Blockchain Asset Recovery Method and Blockchain Asset Recovery System
By introducing multiple clients and blockchain nodes into the blockchain asset recovery system, and using signature request and verification information mechanisms, the problem of blockchain asset recovery in the existing technology relying on third-party platforms is solved, and a high-security blockchain asset recovery is achieved.
Patent Information
- Application Number
- CN202310140800.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-15
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2043-02-15
AI Technical Summary
Existing blockchain asset recovery methods rely on the credibility of third-party platforms and are vulnerable to malicious administrators or hackers, making it difficult to recover private keys and blockchain assets difficult to recover.
By introducing multiple clients and blockchain nodes into the blockchain asset recovery system, using the signature request and verification information mechanism, we ensure that only authorized clients can recover private keys and operation permissions, and improve the security of asset recovery.
It realizes the recovery of blockchain assets on the basis of ensuring the security of blockchain assets, avoids asset losses caused by malicious attacks, and improves the reliability and security of asset recovery.
Smart Images

Figure CN116318714B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of blockchain technology, and particularly to a blockchain asset recovery method and a blockchain asset recovery system. Background Art
[0002] Due to the characteristics of blockchain such as being publicly transparent, decentralized, and immutable, blockchain assets have emerged. For blockchain assets, a user having the private key for the blockchain asset means having the operation permission for the blockchain asset. Therefore, the security of blockchain assets is closely related to the security of the private key. Once the private key is lost or forgotten, it means losing the operation permission for the blockchain asset.
[0003] In related technologies, if a user loses the operation permission for a blockchain asset due to the loss or forgetting of the private key, the blockchain asset can be recovered by recovering the private key, so as to regain the operation permission for the blockchain asset. For example, the user entrusts the private key to a third-party platform as a "cloud wallet", and when the private key is lost, the third-party platform is used to recover the private key.
[0004] However, the above method depends on the trust level of the third-party platform. Once a malicious administrator or a hacker attack event occurs, it will be difficult to recover the user's private key, and thus it will be difficult to recover the blockchain asset. Summary of the Invention
[0005] Embodiments of this application provide a blockchain asset recovery method and a blockchain asset recovery system, which can ensure the security of blockchain assets while realizing the recovery of blockchain assets. The technical solution is as follows:
[0006] In a first aspect, a blockchain asset recovery method is provided. The method is applied to a blockchain asset recovery system, which includes a first client, multiple second clients, and a blockchain node. A blockchain is configured on the blockchain node. The method includes:
[0007] In response to a reconfiguration operation of a key, the first client sends a first signature request to the multiple second clients. The key is used to operate on the blockchain assets of the first client on the blockchain, and the first signature request instructs to sign the reconfiguration operation;
[0008] The first client receives first signatures generated by the multiple second clients based on the first signature request. The first signature indicates that the second client has authorized the first client to reconfigure the key;
[0009] The first client sends a first asset recovery request to the blockchain node based on the reconfigured key, verification information, and multiple received first signatures. The verification information is used to verify whether the second client is in the client list published by the first client on the blockchain. The client list indicates multiple clients authorized for the reconfiguration operation.
[0010] The blockchain node receives the first asset recovery request, and based on the verification information, verifies whether the second client corresponding to the first signature is in the client list. If the number of first signatures that pass the verification is greater than or equal to the target threshold, the blockchain node restores the operation permission of the first client for the blockchain asset based on the reconfigured key.
[0011] In the above method, the first client, in response to the reconfiguration operation of the key, requests multiple second clients to sign the reconfiguration operation to restore the blockchain asset of the first client on the blockchain. Then, the first client requests the blockchain node to restore the blockchain asset based on the multiple received first signatures, the reconfigured key, and the verification information. In this process, the blockchain node needs to verify, according to the verification information, whether the second client corresponding to the first signature is truly authorized for the reconfiguration operation. That is, the client information authorized for the reconfiguration operation is not publicly available on the blockchain. Therefore, the above method ensures the security of the blockchain asset while realizing the recovery of the blockchain asset.
[0012] In some embodiments, when the blockchain node receives the first asset recovery request and verifies whether the second client corresponding to the first signature is in the client list based on the verification information, it includes:
[0013] The blockchain node receives the first asset recovery request and obtains the client list from the blockchain. The client list includes the verification addresses of multiple clients authorized for the reconfiguration operation. The verification address of the client is generated based on the verification information and the address of the client.
[0014] The blockchain node generates the verification address of the second client based on the verification information and the address of the second client corresponding to the first signature.
[0015] If the verification address of the second client is in the client list and the verification of the first signature passes based on the public key of the second client, the blockchain node determines that the first signature passes the verification.
[0016] In some embodiments, if the number of the first signatures that pass the verification is greater than or equal to the target threshold, based on the reconfigured key, restoring the operation authority of the first client for the blockchain asset includes:
[0017] If the number of the first signatures that pass the verification is greater than or equal to the target threshold, the blockchain node publishes first status information on the blockchain, and the first status information indicates that the blockchain asset is being restored;
[0018] If the blockchain node does not receive a malicious behavior report within the target time period, based on the reconfigured key, restoring the operation authority of the first client for the blockchain asset, where the malicious behavior report indicates that the behavior of restoring the blockchain asset is a malicious behavior.
[0019] In some embodiments, the method further includes:
[0020] A target second client among the multiple second clients obtains the first status information from the blockchain within the target time period;
[0021] The target second client sends a notification message to the first client, and the notification message is used to notify the first client that the blockchain asset is being restored, so that the first client determines whether the behavior of restoring the blockchain asset is a malicious behavior, and if so, sends the malicious behavior report to the blockchain node.
[0022] In some embodiments, the method further includes:
[0023] If the first client does not reconfigure the key and receives the notification message sent by the target second client, the first client sends the malicious behavior report to the blockchain node based on the verification information and the second clients among the multiple second clients except the target second client.
[0024] In some embodiments, the method further includes:
[0025] If the blockchain node receives the malicious behavior report within the target time period, it publishes second status information on the blockchain, and the second status information indicates that the restoration of the blockchain asset has been stopped.
[0026] Through the above method, if the number of first signatures that pass the verification is greater than or equal to the target threshold, the blockchain node sets a protection period for the blockchain assets based on the target time period to ensure the security of the blockchain assets and prevent malicious actors from maliciously restoring the blockchain assets. That is, within the target time period, any honest guardian can revoke the blockchain asset restoration behavior, which can ensure the security of the blockchain assets and achieve 1 / n security, where n is the number of guardians.
[0027] In some embodiments, the method further includes:
[0028] If the first client is in an offline state, in response to the reconfiguration operation, the first client sends a second signature request to multiple second clients, the second signature request instructing to sign the reconfiguration operation, and sends a second asset restoration request to the blockchain node, the second signature request carrying the verification information;
[0029] The second client receives the second signature request, generates a second signature, and based on the reconfigured key, the second signature, and the verification information, sends the second asset restoration request to the blockchain node, the second signature indicating that the second client has authorized the first client to reconfigure the key;
[0030] The blockchain node receives the second asset restoration requests sent by multiple second clients, and based on the verification information, verifies whether the second clients corresponding to the second signatures are in the client list. If the number of the second signatures that pass the verification is greater than the target threshold, based on the reconfigured key, the blockchain node restores the operation permission of the first client for the blockchain assets.
[0031] Through the above method, when the first client is in an offline state, the restoration of blockchain assets can also be achieved, and the security of the blockchain assets is ensured.
[0032] In some embodiments, the verification information includes at least one of a random number and a password.
[0033] In some embodiments, the restoring the operation permission of the first client for the blockchain assets based on the reconfigured key includes:
[0034] Updating the address with operation permission for the blockchain assets to the address corresponding to the reconfigured key.
[0035] In some embodiments, the first client sending a first signature request to multiple second clients in response to a reconfiguration operation of the key includes:
[0036] In response to the reconfiguration operation, the first client sends the first signature request to the multiple second clients based on the address corresponding to the key before reconfiguration and the address corresponding to the key after reconfiguration.
[0037] In a second aspect, an embodiment of the present application provides a blockchain asset recovery system, which includes a first client, multiple second clients, and a blockchain node, and a blockchain is configured on the blockchain node;
[0038] The first client is used to:
[0039] In response to an operation of reconfiguring a key, send a first signature request to the multiple second clients, where the key is used to operate on the blockchain assets of the first client on the blockchain, and the first signature request instructs to sign the reconfiguration operation;
[0040] Receive first signatures generated by the multiple second clients based on the first signature request, where the first signatures indicate that the second clients have authorized the first client to reconfigure the key;
[0041] Based on the reconfigured key, verification information, and the received multiple first signatures, send a first asset recovery request to the blockchain node, where the verification information is used to verify whether the second client is in the client list published by the first client on the blockchain, and the client list indicates multiple clients with authorization permissions for the reconfiguration operation;
[0042] The blockchain node is used to:
[0043] Receive the first asset recovery request, verify based on the verification information whether the second client corresponding to the first signature is in the client list, and if the number of verified first signatures is greater than or equal to a target threshold, restore the operation permission of the first client for the blockchain assets based on the reconfigured key.
