Blockchain-based data processing method, apparatus, device, medium, and product
By generating selectively disclosed object verification data in the blockchain network and using Merkle trees and obfuscated data to protect object information, the problem of insufficient data security in the object verification process is solved, and more secure object verification is achieved.
Patent Information
- Application Number
- CN202210036846.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-13
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2042-01-13
AI Technical Summary
In blockchain networks, the exposure of object information during object verification leads to insufficient data security, and existing technologies are unable to effectively protect object data security.
By selectively disclosing object verification data, object verification data (VP data) is generated, disclosing only the information of objects that need to be verified while hiding the information that is not selected, thus protecting data security by using Merkle trees and obfuscated data.
It enables the selective disclosure of object information during object verification, improving data security, protecting the privacy of object data, and enhancing the security of the verification process.
Smart Images

Figure CN116488817B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computers, and particularly relates to a data processing method and device based on a blockchain, equipment, a medium and a product. BACKGROUND
[0002] With the rapid development of the blockchain technology, the object verification mode in the blockchain network gradually evolves from centralization to decentralization. In a DID (Decentralized ID) verification system, each object can be a Holder of its own object information, and manages the object information by VC (Verifiable Claims) data. In the DID verification process of the DID verification system, the Holder can generate VP (Verifiable Presentation) data according to the VC data, and the Verifier can verify the object by the VP data. In the above DID verification process, the object information is contained in the VC data and the VP data, and the object information is exposed in the DID verification process, which is not conducive to protecting the data security of the object in the object verification process. SUMMARY
[0003] The embodiments of the present application provide a data processing method and device based on a blockchain, equipment, a medium and a product, which can selectively disclose object information used for object verification, and is conducive to protecting the data security of the object in the object verification process.
[0004] In one aspect, the embodiments of the present application provide a data processing method based on a blockchain, which comprises the following steps.
[0005] Obtaining object claim data of a target object, the object claim data comprising object information of the target object, the object information comprising M target data, M being an integer greater than 1; determining a data set according to the object claim data, the data set comprising object data pairs, each object data pair comprising a target data and verification data of the target data, N target data in the data set being selected and determined from the M target data, N being a positive integer less than or equal to M; generating object verification data of the target object according to the data set, the object verification data comprising the object data pairs; submitting verification expression data corresponding to the object verification data, the verification expression data comprising a to-be-verified object data pair; wherein, in the verification process, if a verification hash matching a root hash corresponding to the target object is obtained according to the target data in the to-be-verified object data pair and the verification data of the target data, it is determined that the target object is verified.
[0006] In the embodiments of the present application, object declaration data (also referred to as VC data) of a target object can be acquired, the object declaration data can include object information of the target object, and the object information can include M target data. Then, a data set can be determined according to the object declaration data, object verification data (also referred to as VP data) of the target object can be generated according to the data set, and verification expression data corresponding to the object verification data can be submitted. The verification expression data can be used for object verification of the target object, and N target data in the data set can be selected and determined from the M target data. That is, the object information to be verified can be selected from the object information of the target object to generate the verification expression data used for object verification, and other unselected object information will not be disclosed in the verification expression data, that is, the object information used for object verification can be selectively disclosed, which is beneficial to protecting the data security of the object in the object verification process.
[0007] In another aspect, the embodiments of the present application provide another data processing method based on a block chain, which comprises:
[0008] Verification expression data submitted by a holding node is acquired. The verification expression data corresponds to object verification data generated by the holding node, and includes object data pairs to be verified. Verification hashes of the object data pairs to be verified are determined according to target data in the object data pairs to be verified and verification data of the target data. If the verification hashes of the object data pairs to be verified match root hashes corresponding to a target object, it is determined that the target object passes the verification. The object verification data is generated according to a data set, and the data set is determined according to object information of the target object included in object declaration data of the target object. The object information includes M target data. The data set includes object data pairs, each object data pair includes a target data and verification data of the target data, N target data in the data set is selected and determined from the M target data, M is an integer greater than 1, and N is a positive integer less than or equal to M.
[0009] In the embodiments of the present application, the verification expression data submitted by the holding node can be obtained, the verification expression data corresponds to the object verification data (also referred to as VP data) generated by the holding node, the object verification data can be generated according to a data set, the data set can be determined according to the object declaration data (also referred to as VC data) of the target object, each object data pair in the data set can include a target data and verification data of the target data, and N target data in the data set can be determined from M target data included in the object declaration data. Then, the to-be-verified object data pair can be included in the verification expression data, and the target object can be verified according to the target data in the to-be-verified object data pair and the verification data of the target data. It can be seen that the verification expression data used for object verification discloses the object information to be verified selected from the object information of the target object, and other object information not selected is not disclosed in the verification expression data. In this way, the object information used for object verification can be selectively disclosed, which is beneficial to protecting the data security of the object in the object verification process.
[0010] Correspondingly, the present application provides a data processing device based on a block chain, which comprises:
[0011] An acquisition unit is configured to acquire object declaration data of a target object, the object declaration data including object information of the target object, the object information including M target data, M being an integer greater than 1; and determine a data set according to the object declaration data, the data set including object data pairs, each object data pair including a target data and verification data of the target data, N target data in the data set being determined from the M target data, N being a positive integer less than or equal to M.
[0012] A processing unit is configured to generate object verification data of the target object according to the data set, the object verification data including the object data pairs; and submit verification expression data corresponding to the object verification data, the verification expression data including to-be-verified object data pairs; wherein, in the process of object verification, if a verification hash matching a root hash corresponding to the target object is obtained according to the target data in the to-be-verified object data pair and the verification data of the target data, it is determined that the target object passes the verification.
[0013] In an implementation manner, the number of the object data pairs is N, an i-th object data pair in the N object data pairs comprises i-th target data and verification data of the i-th target data; the verification data of the i-th target data comprises: confusion data allocated for the i-th target data in a Merkle tree of a target object, and verification information corresponding to the i-th target data determined in the Merkle tree of the target object; the Merkle tree of the target object is determined according to M target data, i is a positive integer less than or equal to N; wherein the confusion data is used to calculate data hash corresponding to the i-th target data in combination with the i-th target data; and the verification information corresponding to the i-th target data is used to calculate verification hash of the i-th object data pair in combination with the data hash corresponding to the i-th target data.
[0014] In an implementation manner, the object verification data further comprises: root hash corresponding to the target object and root signature corresponding to the target object; the root hash corresponding to the target object is determined in the Merkle tree of the target object, the root signature corresponding to the target object is obtained by encrypting the root hash corresponding to the target object by using a private key of a generation node generating the object declaration data, and the root signature corresponding to the target object is used to verify the root hash corresponding to the target object; after the root hash corresponding to the target object is verified by using the root signature corresponding to the target object, the root hash corresponding to the target object is used to verify the verification hash of the object data pair in the object verification data.
[0015] In an implementation manner, the number of the object data pairs is N; the processing unit is configured to determine the data set according to the object declaration data, and specifically configured to perform the following steps:
[0016] receiving an object verification request sent by a verification node, the object verification request carrying an object data type requested to be verified; selecting N target data matched with the object data type from the M target data according to the indication of the object data type; obtaining verification data of each target data in the N target data; and determining N object data pairs according to the N target data and the verification data of each target data.
[0017] In an implementation manner, the number of the object data pairs is N, and the data set comprises the N object data pairs; the processing unit is configured to determine the data set according to the object declaration data, and specifically configured to perform the following steps:
[0018] displaying an object information selection interface, and displaying the M target data in the object information selection interface; in response to a selection operation on the M target data in the object information selection interface, determining N target data selected by the selection operation; obtaining verification data of each target data in the N target data; and determining N object data pairs according to the N target data and the verification data of each target data.
[0019] In an implementation manner, the processing unit is further configured to perform the following steps:
[0020] The object declaration obtaining request is used to trigger the issuing node to obtain the object document of the target object based on the object identifier of the target object for verification, and generate the object declaration data of the target object according to the object information of the target object and output the object declaration data after the object document of the target object is verified.
[0021] In an implementation manner, the processing unit is further configured to perform the following steps when submitting the verification expression data corresponding to the object verification data:
[0022] The verification expression data is uploaded to the blockchain, and the verification node is set as a visible node of the verification expression data in the blockchain, where the visible node of the verification expression data refers to a node that is allowed to obtain the verification expression data from the blockchain.
[0023] Correspondingly, the embodiment of the application provides another data processing apparatus based on a blockchain, which comprises:
[0024] The obtaining unit is configured to obtain the verification expression data submitted by the holding node, the verification expression data corresponding to the object verification data generated by the holding node, and the verification expression data comprising an object data pair to be verified.
[0025] The processing unit is configured to determine a verification hash of the object data pair to be verified according to the target data in the object data pair to be verified and the verification data of the target data, and determine that the target object is verified if the verification hash of the object data pair to be verified matches a root hash corresponding to the target object.
[0026] The object verification data is generated according to a data set, the data set is determined according to object information of the target object included in the object declaration data of the target object, the object information comprises M target data, the data set comprises object data pairs, each object data pair comprises a target data and verification data of the target data, N target data in the data set is selected and determined from the M target data, M is an integer greater than 1, and N is a positive integer less than or equal to M.
[0027] In an implementation manner, the number of the object data pairs to be verified is N, and the verification expression data comprises the N object data pairs to be verified; the verification expression data further comprises a root hash corresponding to the target object and a root signature corresponding to the target object; the root signature corresponding to the target object is obtained by encrypting the root hash corresponding to the target object by using a private key of the issuing node generating the object declaration data; and the processing unit is further configured to perform the following steps:
[0028] The root signature corresponding to the target object is decrypted using the public key of the issuing node to obtain a decrypted hash corresponding to the target object; if the decrypted hash corresponding to the target object matches the root hash corresponding to the target object, it is determined that the root hash corresponding to the target object is verified; wherein, after the root hash corresponding to the target object is verified, the verification hash of the to-be-verified object data pair matches the root hash corresponding to the target object, which means that the verification hashes of the N to-be-verified object data pairs all match the root hash corresponding to the target object.
[0029] In an implementation manner, before the processing unit decrypts the root signature corresponding to the target object using the public key of the issuing node to obtain a decrypted hash corresponding to the target object, the processing unit further performs the following steps:
[0030] Obtain the first signature information generated by the holding node, the second signature information generated by the issuing node, and the object document of the target object, the first signature information being obtained by encrypting the verification expression data using the private key of the target object, the second signature information being obtained by encrypting the object declaration data using the private key of the issuing node, and the object document of the target object containing the public key of the target object; if the first signature information is verified using the public key of the target object, obtain the object document of the issuing node; the object document of the issuing node includes the public key of the issuing node; if it is determined that the object document of the issuing node is issued according to the trusted identifier in the trusted list, verify the second signature information according to the public key of the issuing node; if the second signature information is verified, trigger the step of decrypting the root signature corresponding to the target object using the public key of the issuing node to obtain a decrypted hash corresponding to the target object.
[0031] In an implementation manner, the number of to-be-verified object data pairs is N, and the verification expression data includes N to-be-verified object data pairs; the root hash corresponding to the target object is uploaded to the blockchain for storage; the processing unit further performs the following steps:
[0032] Obtain the root hash corresponding to the target object from the blockchain; wherein, the verification hash of the to-be-verified object data pair matches the root hash corresponding to the target object, which means that the verification hashes of the N to-be-verified object data pairs all match the root hash corresponding to the target object.
