Transaction processing method, apparatus, device, and medium
By combining threshold signature and multi-signature strategies, and leveraging the collaborative work of key sharding and signature management devices, the problem of digital resource security caused by key leakage in blockchain transactions is solved, achieving higher transaction security and contract resource protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2023-05-23
- Publication Date
- 2026-05-19
AI Technical Summary
In blockchain transaction scenarios, the leakage of an account's unique key leads to low security of digital resources, and existing technologies are insufficient to effectively protect the security of digital resources on contracts.
The system employs threshold signature and multi-signature strategies. The resource client is determined by the network connection status between the business terminal and the resource management server. Transaction signing is performed using key sharding, and remote signature management information is generated by combining multiple signature management devices. Finally, the blockchain node verifies the transaction signature.
It improves the security of digital resources on target business contracts, prevents resource loss due to key leakage, and enhances the security and reliability of transactions.
Smart Images

Figure CN116977073B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of blockchain technology, and in particular to transaction processing methods, apparatus, devices and media. Background Technology
[0002] In blockchain-based transaction scenarios, when a business entity initiates a transaction, it needs to sign the transaction and then send the transaction and its signature to the blockchain network. The blockchain network can only execute the transaction after verifying the transaction signature. Currently, a business entity's account can correspond to a single key, which is stored through a resource management client. The business entity only needs to sign the transaction to be signed using the single key stored in the resource management client to transfer digital resources in the account.
[0003] In practice, it has been found that once the unique key corresponding to an account is leaked, the digital resources in that account will be out of control, resulting in low security for the digital resources in the account. Summary of the Invention
[0004] This application provides a transaction processing method, apparatus, device, and medium that can combine threshold signature strategy and multi-signature strategy to sign transactions to be signed, thereby ensuring the security of digital resources on the target business contract.
[0005] This application provides a transaction processing method, executed by a business terminal; the method includes:
[0006] If the network connection between the business terminal and the resource management server is in a connected state, then the resource client used to participate in the transaction signing is determined as the first resource client based on the first business transaction signature strategy in the target transaction signature strategy; the first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy; the threshold signature strategy and the multi-signature strategy are deployed in the target business contract on the blockchain; the target business contract is obtained by the business object after registering the contract on the blockchain through the blockchain node; the contract address of the target business contract is the target contract address returned by the blockchain node to the business object;
[0007] The first business transaction to be signed is determined by the first resource client and associated with the target contract address. When the first key fragment of the business object is obtained, the first business transaction to be signed is signed by the first key fragment to obtain the first signature fragment.
[0008] Based on the multi-signature strategy, N signature management devices are identified that are associated with the business object, and the N signature management devices are notified to generate N remote signature management information associated with the first business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information.
[0009] Based on a threshold signature strategy, the first signature fragment and the first business transaction to be signed are sent to the resource management server. The resource management server then signs the first business transaction using the second key fragment of the business object to obtain the second signature fragment. Using the second signature fragment and the first signature fragment, the resource management server aggregates the first aggregated signature information. When the first business transaction to be signed is considered the first signed business transaction, the resource management server sends the first aggregated signature information and the first signed business transaction to the blockchain node. The blockchain node, upon receiving the first aggregated signature information and K remote signature management information, invokes the target business contract on the blockchain based on the target contract address. Using the first business transaction signature strategy indicated by the target business contract, the blockchain node verifies the first signed business transaction to obtain the transaction verification result. K is a positive integer less than or equal to N.
[0010] This application provides a transaction processing method, executed by a blockchain node; the method includes:
[0011] The system acquires a first signed business transaction and a first aggregated signature information associated with the business terminal. The first signed business transaction is determined based on a first business transaction to be signed. The first business transaction to be signed is determined by a first resource client running on the business terminal. The first resource client is a resource client used to participate in transaction signing, determined based on the first business transaction signature strategy in the target transaction signature strategy, when the network connection between the business terminal and the resource management server is in a connected state. The first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy. The first aggregated signature information is obtained by aggregating a second signature fragment and a first signature fragment. The first signature fragment is obtained by the business terminal signing the first business transaction to be signed using the first key fragment of the business object. The second signature fragment is obtained by the resource management server signing the first business transaction to be signed using the second key fragment of the business object when it receives the first signature fragment and the first business transaction to be signed sent by the business terminal based on the threshold signature strategy.
[0012] When K remote signature management information associated with the first signed business transaction is obtained, the target business contract on the blockchain is invoked based on the target contract address associated with the first signed business transaction; the K remote signature management information associated with the first signed business transaction is generated by K signature management devices based on the first business transaction to be signed; one signature management device corresponds to one remote signature management information; the K signature management devices are the signature management devices among the N signature management devices associated with the business object determined by the business terminal based on the multi-signature strategy; K and N are positive integers, and K is less than or equal to N;
[0013] By using the first business transaction signature strategy indicated by the target business contract, the first signed business transaction is verified to obtain the transaction verification result of the first signed business transaction.