[0044] In some embodiments, the blockchain node is used to:
[0045] Receive the first asset recovery request, obtain the client list from the blockchain, where the client list includes verification addresses of multiple clients with authorization permissions for the reconfiguration operation, and the verification address of the client is generated based on the verification information and the address of the client;
[0046] Generate a verification address of the second client based on the verification information and the address of the second client corresponding to the first signature;
[0047] If the verification address of the second client is in the client list and the first signature is verified successfully based on the public key of the second client, it is determined that the first signature verification is passed.
[0048] In some embodiments, the blockchain node is configured to:
[0049] If the number of the first signatures that pass the verification is greater than or equal to the target threshold, publish first status information on the blockchain, where the first status information indicates that the blockchain asset is being restored;
[0050] If no malicious behavior report is received within the target time period, based on the reconfigured key, restore the operation permission of the first client for the blockchain asset, where the malicious behavior report indicates that the behavior of restoring the blockchain asset is a malicious behavior.
[0051] In some embodiments, a target second client among multiple second clients is configured to obtain the first status information from the blockchain within the target time period; send a notification message to the first client, where the notification message is used to notify the first client that the blockchain asset is being restored, so that the first client can determine whether the behavior of restoring the blockchain asset is a malicious behavior, and if so, send the malicious behavior report to the blockchain node.
[0052] In some embodiments, the first client is further configured to: if the key is not reconfigured and receives the notification message sent by the target second client, based on the verification information and second clients among multiple second clients other than the target second client, send the malicious behavior report to the blockchain node.
[0053] In some embodiments, the blockchain node is further configured to:
[0054] If the malicious behavior report is received within the target time period, publish second status information on the blockchain, where the second status information indicates that the restoration of the blockchain asset has been stopped.
[0055] In some embodiments, the first client is further configured to: if the first client is in an offline state, in response to the reconfiguration operation, send a second signature request to multiple second clients, where the second signature request indicates signing the reconfiguration operation, and send a second asset restoration request to the blockchain node, and the second signature request carries the verification information;
[0056] The second client is further configured to: receive the second signature request, generate a second signature, and send the second asset recovery request to the blockchain node based on the reconfigured key, the second signature, and the verification information, where the second signature indicates that the second client has authorized the first client to reconfigure the key;
[0057] The blockchain node is further configured to: receive the second asset recovery requests sent by multiple second clients, and based on the verification information, verify whether the second client corresponding to the second signature is in the client list. If the number of second signatures that pass the verification is greater than the target threshold, restore the operation permission of the first client for the blockchain asset based on the reconfigured key.
[0058] In some embodiments, the verification information includes at least one of a random number and a password.
[0059] In some embodiments, the blockchain node is configured to:
[0060] Update the address having the operation permission for the blockchain asset to the address corresponding to the reconfigured key.
[0061] In some embodiments, the first client is configured to:
[0062] In response to the reconfiguration operation, the first client sends the first signature request to multiple second clients based on the address corresponding to the key before reconfiguration and the address corresponding to the reconfigured key.
[0063] In a third aspect, an embodiment of the present application provides a blockchain asset recovery device, which is configured in a first client in a blockchain asset recovery system. The system further includes multiple second clients and a blockchain node, and a blockchain is configured on the blockchain node. The device includes at least one functional module for performing the functions of the first client in the blockchain asset recovery method provided in the foregoing first aspect or any one of the possible implementation manners of the first aspect.
[0064] In a fourth aspect, an embodiment of the present application provides a blockchain asset recovery device, which is configured in a blockchain node in a blockchain asset recovery system. The system further includes a first client and multiple second clients, and a blockchain is configured on the blockchain node. The device includes at least one functional module for performing the functions of the blockchain node in the blockchain asset recovery method provided in the foregoing first aspect or any one of the possible implementation manners of the first aspect.
[0065] Fifth aspect, an embodiment of the present application provides a blockchain asset recovery device, which is configured in a second client in a blockchain asset recovery system. The system further includes a first client and a blockchain node, and a blockchain is configured on the blockchain node. The device includes at least one functional module for performing the functions of the second client in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect.
[0066] Sixth aspect, an embodiment of the present application provides a computing device, which includes a processor and a memory. The memory is used to store at least one program code, and the at least one program code is loaded and executed by the processor to perform the functions of the first client in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect; or, the functions of the blockchain node in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect; or, the functions of the second client in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect.
[0067] Seventh aspect, an embodiment of the present application provides a computer-readable storage medium, which is used to store at least one program code, and the at least one program code is used to implement the functions of the first client in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect; or, the functions of the blockchain node in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect; or, the functions of the second client in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect. The storage medium includes but is not limited to volatile memory, such as random access memory, and non-volatile memory, such as flash memory, hard disk drive (HDD), and solid state drive (SSD).
[0068] In an eighth aspect, an embodiment of the present application provides a computer program product. When the computer program product runs on a computing device, it enables the computing device to implement the functions of the first client in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect; or, the functions of the blockchain node in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect; or, the functions of the second client in the blockchain asset recovery method provided in the foregoing first aspect or any possible implementation manner of the first aspect. The computer program product can be a software installation package. In the case where it is necessary to implement the foregoing blockchain asset recovery method, the computer program product can be downloaded and executed on the computing device. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] Figure 1 is a schematic diagram of an implementation environment provided by an embodiment of the present application;
[0070] Figure 2 is a schematic diagram of the hardware structure of a computing device provided by an embodiment of the present application;
[0071] Figure 3 is a schematic diagram of the structure of a computing device cluster provided by an embodiment of the present application;
[0072] Figure 4 is a schematic diagram of the connection method of a computing device cluster provided by an embodiment of the present application;
[0073] Figure 5 is a schematic diagram of a blockchain asset recovery method provided by an embodiment of the present application;
[0074] Figure 6 is a flowchart of a blockchain asset recovery method provided by an embodiment of the present application;
[0075] Figure 7 is a schematic diagram of another blockchain asset recovery method provided by an embodiment of the present application;
[0076] Figure 8 is a flowchart of another blockchain asset recovery method provided by an embodiment of the present application;
[0077] Figure 9 is a schematic diagram of the structure of a blockchain asset recovery device provided by an embodiment of the present application;
[0078] Figure 10 is a schematic diagram of the structure of another blockchain asset recovery device provided by an embodiment of the present application;
[0079] Figure 11It is a schematic structural diagram of another blockchain asset recovery device provided by an embodiment of the present application. Detailed implementation manners
[0080] To make the objectives, technical solutions, and advantages of the present application clearer, the embodiments of the present application will be further described in detail below in conjunction with the accompanying drawings.
[0081] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.), and signals involved in the present application are all authorized by users or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions. For example, the verification information, client list, etc. involved in the present application are obtained under full authorization.
[0082] For the convenience of understanding, the key terms and key concepts involved in the present application will be described below first.
[0083] Blockchain is a brand-new distributed infrastructure and computing paradigm that uses a block-chain data structure to verify and store data, uses a distributed node consensus algorithm to generate and update data, uses cryptography to ensure the security of data transmission and access, and uses smart contracts composed of automated script codes to program and operate data. Essentially, a blockchain is a decentralized database, a string of data blocks generated by using cryptographic methods, and each data block contains information about a batch of network transactions, which is used to verify the validity (anti-counterfeiting) of the information and generate the next block.
[0084] Non-fungible token (NFT) is a data unit on a blockchain. Each token can represent a unique digital asset as an electronic authentication or certificate of virtual commodity ownership. Due to its non-interchangeable nature, NFTs can represent digital assets such as paintings, artworks, sounds, videos, items in games, or other forms of creative works. Although the works themselves can be infinitely copied, these tokens representing them can be fully traced on their underlying blockchains, so they can provide proof of ownership for buyers. In the embodiments of the present application, they are collectively referred to as blockchain assets on the blockchain.
[0085] Smart contract is a computer protocol designed to spread, verify, or execute contracts in an information-based manner, which is embodied as an automatically executable computer program on a distributed ledger.
[0086] The application scenarios and implementation environments involved in the present application will be introduced below.
[0087] The technical solution provided by the embodiments of this application can be applied to scenarios for restoring blockchain assets on a blockchain. For example, a user operates on the blockchain assets of the user on the blockchain through a key. If the user loses the key and thus loses the operation permission for the blockchain assets, it is necessary to restore the blockchain assets to regain the operation permission for the blockchain assets. In the embodiments of this application, a method and a system for restoring blockchain assets are provided, which can ensure the security of blockchain assets while realizing the restoration of blockchain assets.
[0088] The following refers to Figure 1 to introduce the implementation environment of this application first.
[0089] Figure 1 is a schematic diagram of an implementation environment provided by the embodiments of this application. As Figure 1 shown, this implementation environment is a blockchain asset restoration system 100, which includes a first client 110, multiple second clients 120, and a blockchain node 130. A blockchain is configured on the blockchain node 130. The first client 110, the multiple second clients 120, and the blockchain node 130 are directly or indirectly connected through a wired network or a wireless network. It should be noted that in the blockchain asset restoration system 100, any form of computing device such as a server, a terminal, etc. can join the blockchain and become a certain node in the system.