[0033] In an implementation manner, the number of the to-be-verified object data pairs is N, the verification expression data includes the N to-be-verified object data pairs; an i-th to-be-verified object data pair in the N to-be-verified object data pairs includes an i-th target data and verification data of the i-th target data, i is a positive integer less than or equal to N; the verification data of the i-th target data includes: confusion data allocated for the i-th target data in a Merkle tree of a target object, and verification information corresponding to the i-th target data determined in the Merkle tree of the target object; the Merkle tree of the target object is determined according to M target data; the processing unit is configured to determine a verification hash of the i-th to-be-verified object data pair according to the i-th target data and the verification data of the i-th target data, and specifically configured to perform the following steps:
[0034] splicing the confusion data and the i-th target data to obtain splicing data; performing hash calculation on the splicing data to obtain a data hash corresponding to the i-th target data; and calculating the verification hash of the i-th to-be-verified object data pair according to the data hash corresponding to the i-th target data and the verification information corresponding to the i-th target data.
[0035] Correspondingly, an embodiment of the present application provides a computer device, which comprises a processor and a computer readable storage medium; wherein the processor is adapted to implement a computer program, the computer readable storage medium stores a computer program, and the computer program is adapted to be loaded and executed by the processor to perform the above-mentioned data processing method based on a block chain.
[0036] Correspondingly, an embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is read and executed by a processor of a computer device to make the computer device perform the above-mentioned data processing method based on a block chain.
[0037] Correspondingly, an embodiment of the present application provides a computer program product or a computer program, which comprises computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to make the computer device perform the above-mentioned data processing method based on a block chain.
[0038] In the embodiment of the present application, object verification data can be generated according to selectively disclosed object information, and then object verification can be performed according to selectively disclosed object information in verification expression data corresponding to the object verification data, and unselected object information is hidden in the object verification process, which is beneficial to protecting the data security of the object in the object verification process. BRIEF DESCRIPTION OF DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, the accompanying drawings in the following description only constitute some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.
[0040] Figure 1 is a structural schematic diagram of a blockchain provided by an embodiment of the present application;
[0041] Figure 2 is a structural schematic diagram of a Merkle tree provided by an embodiment of the present application;
[0042] Figure 3 is a structural schematic diagram of a blockchain network provided by an embodiment of the present application;
[0043] Figure 4 is a structural schematic diagram of another Merkle tree provided by an embodiment of the present application;
[0044] Figure 5a is a schematic diagram of a derivation process of obfuscated data provided by an embodiment of the present application;
[0045] Figure 5b is a schematic diagram of another derivation process of obfuscated data provided by an embodiment of the present application;
[0046] Figure 5c is a schematic diagram of another derivation process of obfuscated data provided by an embodiment of the present application;
[0047] Figure 6 is a flowchart of a data processing method based on a blockchain provided by an embodiment of the present application;
[0048] Figure 7a is a flowchart of an issuing process of an object document provided by an embodiment of the present application;
[0049] Figure 7b is a flowchart of a generation process of object declaration data provided by an embodiment of the present application;
[0050] Figure 7c is a schematic diagram of an object information selection interface provided by an embodiment of the present application;
[0051] Figure 7d is a flowchart of a generation process of object verification data provided by an embodiment of the present application;
[0052] Figure 8 is a flowchart of another data processing method based on a blockchain provided by an embodiment of the present application;
[0053] Figure 9 is a flowchart of an object verification process provided by an embodiment of the present application;
[0054] Figure 10 is a scenario diagram of a data processing scenario based on a blockchain provided by an embodiment of the present application;
[0055] Figure 11 is a structural diagram of a data processing apparatus based on a blockchain provided by an embodiment of the present application;
[0056] Figure 12 is a structural diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0057] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.
[0058] In order to more clearly understand the technical solutions provided by the embodiments of the present application, the key terms related to the embodiments of the present application are introduced first:
[0059] (1) Blockchain. Blockchain is a new application mode of distributed data storage, peer-to-peer transmission, consensus mechanism, encryption algorithm and other computer technologies. Blockchain is essentially a decentralized database, which is a chain of blocks associated using cryptographic methods. Each block contains information about a batch of network transactions, which is used to verify the validity (anti-fake) of the information and generate the next block. As shown in Figure 1 , the blockchain is composed of multiple blocks. The genesis block includes a block header and a block body. The block header stores input information characteristic values, version numbers, timestamps and difficulty values. The block body stores input information. The next block of the genesis block takes the genesis block as the parent block. The next block also includes a block header and a block body. The block header stores the input information characteristic values of the current block, the block header characteristic values of the parent block, the version number, the timestamp and the difficulty value. This is done recursively, so that the block data stored in each block in the blockchain is associated with the block data stored in the parent block, ensuring the security of the input information in the block.
[0060] (2) DID verification system. The DID verification system and the PKI (Public Key Infrastructure) verification system are two concepts in relative existence. The PKI verification system is a centralized object verification system, and the PKI verification system can centrally control each object in the system; specifically, the PKI verification system can control the object information of each object in the PKI verification system by a trusted third-party authority object (for example, a CA (Certificate Authority)). The DID verification system is a decentralized object verification system, and the DID verification system controls each object in the system in a decentralized manner; specifically, the object information of each object in the DID verification system is not controlled by a trusted third-party authority object, but is controlled by each object independently.
[0061] The DID verification system can assign each object in the DID verification system DID identification data, and the DID identification data can include a DID identification and a DID document (DIDDocument) associated with the DID identification. The DID identification of any object can uniquely identify the object in the DID verification system, and the DID document of any object can be an identification description document of the object in the DID verification system. The DID document of any object can include, but is not limited to, the DID identification of the object, the public key of the object, the DID identification of the issuer of the DID document of the object, and the signature information of the issuer. It should be noted that the DID verification system can also maintain a trusted list, and the trusted list can include DID identifications trusted by the DID verification system. The owners of these trusted DID identifications can issue DID documents for objects in the DID verification system, that is, the owners of the trusted DID identifications in the trusted list can act as issuers of the DID document, and the DID document issued by the trusted issuer is considered to be trusted in the DID verification system.
[0062] In addition, three important objects can be included in the DID verification system, which are Issuer (issuer), Holder (holder) and Verifier (verifier). The three types of objects are introduced as follows: 1. Issuer is the issuer of VC data. An object in the DID verification system can request the Issuer to generate VC data, and the Issuer can generate VC data of the object according to the object information of the object. 2. Holder is the holder of VC data. After an object in the DID verification system requests the Issuer to generate VC data, the object can obtain the generated VC data, and the object becomes the holder of the VC data. The Holder can also generate VP data according to the VC data. 3. Verifier is the verifier of VP data. The Verifier can obtain the VP data generated by the Holder and verify the VP data to verify the object of the Holder generating the VP data. It should be noted that the DID verification system can be understood as a blockchain network. The nodes used by the Holder and the Verifier are usually deployed as SPV (Simplified Payment Verification) nodes in the blockchain network. The SPV node can also be called a light node, which can synchronize all block headers and visible transaction data from the blockchain. Based on the above concept of SPV node, in addition to uploading the VC data to the blockchain, the Issuer can also set the VC data visible to the Holder of the VC data on the blockchain. In this way, during data clearing, the Holder can obtain the VC data visible to the Holder from the blockchain. The so-called data clearing refers to the process of synchronizing block headers and visible transaction data from the blockchain by the SPV node. Similarly, in addition to uploading the VP data of an object to the blockchain, the Holder can also set the VP data visible to the Verifier of the VP data on the blockchain. In this way, during data clearing, the Verifier can obtain the VP data visible to the Verifier from the blockchain.
[0063] (3) VC data. The VC data of the Holder is a file endorsed by the object information of the Holder given by the Issuer, and the VC data of the Holder can be used to declare the object information of the Holder. Generally, the VC data can include but is not limited to: issuance related data, declaration data, proof data, etc.; wherein the issuance related data can include but is not limited to: the issuance time of the VC data, the unique identifier of the VC data, the information of the Issuer, etc.; the declaration data can include but is not limited to: the DID identifier of the Holder, the object information of the Holder, etc.; the proof data in the VC data can be used to verify the VC data, and can include but is not limited to: the public key of the Issuer, the signature of the Issuer on the declaration data (for example, the signature of the Issuer on the declaration data by using the private key of the Issuer).
[0064] (4) VP data. The VP data refers to a file encrypted by the Holder on the VC data (for example, a file encrypted by the Holder on the VC data by using the private key of the Holder), and the VP data can be used to verify the object of the Holder. Generally, the VP data can include but is not limited to: VC data and proof data; wherein the proof data in the VP data can be used to verify the VP data, and can include but is not limited to: the public key of the Holder, the signature of the Holder on the VC data (for example, the signature of the Holder on the VC data by using the private key of the Holder).
[0065] (5) MerkleTree. MerkleTree is a tree data structure based on a hash algorithm, and MerkleTree can be a M-ary tree, M can be an integer greater than or equal to 2, and the common structure of MerkleTree is a binary tree. Taking a binary tree as an example below, Figure 2The illustrated MerkleTree is introduced as an example. N0, N1, N2, and N3 are four leaf nodes of the MerkleTree, and D0, D1, D2, and D3 are the underlying data of the four leaf nodes, respectively. The node value corresponding to the N0 node can be a hash value obtained by performing hash calculation on D0 using a hash algorithm. The node value corresponding to the N1 node can be a hash value obtained by performing hash calculation on D1 using a hash algorithm. Similarly, the node value corresponding to the N2 node and the node value corresponding to the N3 node can be calculated. N4 and N5 are intermediate nodes of the MerkleTree. The node value corresponding to the N4 node can be a hash value obtained by performing hash calculation on N0+N1 using a hash algorithm. The node value corresponding to the N5 node can be a hash value obtained by performing hash calculation on N2+N3 using a hash algorithm. N0+N1 means concatenating N0 and N1. Root represents the root node of the MerkleTree. The node value corresponding to the Root node can be a hash value obtained by performing hash calculation on N4+N5 using a hash algorithm, which can be referred to as the root hash of the MerkleTree.
[0066] The data verification process in the MerkleTree can be seen from the following description: when the underlying data of the MerkleTree needs to be verified, the underlying data to be verified, the index data corresponding to the underlying data in the MerkleTree, the verification path corresponding to the underlying data in the MerkleTree, and the root hash of the MerkleTree can be obtained. Then, the verification hash corresponding to the underlying data can be calculated according to the underlying data to be verified, the index data corresponding to the underlying data, and the verification path corresponding to the underlying data. If the verification hash corresponding to the underlying data matches the root hash of the MerkleTree (i.e., the verification hash corresponding to the underlying data is the same as the root hash of the MerkleTree), it can be considered that the underlying data is verified. For example, if the underlying data D0 needs to be verified, the index data corresponding to D0 in the MerkleTree, the verification path corresponding to D0 in the MerkleTree, and the root hash of the MerkleTree can be obtained. Then, the verification hash corresponding to D0 can be calculated according to D0, the index data corresponding to D0, and the verification path corresponding to D0. If the verification hash corresponding to D0 matches the root hash of the MerkleTree, it can be considered that D0 is verified. Figure 2If the verification of the basic data D1 in the MerkleTree is passed, the index data 1 corresponding to D1 in the MerkleTree (for example, the index data of D0, D1, D2 and D3 from left to right are 0, 1, 2 and 3 respectively), the verification path [N0, N5] corresponding to D1 in the MerkleTree, and the node value corresponding to the root node (that is, the root hash of the MerkleTree) can be obtained. Then, if the verification hash corresponding to D1 calculated according to D1, the index data 1 corresponding to D1, the verification path [N0, N5] corresponding to D1 is the same as the node value corresponding to the root node, it can be determined that the verification of D1 is passed. The hash algorithm can include but is not limited to MD (Message-Digest Algorithm, message digest algorithm) 4, MD5, SHA (Secure Hash Algorithm, secure hash algorithm) 1, SHA256, SHA512 algorithm, etc., which is not limited in the embodiment of the application.