[0014] One embodiment of this application provides a transaction processing apparatus, which is operated by a business terminal; the apparatus includes:
[0015] The resource client determination module is used to determine the resource client participating in transaction signing as the first resource client based on the first business transaction signature strategy in the target transaction signature strategy if the network connection status between the business terminal and the resource management server is connected. The first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy. The threshold signature strategy and the multi-signature strategy are deployed in the target business contract on the blockchain. The target business contract is obtained by the business object after registering the contract on the blockchain through the blockchain node. The contract address of the target business contract is the target contract address returned by the blockchain node to the business object.
[0016] The threshold signature module is used to determine the first business transaction to be signed associated with the target contract address through the first resource client. When the first key fragment of the business object is obtained, the first business transaction to be signed is signed through the first key fragment to obtain the first signature fragment.
[0017] The multi-signature module is used to determine N signature management devices associated with a business object based on a multi-signature strategy, and to notify the N signature management devices to generate N remote signature management information associated with the first business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information;
[0018] The sending module is used to send the first signature fragment and the first business transaction to be signed to the resource management server based on a threshold signature strategy. This allows the resource management server to sign the first business transaction to be signed using the second key fragment of the business object, obtaining a second signature fragment. Then, it aggregates the second and first signature fragments to obtain a first aggregated signature information. When the first business transaction to be signed is considered the first signed business transaction, the first aggregated signature information and the first signed business transaction are sent to the blockchain node. The blockchain node, upon receiving the first aggregated signature information and K remote signature management information, calls the target business contract on the blockchain based on the target contract address. Using the first business transaction signature strategy indicated by the target business contract, it verifies the first signed business transaction to obtain the transaction verification result. K is a positive integer less than or equal to N.
[0019] This application provides a transaction processing apparatus, executed by a blockchain node; the apparatus includes:
[0020] The acquisition module is used to acquire the first signed business transaction and the first aggregated signature information associated with the business terminal. The first signed business transaction is determined based on the first business transaction to be signed. The first business transaction to be signed is determined by the first resource client running on the business terminal. The first resource client is a resource client used to participate in transaction signing, determined based on the first business transaction signature strategy in the target transaction signature strategy, when the network connection between the business terminal and the resource management server is in a connected state. The first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy. The first aggregated signature information is obtained by aggregating the second signature fragment and the first signature fragment. The first signature fragment is obtained by the business terminal signing the first business transaction to be signed using the first key fragment of the business object. The second signature fragment is obtained by the resource management server signing the first business transaction to be signed using the second key fragment of the business object when it receives the first signature fragment and the first business transaction to be signed sent by the business terminal based on the threshold signature strategy.
[0021] The contract invocation module is used to invoke the target business contract on the blockchain based on the target contract address associated with the first signed business transaction when K remote signature management information associated with the first signed business transaction are obtained. The K remote signature management information associated with the first signed business transaction are generated by K signature management devices based on the first business transaction to be signed. One signature management device corresponds to one remote signature management information. The K signature management devices are the signature management devices among the N signature management devices associated with the business object determined by the business terminal based on the multi-signature strategy. K and N are positive integers, and K is less than or equal to N.
[0022] The transaction verification module is used to verify the first signed business transaction through the first business transaction signature strategy indicated by the target business contract, and obtain the transaction verification result of the first signed business transaction.
[0023] One aspect of this application provides a computer-readable storage medium storing a computer program adapted to be loaded and executed by a processor, so that a computer device having the processor performs the method provided in this application.
[0024] One embodiment of this application provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method provided in this application embodiment.