[0090] The first client 110 operates on the blockchain assets of the first client 110 on the blockchain through a key. Schematically, the first client 110 runs on the terminal used by the user. For example, the terminal is a smart phone, a tablet computer, a vehicle-mounted terminal, a handheld game console, etc., and this application is not limited thereto. Schematically, the first client 110 calls the blockchain through a software development kit (SDK) / application programming interface (API) provided by the blockchain. For example, the first client 110 sends an access request for the blockchain assets to the blockchain node 130 through the SDK to realize the access to the blockchain assets. In the embodiments of this application, the key pairs of the first client 110 appear in pairs, including a private key and a public key. The private key is kept by the first client itself (or by the user himself), and the public key can be publicly announced. For blockchain assets, the owner of the blockchain assets is a string of addresses, that is, the hash value of the public key, and the private key corresponding to the public key truly owns the blockchain assets, that is, has the operation permission for the blockchain assets.
[0091] A plurality of second clients 120 are used to receive a signature request sent by the first client 110 in response to a key reconfiguration operation, generate a corresponding signature according to the signature request, and return it to the first client 110. The signature request indicates signing the reconfiguration operation. Schematically, the second client 120 runs on the terminal used by the user. For example, the terminal is a smart phone, a tablet computer, a vehicle-mounted terminal, a handheld game console, etc., and the present application is not limited thereto.
[0092] A blockchain is configured on the blockchain node 130. Schematically, the blockchain node 130 maintains the blockchain through a smart contract. For example, the smart contract includes a blockchain asset contract and a blockchain asset recovery contract. Among them, the blockchain asset contract is used to record the description information and ownership relationship of the blockchain asset. For example, the description information of the blockchain asset A indicates the content of the blockchain asset A, and the ownership relationship of the blockchain asset A indicates that the first client 110 has the operation permission for the blockchain asset A. The blockchain asset recovery contract is used to record the relevant information for recovering the blockchain asset (this part of the content will be introduced in detail in the subsequent method embodiments and will not be elaborated here). In addition, the number of blockchain nodes 130 in the present application is not limited, and the illustration in the figure is only for schematic explanation.
[0093] In some embodiments, the blockchain node 130 is an independent physical server, or a server cluster or distributed system composed of multiple physical servers. In other embodiments, the blockchain node 130 is deployed on a cloud platform, which is short for a cloud computing platform and refers to a service based on hardware resources and software resources, providing computing, network, and storage capabilities. Through the network "cloud", huge data calculations are processed remotely and then returned to the user, with characteristics such as large scale, distribution, virtualization, high availability, scalability, on-demand service, and security. The cloud platform can achieve the rapid allocation and release of configurable computing resources with a relatively small management cost or a relatively low interaction complexity between the user and the service provider. Schematically, the cloud platform is a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery network (CDN), and big data and artificial intelligence platforms, and the present application is not limited thereto.
[0094] In some embodiments, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is generally the Internet, but can also be any network, including but not limited to any combination of a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network. In some implementations, technologies and / or formats including hyper text markup language (HTML), extensible markup language (XML), etc. are used to represent the data exchanged through the network. In addition, conventional encryption technologies such as secure socket layer (SSL), transport layer security (TLS), virtual private network (VPN), internet protocol security (IPsec), etc. can also be used to encrypt all or some of the links. In other embodiments, custom and / or dedicated data communication technologies can also be used to replace or supplement the above-mentioned data communication technologies.
[0095] The hardware structure related to the above-mentioned implementation environment will be introduced below.
[0096] An embodiment of the present application provides a computing device that can be configured as any node in the above-mentioned blockchain asset recovery system.
[0097] Schematically, refer to Figure 2 , Figure 2 which is a schematic diagram of the hardware structure of a computing device provided by an embodiment of the present application. As Figure 2 shown, the computing device 200 includes a memory 201, a processor 202, a communication interface 203, and a bus 204. Among them, the memory 201, the processor 202, and the communication interface 203 are communicatively connected to each other through the bus 204.
[0098] The memory 201 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. Schematically, taking the computing device that can be configured as the first client 110 above as an example, the memory 201 is used to store at least one segment of program code. When the program code stored in the memory 201 is executed by the processor 202, the processor 202 and the communication interface 203 are used to execute the steps involved in the first client 110 in the following blockchain asset recovery method. Taking the computing device that can be configured as the second client 120 above as an example, the memory 201 is used to store at least one segment of program code. When the program code stored in the memory 201 is executed by the processor 202, the processor 202 and the communication interface 203 are used to execute the steps involved in the second client 120 in the following blockchain asset recovery method. Taking the computing device that can be configured as the blockchain node 130 above as an example, the memory 201 is used to store at least one segment of program code. When the program code stored in the memory 201 is executed by the processor 202, the processor 202 and the communication interface 203 are used to execute the steps involved in the blockchain node 130 in the following blockchain asset recovery method.
[0099] The processor 202 can be a network processor (NP), a central processing unit (CPU), an application-specific integrated circuit (ASIC), or an integrated circuit used to control the execution of the program of the solution of this application. The processor 202 can be a single-CPU processor or a multi-CPU processor. The number of the processors 202 can be one or multiple.
[0100] The communication interface 203 uses a transceiver module such as a transceiver to implement communication between the computing device 200 and other devices or communication networks. For example, data can be obtained through the communication interface 203.
[0101] Among them, the memory 201 and the processor 202 can be separately arranged or integrated together.
[0102] The bus 204 may include a path for transmitting information between various components of the computing device 200 (for example, the memory 201, the processor 202, and the communication interface 203).
[0103] The embodiment of the present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be configured as a blockchain node in the above-mentioned implementation environment. Figure 3 It is a schematic structural diagram of a computing device cluster provided by the embodiment of the present application. As Figure 3 shown, the computing device cluster includes at least one computing device 200. The same instructions for executing the blockchain asset recovery method may be stored in the memory 201 of one or more computing devices 200 in the computing device cluster. In some possible implementation manners, partial instructions for executing the blockchain asset recovery method may also be separately stored in the memory 201 of one or more computing devices 200 in the computing device cluster. In other words, a combination of one or more computing devices 200 can jointly execute the instructions of the blockchain asset recovery method. It should be noted that different instructions may be stored in the memory 201 of different computing devices 200 in the computing device cluster, respectively for executing partial functions of the blockchain node. In some embodiments, one or more computing devices in the computing device cluster can be connected through a network. Among them, the network can be a wide area network or a local area network, etc. Figure 4 It is a schematic diagram of the connection manner of a computing device cluster provided by the embodiment of the present application. As Figure 4 shown, two computing devices 200 are connected through a network. Specifically, they are connected to the network through the communication interfaces in each computing device. It should be understood that Figure 4 the functions shown in the computing device 200 can also be completed by multiple computing devices 200.
[0104] Based on the above introduction to the implementation environment of the present application, the blockchain asset recovery method provided by the present application will be introduced below.
[0105] Schematically, referring to Figure 5 , Figure 5 It is a schematic diagram of a blockchain asset recovery method provided by the embodiment of the present application. As Figure 5As shown, this blockchain asset recovery method is applied to a blockchain asset recovery system, which includes a first client, multiple second clients, and a blockchain node. A blockchain is configured on the blockchain node. The first client calls the blockchain asset contract deployed on the blockchain node through the SDK to operate on the blockchain assets (such as digital assets like videos and pictures) of the first client on the blockchain. Additionally, a blockchain asset recovery contract is deployed on the blockchain node. The first client calls this blockchain asset recovery contract through the SDK to pre-publish the client list to the blockchain. The clients indicated by the client list can authorize the first client to reconfigure the key. After the first client reconfigures the key, it requests the multiple second clients to sign the reconfiguration operation, and then calls the blockchain asset recovery contract through the SDK to recover the blockchain assets. During this process, if the first client is in an online state (i.e., there is a normal communication connection between the first client and the blockchain node), the first client can directly send an asset recovery request to the blockchain node to request the recovery of the blockchain assets; if the first client is in an offline state (i.e., the communication connection between the first client and the blockchain node is abnormal), the first client can send an asset recovery request to the blockchain node through the target second client to request the recovery of the blockchain assets, where the target second client can be understood as the second client trusted by the first client, or in other words, an honest second client. The following is through Figure 6 and Figure 8 The embodiments shown will separately introduce the above two blockchain asset recovery methods.
[0106] Figure 6 is a flowchart of a blockchain asset recovery method provided by an embodiment of this application. As shown in Figure 6 shown, this method is applied to a blockchain asset recovery system, which includes a first client, multiple second clients, and a blockchain node. A blockchain is configured on the blockchain node. Taking the interaction between each node in this system as an example for introduction, this method includes the following steps 601 to step 608.
[0107] 601. In response to the operation of publishing the client list, the first client sends a publishing request for the client list to the blockchain node. The client list indicates multiple clients that have the authorization permission for the operation of reconfiguring the key of the first client.
[0108] In the embodiments of the present application, the key is used to operate on the blockchain assets of the first client on the blockchain. That is, the first client operates on the blockchain assets of the first client on the blockchain through the key. Among them, the keys of the first client appear in pairs, including a private key and a public key. The private key is kept by the first client itself, and the public key can be made public. For blockchain assets, the owner of the blockchain assets is a string of addresses, that is, the hash value of the public key, and the private key corresponding to the public key truly owns the blockchain assets, that is, has the operation authority for the blockchain assets. Schematically, the first client runs on the terminal used by the user, and the blockchain asset contract is deployed on the blockchain node. The first client can respond to the operation performed by the user on the terminal, send a request to the blockchain node to call the blockchain asset contract, and operate on the blockchain assets of the first client on the blockchain.