[0067] Based on the above description of the key terms, the embodiment of the application provides a data processing scheme based on a block chain. The data processing scheme based on the block chain improves the existing DID verification process. The improved DID verification process can be referred to the following description: first, the object information of the target object in the DID verification system can include multiple target data. In the process of generating the VC data of the target object according to the object information of the target object, the Issuer can generate the MerkleTree of the target object based on the object information of the target object, and generate the VC data of the target object based on the generated MerkleTree and the object information of the target object. Second, based on the VC data of the target object, the Holder (here, the Holder is the target object) can select the target data used for object verification of the target object from the object information contained in the VC data of the target object, and generate the VP data according to the selected target data and the verification data (for example, the verification path, the root hash of the MerkleTree, etc. mentioned above) of the selected target data in the MerkleTree of the target object. Then, the Verifier can perform object verification on the target object based on the selected target data and the verification data of the selected target data contained in the VP data. It is not difficult to see that in the improved DID verification process, the target data to be verified is disclosed in the VP data, and the target data not to be verified is hidden in the VP data. In this way, the object information used for DID verification can be selectively disclosed, which is beneficial to protecting the data security of the object in the DID verification process and improving the security of the DID verification process.
[0068] The data processing scheme based on the block chain provided by the embodiment of the application can be used in the DID verification process. Figure 3The illustrated blockchain network 30 is implemented, which can include at least an issuing node 301, a holding node 302, and a verifying node 303. The issuing node 301, the holding node 302, and the verifying node 303 can establish a direct communication connection through wired communication or an indirect communication connection through wireless communication. It should be noted that the number of the issuing node 301, the holding node 302, and the verifying node 303 is not limited in the embodiments of the present application, Figure 3 The blockchain network 30 illustrated includes one issuing node 301, one holding node 302, and one verifying node 303, which are only used for example. In the actual DID verification scenario, the blockchain network 30 can include one or more issuing nodes 301, one or more holding nodes 302, and one or more verifying nodes 303.
[0069] Any node in the blockchain network 30 can be a terminal or a server. The terminal mentioned in the embodiments of the present application can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, a vehicle terminal, a smart television, and the like, but is not limited thereto. The server mentioned in the embodiments of the present application can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and basic cloud computing services such as big data, and the like, which are not limited in the embodiments of the present application. The issuing node 301, the holding node 302, and the verifying node 303 in the blockchain network 30 will be introduced as follows:
[0070] (1) Issuing node 301. The issuing node 301 is a node used by the Issuer in the blockchain network 30. In the process of generating the VC data of the Holder according to the object information of the Holder, the issuing node 301 can generate the Merkle Tree of the Holder according to the object information of the Holder, and then generate the VC data of the Holder according to the Merkle Tree of the Holder and the object information of the Holder. The process of generating the Merkle Tree of the Holder according to the object information of the Holder can be referred to in the description of the holding node 302. Figure 4The illustrated Merkle Tree: As can be known from the foregoing, the object information of the Holder can include multiple target data of the Holder, the issuing node 301 can derive multiple obfuscated data based on a random seed (salt), then can assign different obfuscated data to each target data, and can splice each target data and the corresponding obfuscated data to form the basic data of the Merkle Tree, and then can perform hash calculation layer by layer to finally obtain the root hash of the Merkle Tree. Compared with the traditional VC data, in addition to the DID identifier and the object information of the Holder, the declaration data of the VC data in the improved DID verification method can further include at least one of the following: the obfuscated data assigned to each target data in the Merkle Tree of the Holder, the root hash of the Merkle Tree, the root signature of the Merkle Tree, and the DID identifier data of the Issuer (such as the DID identifier of the Issuer, the public key of the Issuer, and the like); wherein the root signature of the Merkle Tree can be obtained by encrypting the root hash of the Merkle Tree by the issuing node 301 (for example, the root signature of the Merkle Tree can be obtained by encrypting the root hash of the Merkle Tree by the issuing node 301 using the private key of the Issuer). After the issuing node 301 generates the VC data of the Holder, the issuing node 301 can upload the VC data to the blockchain, and set the holding node 302 (i.e. the node used by the Holder in the blockchain network 30) as the visible node of the VC data in the blockchain; the issuing node 301 can also upload the root hash of the Merkle Tree of the target object and the root signature of the Merkle Tree of the target object to the blockchain to ensure that the root hash of the Merkle Tree and the root signature of the Merkle Tree cannot be tampered with.
[0071] (2) Holding Node 302. Holding Node 302 is the node used by Holder in blockchain network 30. Holding Node 302 can obtain Holder's VC data from the blockchain, and can select target data to be verified from the Holder's object information contained in the VC data. It then determines the verification data of the target data to be verified in Holder's MerkleTree, and generates VP data based on the target data to be verified and its verification data. The verification data of the target data to be verified may include at least one of the following: obfuscation data assigned to the target data to be verified in Holder's MerkleTree, index data corresponding to the target data to be verified determined in Holder's MerkleTree, and verification path corresponding to the target data to be verified determined in Holder's MerkleTree, etc. In other words, compared with traditional VP data, traditional VP data discloses all target data contained in the VC data, while the VP data in the improved DID verification method discloses the selected target data to be verified and its verification data. Figure 4 Taking the MerkleTree as an example, if the target data to be verified is target data 2, the improved VP data may include, but is not limited to: target data 2, obfuscated data 2, index data 2, and verification path [N0, N5]; where verification path [N0, N5] specifically refers to the node values corresponding to node N0 and node N5. After holding node 302 generates the Holder's VP data, it can upload the VP data to the blockchain, and set the verification node 303 (i.e., the node used by the Verifier in blockchain network 30) as a visible node for the secret VP data in the blockchain.
[0072] (3) Verification Node 303. Verification Node 303 is the node used by Verifier in blockchain network 30. After obtaining the VP data of Holder from the blockchain, Verification Node 303 can verify the target data to be verified based on the verification data of the target data to be verified in the VP data. The verification process is described as follows: Verification Node 303 can calculate the verification hash of Merkle tree based on the target data to be verified, the obfuscated data corresponding to the target data to be verified, the index data corresponding to the target data to be verified, and the verification path corresponding to the target data to be verified. Then, the verification hash of Merkle tree can be compared with the real root hash of the Merkle tree of Holder. If the verification hash of Merkle tree is the same as the real root hash of Merkle tree, it can be determined that the target data to be verified has been verified, that is, the Holder has been verified.
[0073] It is important to note that in this embodiment, obfuscated data is used to concatenate the target data to avoid collision leakage of the target data. Collision leakage of target data can be understood as follows: although the VP data discloses the selected target data that needs verification, but not the target data that does not need verification, the VP data may disclose the hash of the target data that does not need verification. Figure 4 Taking the MerkleTree as an example, if the target data to be verified is target data 2, then the verification path [N0, N5] corresponding to target data 2 discloses the hash corresponding to target data 1 (i.e., the node value corresponding to node N0). In this case, if obfuscated data is not used to concatenate target data 1, then all possible target data 1s can be enumerated and the hash corresponding to the enumerated target data 1 can be calculated. When the hash corresponding to a certain enumerated target data 1 collides with N0 (i.e. is the same), it will cause the leakage of target data 1. Therefore, in this embodiment, obfuscated data is used to concatenate target data, which can avoid the collision leakage of target data, thereby effectively hiding the target data not disclosed in the object verification process.
[0074] Furthermore, the obfuscated data corresponding to each target data in MerkleTree is different. The obfuscated data for each target data can be derived from the same random seed or from different random seeds. The derivation process can specifically involve hash calculation using a hash algorithm. The methods for deriving obfuscated data mentioned in the embodiments of this application may include... Figures 5a-5c Any of the derivation methods shown: such as Figure 5a As shown, the obfuscated data corresponding to each target data can be obtained through deep derivation based on the same random seed. Obfuscated data 1 is obtained by hashing the random seed using a hash algorithm, obfuscated data 2 is obtained by hashing obfuscated data 1 using a hash algorithm, and so on, to calculate all obfuscated data. The hash algorithm used in this deep derivation method based on the same random seed can be the same hash algorithm or different hash algorithms. Figure 5a The derivation methods shown all use the same hash algorithm, and this application does not limit this approach. For example... Figure 5b As shown, the obfuscated data corresponding to each target data can be obtained through breadth-first derivation based on the same random seed. Obfuscated data 1 is obtained by hashing the random seed using hash algorithm 1, obfuscated data 2 is obtained by hashing the random seed using hash algorithm 2, and so on, to calculate all obfuscated data. The hash algorithms used in this breadth-first derivation method based on the same random seed are different for each data type. For example... Figure 5cAs shown, the confusion data corresponding to each target data can be derived based on different random seeds, confusion data 1 is obtained by hashing calculation of random seed 1 using a hash algorithm, confusion data 2 is obtained by hashing calculation of random seed 2 using a hash algorithm, and all confusion data can be calculated in this way. The random seeds used in the confusion data derivation method based on different random seeds are different, and the hash algorithm used can be the same hash algorithm.
[0075] In the embodiments of the present application, the target data that needs to be verified can be selectively disclosed in the process of generating VP data based on VC data, and the target data that does not need to be verified can be hidden, which is beneficial to protect the data security of the object in the object verification process based on VP data, and makes the object verification process more secure and reliable. It can be understood that the blockchain network 30 described in the embodiments of the present application is used to more clearly illustrate the technical solutions of the embodiments of the present application, and does not constitute a limitation on the technical solutions provided by the embodiments of the present application. It can be understood by those skilled in the art that with the evolution of the blockchain network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems. In addition, in the subsequent specific embodiments of the present application, the object information and other related data of the object are involved. When the embodiments of the present application are applied to specific products or technologies, the permission or consent of the object is required, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions.
[0076] The blockchain-based data processing scheme provided by the embodiments of the present application will be described in more detail below with reference to the accompanying drawings:
[0077] The embodiments of the present application provide a blockchain-based data processing method, which mainly introduces the process of generating VP data based on VC data. The blockchain-based data processing method can be executed by a holding node. The holding node mentioned in the embodiments of the present application refers to a node used by a target object in a blockchain network. For example, Figure 6 As shown, the blockchain-based data processing method can include the following steps S601-S604:
[0078] S601, obtaining object declaration information of a target object.
[0079] The object declaration information of the target object (i.e. the VC data mentioned above) can include object information of the target object, and the object information of the target object can include a plurality of target data of the target object; wherein the target data refers to the characterization data of the target object.
[0080] Before the holding node obtains the object declaration information of the target object, the object declaration information of the target object can be generated by an issuing node (i.e., a node used by an Issuer in the blockchain network) according to the object information of the target object after the DID identifier data of the target object is confirmed. The following describes the process in combination with Figure 7a and Figure 7b .
[0081] As shown in Figure 7a , the attestation node is a node used by a trusted object document issuer in the blockchain network, that is, the DID identifier corresponding to the attestation node is included in the trusted list mentioned above. (1) The holding node can send the object document (i.e., the DID document) of the target object to the attestation node. The object document of the target object can include the object identifier (i.e., the DID identifier) of the target object, the public key of the target object, and the signature information of the target object. The signature information of the target object can be encrypted by the holding node using the private key of the target object on the object identifier and the public key of the target object. That is, the issuer of the object document of the target object is the target object itself at this time. Such an object document is not trusted, and therefore the object document of the target object needs to be sent to the attestation node for signing by the trusted attestation node. (2) After receiving the object document of the target object, the attestation node can verify the object document of the target object. The attestation node verifying the object document of the target object can include at least one of the following: the attestation node can verify the signature information of the target object using the public key of the target object, the attestation node can verify the object identifier of the target object (e.g., verify whether the object identifier of the target object is unique and exists, whether it is fake, etc.), and the like. If the attestation node verifies the object document of the target object, it can sign the object document of the target object to obtain the signed object document of the target object. The attestation node signing the object document of the target object can include: the attestation node can add the DID identifier corresponding to the attestation node and the signature information of the attestation node in the object document of the target object to obtain the signed object document of the target object. The signature information of the attestation node can be encrypted by the private key of the attestation node on the object identifier and the public key of the target object. (3) The attestation node can upload the signed object document of the target object to the blockchain for storage. (4) The attestation node can receive the storage result returned by the blockchain. (5) The attestation node can return a document signature notification to the holding node, which is used to notify the holding node that the object document of the target object has been signed and uploaded to the blockchain for storage. Through the process shown in Figure 7a , the object document of the target object is signed by the trusted attestation node and uploaded to the blockchain for storage, so that the signed object document of the target object stored in the blockchain is secure and trusted.