[0025] In this embodiment, based on the network connection status between the business terminal and the resource management server, a resource client (such as a first resource client) can be determined to sign the business transaction to be signed associated with the target business contract. The resource client can use the key stored in its database (such as a first key fragment) to sign the business transaction to be signed (such as a first business transaction to be signed) based on a threshold signature strategy, obtaining a first signature fragment. Then, the resource management client signs the business transaction to be signed based on another key fragment (such as a second key fragment), obtaining a second signature fragment. These multiple signature fragments are then aggregated to obtain aggregated signature information. Furthermore, a multi-signature strategy can be used to notify N signature management devices to sign the business transaction to be signed, obtaining remote signature management information. This allows subsequent blockchain nodes to verify the signed business transaction based on the aggregated signature information and the remote signature management information. Therefore, combining the threshold signature strategy and the multi-signature strategy to sign the business transaction to be signed ensures the security of digital resources on the target business contract. Attached Figure Description
[0026] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 This is a schematic diagram of a system architecture provided in an embodiment of this application;
[0028] Figure 2 This is a schematic diagram of a data interaction scenario provided in an embodiment of this application;
[0029] Figure 3 This is a schematic diagram of another data interaction scenario provided in an embodiment of this application;
[0030] Figure 4 This is a schematic diagram of a resource management client for a business object provided in an embodiment of this application;
[0031] Figure 5 This is a flowchart illustrating a transaction processing method provided in an embodiment of this application;
[0032] Figure 6 This is a flowchart illustrating a business contract registration method provided in an embodiment of this application;
[0033] Figure 7 This is a schematic diagram of data interaction provided in an embodiment of this application;
[0034] Figure 8 This is a data interaction diagram of a third business transaction signature strategy provided in an embodiment of this application;
[0035] Figure 9 This is a flowchart illustrating a transaction processing method provided in an embodiment of this application;
[0036] Figure 10 This is a schematic diagram of data interaction provided in an embodiment of this application;
[0037] Figure 11 This is a data interaction diagram of a fourth business transaction signature strategy provided in an embodiment of this application;
[0038] Figure 12 This is a flowchart illustrating a transaction processing method provided in an embodiment of this application;
[0039] Figure 13 This is a schematic diagram of a business management contract deployment process provided in an embodiment of this application;
[0040] Figure 14 This is a functional diagram corresponding to a business contract provided in an embodiment of this application;
[0041] Figure 15 This is a flowchart illustrating a transaction processing method provided in an embodiment of this application;
[0042] Figure 16 This is a schematic diagram of the structure of a transaction processing device provided in an embodiment of this application;
[0043] Figure 17This is a schematic diagram of the structure of a transaction processing device provided in an embodiment of this application;
[0044] Figure 18 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0045] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0046] Please see Figure 1 , Figure 1 This is a schematic diagram of a system architecture provided in an embodiment of this application. For example... Figure 1 As shown, the system architecture may include a terminal device cluster 100a, a resource management service cluster 200a, and a blockchain network 300a.
[0047] It should be understood that, for ease of understanding, the embodiments of this application may... Figure 1 The terminal device cluster 100a shown may include one or more terminal devices. The number of terminal devices in this terminal device cluster 100a is not limited here. Figure 1 As shown, the terminal devices in terminal device cluster 100a can include terminal device 110a, terminal device 110b, ..., terminal device 110n, etc. The application client running on any terminal device can specifically be a resource client, also known as a resource management client. A resource management client can be a tool responsible for managing digital resources. It can store the private key of a business object in an encrypted file, and then sign transactions to be signed (such as transactions transferring digital resources to other accounts) based on the private key stored in the resource management client. The signed transaction and the transaction signature are then sent to the blockchain to realize the transfer of digital resources on the blockchain. This resource client can be a hardware device or a software program. It is understood that one or more resource management clients can run on a single terminal device; there is no limit to the number of resource management clients running on a single terminal device. It is also understood that the same business object can correspond to one or more resource management clients, and multiple resource management clients corresponding to the same business object can run on the same terminal device or on different terminal devices; there is no restriction here.
[0048] This resource client can be used to implement resource management business functions and can establish a communication connection with a decentralized application client based on these functions. For example, in one possible implementation, the decentralized application can be the application that initiates the business transaction. It then determines the business transaction to be signed based on the resource client and uses the key (such as a private key) stored in the resource management client to sign the transaction, thus obtaining a signed transaction. It should be understood that the decentralized application associated with the business object can be integrated with the resource client (i.e., the resource client) and run on the same terminal device (e.g., the aforementioned terminal device 110a), or it can run on different terminal devices; this is not limited here. For ease of description, the terminal device that determines the business transaction to be signed in this embodiment can be referred to as the business terminal.
[0049] It is understood that the embodiments of this application can be applied to financial scenarios, in which case the digital resources corresponding to the resource management client can be legally recognized digital assets. The embodiments of this application can also be applied to gaming scenarios, in which case the digital resources corresponding to the resource management client can be game items that can be traded or exchanged, etc., without limitation.
[0050] The resource management service cluster 200a (also known as the resource management server cluster) may include one or more resource management service devices (also known as resource management servers or resource management backend servers) for storing key shards of business objects. The number of resource management servers in the resource management service cluster 200a will not be limited here. Figure 1 As shown, the resource management servers in the resource management server cluster 200a can include resource management server 120a, resource management server 120b, ..., resource management server 120n. For example... Figure 1 As shown, the resource management server in resource management server cluster 200a can communicate with... Figure 1 Some or all of the terminal devices in the terminal device cluster 100a shown are connected to the network so that they can interact with some or all of the terminal devices in the terminal device cluster 100a through the network connection.
[0051] Among them, such as Figure 1 The blockchain network 300a shown may include multiple blockchain nodes (i.e., consensus nodes participating in record-keeping on the blockchain), and the number of blockchain nodes (i.e., consensus nodes participating in record-keeping on the blockchain) in blockchain network 100d will not be limited here. Figure 1As shown, the multiple blockchain nodes in blockchain network 300a may specifically include blockchain node 11a, blockchain node 11b, blockchain node 11c, and blockchain node 11d. The blockchain nodes in this blockchain network can be used to maintain the blockchain, for example, Figure 1 The blockchain 11e shown is an example. Figure 1 As shown, terminal devices in terminal device cluster 100a (such as terminal device 110a) can establish network connections with blockchain nodes 11a, 11b, 11c, and 11d to interact with a specific blockchain node in blockchain network 300a when the terminal device in terminal device cluster 100a is connected to the blockchain network 300a. For example, terminal device 110a can act as a business terminal, and through a certain business transaction signing strategy, write signed business transactions associated with business objects onto the blockchain maintained by these blockchain nodes.