[0109] Among them, a blockchain asset recovery contract is also deployed on the blockchain node, which is used to recover the blockchain assets of the client on the blockchain. For the first client, the first client pre-configures a client list, and the clients indicated by the client list have the authorization authority for the operation of reconfiguring the key of the first client. Then, in response to the publication operation of the client list, the first client sends a publication request for the client list to the blockchain node to call the blockchain asset recovery contract and publish the client list on the blockchain. Subsequently, if the first client reconfigures the key, it can realize the recovery of the blockchain assets based on the clients indicated by the client list. In other words, the clients indicated by the client list can be understood as the guardians of the blockchain assets of the first client, or the clients trusted by the first client.
[0110] In some embodiments, the client list includes verification addresses of multiple clients authorized for reconfiguration operations, and the verification address of the client is generated based on verification information and the address of the client. Among them, the verification information is generated by the first client and includes at least one of a random number (nonce) and a password. Schematically, for any client indicated by the client list, the first client concatenates the address of the client and the verification information, calculates the hash value of the concatenated content, and obtains the verification address of the client. That is to say, the verification address of the client is an anonymized address, and the first client does not publish the real addresses of these clients on the blockchain, thus ensuring the security of client information, that is, ensuring the security of guardian information. In addition, the publishing request for the client list may also carry other relevant information for blockchain asset recovery to further enhance the security of blockchain asset recovery. For example, the publishing request also carries a target threshold (used to indicate the minimum number of clients authorized to reconfigure the key, such as the target threshold k = 5, k is a positive integer), a target time period (used to indicate the protection period for blockchain asset recovery, such as the target time period t = 1 day, t is a positive integer), and so on. This application is not limited to this.
[0111] 602. The blockchain node receives the publishing request and publishes the client list on the blockchain.
[0112] In the embodiment of the present application, the blockchain node receives the publishing request, verifies the address of the first client. If the verification passes, the client list is published on the blockchain in the form of a block. For example, based on the address of the first client, the blockchain node calls the blockchain asset contract to determine whether the address of the first client matches the ownership of the blockchain asset. If it matches, it is determined that the verification passes. Of course, based on the foregoing step 601, the publishing request may also carry other relevant information for blockchain asset recovery. Similarly, the blockchain node publishes these information and the client list on the blockchain in the form of a block together. This application is not limited to this.
[0113] After the above steps 601 and 602, the first client publishes the client list on the blockchain. Subsequently, if the first client reconfigures the key, it can achieve blockchain asset recovery based on the clients indicated by the client list. This process can also be understood as the process of the first client setting guardians for the blockchain asset. The following is an example of this process: For example, the address of the first client is represented as addr alice , and the addresses of the guardians are represented as {addr 1 , …, addr n}, where n is a positive integer. The first client sets a target threshold k and a target time period t, and generates verification information (such as a random number nonce). The first client concatenates the addresses of the guardians with the verification information, calculates the hash value of the concatenated content, and generates the verification addresses of the guardians {HASH(addr 1 ||nonce), …, HASH(addr n ||nonce)}, which is also the client list list addr . Then, in response to the publishing operation of the client list, the first client sends a publishing request for the client list to the blockchain node. The publishing request carries information such as the client list, the target threshold, and the target time period. The blockchain node receives the publishing request, invokes the blockchain asset recovery contract, and publishes this information in the form of a block on the blockchain. It should be understood that if the verification information includes a random number and a password, the first client can concatenate the address of the guardian, the random number, and the password, calculate the hash value of the concatenated content, and generate the verification address of the guardian. This application is not limited to this.
[0114] Next, through steps 603 to 608, the process of the first client recovering blockchain assets by reconfiguring the key will be introduced.
[0115] 603. In response to the reconfiguration operation of the key, the first client sends a first signature request to multiple second clients. The first signature request instructs to sign the reconfiguration operation.
[0116] In the embodiment of this application, in response to the reconfiguration operation of the key, the first client generates a reconfigured key, and based on the address corresponding to the key before reconfiguration and the address corresponding to the key after reconfiguration, sends a first signature request to multiple second clients. Here, the address corresponding to the key refers to the hash value of the public key, which is also the address of the first client. Schematically, the address corresponding to the key before reconfiguration is also called the old address of the first client, and the address corresponding to the key after reconfiguration is also called the new address of the first client. The first client generates a first message based on the new address and the old address, and sends a first signature request to multiple second clients. For example, the old address of the first client is represented as addr alice , the new address is represented as addr’ alice , the first message is represented as m = addr alice ||addr’ alice . The first client can send the first signature request to the second client by sending an email or a text message, etc. This application is not limited to this.
[0117] It should be noted that in this step, the second client refers to the client that the first client believes has the authorization permission for the reconfiguration operation. It should be understood that although the first client pre-publishes the client list on the blockchain, it is possible that the first client will send the first signature request to a client that does not exist in the client list. Therefore, the object to which the first client sends the first signature request is referred to as the second client here.
[0118] 604. In response to the first signature request, the second client generates a first signature and sends the first signature to the first client, where the first signature indicates that the second client has authorized the first client to reconfigure the key.
[0119] In the embodiment of the present application, for any second client, in response to the first signature request, the second client generates a first signature based on the private key of the second client and sends the first signature to the first client. For example, taking the first signature request carrying the first message as an example, the second client signs the first message based on the private key of the second client to generate the first signature.
[0120] 605. The first client receives the first signatures generated by multiple second clients based on the first signature request.
[0121] 606. The first client sends a first asset recovery request to the blockchain node based on the reconfigured key, the verification information, and the multiple first signatures received.
[0122] In the embodiment of the present application, the first asset recovery request indicates the recovery of the blockchain assets of the first client on the blockchain, or in other words, the update of the address of the blockchain assets, so that the first client can regain the operation permission for the blockchain assets. Additionally, based on the aforementioned steps 601 and 602, the first client pre-publishes the client list on the blockchain, and the client list includes the verification addresses of multiple clients that have the authorization permission for the reconfiguration operation. The verification address of the client is generated based on the verification information and the address of the client. That is to say, the information of these clients that have the authorization permission for the reconfiguration operation is not public on the blockchain. Therefore, in this step, the first client also sends the verification information to the blockchain node to enable the blockchain node to verify the identity of the second client. That is to say, in this step, the verification information sent by the first client is used to verify whether the second client is in the client list published by the first client on the blockchain.
[0123] Schematically, the first client sends a first asset recovery request to the blockchain node based on the address corresponding to the reconfigured key (i.e., the new address of the first client), the verification information, and the multiple first signatures received. In some embodiments, the first asset recovery request further carries the address corresponding to the key before reconfiguration (i.e., the old address of the first client) and the address of the second client corresponding to the first signature.
[0124] In some embodiments, if the number of first signatures received by the first client is greater than or equal to the target threshold, the first client sends a first asset recovery request to the blockchain node. That is, after the first client receives a sufficient number of first signatures, it then sends a first asset recovery request to the blockchain node, which can improve the success rate of blockchain asset recovery and avoid the failure of blockchain asset recovery due to insufficient number of first signatures.
[0125] 607. The blockchain node receives the first asset recovery request.
[0126] 608. The blockchain node, based on the verification information, verifies whether the second client corresponding to the first signature is in the client list. If the number of verified first signatures is greater than or equal to the target threshold, it restores the operation authority of the first client for the blockchain asset based on the reconfigured key.
[0127] In the embodiments of the present application, restoring the operation authority of the first client for the blockchain asset based on the reconfigured key means that the blockchain node updates the address having the operation authority for the blockchain asset to the address corresponding to the reconfigured key, that is, updates it to the new address of the first client. It should be noted that in the embodiments of the present application, the first client does not need to recover each blockchain asset one by one. Through the above process, the blockchain node can recover all the blockchain assets of the first client on the blockchain, improving the efficiency of blockchain asset recovery. Of course, the first client can also initiate an asset recovery request for some blockchain assets to enhance the security of blockchain assets and meet personalized needs. The present application is not limited thereto.
[0128] Next, taking any one of the first signatures as an example, the process of the blockchain node verifying the first signature based on the verification information will be introduced. Schematically, this process includes the following steps A to C:
[0129] Step A. The blockchain node receives the first asset recovery request and obtains the client list from the blockchain. The client list includes the verification addresses of multiple clients having the authorization authority for the reconfiguration operation, and the verification address of the client is generated based on the verification information and the address of the client.
[0130] Among them, the first asset recovery request carries the address corresponding to the key before reconfiguration, that is, the old address of the first client. The blockchain node obtains the client list from the blockchain based on the address corresponding to the key before reconfiguration. Additionally, based on the foregoing steps 601 and 602, the first client can publish information such as the client list, the target threshold, and the target time period in the form of a block on the blockchain. For example, this information is stored in the target block. Correspondingly, in this step, the blockchain node obtains the target block from the blockchain and parses the target block to obtain information such as the client list, the target threshold, and the target time period.
[0131] Step B: The blockchain node generates a verification address for the second client based on the verification information and the address of the second client corresponding to the first signature.