[0082] As shown in Figure 7b (1) The holding node can send an object declaration acquisition request to the issuing node, and the object declaration acquisition request can carry the object identifier of the target object and the object information of the target object. (2) The issuing node can obtain the object document of the target object from the blockchain based on the object identifier of the target object (here, the object document of the target object can specifically refer to the signed object document of the target object). (3) The blockchain returns the signed object document of the target object to the issuing node. (4) The issuing node can verify the signed object document of the target object; wherein the issuing node verifying the signed object document of the target object can include the issuing node verifying the signature information of the proof node using the public key of the proof node. (5) If the signed object document of the target object is verified, the issuing node can generate the object declaration data of the target object according to the object information of the target object. Wherein the process of the issuing node generating the object declaration data of the target object according to the object information of the target object can include: first, the issuing node can generate the Merkle tree of the target object according to the object information of the target object (for details, see the generation process of the Merkle tree described in the above Figure 4 embodiment); second, the issuing node can encrypt the root hash of the Merkle tree using the private key of the issuing node to obtain the root signature of the Merkle tree; then, the issuing node can generate the object declaration data of the target object according to the object information of the target object, the confusion data allocated to each target data in the object information in the Merkle tree of the target object, the root hash of the Merkle tree of the target object, the root signature of the Merkle tree of the target object, and the DID identifier of the issuing node, the public key of the issuing node. (6) The issuing node can output the object declaration data of the target object; wherein the issuing node outputting the object declaration data of the target object can be understood as: the issuing node uploading the object declaration data of the target object to the blockchain for storage, and setting the holding node as the visible node of the object declaration data of the target object in the blockchain; the visible node of the object declaration data of the target object refers to the node that is allowed to obtain the object declaration data of the target object from the blockchain. In addition to uploading the object declaration data of the target object to the blockchain, the issuing node can also upload the root hash of the Merkle tree of the target object and the root signature of the Merkle tree of the target object to the blockchain to ensure that the root hash of the Merkle tree of the target object and the root signature of the Merkle tree of the target object cannot be tampered with. (7) The issuing node can also issue an object declaration notification to the holding node, and the object declaration notification is used to notify that the generated object declaration data of the target object has been uploaded to the blockchain. Through Figure 7bAccording to the illustrated process, after the issuing node confirms the DID identification data of the target object, the object declaration data of the target object can be generated according to the object information of the target object, so that the object declaration data of the target object can be generated after the target object is confirmed to be a legal object, thereby improving the security; and by generating the Merkle tree of the target object, the object declaration data of the target object can have the ability to hide the object information.
[0083] It should be noted that the data uploaded to the blockchain for storage mentioned in the embodiments of the present application can mean that the data is sent to the full node in the blockchain network, and the full node uploads the data to the blockchain for storage, and the full node sets the visibility state of the data; for example, in Figure 7b In the illustrated embodiments, if the issuing node is a full node, uploading the object declaration data of the target object to the blockchain for storage can mean that the issuing node uploads the object declaration data of the target object to the blockchain for storage, and the issuing node sets the visibility state of the object declaration data of the target object in the blockchain; if the issuing node is a light node, uploading the object declaration data of the target object to the blockchain for storage can mean that the issuing node sends the object data of the target object to the full node, the full node uploads the object declaration data of the target object to the blockchain for storage, and the full node sets the visibility state of the object declaration data of the target object in the blockchain. The full node refers to a node in the blockchain network that has a complete blockchain, and the full node needs to occupy memory to synchronize all blockchain data, can independently verify all transactions on the blockchain and update data in real time, and is mainly responsible for broadcasting and verifying transactions in the blockchain. In addition, Figure 7b In the illustrated embodiments, uploading the object declaration data of the target object to the blockchain and setting the object declaration data of the target object in the blockchain is only for example, and in actual application scenarios, the issuing node can also directly send the object declaration data of the target object to the holding node, that is, the holding node can obtain the object declaration data of the target object from the blockchain, or the holding node can receive the object declaration data of the target object sent by the issuing node.
[0084] S602, determining a data set according to the object declaration data.
[0085] After obtaining the object declaration data of the target object, the holding node can determine a data set according to the object declaration data of the target object. In order to facilitate understanding of the process of determining a data set according to the object declaration data of the target object in the embodiments of the present application, the number of target data included in the object information of the target object can be represented as M, that is, the object information of the target object can include M target data, and M is an integer greater than 1.
[0086] The data set determined according to the object declaration data of the target object can include N object data pairs, each of the N object data pairs can include a target data and verification data of the target data, the N target data included in the data set can be determined from M target data, N is a positive integer less than or equal to M. Wherein, the N target data can be determined from the M target data according to the object data type indicated by the object verification request sent by the verification node, or the N target data can be determined from the M target data in response to the selection operation on the M target data, which will be introduced as follows:
[0087] (1) The N target data can be determined from the M target data according to the object data type indicated by the object verification request sent by the verification node. Specifically, the holding node can receive the object verification request sent by the verification node (i.e. the node used by the verifier in the blockchain network), and the object verification request can carry the object data type requested to be verified; the holding node can select N target data matching the object data type from the M target data according to the indication of the object data type; then, the holding node can obtain the verification data of each target data in the N target data, and determine N object data pairs according to the N target data and the verification data of each target data, that is, determine the data set. For example, the object data type carried in the object verification request is the basic information type, and the target data matching the basic information type is selected from the object information of the target object. For another example, the object data type carried in the object verification request is the job information type, and the target data matching the job information type is selected from the object information of the target object. In this way, the target data disclosed in the object verification data can be selected as needed, and the unselected target data is hidden for the object verification data.
[0088] (2) The N target data can be determined from the M target data in response to the selection operation on the M target data. Specifically, the holding node can display an object information selection interface, and the object information selection interface can display the M target data; the holding node can determine the N target data selected by the selection operation on the M target data in the object information selection interface in response to the selection operation; then, the holding node can obtain the verification data of each target data in the N target data, and determine N object data pairs according to the N target data and the verification data of each target data, that is, determine the data set. An exemplary object information selection interface is as follows: Figure 7cAs shown, the object information selection interface displays target data including target data 1-target data 8, and the selected target data includes target data 1-target data 4. In this way, users can independently select the target data disclosed in the object verification data; unselected target data is hidden from the object verification data.
[0089] The above content introduced two methods for selecting N target data from M target data. The following focuses on the validation data for the target data. The validation data for each of the N target data can be different or the same, as described below:
[0090] (1) The verification data for each of the N target data can be different, meaning that each of the N target data corresponds to different verification data. Here, we take the verification data of the target data in the i-th object data pair as an example. The verification data of the target data in all other object data pairs except the i-th object data pair can be found in the verification data of the i-th object data pair. The i-th object data pair can include the i-th target data and its verification data. The verification data of the i-th target data can include at least one of the following: obfuscation data allocated to the i-th target data in the Merkle tree of the target object, index data corresponding to the i-th target data determined in the Merkle tree of the target object, and verification information (i.e., verification path) corresponding to the i-th target data determined in the Merkle tree of the target object. The Merkle tree of the target object can be determined based on the M target data, where i is a positive integer less than or equal to N. Specifically, the obfuscated data corresponding to the i-th target data can be used to calculate the data hash corresponding to the i-th target data; the verification information corresponding to the i-th target data is used to calculate the verification hash of the i-th object data pair by combining the data hash corresponding to the i-th target data. Figure 4 Taking the Merkle tree shown as an example, target data 2 and target data 4 are selected from 4 target data. The verification data of target data 2 may include: obfuscated data 2, the index data corresponding to target data 2, and the verification path [N0, N5] corresponding to target data 2. The verification data of target data 4 may include: obfuscated data 4, the index data corresponding to target data 4, and the verification path [N2, N4] corresponding to target data 4.
[0091] (2) The verification data of each of the N target data can be the same, that is, the N target data can correspond to the same verification data. The same verification data can include at least one of the following: the confusion data respectively assigned to the N target data in the Merkle tree of the target object, the index data respectively corresponding to the N target data determined in the Merkle tree of the target object, and the common verification information (i.e., the common verification path) corresponding to the N target data determined in the Merkle tree of the target object, that is, the verification paths corresponding to the N target data can be the same. Among them, the confusion data respectively assigned to the N target data, the index data respectively corresponding to the N target data, and the common verification information corresponding to the N target data can be used to calculate the common verification hash of the N object data pairs. For example, as shown in the Merkle tree, the target data selected from the four target data are target data 2 and target data 4; the common verification data of the target data 2 and the target data 4 can include confusion data 2, confusion data 4, index data corresponding to the target data 2, index data corresponding to the target data 4, and common verification path [N0, N2]. Figure 4
[0092] S603, generating object verification data according to the data set.
[0093] After determining the data set according to the object declaration data, the holding node can generate object verification data according to the data set. Generating object verification data according to the data set can include any one of the following two: ① directly generating object verification data according to the data set, and the object verification data can include the data set, that is, the object verification data can include the object data pair (i.e., the N object data pair). ② generating object verification data according to the data set, the root hash corresponding to the target object (i.e., the root hash of the Merkle tree of the target object mentioned in the foregoing), and the root signature corresponding to the target object (i.e., the root signature of the Merkle tree of the target object mentioned in the foregoing), and the object verification data can include: the data set, the root hash corresponding to the target object, and the root signature corresponding to the target object, that is, the object verification data can include: the object data pair (i.e., the N object data pair), the root hash corresponding to the target object, and the root signature corresponding to the target object.
[0094] Among them, the root hash corresponding to the target object is determined in the Merkle tree of the target object, and the root signature corresponding to the target object can be obtained by encrypting the root hash corresponding to the target object with the private key of the issuing node generating the object declaration data. The root signature corresponding to the target object can be used to verify the root hash corresponding to the target object; after the root hash corresponding to the target object is verified by the root signature corresponding to the target object, the root hash corresponding to the target object can be used to verify the verification hash of the object data pair included in the data set.
[0095] S604, submit the verification expression data corresponding to the object verification data, the verification expression data including the to-be-verified object data pair, and in the process of verifying the object, if a verification hash matching a root hash corresponding to a target object is obtained according to target data in the to-be-verified object data pair and the verification data of the target data, it is determined that the target object is verified.
[0096] After generating the object verification data according to the data set, the holding node can submit the verification expression data corresponding to the object verification data. It can be understood that the target data contained in the generated object verification data may be tampered with, so the generated object verification data may be different from the submitted object verification data. In order to facilitate the expression of this different case, the submitted object verification data is expressed as the verification expression data corresponding to the object verification data here; that is, if the generated object verification data is not tampered with, that is, the generated object verification data and the submitted object verification data are the same data, the verification expression data is the object verification data; if the generated object verification data is tampered with, that is, the generated object verification data and the submitted object verification data are different data, the verification expression data is the tampered object verification data.