[0052] It is understandable that blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer. A blockchain includes a series of blocks sequentially generated in chronological order. Once a new block is added to the blockchain, it is not removed. Each block records the data packaged and submitted by the blockchain nodes in the blockchain system. It should be noted that the blockchain network 300a in this embodiment can be a layered structure or a single-layer structure; the specific structure of the blockchain network 300a is not limited here.
[0053] In other words, this application embodiment can utilize the decentralized, traceable, and tamper-proof characteristics of blockchain to send the signature information obtained after signing a transaction (e.g., Tx1) and the signed transaction (e.g., Tx1) together to the blockchain node. This allows the blockchain node to verify the signature of the transaction. After the signature verification is successful, the transaction (e.g., Tx1) is added to the transaction pool as a legitimate transaction. This allows multiple transactions containing this transaction (e.g., Tx1) to be packaged into a target block in the transaction pool, and the packaged target block is then uploaded to the blockchain maintained by the blockchain node.
[0054] It should be understood that, in this embodiment, the private key stored by a resource client can be the complete key or key fragment corresponding to the contract management address information (also called management address information) of a resource management contract (also called a business contract) registered on the blockchain. This resource management contract can be a smart contract for a business object to register a contract on the blockchain. Registering a resource management contract on the blockchain is equivalent to registering a resource management contract account. A contract account is a special type of account on the blockchain, created by smart contract code, and can perform predetermined operations, such as transferring assets and storing data. Contract accounts can only be controlled by contract code and are therefore also called Non-Externally Owned Accounts (NEOA). In the blockchain, contract accounts and regular accounts (EOAs) can interact with each other; for example, a regular account can send transactions to a contract account, and a contract account can also send transactions to a regular account. The difference is that the operation of a contract account is controlled by smart contract code, while the operation of a regular account is controlled by a private key. An EOA refers to a regular blockchain account controlled by a private key. EOA (Exclusive Access Provider) can send transactions, transfer assets, and perform other operations. These are user-created, possess private keys, and can directly interact with the blockchain network. This resource management contract can be managed by a contract management client, which stores and manages smart contracts on the blockchain. It can interact with, execute, and manage smart contracts on the blockchain. Contract management clients typically include a user-friendly interface, allowing users to view and manage the status and transaction history of their smart contracts. Some common contract management clients include MetaMask, MyEtherWallet, Trust Wallet, and Ledger NanoS. The concept of smart contracts possesses three key elements: commitment, agreement, and digital form, thus extending the application scope of blockchain to all aspects of transactions, payments, settlements, and clearing in the financial industry. A smart contract is a contract that immediately executes its terms when a pre-compiled condition is triggered, similar to the if-then statement in a computer program. In essence, smart contracts can be executed within a blockchain node based on a smart contract virtual machine. A smart contract virtual machine is a virtual machine capable of executing smart contracts. A smart contract is an automatically executed contract defined in the form of programming code. A smart contract virtual machine (EVM) can understand and execute this code to implement the functionality of a smart contract. EVMs are commonly used on blockchain platforms because they ensure the security and reliability of smart contracts on distributed networks. For example, the EVM can be a smart contract virtual machine that enables smart contracts written in Solidity (a contract programming language) to execute on a blockchain network.
[0055] It is understandable that a complete key or key shards can be used to sign transactions associated with the resource management contract (such as transactions transferring digital resources within the resource management contract, or transactions querying the quantity of digital resources within the resource management contract). Blockchain nodes can only invoke the resource management contract after obtaining a certain number of transaction signatures corresponding to the contract management address information. This allows for functions such as transferring digital resources within the resource management contract and querying the quantity of digital resources within the contract, thereby enabling the joint management of digital resources on the resource management contract by the business objects corresponding to each contract management address. It is also understood that the contract management address information of a resource management contract can include the key address information corresponding to the complete key and key shards held by the business object that initiated the registration of the resource management contract, and can also include the key address information corresponding to the complete key or key shards held by other business objects; there are no restrictions here. For example, if the resource management address information associated with the resource management contract includes dr1, dr2, dr3, and dr4, and the preset signature threshold is 2, then the keys corresponding to any two or more resource management address information (such as dr1 and dr2) are needed to sign the transaction to be signed to obtain the corresponding transaction signature information. The two or more transaction signature information and the signed transaction are sent to the blockchain node. The blockchain node verifies that the signed transaction has been signed by the keys corresponding to two or more resource management address information based on the received transaction signature information, and then calls the resource management contract to execute the signed business transaction.
