried (before the data is uploaded to the blockchain). After configuring the corresponding permissions to the second blockchain node, the second device can view government information stored in the blockchain network and promptly learn of adjustments and / or additions to users' electronic certificates. When changes occur to electronic certificates (e.g., changes to legal entity information), these changes can be promptly recorded in the main ledger, improving the accuracy and real-time nature of electronic certificates and preventing the second device from obtaining incorrect government information.
[0104] If the query permissions of the second device do not match the permission information of the ledger to be queried, the query request will be rejected and the user will be reminded that they do not have query permissions.
[0105] S206, the ledger information is sent to the second device.
[0106] Optionally, after a query is completed, the query record is saved in the blockchain network's ledger. Since the blockchain network is a peer-to-peer (P2P) network system with a distributed data storage structure, where nodes reach a consensus mechanism, the data within the blockchain is distributed across sequentially linked "blocks." Each subsequent block contains a data summary of the previous block, and depending on the specific consensus mechanism, all or some nodes achieve full data backup. As those skilled in the art know, because the blockchain network system operates under a corresponding consensus mechanism, data already recorded in the blockchain database is difficult for arbitrary nodes to tamper with. For example, in a blockchain using Proof-of-Work (PoW) consensus, an attack requiring at least 51% of the network's computing power is needed to potentially tamper with existing data. Therefore, the blockchain system possesses data security and attack / tamper resistance characteristics unmatched by other centralized database systems. Thus, data recorded in the distributed database of the blockchain cannot be attacked or tampered with, thereby ensuring the authenticity and reliability of electronic certificates stored in the distributed database of the blockchain and preventing alterations to the electronic certificates.
[0107] In these optional embodiments, different devices can be authorized and managed, allowing different second devices to have different query permissions. When a second device needs to query ledger information, its query permissions can be verified to determine whether it has the authority to query the ledger, thereby strictly controlling the permissions of the second devices and further improving the security of electronic certificate data storage.
[0108] In one embodiment, after step 103, the method may further perform the following steps:
[0109] S301, Receive a query request, the query request including the user's identity information.
[0110] Optionally, it can receive query requests from a second device, such as when a user needs to use electronic certificates when accessing government services from a participating party, and can directly query the second device in the participating party; or it can receive query requests from a third device (i.e., the user's own terminal device), such as when a user checks the processing progress of their electronic certificates on an application on their own terminal device.
[0111] Optionally, the identity information may be the user's (the holder of the electronic certificate) fingerprint information, facial information, terminal device information, etc.
[0112] S302, Obtain the permission information corresponding to the identity information in the blockchain network.
[0113] In some optional embodiments, unified identity authentication can be performed on electronic certificates, thereby enabling real-name authentication of each electronic certificate, ensuring user privacy, and improving the security of electronic certificate storage.
[0114] like Figure 3 As shown, in one possible implementation, a user can first register and log in on a second device, then perform real-name authentication through a unified identity authentication center, and then send the real-name authentication information to the real-name authentication center. The real-name authentication center then sends the real-name certificate back to the unified identity authentication center, which stores the real-name certificate on the blockchain to the target node, thereby completing the real-name authentication of each electronic certificate.
[0115] In these optional embodiments, the electronic certificate holder's electronic document information includes the holder's personal privacy data. To prevent any user from arbitrarily accessing other users' electronic document information, access control can be implemented for this privacy data. This reduces trust issues arising from information inconsistencies, achieves responsibility management, and ensures traceability of information utilization.
[0116] S303, if the permission information corresponding to the identity information matches the preset permission information, a third electronic certificate is obtained from the plurality of first nodes, and the query record of the third electronic certificate is recorded in the general ledger.
[0117] S304, Send the third electronic certificate.
[0118] Optionally, the preset permission information can be the real-name authentication information of the electronic certificate itself. The third electronic certificate is the electronic certificate that the user wants to query.
[0119] In these optional embodiments, by verifying the identity information of the user who needs to query, and checking whether the user has the permission to query the electronic certificate, if the permission matches the real-name authentication information of the electronic certificate to be queried, the third electronic certificate to be queried is obtained from the first node. This ensures the user's privacy.