[0097] The verification expression data corresponding to the submitted object verification data can include any of the following: uploading the verification expression data to the block chain, and setting the verification node as a visible node of the verification expression data in the block chain. The visible node of the verification expression data refers to a node that allows the verification expression data to be obtained from the block chain, that is, the verification node can obtain the visible verification expression data from the block chain; or sending the verification expression data to the verification node, that is, the verification node can receive the verification expression data sent by the holding node. The verification expression data can include the to-be-verified object data pair, and the to-be-verified object data pair corresponds to the object data pair. In the process of verifying the target object based on the verification expression data, if a verification hash matching a root hash corresponding to a target object is obtained according to target data in the to-be-verified object data pair and the verification data of the target data, it can be determined that the target object is verified.
[0098] The process of generating the object verification data of the target object according to the object declaration data of the target object described in steps S601 to S604 in the embodiments of the present application can be summarized as Figure 7dThe flowchart shows that: (1) The holding node can request the target object declaration data of the target object from the blockchain (or the holding node can receive the target object declaration data of the target object sent by the issuing node). (2) The blockchain returns the target object declaration data of the target object to the holding node. (3) The holding node can select the target data determined to be verified (that is, N target data) from the plurality of target data contained in the target object declaration data of the target object, and generate the object verification data of the target object according to the target data to be verified, the confusion data allocated to the target data to be verified in the Merkle tree of the target object, the index data corresponding to the target data to be verified determined in the Merkle tree of the target object, and the verification path corresponding to the target data to be verified determined in the Merkle tree of the target object. (4) The holding node can upload the verification expression data corresponding to the object verification data to the blockchain, and set the verification node in the blockchain as the visible node of the verification expression data (or the holding node can send the verification expression data corresponding to the object verification data to the verification node). (5) The blockchain returns the upload success notification to the holding node, and the upload success notification is used to notify that the verification expression data has been successfully stored, and the visible state of the verification expression data has been successfully set.
[0099] In the embodiments of the present application, the Merkle tree of the target object is spliced by the confusion data target data, the object declaration data of the target object with object information hiding function can be generated based on the Merkle tree of the target object, and the object verification data of the target object with object information hiding function can be generated based on the Merkle tree of the target object, so that the target data to be verified can be disclosed, the target data not to be verified can be hidden, the minimum disclosure of object information can be achieved, and the maximum protection of object data security can be achieved.
[0100] The embodiments of the present application provide a data processing method based on a blockchain. The data processing method based on the blockchain mainly introduces an object verification process based on VP data. The data processing method based on the blockchain can be executed by a verification node. The verification node mentioned in the embodiments of the present application refers to a node used by a verifier in a blockchain network. Figure 8 As shown in the figure, the data processing method based on the blockchain can include the following steps S801-S803:
[0101] S801, obtaining verification expression data submitted by a holding node, the verification expression data including a to-be-verified object data pair.
[0102] The verification node can obtain the verification expression data submitted by the holding node into the blockchain from the blockchain, or the verification node can receive the verification expression data sent by the holding node. The verification expression data corresponds to the object verification data generated by the holding node. The object verification data can be generated according to a data set. The data set can be determined according to object information of a target object included in object declaration data of the target object. The object information can include M target data. The data set can include object data pairs. Each object data pair can include a target data and verification data of the target data. N target data in the data set can be selected and determined from the M target data. M is an integer greater than 1. N is a positive integer less than or equal to M.
[0103] In S802, a verification hash of the to-be-verified object data pair is determined according to the target data and the verification data of the target data in the to-be-verified object data pair.
[0104] After obtaining the verification expression data submitted by the holding node, the verification node can determine a verification hash of a to-be-verified object data pair according to target data and verification data of the target data in the to-be-verified object data pair included in the verification expression data. As known from the foregoing, the object verification data can include N object data pairs. The number of to-be-verified object data pairs included in the verification expression data can be N, that is, the verification expression data can include N to-be-verified object data pairs. Each of the N to-be-verified object data pairs can include a target data and verification data of the target data.
[0105] For the case that the verification data of each target data in the N to-be-verified object data pairs is different, determining the verification hash of the to-be-verified object data pair according to the target data in the to-be-verified object data pair and the verification data of the target data can include: determining the verification hash of the N to-be-verified data pairs according to the target data in each object data pair in the N to-be-verified object data pairs and the verification data of the target data. In order to facilitate understanding of the calculation process of the verification hash, the calculation process of the verification hash of the i-th to-be-verified object data pair in the N to-be-verified object data pairs is taken as an example for introduction, and the calculation process of the verification hash of the other to-be-verified object data pairs in the N to-be-verified object data pairs except the i-th to-be-verified object data pair can be referred to the calculation process of the verification hash of the i-th to-be-verified object data pair, i is a positive integer less than or equal to N; the i-th to-be-verified object data pair includes the i-th target data and the verification data of the i-th target data, and the verification data of the i-th target data can include at least one of the following: the confusion data allocated for the i-th target data in the Merkle tree of the target object and the verification information (i.e., the verification path) corresponding to the i-th target data determined in the Merkle tree of the target object; the Merkle tree of the target object is determined according to M target data. The process of determining the verification hash of the i-th to-be-verified object data pair according to the i-th target data and the verification data of the i-th target data can include: splicing the confusion data with the i-th target data to obtain spliced data; performing hash calculation on the spliced data to obtain the data hash corresponding to the i-th target data; and calculating the verification hash of the i-th object data pair according to the data hash corresponding to the i-th target data and the verification information corresponding to the i-th target data. The process of calculating the verification hash of the i-th object data pair according to the data hash corresponding to the i-th target data and the verification information corresponding to the i-th target data can include: calculating the verification hash of the i-th object data pair according to the data hash corresponding to the i-th target data, the index data corresponding to the i-th target data, and the verification information corresponding to the i-th target data.
[0106] For the case that the verification data of each target data in the N object data pairs to be verified is the same, that is, the N object data pairs to be verified correspond to the same verification data, according to the target data in the object data pair to be verified and the verification data of the target data, determining the verification hash of the object data pair to be verified can include: according to the N target data in the N object data pairs to be verified and the same verification data, determining the common verification hash of the N object data pairs to be verified. Wherein, the same verification data can include at least one of the following: the confusion data assigned to each of the N target data in the target object's Merkle tree, the index data corresponding to each of the N target data determined in the target object's Merkle tree, and the common verification information (i.e. common verification path) corresponding to the N target data determined in the target object's Merkle tree. According to the N target data in the N object data pairs to be verified and the same verification data, determining the common verification hash of the N object data pairs to be verified can include: splicing the confusion data assigned to each of the N target data with the corresponding target data to obtain N splicing data; performing hash calculation on the N splicing data respectively to obtain N data hashes, and calculating the common verification hash of the N object data pairs to be verified according to the N data hashes and the common verification information. Wherein, according to the N data hashes and the common verification information, calculating the common verification hash of the N object data pairs to be verified can include: according to the N data hashes, the index data corresponding to each of the N target data, and the common verification path, calculating the common verification hash of the N object data pairs to be verified.
[0107] S803, if the verification hash of the object data pair to be verified matches the root hash corresponding to the target object, it is determined that the target object is verified.
[0108] After determining the verification hash of the object data pair to be verified according to the target data in the object data pair to be verified and the verification data of the target data, the verification node can perform matching check on the verification hash of the object data pair to be verified and the root hash corresponding to the target object. If the verification hash of the object data pair to be verified matches the root hash corresponding to the target object, the verification node can determine that the target object is verified. Wherein, the root hash corresponding to the target object refers to the root hash of the target object's Merkle tree, and the root hash corresponding to the target object can be included in the verification expression data, or the root hash corresponding to the target object can be uploaded to the blockchain for storage.
[0109] When the root hash corresponding to the target object can be contained in the verification expression data, the verification expression data can further contain a root signature corresponding to the target object, and the root signature corresponding to the target object can be obtained by encrypting the root hash corresponding to the target object by using a private key of a node that generates object declaration data of the target object; in this case, the root signature corresponding to the target object can be decrypted by using a public key of the node to obtain a decrypted hash corresponding to the target object, and if the decrypted hash corresponding to the target object matches the root hash corresponding to the target object, it can be determined that the root hash corresponding to the target object is verified. After the root hash corresponding to the target object is verified, the verification hash of the object data pair to be verified can be matched with the root hash corresponding to the target object, and the root hash corresponding to the target object used for object verification can be ensured to be reliable by verifying the root hash corresponding to the target object by using the root signature corresponding to the target object. Alternatively, when the root hash corresponding to the target object is uploaded to the blockchain for storage, the root hash corresponding to the target object can be obtained from the blockchain, and the verification hash of the object data pair to be verified can be matched with the root hash corresponding to the target object, and the root hash corresponding to the target object stored in the blockchain is tamper-proof, which can ensure that the root hash corresponding to the target object used for object verification is reliable.
[0110] For the case that the verification data of each target data in the N object data pairs to be verified is different, matching the verification hash of the object data pair to be verified with the root hash corresponding to the target object means matching the verification hashes of the N object data pairs to be verified with the root hash corresponding to the target object respectively, and the verification hash of the object data pair to be verified matches the root hash corresponding to the target object means that the verification hashes of the N object data pairs to be verified all match the root hash corresponding to the target object. For the case that the verification data of each target data in the N object data pairs to be verified is the same, matching the verification hash of the object data pair to be verified with the root hash corresponding to the target object means matching the common verification hash of the N object data pairs to be verified with the root hash corresponding to the target object, and the verification hash of the object data pair to be verified matches the root hash corresponding to the target object means that the common verification hash of the N object data pairs to be verified matches the root hash corresponding to the target object.
[0111] In addition, before the verification node decrypts the root signature corresponding to the target object by using the public key of the issuing node to obtain the decrypted hash corresponding to the target object, the verification node can also obtain the first signature information generated by the holding node, the second signature information generated by the issuing node, and the object document of the target object. The object document of the target object can include the public key of the target object. The first signature information can be obtained by encrypting the verification expression data by using the private key of the target object. The second signature information can be obtained by encrypting the object declaration data by using the private key of the issuing node. The object document of the target object includes the public key of the target object. More specifically, the first signature information, the second signature information, and the object document of the target object (here, it can refer to the signed object document of the target object) can be obtained by the verification node from the blockchain. The first signature information can be uploaded to the blockchain by the holding node. The second signature information can be uploaded to the blockchain by the issuing node. The object document of the target object can be uploaded to the blockchain by the proving node. Secondly, the verification node can verify the first signature information by using the public key of the target object. If the first signature information is verified by using the public key of the target object, the verification node can obtain the object document of the issuing node. The object document of the issuing node can include the public key of the issuing node. Then, if the verification node determines that the object document of the issuing node is issued according to the trusted identifier in the trusted list, that is, the issuer of the object document of the issuing node is trusted, the verification node can verify the second signature information according to the public key of the issuing node. If the second signature information is verified, the verification node can decrypt the root signature corresponding to the target object by using the public key of the issuing node to obtain the decrypted hash corresponding to the target object for verifying the root hash corresponding to the target object. It should be noted that the verification node can verify the second signature information by using the public key of the issuing node, but cannot obtain the object declaration data of the target object.
[0112] Similarly, before the root hash corresponding to the target object is obtained from the blockchain for object verification, the verification node can also obtain the first signature information generated by the holding node, the second signature information generated by the issuing node, and the object document of the target object. The object document of the target object can include the public key of the target object, the first signature information can be obtained by encrypting the verification expression data using the private key of the target object, and the second signature information can be obtained by encrypting the object declaration data using the private key of the issuing node. The object document of the target object includes the public key of the target object. Secondly, the verification node can verify the first signature information using the public key of the target object. If the first signature information is verified using the public key of the target object, the verification node can obtain the object document of the issuing node. Then, if the verification node determines that the object document of the issuing node is issued according to the trusted identifier in the trusted list, i.e., determines that the issuer of the object document of the issuing node is trusted, the verification node can obtain the root hash corresponding to the target object for object verification from the blockchain.