[0132] Among them, the blockchain node splices the verification information with the address of the second client corresponding to the first signature, calculates the hash value of the spliced content, and generates the verification address for the second client.
[0133] Step C: If the verification address of the second client is in the client list and the verification of the first signature passes based on the public key of the second client, the blockchain node determines that the verification of the first signature passes.
[0134] Among them, the blockchain node compares the verification address of the second client with the verification addresses in the client list. If the verification address of the second client is in the client list, it indicates that the second client has the authorization permission for the reconfiguration operation. Or, the second client is the guardian set by the first client for the blockchain assets. Based on this, the blockchain node verifies the first signature based on the public key of the second client. If the verification passes, it determines that the verification of the first signature passes.
[0135] For any first signature received by the blockchain node, the blockchain node performs the verification process as shown in the above steps A to C. If the number of first signatures that pass the verification is greater than or equal to the target threshold, based on the key after reconfiguration, the operation permission of the first client for the blockchain assets is restored.
[0136] Through the above steps 603 to 608, the process of the first client restoring blockchain assets by reconfiguring the key is introduced. In some embodiments, if the number of first signatures that pass the verification is greater than or equal to the target threshold, the blockchain node sets a protection period for the blockchain assets based on the target time period to ensure the security of the blockchain assets and prevent malicious actors from maliciously restoring the blockchain assets. The following introduces this process, including the following steps 1 and 2:
[0137] Step 1. If the number of the first signatures that pass the verification is greater than or equal to the target threshold, the blockchain node publishes the first status information on the blockchain, where the first status information indicates that the blockchain assets are being restored.
[0138] After the blockchain node publishes the first status information on the blockchain, any client accessing the blockchain can timely obtain the first status information. If any one of the multiple second clients notifies the first client in a timely manner after obtaining the first status message, the first client can determine whether the current act of restoring the blockchain assets is a malicious act, or in other words, whether the current act of restoring the blockchain assets is initiated by the first client itself. Schematically, the target second client among the multiple second clients obtains the first status information from the blockchain within the target time period; the target second client sends a notification message to the first client, where the notification message is used to notify the first client that the blockchain assets are being restored, so that the first client can determine whether the act of restoring the blockchain assets is a malicious act. If so, a malicious act report is sent to the blockchain node, and the malicious act report indicates that the act of restoring the blockchain assets is a malicious act. The target time period is also the protection period of the blockchain assets preset by the first client.
[0139] Step 2. If the blockchain node does not receive a malicious act report within the target time period, based on the reconfigured key, the operation permission of the first client for the blockchain assets is restored.
[0140] If the blockchain node does not receive a malicious act report within the target time period, it indicates that the current act of restoring the blockchain assets is indeed initiated by the first client itself rather than a malicious act by a wrongdoer. Therefore, based on the reconfigured key, the operation permission of the first client for the blockchain assets is restored.
[0141] In some embodiments, if a blockchain node receives a malicious behavior report within a target time period, it publishes second status information on the blockchain, and the second status information indicates that the restoration of blockchain assets has been stopped. As can be seen from the foregoing step 1, after obtaining the first status information, the target second client will send a notification message to the first client. If the first client receives the notification message and finds that the current behavior of restoring blockchain assets is not initiated by the first client itself, the first client can send a malicious behavior report to the blockchain node to stop the blockchain node from restoring blockchain assets. It should be understood that since the notification message is sent by the target second client, it indicates that the target second client is trustworthy or honest. Based on this, the first client determines the second clients other than the target second client among the multiple second clients as malicious clients, and publishes the list of these malicious clients on the blockchain through the target second client. That is, within the target time period, any honest guardian can revoke the current blockchain asset restoration behavior, which can ensure the security of blockchain assets and achieve 1 / n security, where n is the number of guardians. Schematically, this process includes: the first client sends a forwarding request for the malicious behavior report to the target second client based on the verification information and the second clients other than the target second client among the multiple second clients. The target second client receives the forwarding request, splices the address of the target second client and the verification information, calculates the hash value of the spliced content to generate the verification address of the target second client, signs the verification address based on the private key of the target second client to generate a third signature, and sends a malicious behavior report to the blockchain node. The malicious behavior report carries the third signature and the addresses of the second clients other than the target second client among the multiple second clients. The blockchain node receives the malicious behavior report, verifies the third signature based on the public key of the target second client. If the verification passes and the verification address of the target second client is in the client list, it publishes second status information on the blockchain, and the second status information includes the addresses of the second clients other than the target second client among the multiple second clients.
[0142] In some other embodiments, if the first client does not reconfigure the key and receives a notification message sent by the target second client, the first client directly sends a malicious behavior report to the blockchain node, that is, the first client sends a malicious behavior report to the blockchain node based on the verification information and the second clients other than the target second client among the multiple second clients. Schematically, this process includes: the first client splices the address and verification information of the first client, calculates a hash value for the spliced content to generate a verification address of the first client, signs the verification address based on the private key of the first client to generate a fourth signature, and sends a malicious behavior report to the blockchain node. The malicious behavior report carries the fourth signature and the addresses of the second clients other than the target second client among the multiple second clients. The blockchain node receives the malicious behavior report, verifies the fourth signature based on the public key of the first client. If the verification passes, the second status information is published on the blockchain, and the second status information includes the addresses of the second clients other than the target second client among the multiple second clients.
[0143] After the above steps 601 to 608, the process of setting a guardian for the blockchain asset by the first client and restoring the blockchain asset by reconfiguring the key when the first client is in an online state is introduced. Next, refer to Figure 7 for an example of the above content.
[0144] Figure 7 is a schematic diagram of another blockchain asset restoration method provided by an embodiment of the present application. As Figure 7 shown, the blockchain asset restoration method is applied to a blockchain asset restoration system, which includes a first client (user), multiple second clients (taking the second clients as guardians as an example), and a blockchain node (configured with a blockchain). Schematically, the blockchain asset restoration method includes the following stages:
[0145] The first stage, the stage of setting a guardian for the blockchain asset.
[0146] At this stage, the first client pre-configures a client list, verification information, a target threshold, and a target time period. Among them, the client list indicates the anonymized identities of the guardians. In response to the publication operation of the client list, a publication request for the client list is sent to the blockchain node to invoke the blockchain asset recovery contract to publish the client list, verification information, target threshold, and target time period on the blockchain. For example, taking the verification information as the random number nonce, the first client selects n guardians, generates the random number nonce, sets the target threshold k, and the target time period t. The first client concatenates the addresses of the guardians with the random number nonce, calculates the hash value of the concatenated content, and generates the verification addresses of the guardians {HASH(addr 1 ||nonce), …, HASH(addr n ||nonce)}, that is, the client list list addr .
[0147] The above first stage is also the above steps 601 to 602, and the specific process will not be elaborated here.
[0148] The second stage: the blockchain asset recovery stage.
[0149] At this stage, if the first client key is lost, in response to the reconfiguration operation of the key, the first client generates a reconfigured key, calculates the hash value of the public key, and obtains the new address of the first client. Then, based on the new address and the old address, the first client generates a first message and sends a first signature request to multiple second clients. For example, the old address of the first client is represented as addr alice , and the new address is represented as addr’ alice , and the first message is represented as m = addr alice ||addr’ alice . The first client can send the first signature request to the second client by sending an email or a text message, etc. This application is not limited to this.
[0150] The second client receives the first signature request, signs the first message based on the private key of the second client, generates a first signature, and sends the first signature to the first client.
[0151] The first client receives the first signatures generated by multiple second clients based on the first signature request. If the number of first signatures received by the first client is greater than or equal to the target threshold, the first client sends a first asset recovery request to the blockchain node. That is, after the first client receives enough first signatures, it then sends a first asset recovery request to the blockchain node. For example, after the first client receives enough first signatures signatures = {σ 1, …, σ i |i ≥ k, i is a positive integer}, and then, based on the signature set signatures, the addresses of the second clients corresponding to the first signature {addr 1 , …, addr n}, the old address addr alice , the new address addr’, alice and the random number nonce, send a first asset recovery request to the blockchain node.
[0152] The blockchain node receives the first asset recovery request. Based on the verification information, it verifies whether the second client corresponding to the first signature is in the client list. If the number of verified first signatures is greater than or equal to the target threshold, it publishes the first status information on the blockchain, indicating that the blockchain asset is being recovered. For example, the blockchain node, based on the old address addr alice of the first client, obtains the client list list addr , the target threshold k, and the target time period t, and for any address addr 1 , …, addr n in the addresses {addr j} of the second client corresponding to the first signature, splices the random number nonce with addr j , calculates the hash value of the spliced content to obtain the corresponding verification address, determines whether the verification address is in the client list. If it is, it verifies the signature σ j using the public key corresponding to addr j . If the signature verification passes, it determines that the signature σ j verifies through, indicating that the guardian j has authorized the first client to reconfigure the key. If the number of verified signatures is greater than or equal to the target threshold k, it publishes the first status information on the blockchain and records the current time as the start time of asset recovery.
[0153] The above second stage is also the above steps 603 to 608, and the specific process will not be elaborated here.
[0154] The third stage, the blockchain asset security guarantee stage.