[0120] In some optional embodiments, many services require the use of a user's personal identification information to verify the user's identity or to process related services. Specifically, for one or more services, the service provider can set up the processing mechanism for the aforementioned services according to the actual needs of those services. A user requesting a certain service can request the service to be processed from the service provider. Before a user needs to process a service, the user can explain the pending service to the service provider. The service provider's terminal device can have an application installed to process the pending service. At this time, the service provider can launch the application through the terminal device. The application can contain relevant information for different services. When the service provider selects a pending service, the terminal device can obtain the relevant information for the pending service and determine the service processing requirements based on the relevant information.
[0121] like Figure 4 As shown, in one possible implementation, when a user needs to conduct business, they can first submit a business application in the local bureau's system. Subsequently, the local bureau's system will display the required electronic certificates. Then, identity authentication is performed on the local bureau's system. Next, the identity authentication credential is queried on the identity chain and sent to the digital identity terminal. The digital identity terminal then sends the authentication result to the local bureau's system. If the authentication is successful, the storage location of the required electronic certificate is obtained from the directory chain, the certificate fingerprint data is obtained from the general ledger chain, and the authorization information is obtained from the transaction chain. Assuming that the required electronic certificate is obtained from the remote electronic certificate database, the remote certificate data is then obtained from the remote electronic certificate database. The remote certificate data is then verified on the general ledger chain to check whether the certificate is authorized and trustworthy certificate data (i.e., verify the authorization information). If so, the electronic certificate is sent to the user. This reduces layers of data intermediaries and data request submissions, maximizes data timeliness and flow, enhances verification and mutual trust among different and heterogeneous entities, thereby improving data authority, promoting data development, and enhancing the collaborative efficiency among the three regions.
[0122] Optionally, when applying for electronic certificates online, users can apply for their own / organization's electronic certificates online after real-name authentication (user data entry and blockchain network data integration are required). When data for electronic certificates needs to be collected, users can generate it manually, and then the blockchain network can directly collect the certificate data by connecting with the issuing department of the electronic certificate data. When a certificate is used, changed, or cancelled, an SMS message can be automatically generated to remind the owner or organization of the electronic certificate.
[0123] Optionally, in this embodiment of the application, some electronic certificates that can be made available to the public can be queried by any user. When querying, users only need to enter the number of the electronic certificate to find the certificate information of the relevant electronic certificate. After the user is real-name authenticated, they can also query the electronic certificates that are already under the real-name authentication.
[0124] Optionally, in this embodiment, electronic certificates in the blockchain network can also be managed through authorization, allowing only authorized entities or institutions to directly query or use the corresponding electronic certificates. If the collected electronic certificate data is incorrect or incomplete, or if the electronic certificate needs to be changed, a new version of the stored electronic certificate can be generated, with the original data marked as a historical version, thus enhancing the timeliness of the data through continuous updates.
[0125] In one embodiment, step 303 above can be specifically performed as follows:
[0126] S3031, obtain the index information of each first electronic certificate in the plurality of first nodes, the index information including user information of the user determined according to the first electronic certificate;
[0127] S3032, Obtain the third electronic certificate from the index information based on the identity information.
[0128] In this embodiment, the index information is defined as an information service system built to discover and locate various electronic certificates scattered across the network. Based on business needs and following a unified index information system standard, the certificate information of relevant electronic certificates is cataloged to generate index information for the electronic certificates, recording the types of certificate information. According to the technical solution of this embodiment, the index information is managed through smart contracts on the blockchain, including: querying, adding, modifying, and managing access permissions for the index information.
[0129] Optionally, this application can also construct a national index chain, wherein the national index chain consists of index nodes for each city; the index nodes of each city's electronic certificate information chain store important information extracted from the city's full set of electronic certificates; each index node shares data through the national index chain and jointly stores national index information; when sharing electronic certificate services across cities, the summary information of the electronic certificates of the natural person or legal person in the city can be obtained by searching the index nodes; if the full set of electronic certificate information of the natural person or legal person is to be obtained, the full set of electronic certificate data needs to be retrieved through the interface between the index nodes and data nodes in the city information chain.