[0113] For the case where the verification expression data includes the root hash corresponding to the target object and the root signature corresponding to the target object in addition to the N object data pairs to be verified, the complete process of object verification by the verification node can be referred to Figure 9 : (1) The verification node obtains the verification expression data submitted by the holding node from the blockchain. (2) The verification node obtains the object document of the target object from the blockchain, and the object document of the target object includes the public key of the target object. (3) The verification node verifies the signature information of the verification expression data (i.e., the first signature information described above) using the public key of the target object. (4) If the signature information of the verification expression data is verified, the verification node obtains the object document of the issuing node from the blockchain, and the object document of the issuing node includes the public key of the issuing node. (5) The verification node determines that the object document of the issuing node is issued according to the trusted identifier in the trusted list. (6) The verification node verifies the signature information of the object declaration data (i.e., the second signature information described above) using the public key of the issuing node. (7) If the signature information of the object declaration data is verified, the verification node can verify the root hash corresponding to the target object in the verification expression data using the public key of the issuing node. (8) If the root hash corresponding to the target object is verified, the verification node can determine the verification hash of the object data pair to be verified according to the target data and the verification data of the target data included in the verification expression data. (9) If the verification hash of the object data pair to be verified matches the root hash corresponding to the target object, it is determined that the target object is verified.
[0114] In the embodiments of the present application, by judging whether the verification hash of the to-be-verified object data pair determined according to the target data and the verification data of the target data contained in the verification expression data matches the root hash corresponding to the target object (that is, the real root hash of the Merkle tree), it can be determined whether the target data selected for disclosure in the verification expression data is tampered with, so as to verify the correctness of the target data selected for disclosure, and the target data not selected is hidden for the verification expression data, which is beneficial to protect the data security of the object in the object verification process. In addition, before verifying the target data selected for disclosure in the verification expression data, the signature information of the verification expression data, the signature information of the object declaration data, and the object document of the issuing node can be verified, so as to further determine the reliability of the object verification result.
[0115] Based on the description of the above method embodiments, the following will be described in combination with Figure 10 The data processing scene based on the blockchain used in the embodiments of the present application is introduced:
[0116] (1) The job seeker can submit the object document of the job seeker to the trusted object in the DID verification system. The trusted object can sign the object document of the job seeker after the object document of the job seeker is verified, and upload the signed object document of the job seeker to the blockchain. The signed object document of the job seeker is trusted in the DID verification system.
[0117] (2) The job seeker submits the object identifier of the job seeker and the object information of the job seeker to the school, and requests the school to generate the VC data with the hiding function according to the object information of the job seeker. The school can obtain the signed object document of the job seeker from the blockchain according to the object identifier of the job seeker. The school can generate the VC data with the hiding function according to the object information of the job seeker after the signed object document of the job seeker is verified, and upload the VC data with the hiding function to the blockchain, and set the VC data with the hiding function visible to the job seeker in the blockchain.
[0118] (3) The job seeker can obtain the VC data with the hiding function from the blockchain, and then select the target data required for job seeking from the VC data with the hiding function according to the job seeking requirement, and generate the VP data with the hiding function according to the target data required for job seeking. The job seeker can upload the VP data with the hiding function to the blockchain, and set the VP data with the hiding function visible to the job seeker's employer in the blockchain.
[0119] (4) The recruitment object in the job-seeking unit of the job-seeker can obtain the VP data with a hiding function from the blockchain. The job-seeking unit can verify whether the VP data with a hiding function is submitted by the job-seeker, whether the DID document of the school is issued by a trusted object, whether the VP data with a hiding function is generated by the school, whether the root hash in the VP data with a hiding function is correct, whether the target data required for job-seeking in the VP data with a hiding function is correct. After the above five verifications are passed, the job-seeking unit can determine that the job-seeker is verified, and can notify the job-seeker to enter the job.
[0120] As can be seen from the above scenario, in the process of job-seeking of the job-seeker, the job-seeker can selectively disclose the target data required for verification, and hide the target data not required for verification. The recruitment object can verify the correctness of the target data required for verification, so that the correctness of the target data required for verification can be verified while the data security of the object is protected.
[0121] The above describes the method of the embodiments of the present application in detail. In order to facilitate better implementation of the above-mentioned scheme of the embodiments of the present application, correspondingly, the device of the embodiments of the present application is provided below.
[0122] Please refer to Figure 11 , Figure 11 is a structural schematic diagram of a data processing device based on a blockchain provided by the embodiments of the present application. The data processing device based on a blockchain can be arranged in the computer device provided by the embodiments of the present application.
[0123] In one embodiment, the data processing device based on a blockchain can be a computer program (including program code) running in a computer device. The computer device can be the aforementioned holding node. The data processing device based on a blockchain can be used to execute the corresponding steps in the method embodiments shown in Figure 6 Please refer to Figure 11 , the data processing device based on a blockchain can include the following units:
[0124] The acquisition unit 1101 is configured to acquire object declaration data of a target object. The object declaration data includes object information of the target object. The object information includes M target data, and M is an integer greater than 1. A data set is determined according to the object declaration data. The data set includes object data pairs. Each object data pair includes a target data and verification data of the target data. N target data in the data set is selected and determined from the M target data, and N is a positive integer less than or equal to M.
[0125] The processing unit 1102 is configured to generate object verification data of the target object according to the data set, the object verification data including object data pairs; and submit verification expression data corresponding to the object verification data, the verification expression data including a to-be-verified object data pair; in the verification process, if a verification hash matching a root hash corresponding to the target object is obtained according to the target data in the to-be-verified object data pair and the verification data of the target data, it is determined that the target object passes the verification.
[0126] In an implementation manner, the number of object data pairs is N, and an i th object data pair in the N object data pairs includes an i th target data and verification data of the i th target data; the verification data of the i th target data includes: confusion data allocated for the i th target data in the Merkle tree of the target object, and verification information corresponding to the i th target data determined in the Merkle tree of the target object; the Merkle tree of the target object is determined according to M target data, i is a positive integer less than or equal to N; wherein the confusion data is used to calculate a data hash corresponding to the i th target data in combination with the i th target data; and the verification information corresponding to the i th target data is used to calculate a verification hash of the i th object data pair in combination with the data hash corresponding to the i th target data.
[0127] In an implementation manner, the object verification data further includes: a root hash corresponding to the target object and a root signature corresponding to the target object; the root hash corresponding to the target object is determined in the Merkle tree of the target object, and the root signature corresponding to the target object is obtained by encrypting the root hash corresponding to the target object by using a private key of a generation node generating the object declaration data; the root signature corresponding to the target object is used to verify the root hash corresponding to the target object; after the root hash corresponding to the target object is verified by using the root signature corresponding to the target object, the root hash corresponding to the target object is used to verify the verification hash of the object data pair in the object verification data.
[0128] In an implementation manner, the number of object data pairs is N; and the processing unit 1102 is configured to determine the data set according to the object declaration data, and specifically configured to perform the following steps:
[0129] receiving an object verification request sent by a verification node, the object verification request carrying an object data type to be verified; selecting N target data matching the object data type from the M target data according to the indication of the object data type; obtaining verification data of each target data in the N target data; and determining N object data pairs according to the N target data and the verification data of each target data.
[0130] In an implementation manner, the number of object data pairs is N, the data set includes N object data pairs; the processing unit 1102 is configured to determine the data set according to the object declaration data, and specifically configured to perform the following steps:
[0131] display an object information selection interface, and display M target data in the object information selection interface; in response to a selection operation on the M target data in the object information selection interface, determine N target data selected by the selection operation; obtain verification data of each of the N target data; and determine N object data pairs according to the N target data and the verification data of each of the N target data.
[0132] In an implementation manner, the processing unit 1102 is further configured to perform the following steps:
[0133] send an object declaration obtaining request to the issuing node, the object declaration obtaining request carrying an object identifier of a target object and object information of the target object; wherein the object declaration obtaining request is used to trigger the issuing node to obtain an object document of the target object based on the object identifier of the target object for verification, and generate object declaration data of the target object according to the object information of the target object after the object document of the target object is verified, and output the object declaration data.
[0134] In an implementation manner, the processing unit 1102 is configured to submit the verification expression data corresponding to the object verification data, and specifically configured to perform the following steps:
[0135] upload the verification expression data to the block chain, and set the verification node as a visible node of the verification expression data in the block chain, wherein the visible node of the verification expression data refers to a node that is allowed to obtain the verification expression data from the block chain.
[0136] In another embodiment, the blockchain-based data processing apparatus can be a computer program (including program code) running in a computer device, which can be the aforementioned verification node. The blockchain-based data processing apparatus can be used to execute the corresponding steps in the method embodiments shown in the drawings. Please refer to Figure 8 Figure 11 The blockchain-based data processing apparatus can include the following units:
[0137] The obtaining unit 1101 is configured to obtain the verification expression data submitted by the holding node, the verification expression data corresponding to the object verification data generated by the holding node, and the verification expression data including the object data pair to be verified.
[0138] The processing unit 1102 is configured to determine a verification hash of the to-be-verified object data pair according to the target data and the verification data of the target data in the to-be-verified object data pair; and determine that the target object is verified successfully if the verification hash of the to-be-verified object data pair matches a root hash corresponding to the target object.
[0139] The object verification data is generated according to a data set, the data set is determined according to object information of the target object included in the object declaration data of the target object, the object information includes M target data, the data set includes object data pairs, each object data pair includes one target data and verification data of the target data, N target data in the data set is selected and determined from the M target data, M is an integer greater than 1, and N is a positive integer less than or equal to M.
[0140] In an implementation manner, the number of the to-be-verified object data pairs is N, and the verification expression data includes the N to-be-verified object data pairs; the verification expression data further includes a root hash corresponding to the target object and a root signature corresponding to the target object; the root signature corresponding to the target object is obtained by encrypting the root hash corresponding to the target object by using a private key of a node for generating the object declaration data; and the processing unit 1102 is further configured to perform the following steps:
[0141] The root signature corresponding to the target object is decrypted by using a public key of the node to obtain a decrypted hash corresponding to the target object; and it is determined that the root hash corresponding to the target object is verified successfully if the decrypted hash corresponding to the target object matches the root hash corresponding to the target object; wherein, after the root hash corresponding to the target object is verified successfully, the verification hash of the to-be-verified object data pair matches the root hash corresponding to the target object means that the verification hashes of the N to-be-verified object data pairs all match the root hash corresponding to the target object.
[0142] In an implementation manner, before the processing unit 1102 decrypts the root signature corresponding to the target object by using the public key of the node to obtain the decrypted hash corresponding to the target object, the processing unit 1102 is further configured to perform the following steps:
[0143] The first signature information generated by the holding node, the second signature information generated by the issuing node, and the object document of the target object are acquired, the first signature information is obtained by encrypting the verification expression data using a private key of the target object, the second signature information is obtained by encrypting the object declaration data using a private key of the issuing node, and the object document of the target object includes a public key of the target object; if the first signature information is verified by the public key of the target object, the object document of the issuing node is acquired; the object document of the issuing node includes a public key of the issuing node; if it is determined that the object document of the issuing node is issued according to a trusted identifier in the trusted list, the second signature information is verified according to the public key of the issuing node; if the second signature information is verified, a step of decrypting a root signature corresponding to the target object using the public key of the issuing node to obtain a decrypted hash of the target object is triggered.
[0144] In an implementation manner, the number of the to-be-verified object data pairs is N, and the verification expression data includes the N to-be-verified object data pairs; the root hash corresponding to the target object is uploaded to the blockchain for storage; the processing unit 1102 is further configured to perform the following steps:
[0145] The root hash corresponding to the target object is acquired from the blockchain; wherein the verification hash of the to-be-verified object data pair matching the root hash corresponding to the target object means that the verification hashes of the N to-be-verified object data pairs all match the root hash corresponding to the target object.