[0056] Understandably, when a resource client storing the complete key signs a business transaction (also known as a transaction awaiting signature) associated with a resource management contract, if a corresponding signature is generated based on the complete key and the transaction awaiting signature, a transaction signature for that transaction can be generated. This method of signing business transactions awaiting signature can be called the complete signature method. Understandably, the resource client storing the complete key is usually not logged in, or in other words, the terminal device running the resource client storing the complete key is usually not connected to the internet. This reduces the possibility of the complete key being leaked, ensuring the security of the complete key and, consequently, the security of the digital resources on the business contract.
[0057] It is understandable that a key fragment stored by a resource client can be obtained by splitting a complete private key. A complete private key can be split into multiple key fragments, but this private key is not completely possessed by any single object. Instead, multiple objects each hold a key fragment and the same public key. Secure multi-party computation (MPC) technology is used to ensure that the various key fragments do not need to be combined into a complete key to generate a valid signature. It is also understandable that when signing a transaction using key fragments, multiple key fragment holding devices corresponding to the same public key need to sign the transaction, resulting in multiple signature fragments. One key fragment holding device can generate a signature fragment based on the key fragments it holds. Furthermore, the signature fragments generated by multiple key fragment holding devices can be aggregated to generate a single transaction signature for the transaction, i.e., aggregated signature information. This method of signing transactions can be called the threshold signature method. In essence, when generating aggregated signature information, aggregation can be performed based on signature fragments whose number is greater than or equal to the key fragmentation threshold. This key fragmentation threshold can be less than or equal to the total number of key fragments, and can be configured based on actual business needs; no restrictions are imposed here. For example, if a complete private key is split into m key fragments (i.e., the total number of key fragments is m), and the key fragmentation threshold is n, then when the selected signature aggregation device for aggregating signature fragments obtains n signature fragments generated from the n key fragments, aggregation processing can be performed based on these n signature fragments to obtain aggregated signature information. The value of n can be less than or equal to m. It is understood that since each key fragment holding device only holds a portion of the key fragments, even if some of the key fragments stored by these holding devices are leaked, the transaction signature for the transaction to be signed cannot be completed without the consent of the business objects holding the corresponding key fragments. Therefore, the resource management contract cannot be invoked to implement the corresponding functions, thus ensuring the security of the digital resources in the resource management contract.
[0058] It is understood that, in the application embodiments, the key shard holding device can be a terminal device of the business object, or a resource management server (such as resource management server 120a, resource management server 120b, ..., resource management server 120n) in the resource management service cluster 200a. The selected signature aggregation device for performing signature shard aggregation can be a terminal device of the business object (such as terminal device 110a), or a resource management server in the resource management service cluster (such as resource management server 120a), and there is no limitation here.
[0059] It is understood that in some embodiments, the terminal device of the business object (such as terminal device 110a) can be used as the business terminal. When the business terminal obtains the business transaction to be signed through the resource management client A that stores the key fragment F1, the business terminal can sign the business transaction to be signed through the key fragment F1 to obtain the signing fragment Q1. It can also notify the resource management server (such as resource management server 120a) that holds other key fragments (such as key fragment F2) that correspond to the same public key as the key fragment F1 to sign the business transaction to be signed to obtain the signing fragment Q2. Then, the signing aggregation device (such as terminal device 110a or resource management server 120a) can aggregate the signing fragment Q1 and the signing fragment Q2 to obtain the aggregated signature information.
[0060] It is understood that in some embodiments, the terminal device of the business object (such as terminal device 110a) can be used as the business terminal. Then, when the business transaction to be signed associated with the resource management contract A is obtained through the resource management client in the business terminal, the transaction to be signed can be signed using the key stored in the resource management client to obtain the corresponding signature information (such as signature information 1). The signature information 1 can be a complete key signature generated based on the complete key, or it can be an aggregated signature information generated based on multiple key fragments. No restriction is made here. Furthermore, the terminal device 110a can notify the terminal devices in the terminal device cluster associated with the contract management address information of resource management contract A to sign the business transaction to be signed, thereby obtaining remote signature management information (such as remote signature management information X1 and remote signature management information X2) associated with the business transaction to be signed. Then, when the business transaction to be signed is treated as a signed business transaction, and the signed business transaction, signature information 1, remote signature management information X1, and remote signature management information X2 are sent to the blockchain node, the blockchain node can only determine that the signed business transaction has been successfully verified if the remote signature management information is greater than or equal to the multi-signature threshold. This signing method based on multiple parties signing to obtain multiple signature information can also be called a multi-signature method. For ease of description, the terminal device associated with the business object that is notified to sign the business transaction to be signed can be called a signature management device. Understandably, the signature management device can determine the signature based on the contract management address information corresponding to the resource management contract of the transaction to be signed initiated by the business object. Each contract management address can have a corresponding key. In other words, the digital resources corresponding to the resource management contract can be jointly managed through the key corresponding to the contract management address. Only when the signature information obtained by signing the transaction based on the key corresponding to a certain number of contract management addresses can the resource management contract be invoked to realize functions such as transferring the digital resources associated with the resource management contract and querying the asset balance, thereby ensuring the security of the digital resources in the resource management contract.