[0155] In this stage, after the blockchain node publishes the first status information on the blockchain, all clients connected to the blockchain can promptly learn the first status information. If the target second client among multiple second clients notifies the first client in a timely manner after obtaining the first status message, the first client can determine whether the current act of restoring blockchain assets is a malicious act, or rather, whether the current act of restoring blockchain assets is initiated by the first client itself. In this process, if the first client's key is lost, the first client designates the second clients among the multiple second clients other than the target second client as malicious clients, and through the target second client, publishes the list of these malicious clients on the blockchain, that is, sends a malicious act report to the blockchain node through the target second client. In other words, an honest guardian can assist the first client, sign the message after obtaining relevant information and send it to the blockchain node to prevent this malicious act and reveal the identities of the malicious clients. If the first client's key is not lost, the first client directly sends a malicious act report to the blockchain node, that is, the first client sends a malicious act report to the blockchain node based on the verification information and the second clients among the multiple second clients other than the target second client. Among them, the first client can use its own key to sign the message for self-verification, prevent this malicious act and reveal the identities of the malicious clients. After receiving the malicious act report, the blockchain node publishes second status information on the blockchain, which indicates that the restoration of blockchain assets has stopped. The second status information includes the addresses of the second clients among the multiple second clients other than the target second client. That is to say, within the protection period of blockchain assets, only one honest guardian is required to ensure the security of blockchain assets, achieving 1 / n security, where n is the number of guardians.
[0156] Fourth stage: The restoration of blockchain assets is completed.
[0157] In this stage, if the blockchain node does not receive a malicious act report within the target time period, based on the reconfigured key, it restores the operation authority of the first client over the blockchain assets, that is, updates the address with the operation authority over the blockchain assets to the address corresponding to the reconfigured key, that is, updates it to the new address of the first client. For example, updates the old address addr alice of the blockchain assets to the new address addr' alice .
[0158] The above-mentioned third and fourth stages are also the relevant content of the malicious act report in step 608 above, and the specific process will not be elaborated here.
[0159] In summary, in the blockchain asset recovery method provided in this application, the first client, in response to a key reconfiguration operation, requests multiple second clients to sign the reconfiguration operation to recover the blockchain assets of the first client on the blockchain. Then, the first client, based on multiple first signatures, the reconfigured key, and verification information, requests the blockchain node to restore the operation permission of the first client for the blockchain assets. Among them, the blockchain node needs to verify, according to the verification information, whether the second client corresponding to the first signature actually has the authorization permission for the reconfiguration operation, that is, the client information with the authorization permission for the reconfiguration operation is not publicly available on the blockchain. Therefore, on the basis of realizing blockchain asset recovery, the above method ensures the security of blockchain assets.
[0160] After the above Figure 6 and Figure 7 , the process of how to recover blockchain assets when the first client is in an online state has been introduced. Next, through Figure 8 , the process of how to recover blockchain assets when the first client is in an offline state will be introduced.
[0161] Figure 8 is a flowchart of another blockchain asset recovery method provided by an embodiment of this application. As Figure 8 shown, this method is applied to a blockchain asset recovery system, which includes a first client, multiple second clients, and a blockchain node. A blockchain is configured on the blockchain node. Taking the interaction between each node in this system as an example, this method includes the following steps 801 to step 807.
[0162] 801. In response to a client list publishing operation, the first client sends a publishing request for the client list to the blockchain node. The client list indicates multiple clients that have authorization permission for the operation of reconfiguring the key of the first client, and this key is used to operate the blockchain assets of the first client on the blockchain.
[0163] Among them, this step is the same as step 601 in the embodiment shown in the foregoing Figure 6 , so it will not be elaborated here.
[0164] 802. The blockchain node receives the publishing request and publishes the client list on the blockchain.
[0165] Among them, this step is the same as step 602 in the embodiment shown in the foregoing Figure 6 , so it will not be elaborated here.
[0166] 803. The first client, in response to the reconfiguration operation of the key, sends a second signature request to multiple second clients. The second signature request indicates signing the reconfiguration operation, and sends a second asset recovery request to the blockchain node. The second signature request carries verification information.
[0167] Among them, the first client is in an offline state. In response to the reconfiguration operation of the key, it generates a reconfigured key. Based on the address corresponding to the key before reconfiguration, the address corresponding to the key after reconfiguration, and the verification information, it sends a second signature request to multiple second clients. Schematically, the address corresponding to the key before reconfiguration is also called the old address of the first client, and the address corresponding to the key after reconfiguration is also called the new address of the first client. The first client generates a second message based on the new address and the old address, and sends a second signature request to multiple second clients. For example, the old address of the first client is represented as addr alice , the new address is represented as addr’ alice , and the second message is represented as m = addr alice || addr’ alice . The first client can send the second signature request to the second client by sending emails or text messages, etc. This application is not limited to this.
[0168] 804. The second client receives the second signature request and generates a second signature, which indicates that the second client has authorized the first client to reconfigure the key.
[0169] Among them, for any second client, in response to the second signature request, the second client generates a second signature based on the private key of the second client.
[0170] 805. The second client sends a second asset recovery request to the blockchain node based on the reconfigured key, the second signature, and the verification information.
[0171] For example, the second client sends a first asset recovery request to the blockchain node based on the second signature σ j , the address addr of the second client j , the old address addr alice , the new address addr’ alice and the random number nonce.
[0172] 806. The blockchain node receives the second asset recovery requests sent by multiple second clients.
[0173] 807. The blockchain node verifies whether the second client corresponding to the second signature is in the client list based on the verification information. If the number of verified second signatures is greater than or equal to the target threshold, based on the reconfigured key, the operation permission of the first client for the blockchain assets is restored.
[0174] Among them, this step is the same as step 608 in the foregoing Figure 6 illustrated embodiment, so it will not be elaborated here.
[0175] After the above steps 801 to 807, the process of how to restore blockchain assets when the first client is in an offline state is introduced. It should be understood that the principle of the above process is the same as that of the foregoing Figure 6 illustrated embodiment, that is, if the first client is in an online state, the first client can directly send an asset restoration request to the blockchain node to request the restoration of the blockchain assets; if the first client is in an offline state, the first client can send an asset restoration request to the blockchain node through the target second client to request the restoration of the blockchain assets, where the target second client can be understood as the second client trusted by the first client, or rather, an honest second client.
[0176] In summary, in the blockchain asset restoration method provided in this application, if the first client is in an offline state, the first client responds to the reconfiguration operation of the key, requests multiple second clients to sign the reconfiguration operation to restore the blockchain assets of the first client on the blockchain, and then the second client requests the blockchain node to restore the operation permission of the first client for the blockchain assets based on the second signature, the reconfigured key, and the verification information. Among them, the blockchain node needs to verify whether the second client corresponding to the second signature actually has the authorization permission for the reconfiguration operation according to the verification information, that is, the client information with the authorization permission for the reconfiguration operation is not publicly available on the blockchain. Therefore, the above method can also achieve the restoration of blockchain assets when the first client is in an offline state and ensure the security of the blockchain assets.
[0177] Figure 9 is a schematic structural diagram of a blockchain asset restoration device provided by an embodiment of this application. This blockchain asset restoration device can be implemented through software, hardware, or a combination of both to become part or all of the functions of the first client in the foregoing blockchain asset restoration system. As Figure 9 shown, this device is configured in the first client in the blockchain asset restoration system. The system further includes multiple second clients and a blockchain node, and a blockchain is configured on the blockchain node. This device includes a sending module 901 and a receiving module 902.
[0178] A sending module 901, configured to send a first signature request to multiple second clients in response to a reconfiguration operation of a key, where the key is used to operate on the blockchain assets of a first client on a blockchain, and the first signature request instructs to sign the reconfiguration operation;
[0179] A receiving module 902, configured to receive first signatures generated by multiple second clients based on the first signature request, where the first signatures indicate that the second clients have authorized the first client to reconfigure the key;
[0180] The sending module 901 is further configured to send a first asset recovery request to a blockchain node based on the reconfigured key, verification information, and the received multiple first signatures. The verification information is used to verify whether the second clients are in a client list published by the first client on the blockchain. The client list indicates multiple clients having authorization permissions for the reconfiguration operation. The first asset recovery request is used for the blockchain node to verify whether the second clients are in the client list based on the verification information. If it is determined that the number of first signatures passing the verification is greater than or equal to a target threshold, based on the reconfigured key, the operation permissions of the first client for the blockchain assets are restored.
[0181] In some embodiments, the verification information includes at least one of a random number and a password.
[0182] In some embodiments, the sending module 901 is configured to send the first signature request to multiple second clients based on the address corresponding to the key before reconfiguration and the address corresponding to the key after reconfiguration in response to the reconfiguration operation.
[0183] With the above device, the first client requests multiple second clients to sign the reconfiguration operation in response to the reconfiguration operation of the key to restore the blockchain assets of the first client on the blockchain. Then, the first client requests the blockchain node to restore the operation permissions of the first client for the blockchain assets based on the multiple first signatures, the reconfigured key, and the verification information. Among them, the blockchain node needs to verify according to the verification information whether the second clients corresponding to the first signatures really have authorization permissions for the reconfiguration operation, that is, the client information having authorization permissions for the reconfiguration operation is not publicly available on the blockchain. Therefore, the above method ensures the security of the blockchain assets while realizing the recovery of the blockchain assets.