[0146] In an implementation manner, the number of the to-be-verified object data pairs is N, and the verification expression data includes the N to-be-verified object data pairs; the i th to-be-verified object data pair in the N to-be-verified object data pairs includes i th target data and verification data of the i th target data, i is a positive integer less than or equal to N; the verification data of the i th target data includes: the confusion data allocated for the i th target data in the Merkle tree of the target object, and the verification information corresponding to the i th target data determined in the Merkle tree of the target object; the Merkle tree of the target object is determined according to M target data; the processing unit 1102 is configured to determine the verification hash of the i th to-be-verified object data pair according to the i th target data and the verification data of the i th target data, and specifically perform the following steps:
[0147] The confusion data is spliced with the i th target data to obtain spliced data; the spliced data is subjected to hash calculation to obtain the data hash corresponding to the i th target data; and the verification hash of the i th to-be-verified object data pair is calculated according to the data hash corresponding to the i th target data and the verification information corresponding to the i th target data.
[0148] According to another embodiment of the present application, Figure 11The units in the blockchain-based data processing apparatus shown can be combined into one or several other units respectively or entirely to constitute, or some of the units can be further split into a plurality of units with smaller functions to constitute, which can achieve the same operation without affecting the implementation of the technical effects of the embodiments of the present application. The above units are divided based on logical functions, and in actual application, the functions of one unit can also be implemented by multiple units, or the functions of multiple units can be implemented by one unit. In other embodiments of the present application, the blockchain-based data processing apparatus can also include other units, and in actual application, these functions can also be assisted by other units, and can be implemented by multiple units in cooperation.
[0149] According to another embodiment of the present application, the blockchain-based data processing apparatus as shown in Figure 6 or Figure 8 the steps involved in the corresponding method shown can be constructed by a computer program (including program code) capable of executing the blockchain-based data processing apparatus as shown in Figure 11 the steps involved in the corresponding method shown can be constructed by a computer program (including program code) capable of executing the blockchain-based data processing apparatus as shown in
[0150] In the embodiments of the present application, the object verification data can be generated according to the selectively disclosed object information, and then the object verification can be performed on the selectively disclosed object information in the corresponding verification expression data according to the object verification data, and the unselected object information is hidden in the object verification process, which is beneficial to protecting the data security of the object in the object verification process.
[0151] Based on the above method and apparatus embodiments, the present application provides a computer device, please refer to Figure 12 , Figure 12 is a structural schematic diagram of a computer device provided by the embodiments of the present application. Figure 12 The computer device shown at least includes a processor 1201, an input interface 1202, an output interface 1203 and a computer readable storage medium 1204. Wherein, the processor 1201, the input interface 1202, the output interface 1203 and the computer readable storage medium 1204 can be connected through bus or other ways.
[0152] The input interface 1202 can be used to obtain the object declaration data of the target object, obtain the verification expression data submitted by the holding node, etc.; the output interface 1203 can be used to submit the verification expression data, output the object declaration data, etc.
[0153] The computer readable storage medium 1204 can be stored in the memory of the computer device, and is used to store a computer program including computer instructions. The processor 1201 is used to execute the program instructions stored in the computer readable storage medium 1204. The processor 1201 (or CPU (Central Processing Unit, Central Processing Unit)) is the computing core and control core of the computer device, which is suitable for implementing one or more computer instructions, and is particularly suitable for loading and executing one or more computer instructions to implement a corresponding method flow or a corresponding function.
[0154] The computer readable storage medium 1204 can be stored in the memory of the computer device, and is used to store a computer program including computer instructions. The processor 1201 is used to execute the program instructions stored in the computer readable storage medium 1204. The processor 1201 (or CPU (Central Processing Unit, Central Processing Unit)) is the computing core and control core of the computer device, which is suitable for implementing one or more computer instructions, and is particularly suitable for loading and executing one or more computer instructions to implement a corresponding method flow or a corresponding function.
[0155] In one embodiment, the computer device can be the aforementioned holding node, and the processor 1201 can load and execute one or more computer instructions stored in the computer readable storage medium 1204 to implement the corresponding steps of the blockchain-based data processing method shown in the above description. Figure 6 The computer instructions in the computer readable storage medium 1204 are loaded and executed by the processor 1201 to implement the following steps:
[0156] Obtain object declaration data of a target object, the object declaration data including object information of the target object, the object information including M target data, M being an integer greater than 1; determine a data set according to the object declaration data, the data set including object data pairs, each object data pair including a target data and verification data of the target data, N target data in the data set being selected and determined from the M target data, N being a positive integer less than or equal to M;
[0157] The object verification data of the target object is generated according to the data set, and the object verification data includes an object data pair; verification expression data corresponding to the object verification data is submitted, and the verification expression data includes a to-be-verified object data pair; in the verification process, if a verification hash matching a root hash corresponding to the target object is obtained according to the target data in the to-be-verified object data pair and the verification data of the target data, it is determined that the target object passes the verification.
[0158] In an implementation manner, the number of object data pairs is N, and an i th object data pair in the N object data pairs includes i th target data and verification data of the i th target data; the verification data of the i th target data includes: obfuscation data allocated for the i th target data in the Merkle tree of the target object, and verification information corresponding to the i th target data determined in the Merkle tree of the target object; the Merkle tree of the target object is determined according to M target data, i is a positive integer less than or equal to N; wherein the obfuscation data is used to calculate a data hash corresponding to the i th target data in combination with the i th target data; and the verification information corresponding to the i th target data is used to calculate a verification hash of the i th object data pair in combination with the data hash corresponding to the i th target data.
[0159] In an implementation manner, the object verification data further includes: a root hash corresponding to the target object and a root signature corresponding to the target object; the root hash corresponding to the target object is determined in the Merkle tree of the target object, and the root signature corresponding to the target object is obtained by encrypting the root hash corresponding to the target object by using a private key of a node issuing the object declaration data; the root signature corresponding to the target object is used to verify the root hash corresponding to the target object; after the root hash corresponding to the target object is verified by using the root signature corresponding to the target object, the root hash corresponding to the target object is used to verify the verification hash of the object data pair in the object verification data.
[0160] In an implementation manner, the number of object data pairs is N; when the computer instructions in the computer readable storage medium 1204 are loaded and executed by the processor 1201 to determine the data set according to the object declaration data, the computer instructions are specifically used to perform the following steps:
[0161] The object verification request sent by the verification node is received, and the object data type to be verified is carried in the object verification request; N target data matching the object data type are selected from the M target data according to the indication of the object data type; the verification data of each target data in the N target data is obtained; and the N object data pairs are determined according to the N target data and the verification data of each target data.
[0162] In an implementation, the number of object data pairs is N, and the data set includes the N object data pairs; the computer instructions in the computer readable storage medium 1204 are loaded and executed by the processor 1201 to determine the data set according to the object declaration data, and specifically used to perform the following steps:
[0163] display an object information selection interface, and the object information selection interface displays M target data; in response to a selection operation on the M target data in the object information selection interface, determine N target data selected by the selection operation; obtain verification data of each of the N target data; and determine N object data pairs according to the N target data and the verification data of each of the N target data.
[0164] In an implementation, the computer instructions in the computer readable storage medium 1204 are loaded and further used by the processor 1201 to perform the following steps:
[0165] send an object declaration obtaining request to the issuing node, and the object declaration obtaining request carries an object identifier of a target object and object information of the target object; wherein the object declaration obtaining request is used to trigger the issuing node to obtain an object document of the target object based on the object identifier of the target object for verification, and generate object declaration data of the target object according to the object information of the target object after the object document of the target object is verified, and output the object declaration data.
[0166] In an implementation, the computer instructions in the computer readable storage medium 1204 are loaded and executed by the processor 1201 to submit the verification expression data corresponding to the object verification data, and specifically used to perform the following steps:
[0167] upload the verification expression data to the blockchain, and set the verification node as a visible node of the verification expression data in the blockchain, wherein the visible node of the verification expression data refers to a node that is allowed to obtain the verification expression data from the blockchain.
[0168] In an embodiment, the computer device can be the aforementioned verification node, and the processor 1201 can load and execute one or more computer instructions stored in the computer readable storage medium 1204 to implement the corresponding steps of the blockchain-based data processing method described above. Figure 8 In an embodiment, the computer device can be the aforementioned verification node, and the processor 1201 can load and execute one or more computer instructions stored in the computer readable storage medium 1204 to implement the corresponding steps of the blockchain-based data processing method described above.
[0169] obtain the verification expression data submitted by the holding node; the verification expression data corresponds to the object verification data generated by the holding node, and the verification expression data includes the object data pair to be verified;
[0170] According to the target data and the verification data of the target data in the to-be-verified object data pair, a verification hash of the to-be-verified object data pair is determined; if the verification hash of the to-be-verified object data pair matches a root hash corresponding to the target object, it is determined that the target object passes the verification.
[0171] The object verification data is generated according to a data set, the data set is determined according to object information of the target object included in the object declaration data of the target object, the object information includes M target data, the data set includes object data pairs, each object data pair includes a target data and verification data of the target data, N target data in the data set is selected and determined from the M target data, M is an integer greater than 1, and N is a positive integer less than or equal to M.
[0172] In an implementation manner, the number of to-be-verified object data pairs is N, and the verification expression data includes N to-be-verified object data pairs; the verification expression data further includes a root hash corresponding to the target object and a root signature corresponding to the target object; the root signature corresponding to the target object is obtained by encrypting the root hash corresponding to the target object by using a private key of a node for generating the object declaration data; the computer instructions in the computer readable storage medium 1204 are loaded by the processor 1201 and further used to perform the following steps:
[0173] The root signature corresponding to the target object is decrypted by using the public key of the node to obtain a decrypted hash corresponding to the target object; if the decrypted hash corresponding to the target object matches the root hash corresponding to the target object, it is determined that the root hash corresponding to the target object passes the verification; wherein, after the root hash corresponding to the target object passes the verification, the verification hash of the to-be-verified object data pair matches the root hash corresponding to the target object means that the verification hashes of the N to-be-verified object data pairs all match the root hash corresponding to the target object.
[0174] In an implementation manner, before the computer instructions in the computer readable storage medium 1204 are loaded and executed by the processor 1201 to decrypt the root signature corresponding to the target object by using the public key of the node to obtain the decrypted hash corresponding to the target object, the computer instructions are further used to perform the following steps:
[0175] Obtain the first signature information generated by the holding node, the second signature information generated by the issuing node, and the object document of the target object, the first signature information being obtained by encrypting the verification expression data using the private key of the target object, the second signature information being obtained by encrypting the object declaration data using the private key of the issuing node, and the object document of the target object containing the public key of the target object; if the first signature information is verified by the public key of the target object, obtain the object document of the issuing node; the object document of the issuing node includes the public key of the issuing node; if it is determined that the object document of the issuing node is issued according to the trusted identifier in the trusted list, verify the second signature information according to the public key of the issuing node; if the second signature information is verified, trigger the step of decrypting the root signature corresponding to the target object using the public key of the issuing node to obtain the decrypted hash corresponding to the target object.
[0176] In an implementation manner, the number of the object data pairs to be verified is N, and the verification expression data includes the N object data pairs to be verified; the root hash corresponding to the target object is uploaded to the blockchain for storage; the computer instructions in the computer readable storage medium 1204 are loaded by the processor 1201 and further used to execute the following steps:
[0177] Obtain the root hash corresponding to the target object from the blockchain; wherein the verification hash of the object data pair to be verified matches the root hash corresponding to the target object means that the verification hashes of the N object data pairs to be verified all match the root hash corresponding to the target object.