[0130] like Figure 5As shown, in one possible implementation, a legal entity with an electronic certificate registers the electronic certificate with an institution in City A. The institution in City A then stores the newly added electronic certificate in City A's electronic certificate repository for centralized management. Subsequently, City A's electronic certificate repository can connect to the blockchain network described in this application, uploading the newly added electronic certificate to the blockchain for verification according to the certificate information. Thus, when the legal entity needs to view or conduct business in City B, it can verify its identity information and retrieve its electronic certificate from the national index chain, storing the query record in the general ledger. Through the tamper-proof and non-repudiation characteristics of blockchain, and by broadcasting information to the blockchain and synchronizing the general ledger, the verification and mutual trust of certificates between different locations and heterogeneous entities are enhanced, thereby improving data authority, promoting data construction, enhancing the collaborative efficiency of the three regions, realizing cross-regional data query and flow, and enhancing the timeliness and circulation of data.
[0131] In these optional embodiments, a multi-center management model is implemented using blockchain technology, reducing intermediate steps in the release, authorization, and remote acquisition of electronic certificate resources, and further facilitating the flow of certificate data across regions, levels, and departments; reducing layers of data agents and data request submissions, and maximizing the timeliness and circulation of data. This solves core issues such as the authenticity and security of electronic certificates, and enables nationwide certificate sharing and querying by establishing a national index chain.
[0132] Figure 6 A schematic diagram of the structure of an electronic certificate storage device provided in one embodiment of this application is shown. For ease of explanation, only the parts related to the embodiment of this application are shown.
[0133] Reference Figure 6 The electronic certificate storage device may include:
[0134] The acquisition module 601 is used to acquire the first electronic certificate sent by the second device, the first electronic certificate including multiple certificate information;
[0135] The first storage module 602 is used to store multiple certificate information in multiple first nodes in a blockchain network. The multiple certificate information corresponds one-to-one with the multiple first nodes. The first node is a node used for storage in the blockchain network. The blockchain network includes the first blockchain node corresponding to the first device.
[0136] Recording module 603 is used to record the storage records of the first electronic certificate in multiple first nodes in the general ledger of the blockchain network;
[0137] Module 604 is used to construct a mapping relationship based on the certificate information. The mapping relationship includes a one-to-one correspondence between multiple certificate information and the certificate information required by multiple business requests. The selection rules for the certificate information required by the business requests are generated based on the certificate information stored in the blockchain network.
[0138] The second storage module 605 is used to store the mapping relationship in the business processing node of the blockchain network.
[0139] In one embodiment, the electronic certificate storage device may further include:
[0140] An encryption module is used to encrypt the private information of the first electronic certificate to obtain encrypted information, wherein the certificate information includes the private information;
[0141] The second storage module is used to store the encrypted information in the target node. The certificate information includes the private information, and the target node is the node among the plurality of first nodes used to store the private information.
[0142] In one embodiment, the electronic certificate storage device may further include:
[0143] The acquisition submodule is used to acquire the query request from the first user to query the second electronic certificate;
[0144] The first decryption module is used to decrypt the encrypted information of the second electronic certificate based on the identity information of the first user when the user to which the second electronic certificate belongs is the first user, so as to obtain the private information of the second electronic certificate.
[0145] The second decryption module is used to send authentication information to the user who owns the second electronic certificate when the user who owns the second electronic certificate is not the first user. If the authentication information is successful, the module decrypts the encrypted information of the second electronic certificate to obtain the private information of the second electronic certificate.
[0146] In one embodiment, the electronic certificate storage device may further include:
[0147] An addition module is provided for adding a second blockchain node to the blockchain network, wherein the second device corresponds to the second blockchain node;
[0148] The first determining module is used to determine the permission information of the second device to query the general ledger based on the user information of the participants, wherein the participants include users using the second device;
[0149] The first receiving module is used to receive the ledger query request from the second device;
[0150] The verification module is used to verify the permission information of the second device based on the ledger query request;
[0151] The second acquisition module is used to acquire ledger information in the general ledger corresponding to the ledger query request when the permission information is verified.