[0184] It should be noted that when the blockchain asset recovery device provided in the above embodiments performs blockchain asset recovery, only the division of the above functional modules is used as an example for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the blockchain asset recovery device provided in the above embodiments and the embodiments of the blockchain asset recovery method belong to the same concept. For the specific implementation process, please refer to the method embodiments and will not be elaborated here.
[0185] Figure 10 FIG. 4 is a schematic structural diagram of another blockchain asset recovery device provided by an embodiment of the present application. This blockchain asset recovery device can be implemented as part or all of the functions of the blockchain node in the foregoing blockchain asset recovery system through software, hardware, or a combination of both. As Figure 10 shown, this device is configured in the blockchain node of the blockchain asset recovery system. The system further includes a first client and multiple second clients. A blockchain is configured on the blockchain node. The device includes a receiving module 1001 and an asset recovery module 1002.
[0186] The receiving module 1001 is configured to receive a first asset recovery request sent by the first client based on the reconfigured key, verification information, and multiple first signatures. The key is used to operate on the blockchain assets of the first client on the blockchain. The first signature is generated by the second client based on a first signature request sent by the first client. The first signature request instructs to sign the reconfiguration operation of the key by the first client. The verification information is used to verify whether the second client corresponding to the first signature is in the client list published by the first client on the blockchain. The client list indicates multiple clients with authorization permissions for the reconfiguration operation. The first signature indicates that the second client has authorized the first client to reconfigure the key;
[0187] The asset recovery module 1002 is configured to, based on the verification information, verify whether the second client corresponding to the first signature is in the client list. If the number of first signatures that pass the verification is greater than or equal to the target threshold, based on the reconfigured key, restore the operation permission of the first client for the blockchain assets.
[0188] In some embodiments, the asset recovery module 1002 is configured to:
[0189] Obtain the client list from the blockchain. The client list includes verification addresses of multiple clients with authorization permissions for the reconfiguration operation. The verification address of the client is generated based on the verification information and the address of the client;
[0190] Generate a verification address for the second client based on the verification information and the address of the second client corresponding to the first signature;
[0191] If the verification address of the second client is in the client list and the verification of the first signature using the public key of the second client passes, determine that the verification of the first signature passes.
[0192] In some embodiments, the asset recovery module 1002 is configured to:
[0193] If the number of verified first signatures is greater than or equal to the target threshold, publish first status information on the blockchain, where the first status information indicates that the blockchain assets are being recovered;
[0194] If no malicious behavior report is received within the target time period, restore the operation permission of the first client for the blockchain assets based on the reconfigured key, where the malicious behavior report indicates that the behavior of recovering the blockchain assets is a malicious behavior.
[0195] In some embodiments, the asset recovery module 1002 is further configured to:
[0196] If a malicious behavior report is received within the target time period, publish second status information on the blockchain, where the second status information indicates that the recovery of the blockchain assets has been stopped.
[0197] In some embodiments, the asset recovery module 1002 is configured to: Update the address with the operation permission for the blockchain assets to the address corresponding to the reconfigured key.
[0198] Through the above device, in response to the reconfiguration operation of the key, the first client requests multiple second clients to sign the reconfiguration operation to recover the blockchain assets of the first client on the blockchain. Then, the first client requests the blockchain node to restore the operation permission of the first client for the blockchain assets based on multiple first signatures, the reconfigured key, and the verification information. Among them, the blockchain node needs to verify according to the verification information whether the second client corresponding to the first signature really has the authorization permission for the reconfiguration operation, that is, the client information with the authorization permission for the reconfiguration operation is not publicly available on the blockchain. Therefore, the above method ensures the security of the blockchain assets while realizing the recovery of the blockchain assets.
[0199] In addition, in the above blockchain asset recovery device, both the receiving module 1001 and the asset recovery module 1002 can be implemented by software or can be implemented by hardware. Exemplarily, next, taking the asset recovery module 1002 as an example, the implementation manner of the asset recovery module 1002 is introduced. Similarly, the implementation manners of other modules can refer to the implementation manner of the asset recovery module 1002.
[0200] As an example of a software functional unit, the asset recovery module 1002 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the asset recovery module 1002 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers for running the code may be distributed in the same availability zone (AZ) or in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Usually, one region may include multiple AZs.
[0201] Similarly, the multiple hosts / virtual machines / containers for running the code may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is achieved through the communication gateway.
[0202] As an example of a hardware functional unit, the asset recovery module 1002 may include at least one computing device. Alternatively, the asset recovery module 1002 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0203] The multiple computing devices included in the asset recovery module 1002 can be distributed in the same region or in different regions. The multiple computing devices included in the asset recovery module 1002 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the asset recovery module 1002 can be distributed in the same VPC or in multiple VPCs. Among them, the multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0204] It should be noted that when the blockchain asset recovery device provided in the above embodiment performs blockchain asset recovery, only the above-mentioned division of each functional module is used for illustration. In actual application, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the blockchain asset recovery device provided in the above embodiment and the blockchain asset recovery method embodiment belong to the same concept. For the specific implementation process, please refer to the method embodiment, which will not be elaborated here.
[0205] Figure 11 It is a schematic structural diagram of another blockchain asset recovery device provided by an embodiment of the present application. The blockchain asset recovery device can be implemented through software, hardware, or a combination of both to become part or all of the functions of the second client in the foregoing blockchain asset recovery system. As Figure 11 shown, the device is configured in the second client in the blockchain asset recovery system. The system further includes a first client and a blockchain node, and a blockchain is configured on the blockchain node. The device includes a receiving module 1101 and a sending module 1102.
[0206] The receiving module 1101 is configured to receive a second signature request sent by the first client. The second signature request is sent by the first client when it is in an offline state in response to a key reconfiguration operation, and the second signature request instructs to sign the reconfiguration operation, and to send a second asset recovery request to the blockchain node. The second signature request carries verification information, and the verification information is used to verify whether the second client is in the client list published by the first client on the blockchain. The client list indicates multiple clients with authorization permissions for the reconfiguration operation;
[0207] A sending module 1102, configured to generate a second signature based on a second signature request, and send a second asset recovery request to a blockchain node based on the reconfigured key, the second signature, and verification information, where the second signature indicates that a second client has authorized a first client to reconfigure the key; the second asset recovery request instructs the blockchain node to verify whether the second client corresponding to the second signature is in a client list based on the verification information, and if the number of verified second signatures is greater than or equal to a target threshold, restore the operation permission of the first client for blockchain assets based on the reconfigured key.
[0208] With the above device, if the first client is in an offline state, in response to an operation of reconfiguring the key, the first client requests multiple second clients to sign the reconfiguration operation to restore the blockchain assets of the first client on the blockchain. Then, the second client requests the blockchain node to restore the operation permission of the first client for blockchain assets based on the second signature, the reconfigured key, and the verification information. Among them, the blockchain node needs to verify according to the verification information whether the second client corresponding to the second signature actually has the authorization permission for the reconfiguration operation, that is, the client information with the authorization permission for the reconfiguration operation is not publicly available on the blockchain. Therefore, the above method can also achieve the restoration of blockchain assets when the first client is in an offline state and ensure the security of blockchain assets.
[0209] It should be noted that when the above-described blockchain asset recovery device performs blockchain asset recovery, only the above-mentioned division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the above-described blockchain asset recovery device and the blockchain asset recovery method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.
[0210] In this application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions. It should be understood that there is no logical or temporal dependence between "first", "second", and "nth", nor are the quantity and execution order limited. It should also be understood that although the following description uses terms such as first and second to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various described examples, the first client can be referred to as the second client, and similarly, the second client can be referred to as the first client. The first client and the second client can both be clients, and in some cases, they can be separate and different clients.
[0211] In this application, the meaning of the term "at least one" refers to one or more, and the meaning of the term "a plurality of" refers to two or more. For example, a plurality of clients refers to two or more clients.
[0212] The above description is only a specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the claims.
[0213] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of program structure information. This program structure information includes one or more program instructions. When loading and executing these program instructions on a computing device, the processes or functions in the embodiments of this application are generated in whole or in part.
[0214] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. This program can be stored in a computer-readable storage medium. The above-mentioned storage medium can be a read-only memory, a magnetic disk, an optical disc, or the like.
[0215] As mentioned above, the above embodiments are only used to illustrate the technical solutions of this application, rather than to limit it; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent substitutions for some of the technical features; and these modifications or substitutions do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A blockchain asset recovery method, characterized in that, the method is applied to a blockchain asset recovery system, the system includes a first client, multiple second clients and a blockchain node, a blockchain is configured on the blockchain node, and the method includes: The first client responds to a reconfiguration operation of the key, and sends a first signature request to the multiple second clients. The key is used to operate the blockchain assets of the first client on the blockchain, and the first signature request instructs to sign the reconfiguration operation; The first client receives first signatures generated by the multiple second clients based on the first signature request. The first signature indicates that the second client has authorized the first client to reconfigure the key; The first client sends a first asset recovery request to the blockchain node based on the reconfigured key, verification information, and the received multiple first signatures. The verification information is used to verify whether the second client is in the client list published by the first client on the blockchain. The client list indicates multiple clients with authorization permissions for the reconfiguration operation; The blockchain node receives the first asset recovery request, and based on the verification information, verifies whether the second client corresponding to the first signature is in the client list. If the number of the first signatures that pass the verification is greater than or equal to the target threshold, based on the reconfigured key, the operation permission of the first client for the blockchain assets is restored.