[0178] In an implementation manner, the number of the object data pairs to be verified is N, and the verification expression data includes the N object data pairs to be verified; the i-th object data pair to be verified in the N object data pairs to be verified includes the i-th target data and the verification data of the i-th target data, i being a positive integer less than or equal to N; the verification data of the i-th target data includes the confusion data allocated for the i-th target data in the Merkle tree of the target object and the verification information corresponding to the i-th target data determined in the Merkle tree of the target object; the Merkle tree of the target object is determined according to M target data; when the computer instructions in the computer readable storage medium 1204 are loaded and executed by the processor 1201 to determine the verification hash of the i-th object data pair to be verified according to the i-th target data and the verification data of the i-th target data, the following steps are specifically used to execute:
[0179] Splice the confusion data and the i-th target data to obtain spliced data; perform hash calculation on the spliced data to obtain the data hash corresponding to the i-th target data; calculate the verification hash of the i-th object data pair to be verified according to the data hash corresponding to the i-th target data and the verification information corresponding to the i-th target data.
[0180] In the embodiments of the present application, the object verification data can be generated according to the selectively disclosed object information, and then the object verification can be performed on the selectively disclosed object information in the corresponding verification expression data of the object verification data, and the unselected object information is hidden in the object verification process, so as to protect the data security of the object in the object verification process.
[0181] According to an aspect of the present application, a computer program product or computer program is provided, which includes computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device executes the blockchain-based data processing method provided in the various optional manners.
[0182] The above merely provides a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A blockchain-based data processing method, characterized in that, The method comprises: acquiring object declaration data of a target object, the object declaration data comprising object information of the target object, the object information comprising M target data, M being an integer greater than 1; determining a data set according to the object declaration data, the data set comprising N object data pairs, each object data pair comprising a target data and verification data of the target data, the N target data in the data set being determined from the M target data, the verification data of each target data in the N target data being different, N being a positive integer less than or equal to M; the verification data of the i-th target data in the N target data comprising: confusion data allocated for the i-th target data in a Merkle tree of the target object, and verification information corresponding to the i-th target data determined in the Merkle tree of the target object, the verification information being a verification path, i being a positive integer less than or equal to N; generating object verification data of the target object according to the data set, the object verification data comprising the object data pairs; submitting verification expression data corresponding to the object verification data, the verification expression data comprising N to-be-verified object data pairs; wherein, in the process of object verification, determining a verification hash of each to-be-verified data pair according to the target data and the verification data of the target data in each to-be-verified object data pair in the N to-be-verified object data pairs, and determining that the target object passes the verification if the verification hashes of the N to-be-verified object data pairs and a root hash corresponding to the target object both match.
2. The method of claim 1, wherein, The i-th object data pair in the N object data pairs comprises the i-th target data and the verification data of the i-th target data; The Merkle tree of the target object is determined according to the M target data; The confusion data is used to calculate a data hash corresponding to the i-th target data in combination with the i-th target data; and the verification information corresponding to the i-th target data is used to calculate a verification hash of the i-th object data pair in combination with the data hash corresponding to the i-th target data.
3. The method of claim 2, wherein, The object verification data further comprises a root hash corresponding to the target object and a root signature corresponding to the target object; The root hash corresponding to the target object is determined in the Merkle tree of the target object, the root signature corresponding to the target object is obtained by encrypting the root hash corresponding to the target object with a private key of an issuing node generating the object declaration data, and the root signature corresponding to the target object is used to verify the root hash corresponding to the target object; After the root hash corresponding to the target object is verified by the root signature corresponding to the target object, the root hash corresponding to the target object is used to verify the verification hashes of the object data pairs in the object verification data.
4. The method according to any one of claims 1 to 3, characterized in that, The number of the object data pairs is N, the data set comprises N object data pairs; and the determining of the data set according to the object declaration data comprises: The object verification request sent by the verification node carries a requested object data type; According to the indication of the object data type, the N target data matching the object data type are selected from the M target data; Obtain the verification data of each target data in the N target data; According to the N target data and the verification data of each target data, the N object data pairs are determined.
5. The method according to any one of claims 1 to 3, wherein The number of object data pairs is N, and the data set includes N object data pairs; The data set is determined according to the object declaration data, including: Display an object information selection interface, and display the M target data in the object information selection interface; In response to the selection operation of the M target data in the object information selection interface, the N target data selected by the selection operation are determined; Obtain the verification data of each target data in the N target data; According to the N target data and the verification data of each target data, the N object data pairs are determined.
6. The method of claim 1, wherein, The method further comprises: Send an object declaration acquisition request to the issuing node, wherein the object declaration acquisition request carries the object identifier of the target object and the object information of the target object; Wherein, the object declaration acquisition request is used to trigger the issuing node to acquire the object document of the target object based on the object identifier of the target object for verification, and after the object document of the target object is verified, the object declaration data of the target object is generated according to the object information of the target object, and the object declaration data is output.
7. The method of claim 1, wherein, The method comprises: The verification expression data corresponding to the object verification data is submitted, including: 8.A blockchain-based data processing method, characterized in that, The verification expression data is uploaded to the block chain, and the verification node is set as the visible node of the verification expression data in the block chain, that is, the node allowed to obtain the verification expression data from the block chain. The method comprises: Obtain the verification expression data submitted by the holding node; The verification expression data corresponds to the object verification data generated by the holding node, and the verification expression data includes N object data pairs to be verified; According to the target data and the verification data of the target data in each object data pair to be verified in the N object data pairs to be verified, the verification hash of each object data pair to be verified is determined; If the verification hashes of the N object data pairs to be verified and the root hash corresponding to the target object are matched, it is determined that the target object is verified. The object verification data is generated according to a data set, the data set is determined according to object information of the target object included in object declaration data of the target object, the object information includes M target data, the data set includes N object data pairs, each object data pair includes one target data and verification data of the target data, the N target data in the data set is selected and determined from the M target data, the verification data of each target data in the N target data is different, M is an integer greater than 1, N is a positive integer less than or equal to M, the verification data of the i-th target data in the N target data includes confusion data allocated for the i-th target data in a Merkle tree of the target object and verification information corresponding to the i-th target data determined in the Merkle tree of the target object, the verification information is a verification path, i is a positive integer less than or equal to N.
9. The method of claim 8, wherein, The verification expression data further includes root hash corresponding to the target object and root signature corresponding to the target object, the root signature corresponding to the target object is obtained by encrypting the root hash corresponding to the target object by using a private key of an issuing node generating the object declaration data, and the method further includes: decrypting the root signature corresponding to the target object by using a public key of the issuing node to obtain a decrypted hash corresponding to the target object; if the decrypted hash corresponding to the target object matches the root hash corresponding to the target object, it is determined that the root hash corresponding to the target object is verified successfully; wherein, after the root hash corresponding to the target object is verified successfully, the verification hash of the object data pair to be verified matches the root hash corresponding to the target object, which means that the verification hashes of the N object data pairs to be verified all match the root hash corresponding to the target object.
10. The method of claim 9, wherein, Before the step of decrypting the root signature corresponding to the target object by using the public key of the issuing node to obtain the decrypted hash corresponding to the target object, the method further includes: obtaining first signature information generated by the holding node, second signature information generated by the issuing node and object document of the target object, the first signature information is obtained by encrypting the verification expression data by using a private key of the target object, the second signature information is obtained by encrypting the object declaration data by using a private key of the issuing node, and the object document of the target object includes a public key of the target object; if the first signature information is verified successfully by using the public key of the target object, the object document of the issuing node is obtained, the object document of the issuing node includes a public key of the issuing node; if it is determined that the object document of the issuing node is issued according to a trusted identifier in a trusted list, the second signature information is verified according to the public key of the issuing node; if the second signature information is verified successfully, the step of decrypting the root signature corresponding to the target object by using the public key of the issuing node to obtain the decrypted hash corresponding to the target object is triggered.
11. The method of claim 8, wherein, The number of the to-be-verified object data pairs is N, the verification expression data includes N to-be-verified object data pairs; the root hash corresponding to the target object is uploaded to the blockchain for storage; the method further includes: Obtaining the root hash corresponding to the target object from the blockchain; Wherein, the verification hash of the to-be-verified object data pair matching the root hash corresponding to the target object means that the verification hash of the N to-be-verified object data pairs matches the root hash corresponding to the target object.
12. The method according to any one of claims 8 to 11, characterized in that, The i-th to-be-verified object data pair in the N to-be-verified object data pairs includes the i-th target data and the verification data of the i-th target data; The Merkle tree of the target object is determined according to the M target data; According to the i-th target data and the verification data of the i-th target data, the process of determining the verification hash of the i-th to-be-verified object data pair includes: Splicing the obfuscated data with the i-th target data to obtain spliced data; Hash calculation is performed on the spliced data to obtain the data hash corresponding to the i-th target data; According to the data hash corresponding to the i-th target data and the verification information corresponding to the i-th target data, the verification hash of the i-th to-be-verified object data pair is calculated. 13.A blockchain-based data processing apparatus, characterized by comprising: The device includes: An acquisition unit is configured to acquire object declaration data of a target object, the object declaration data including object information of the target object, the object information including M target data, M being an integer greater than 1; A processing unit is configured to determine a data set according to the object declaration data, the data set including N object data pairs, each object data pair including a target data and verification data of the target data, N target data in the data set being selected from the M target data, the verification data of each target data in the N target data being different, N being a positive integer less than or equal to M; the verification data of the i-th target data in the N target data includes obfuscated data allocated to the i-th target data in a Merkle tree of the target object and verification information corresponding to the i-th target data determined in the Merkle tree of the target object, the verification information being a verification path, i being a positive integer less than or equal to N; The processing unit is further configured to generate object verification data of the target object according to the data set, the object verification data including the object data pairs; The processing unit is further configured to submit verification expression data corresponding to the object verification data, the verification expression data including N to-be-verified object data pairs; wherein, in the process of object verification, the verification hash of each to-be-verified data pair is determined according to the target data and the verification data of the target data in each to-be-verified object data pair in the N to-be-verified object data pairs, and if the verification hashes of the N to-be-verified object data pairs all match the root hash corresponding to the target object, it is determined that the target object is verified. 14.A blockchain-based data processing apparatus, characterized by comprising: The device includes: An acquisition unit is configured to acquire verification expression data submitted by a holding node, wherein the verification expression data corresponds to object verification data generated by the holding node, and the verification expression data includes N object data pairs to be verified; A processing unit is configured to determine a verification hash of each object data pair to be verified according to target data in each object data pair to be verified and verification data of the target data; The processing unit is further configured to determine that the target object passes verification if the verification hashes of the N object data pairs to be verified all match a root hash corresponding to the target object; The object verification data is generated according to a data set, the data set is determined according to object information of the target object included in object declaration data of the target object, the object information includes M target data, the data set includes N object data pairs, each object data pair includes one target data and verification data of the target data, the N target data in the data set is selected from the M target data, the verification data of each target data in the N target data is different, M is an integer greater than 1, N is a positive integer less than or equal to M, the verification data of the i th target data in the N target data includes confusion data allocated for the i th target data in a Merkle tree of the target object and verification information corresponding to the i th target data determined in the Merkle tree of the target object, the verification information refers to a verification path, i is a positive integer less than or equal to N.
15. A computer device, comprising: The computer device includes: A processor adapted to implement a computer program; A computer readable storage medium storing a computer program, the computer program being adapted to be loaded and executed by the processor to implement the blockchain-based data processing method according to any one of claims 1-7, or the blockchain-based data processing method according to any one of claims 8-12.
16. A computer readable storage medium characterized by: The computer readable storage medium stores a computer program, the computer program being adapted to be loaded and executed by the processor to implement the blockchain-based data processing method according to any one of claims 1-7, or the blockchain-based data processing method according to any one of claims 8-12.
17. A computer program product, characterised in that, The computer program product includes computer instructions, which, when executed by a processor, implement the blockchain-based data processing method according to any one of claims 1-7, or the blockchain-based data processing method according to any one of claims 8-12.
Citation Information
Patent Citations
Attribute data processing method and device, equipment and medium
CN113779637A