[0061] Optionally, in some cases, the resource management server may lose connection between the terminal device and the server for various reasons, such as the server vendor ceasing service, server hardware failure, server software problems, network connectivity issues, etc. Therefore, if a business object initiates a transaction request for a resource management contract through a business terminal, and the resource management server is unavailable, it is impossible to sign the transaction initiated by the business object based on the key fragments stored on the resource management server. Consequently, aggregated signature information cannot be obtained based on the threshold signature strategy. Therefore, it is necessary to use the business object's complete key to sign the transaction.
[0062] Based on the above description, this application provides a transaction processing scheme that can determine a resource client (such as a first resource client) for signing a business transaction to be signed associated with a target business contract based on the network connection status between the business terminal and the resource management server. It can use the key stored in the resource client (such as a first key fragment) to sign the business transaction to be signed (such as a first business transaction to be signed) based on a threshold signature strategy, obtaining a first signature fragment. Then, the resource management client signs the business transaction to be signed based on another key fragment (such as a second key fragment), obtaining a second signature fragment. This aggregated signature information is obtained by aggregating multiple signature fragments. Furthermore, a multi-signature strategy can be used to notify N signature management devices to sign the business transaction to be signed, obtaining remote signature management information. This allows subsequent blockchain nodes to verify the signed business transaction based on the aggregated signature information and the remote signature management information. Therefore, by combining a threshold signature strategy and a multi-signature strategy to sign business transactions, the security of digital resources on the target business contract is ensured.
[0063] For further information, please refer to [link / reference]. Figure 2 , Figure 2 This is a schematic diagram illustrating a data interaction scenario provided in an embodiment of this application. For example... Figure 2 The service terminal 20a shown can be the above Figure 1 In the terminal device cluster of the corresponding embodiment, the service terminal 20a integrates and runs a resource management client 1, which is used for storage. Figure 2 The key fragment of business object A shown is (e.g., key fragment F1). Similarly, as... Figure 2 The resource management server 20b shown can be the above Figure 1The corresponding embodiment stores key fragments (e.g., key fragment F2) of the business object. Key fragment F1 and key fragment F2 both correspond to the same key address information (i.e., the same threshold signature key address information). It can be seen that the network connection status between the business terminal 20a and the resource management server 20b is connected.
[0064] like Figure 2 As shown, when business object A initiates a transaction request (step S21), the business terminal 20a, which integrates and runs the resource management client 1, can obtain the business transaction TX1 to be signed associated with the target contract address through the resource management client, and sign TX1 using key fragment F1 to obtain signature fragment M1 (step S22). Then, the business terminal 20a sends the business transaction TX1 to be signed and signature fragment M1 to the resource management server (step S23). The resource management server 20b signs TX1 using the hosted key fragment F2 to obtain signature fragment M2, and aggregates the signature information based on signature fragment M1 and signature fragment M2 (step S24). Then, the resource management server 20b sends the aggregated signature information and the signed business transaction TX1 to the blockchain network (step S25). Furthermore, the business terminal can notify the signature management device to sign the business transaction TX1 to be signed (step S26). The signature management device 20c integrates a resource client 2. The signature management device 20c can then use the key stored in the resource client 2 to sign the transaction TX1 to be signed, obtaining remote signature management information (step S27). The signature management device 20c can then send the remote signature management information to the blockchain network (step S28). Optionally, the signature management device 20c can also return the remote signature management information to the business terminal 20a, which in turn sends the remote signature management information to the blockchain network; this is not limited here. Further, the blockchain network verifies the signature of the business transaction TX1, and executes the business transaction TX1 upon successful verification (step S29). It is understood that, taking a blockchain node in the blockchain network as an example, the signature verification of the business transaction TX1 may include verifying both the aggregated signature information and the remote management signature information. Therefore, the business transaction TX1 is considered successfully verified only when the aggregated signature information is verified and the number of verified remote management signatures is greater than or equal to the multi-signature threshold. Furthermore, the blockchain node can collect the signature verification results of other blockchain nodes in the blockchain network for the business transaction TX1. If there are signature verification results exceeding a certain threshold in the collected verification results indicating that the business transaction TX1 has been successfully verified, then the business transaction TX1 will be executed.
[0065] It should be understood that the business terminal 20a signing the transaction to be signed based on key fragment F1 to obtain signature fragment M1, and sending the transaction to be signed TX1 and signature fragment M1 to the resource management server can be performed based on a threshold signature policy. The business terminal 20a notifying the signature management device 20c to sign the transaction to be signed TX1 can be performed based on a multi-signature policy.