[0152] The first sending module is used to send the ledger information to the second device.
[0153] In one embodiment, the electronic certificate storage device may further include:
[0154] The second receiving module is used to receive a query request, the query request including the user's identity information;
[0155] The third acquisition module is used to acquire permission information corresponding to the identity information in the blockchain network;
[0156] The fourth acquisition module is used to acquire a third electronic certificate from the plurality of first nodes when the permission information corresponding to the identity information matches the preset permission information, and to record the query record of the third electronic certificate in the general ledger;
[0157] The second sending module is used to send the third electronic certificate.
[0158] In one embodiment, the electronic certificate storage device may further include:
[0159] The fifth acquisition module is used to acquire the index information of each first electronic certificate in the plurality of first nodes, the index information including user information of the user determined based on the first electronic certificate;
[0160] The sixth acquisition module is used to acquire the third electronic certificate from the index information based on the identity information.
[0161] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. They are devices corresponding to the above-mentioned battery thermal runaway early warning method. All implementation methods in the above-mentioned method embodiments are applicable to the embodiments of this device. For details on its specific functions and the technical effects it brings, please refer to the method embodiment section. It will not be repeated here.
[0162] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0163] Figure 7 A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown.
[0164] The device may include a processor 701 and a memory 702 storing program instructions.
[0165] When processor 701 executes the program, it implements the steps in any of the above method embodiments.
[0166] For example, the program can be divided into one or more modules / units, one or more of which are stored in memory 702 and executed by processor 701 to complete this application. The one or more modules / units can be a series of program instruction segments capable of performing a specific function, which describe the execution process of the program in the device.
[0167] Specifically, the processor 701 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0168] Memory 702 may include mass storage for data or instructions. For example, and not limitingly, memory 702 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 702 may include removable or non-removable (or fixed) media. Where appropriate, memory 702 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 702 is non-volatile solid-state memory.
[0169] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the methods according to one aspect of this disclosure.
[0170] The processor 701 implements any of the methods described in the above embodiments by reading and executing program instructions stored in the memory 702.
[0171] In one example, the electronic device may also include a communication interface 703 and a bus 710. The processor 701, memory 702, and communication interface 703 are connected via the bus 710 and communicate with each other.
[0172] The communication interface 703 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0173] Bus 710 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 710 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.
[0174] Furthermore, in conjunction with the methods in the above embodiments, this application embodiment can provide a storage medium for implementation. This storage medium stores program instructions; when these program instructions are executed by a processor, they implement any of the methods in the above embodiments.
[0175] This application also provides a chip, which includes a processor and a communication interface. The communication interface and the processor are coupled. The processor is used to run programs or instructions to implement the various processes of the above method embodiments and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0176] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0177] This application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the above method embodiments and achieve the same technical effects. To avoid repetition, it will not be described again here.
[0178] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0179] The functional modules shown in the above block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on machine-readable media or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable media" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer grids such as the Internet, intranets, etc.
[0180] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0181] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to create a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0182] The above are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. A method for storing electronic certificates, applied to a first device, characterized in that, The method includes: Obtain a first electronic certificate sent by a second device. The first electronic certificate includes multiple certificate information, and the certificate information includes at least one of general ledger information, transaction information, directory information, and identity information. The multiple certificate information is stored in multiple first nodes in a blockchain network. The multiple certificate information corresponds one-to-one with the multiple first nodes. The first node is a storage node in the blockchain network. The blockchain network includes a first blockchain node corresponding to the first device. The first node includes at least one of the following: a general ledger node for storing the general ledger information, a transaction node for storing the transaction information, a directory node for storing the directory information, and an identity node for storing the identity information. The storage records of the first electronic certificate on the multiple first nodes are recorded in the general ledger of the blockchain network; Based on the multiple certificate information, a mapping relationship is constructed, in which the multiple certificate information and the certificate information required by multiple business requests correspond one-to-one. The certificate information required by the business requests is generated based on the attribute fields and identifier fields of the certificate information stored in the blockchain network. The mapping relationship is stored in the business processing node of the blockchain network. The business processing node is used to respond to the business request and retrieve the certificate information from the corresponding first node according to the mapping relationship.