2. The method according to claim 1, characterized in that, when the blockchain node receives the first asset recovery request and verifies whether the second client corresponding to the first signature is in the client list based on the verification information, it includes: The blockchain node receives the first asset recovery request, and obtains the client list from the blockchain. The client list includes verification addresses of multiple clients with authorization permissions for the reconfiguration operation. The verification address of the client is generated based on the verification information and the address of the client; The blockchain node generates a verification address of the second client based on the verification information and the address of the second client corresponding to the first signature; If the verification address of the second client is in the client list and the first signature is verified successfully based on the public key of the second client, the blockchain node determines that the first signature passes the verification.
3. The method according to claim 1 or 2, characterized in that, the step of if the number of the first signatures that pass the verification is greater than or equal to the target threshold, based on the reconfigured key, restoring the operation permission of the first client for the blockchain assets, includes: If the number of the first signatures that pass the verification is greater than or equal to the target threshold, the blockchain node publishes first status information on the blockchain, and the first status information indicates that the blockchain assets are being recovered; If the blockchain node does not receive a malicious behavior report within the target time period, based on the reconfigured key, restore the operation permission of the first client for the blockchain asset, where the malicious behavior report indicates that the behavior of restoring the blockchain asset is a malicious behavior.
4. The method according to claim 3, wherein, the method further includes: A target second client among the multiple second clients obtains the first status information from the blockchain within the target time period; The target second client sends a notification message to the first client, and the notification message is used to notify the first client that the blockchain asset is being restored, so that the first client determines whether the behavior of restoring the blockchain asset is a malicious behavior, and if so, sends the malicious behavior report to the blockchain node.
5. The method according to claim 4, wherein, the method further includes: If the first client does not reconfigure the key and receives the notification message sent by the target second client, the first client sends the malicious behavior report to the blockchain node based on the verification information and the second clients among the multiple second clients except the target second client.
6. The method according to claim 3, wherein, the method further includes: If the blockchain node receives the malicious behavior report within the target time period, publish second status information on the blockchain, where the second status information indicates that the restoration of the blockchain asset has been stopped.
7. The method according to claim 1 or 2, wherein, the method further includes: If the first client is in an offline state, the first client responds to the reconfiguration operation, sends a second signature request to the multiple second clients, the second signature request indicates signing the reconfiguration operation, and sends a second asset restoration request to the blockchain node, and the second signature request carries the verification information; The second client receives the second signature request, generates a second signature, and based on the reconfigured key, the second signature, and the verification information, sends the second asset restoration request to the blockchain node, where the second signature indicates that the second client has authorized the first client to reconfigure the key; The blockchain node receives the second asset restoration requests sent by the multiple second clients, and based on the verification information, verifies whether the second client corresponding to the second signature is in the client list. If the number of the second signatures that pass the verification is greater than the target threshold, based on the reconfigured key, restore the operation permission of the first client for the blockchain asset.
8. The method according to claim 1 or 2, wherein, the verification information includes at least one of a random number and a password.
9. The method according to claim 1 or 2, wherein, Restoring the operation authority of the first client for the blockchain asset based on the reconfigured key includes: Updating the address with operation authority for the blockchain asset to the address corresponding to the reconfigured key.
10. The method according to claim 1 or 2, characterized in that in response to the reconfiguration operation of the key, the first client sends a first signature request to a plurality of the second clients, including: In response to the reconfiguration operation, the first client sends the first signature request to a plurality of the second clients based on the address corresponding to the key before reconfiguration and the address corresponding to the key after reconfiguration.
11. A blockchain asset restoration system, characterized in that the system includes a first client, a plurality of second clients, and a blockchain node, and a blockchain is configured on the blockchain node; The first client is used for: In response to the reconfiguration operation of the key, sending a first signature request to a plurality of the second clients, where the key is used to operate the blockchain asset of the first client on the blockchain, and the first signature request instructs to sign the reconfiguration operation; Receiving first signatures generated by the plurality of second clients based on the first signature request, where the first signatures indicate that the second clients have authorized the first client to reconfigure the key; Based on the reconfigured key, verification information, and the received plurality of first signatures, sending a first asset restoration request to the blockchain node, where the verification information is used to verify whether the second client is in the client list published by the first client on the blockchain, and the client list indicates a plurality of clients with authorization authority for the reconfiguration operation; The blockchain node is used for: Receiving the first asset restoration request, verifying based on the verification information whether the second client corresponding to the first signature is in the client list, and if the number of the first signatures passing the verification is greater than or equal to the target threshold, restoring the operation authority of the first client for the blockchain asset based on the reconfigured key.
12. A blockchain asset restoration device, characterized in that the device is configured in the first client of the blockchain asset restoration system, the system further includes a plurality of second clients and a blockchain node, and a blockchain is configured on the blockchain node, and the device includes: A sending module, used for, in response to the reconfiguration operation of the key, sending a first signature request to a plurality of the second clients, where the key is used to operate the blockchain asset of the first client on the blockchain, and the first signature request instructs to sign the reconfiguration operation; A receiving module, used for receiving first signatures generated by the plurality of second clients based on the first signature request, where the first signatures indicate that the second clients have authorized the first client to reconfigure the key; The sending module is further configured to send a first asset recovery request to the blockchain node based on the reconfigured key, the verification information, and the multiple received first signatures. The verification information is used to verify whether the second client is in the client list published by the first client on the blockchain. The client list indicates multiple clients with authorization permissions for the reconfiguration operation. The first asset recovery request is used for the blockchain node to verify whether the second client is in the client list based on the verification information. If the number of the first signatures that pass the verification is greater than or equal to the target threshold, the blockchain node restores the operation permission of the first client for the blockchain asset based on the reconfigured key.
13. A blockchain asset recovery device, characterized in that, the device is configured in a blockchain node in a blockchain asset recovery system. The system further includes a first client and multiple second clients. A blockchain is configured on the blockchain node. The device includes: a receiving module, configured to receive a first asset recovery request sent by the first client based on a reconfigured key, verification information, and multiple first signatures. The key is used to operate on the blockchain assets of the first client on the blockchain. The first signature is generated by the second client based on a first signature request sent by the first client. The first signature request indicates signing for the reconfiguration operation of the key by the first client. The verification information is used to verify whether the second client corresponding to the first signature is in the client list published by the first client on the blockchain. The client list indicates multiple clients with authorization permissions for the reconfiguration operation. The first signature indicates that the second client has authorized the first client to reconfigure the key; an asset recovery module, configured to verify whether the second client corresponding to the first signature is in the client list based on the verification information. If the number of the first signatures that pass the verification is greater than or equal to the target threshold, the operation permission of the first client for the blockchain asset is restored based on the reconfigured key.
14. A blockchain asset recovery device, characterized in that, the device is configured in a second client in a blockchain asset recovery system. The system further includes a first client and a blockchain node. A blockchain is configured on the blockchain node. The device includes: A receiving module, configured to receive a second signature request sent by the first client. The second signature request is sent by the first client in an offline state in response to a key reconfiguration operation, and the second signature request indicates signing the reconfiguration operation. The receiving module is further configured to send a second asset recovery request to the blockchain node. The second signature request carries verification information, which is used to verify whether the second client is in the client list published by the first client on the blockchain. The client list indicates multiple clients that have authorization permissions for the reconfiguration operation. A sending module, configured to generate a second signature based on the second signature request, and send the second asset recovery request to the blockchain node based on the reconfigured key, the second signature, and the verification information. The second signature indicates that the second client has authorized the first client to reconfigure the key. The second asset recovery request instructs the blockchain node to verify whether the second client corresponding to the second signature is in the client list based on the verification information. If the number of verified second signatures is greater than or equal to a target threshold, the blockchain node restores the operation permission of the first client for the blockchain asset based on the reconfigured key.
15. A computing device, characterized in that, the computing device includes a processor and a memory. The memory is used to store at least one program code segment, and the at least one program code segment is loaded and executed by the processor to perform the steps executed by the first client in the blockchain asset recovery method according to any one of claims 1 to 10; or, the steps executed by the second client in the blockchain asset recovery method according to any one of claims 1 to 10; or, the steps executed by the blockchain node in the blockchain asset recovery method according to any one of claims 1 to 10.
16. A computer-readable storage medium, characterized in that, the computer-readable storage medium is used to store at least one program code segment, and the at least one program code segment is used to perform the steps executed by the first client in the blockchain asset recovery method according to any one of claims 1 to 10; or, the steps executed by the second client in the blockchain asset recovery method according to any one of claims 1 to 10; or, the steps executed by the blockchain node in the blockchain asset recovery method according to any one of claims 1 to 10.
17. A computer program product, characterized in that, when the computer program product runs on a computing device, it causes the computing device to perform the steps executed by the first client in the blockchain asset recovery method according to any one of claims 1 to 10; or, the steps executed by the second client in the blockchain asset recovery method according to any one of claims 1 to 10; or, the steps executed by the blockchain node in the blockchain asset recovery method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Method for recovering blockchain assets through smart contract, wallet and blockchain node
CN111369242A
Systems and methods for addressing security-related vulnerabilities arising in relation to off-blockchain channels in the event of failures in a network
US20200213085A1