[0066] For further details, please see Figure 3 , Figure 3 This is a schematic diagram of another data interaction scenario provided in an embodiment of this application. For example... Figure 3 The service terminal 30a shown can be the above Figure 1 In the terminal device cluster of the corresponding embodiment, the service terminal 30a integrates and runs a resource management client 3, which is used for storage. Figure 3 The complete key (e.g., complete key P) of business object A is shown. It can be seen that the network connection between business terminal 30a and the resource management server is not connected; therefore, the resource management server is not involved in this data transaction scenario diagram.
[0067] like Figure 3As shown, when business object A initiates a transaction request (step S31), the business terminal 30a can activate resource client 3, obtain the business transaction TX2 to be signed associated with the target contract address through resource management client 3, and sign TX2 using the full key P to obtain the full key signature G (step S32). Then, business terminal 30a sends the full key signature G and the signed business transaction TX2 to the blockchain network (step S33). Furthermore, business terminal 30a can notify signature management device 30b to sign the business transaction TX2 to be signed (step S34). The signature management device 30b integrates and runs resource client 4, and thus the signature management device 30b can use the key stored in the resource client 4 to sign the business transaction TX2 to be signed, obtaining remote signature management information (step S35). Then, the signature management device 30b can send the remote management signature information to the blockchain network (step S36). Optionally, the signature management device 30b can also return the remote signature management information to the business terminal 30a, which in turn sends the remote signature management information to the blockchain network. No limitation is imposed here. Furthermore, the blockchain network can verify the signature of business transaction TX2, and execute business transaction TX2 upon successful verification (step S37). Taking a blockchain node in the blockchain network as an example, the signature verification of business transaction TX2 by this blockchain node can include verifying the full key signature and the remote management signature information. Therefore, business transaction TX2 is determined to be successfully verified when the full key signature verification passes and the number of verified remote management signatures is greater than or equal to the multi-signature threshold. Furthermore, this blockchain node can collect verification results for business transaction TX2 from other blockchain nodes in the blockchain network. If any of the collected verification results exceed a certain threshold, indicating successful verification of business transaction TX2, then business transaction TX2 is executed. It should be understood that the business terminal 30a signing the transaction to be signed based on the complete key P to obtain the complete key signature G, and sending the transaction to be signed TX2 and the complete key signature G to the blockchain network, can be executed based on a complete signature policy. The business terminal 30a notifying the signature management device 30b to sign the transaction to be signed TX2 can be executed based on a multi-signature policy.
[0068] It is understandable that, for a business object A, the contract management address information of the resource management contract registered by business object A may include the key address information corresponding to the complete key held by business object A, and may also include the key address information corresponding to the key fragments held by the business object. Please refer to [link to relevant documentation]. Figure 4 , Figure 4This is a schematic diagram of a resource management client for a business object provided in an embodiment of this application. For example... Figure 4 As shown, the business terminal corresponding to this business object can run a first resource client 401 to store the first key fragment of the threshold signature, and the resource management server can run a managed resource client 402 to store the second key fragment of the threshold signature. This managed resource client 402 can also store the second key fragment of the business object. The first key fragment and the second key fragment (i.e., 401a) both correspond to the same management address information. The business object can also be associated with a second resource client 403 to store the complete key. This complete key (i.e., 403a) corresponds to a management address information. This second resource client is usually offline to ensure the security of the complete key.
[0069] Under normal circumstances, business entities can sign transactions using the threshold signature method. This means that a hot resource client storing the first key fragment can sign the transaction, and a resource management client can sign the transaction using the second key fragment stored in the hot resource client. This results in a final aggregated signature, with a small signature data size, ensuring security without increasing transaction costs and offering good usability. Furthermore, the participation of key fragments reaching a certain threshold is required to complete the transaction, clearly identifying the signer and facilitating oversight. In cases where threshold signatures are impossible due to resource management server unavailability or lost key fragments, the business entity will then activate the resource client storing the complete key to sign the transaction. This eliminates the need for resource management server involvement, resulting in higher availability.
[0070] It is understood that the transaction signature strategy corresponding to the embodiments of this application can also be applied to other scenarios requiring digital signatures, such as in the approval process of enterprise management. Important data within an enterprise can be assigned to corresponding management objects, such as Object A, Object B, and Object C. Object A, Object B, and Object C each hold a corresponding key fragment and a full key. In daily operations, each management object can use the key fragment to sign the download request for important data based on a threshold signature strategy, indicating agreement to download the important data. If the key fragment is lost or the server is unavailable, a full key can be used to sign the request, and the download of the important data requires the consent of a certain number of objects. The database storing the important data can verify the signature information associated with the download request after receiving the signed download request. Only when the verification is successful can the important data be sent to the object that initiated the download request.