2. The method of claim 1, wherein, The step of storing the first electronic certificate in multiple first nodes of a blockchain network based on the certificate information of the first electronic certificate includes: The private information of the first electronic certificate is encrypted to obtain encrypted information, wherein the certificate information includes the private information; The encrypted information is stored in a target node, which is one of the plurality of first nodes used to store the private information.
3. The method of claim 2, wherein, After storing the encrypted information in the target node, the method further includes: Obtain the query request from the first user to query the second electronic certificate; If the user who owns the second electronic certificate is the first user, the encrypted information of the second electronic certificate is decrypted based on the identity information of the first user to obtain the private information of the second electronic certificate. If the user who owns the second electronic certificate is not the first user, authentication information is sent to the user who owns the second electronic certificate. If the authentication information is successful, the encrypted information of the second electronic certificate is decrypted to obtain the private information of the second electronic certificate.
4. The method of claim 1, wherein, Before obtaining the first electronic certificate sent by the second device, the following steps are included: A second blockchain node is added to the blockchain network, and the second device corresponds to the second blockchain node; Based on the user information of the participants, the permission information of the second device to query the general ledger is determined, wherein the participants include users using the second device; Receive the ledger query request from the second device; Based on the ledger query request, the permission information of the second device is verified; If the permission information is verified, retrieve the ledger information corresponding to the ledger query request from the general ledger; The ledger information is sent to the second device.
5. The method according to claim 1, characterized in that, After recording the storage records of the first electronic certificate on the plurality of first nodes in the general ledger of the blockchain network, the method further includes: Receive a query request, the query request including the user's identity information; Obtain the permission information corresponding to the identity information in the blockchain network; If the permission information corresponding to the identity information matches the preset permission information, a third electronic certificate is obtained from the plurality of first nodes, and the query record of the third electronic certificate is recorded in the general ledger; Send the third electronic certificate.
6. The method according to claim 5, characterized in that, Obtaining the second electronic certificate from the plurality of first nodes includes: Obtain the index information of each first electronic certificate in the plurality of first nodes, wherein the index information includes user information of the user determined based on the first electronic certificate; The third electronic certificate is obtained from the index information based on the identity information.
7. An electronic certificate storage device, applied to a first device, characterized in that, The device includes: The acquisition module is used to acquire a first electronic certificate sent by the second device. The first electronic certificate includes multiple certificate information, and the certificate information includes at least one of general ledger information, transaction information, directory information, and identity information. The first storage module is used to store the multiple certificate information in multiple first nodes in a blockchain network. The multiple certificate information corresponds one-to-one with the multiple first nodes. The first node is a storage node in the blockchain network. The blockchain network includes a first blockchain node corresponding to the first device. The first node includes at least one of the following: a general ledger node for storing the general ledger information, a transaction node for storing the transaction information, a directory node for storing the directory information, and an identity node for storing the identity information. A recording module is used to record the storage records of the first electronic certificate on the multiple first nodes in the general ledger of the blockchain network; The construction module is used to construct a mapping relationship based on the multiple certificate information, wherein the multiple certificate information and the certificate information required by multiple business requests correspond one-to-one in the mapping relationship, and the certificate information required by the business requests is generated based on the attribute fields and identifier fields of the certificate information stored in the blockchain network; The second storage module is used to store the mapping relationship in the business processing node of the blockchain network. The business processing node is used to respond to the business request and retrieve the certificate information from the corresponding first node according to the mapping relationship.
8. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the electronic certificate storage method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the electronic certificate storage method as described in any one of claims 1-6.
10. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device performs the electronic certificate storage method as described in any one of claims 1-6.