[0071] It should be understood that, in the embodiments of this application, the facial (or other biometric) recognition technology involved, when applied to specific products or technologies, the collection, use, and processing of related data (e.g., facial information) should comply with national laws and regulations. It is understood that, before collecting facial information, the embodiments of this application will inform the information processing rules and solicit opinions from business stakeholders (e.g., the aforementioned...). Figure 2 The business entity A shown here has given its separate consent, and the facial information is processed in strict accordance with legal and regulatory requirements and personal information processing rules, and technical measures are taken to ensure the security of related data.
[0072] It is understood that, in the embodiments of this application, the terminal device that integrates and runs a resource management client may include: smartphones, tablets, laptops, desktop computers, wearable devices (such as smartwatches and smart bracelets), smart home devices, head-mounted devices, smart vehicle devices, and other smart terminals.
[0073] In this embodiment, the business service device that integrates and runs a key hosting client can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0074] It is understood that the above scenarios are merely examples and do not constitute a limitation on the application scenarios of the technical solutions provided in the embodiments of this application. The technical solutions of this application can also be applied to other scenarios. For example, as those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0075] Further, please see Figure 5 , Figure 5 This is a schematic flowchart of a transaction processing method provided in an embodiment of this application. The method can be executed by a business terminal, such as the terminal device 110a described above. The method may include at least the following steps S501-S504.
[0076] S501. If the network connection status between the business terminal and the resource management server is connected, then the resource client used to participate in the transaction signing is determined as the first resource client based on the first business transaction signature strategy in the target transaction signature strategy; the first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy; the threshold signature strategy and the multi-signature strategy are deployed in the target business contract on the blockchain; the target business contract is obtained by the business object after registering the contract on the blockchain through the blockchain node; the contract address of the target business contract is the target contract address returned by the blockchain node to the business object.
[0077] If the network connection status between the business terminal and the resource management server is "connected," it means that the business terminal and the resource management server can exchange data.
[0078] The first business transaction signature strategy can be a strategy used for transaction signing when the network connection between the business terminal and the resource management server is in a connected state. It is understood that this first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy.
[0079] The first resource client can be a resource client used to obtain business transactions to be signed and sign them using the stored key when the network connection between the business terminal and the resource management server is established. It can be understood that this first resource client can be a resource client used for frequent transaction signing, also known as a daily-use resource client or a hot resource client. The key stored in this first resource client can be a key fragment. Therefore, it needs to obtain a signature fragment obtained by signing other key fragments with the same public key or key address information as the key fragment, and then combine this signature fragment with the signature fragment obtained by signing transactions using the key fragment stored in the first resource client to generate an aggregate signature information, thus completing the transaction signing of the business transaction to be signed by the first resource client.
[0080] The threshold signature strategy can be used to instruct the business object to sign the business transaction to be signed based on the threshold signature method described above. That is, a signature fragment is obtained by signing the business transaction to be signed using the key fragment stored in the first resource client. Then, one or more other signature fragments are obtained by signing the business transaction to be signed using other devices (such as the resource management server in the resource management service cluster 200a). Then, the signature aggregation device (such as a business terminal or a resource management server in the resource management service cluster) aggregates the signature fragment generated by the first resource client and the first or more signature fragments generated by the resource management server to obtain aggregated signature information.
[0081] It is understood that a multi-signature strategy can be used to instruct business objects to sign transactions to be signed based on the aforementioned multi-signature method. Specifically, it instructs the signature management device to sign transactions associated with the resource management contract. This signature management device runs a resource client associated with the key corresponding to the contract management address information in the resource management contract. The signature management device then uses the key stored in the running resource client, corresponding to the contract management address information, to sign the transaction to be signed, obtaining remote signature management information. This remote signature management information can include the transaction to be signed and remote signature information, or it can be just remote signature information. Remote signature information refers to the signature information obtained by the signature management device using the key stored in the running resource client, corresponding to the contract management address information, to sign the transaction to be signed. It is understood that a blockchain node can only determine that the signed transaction has been successfully verified when it successfully verifies remote signature information greater than or equal to the multi-signature threshold indicated by the multi-signature strategy, and when it successfully verifies the signature information (such as aggregated signature information or full key signature) obtained by the business object using its own key (such as key shards or a complete business key).
[0082] It is understandable that the first business transaction signature strategy can be deployed in the target business contract on the blockchain. This target business contract is the resource management contract associated with the first resource client, meaning that the contract management address information of the target business contract includes the key address information corresponding to the key shards stored by the first resource client. It is also understandable that the threshold signature strategy and multi-signature strategy are deployed in the target business contract, allowing subsequent blockchain nodes to perform transaction verification (also known as signature verification) on the received signed business transactions based on the threshold signature strategy and multi-signature strategy in the target business contract.
[0083] This can be understood as the target business contract being obtained through contract registration on the blockchain, and the business object can obtain the contract address of the registered target business contract returned by the block node, i.e., the target contract address. The target contract address refers to the contract address of the target business contract.
[0084] Specifically, the business object is associated with a second resource client, which stores the business object's complete key (also called the complete key). The key address information of the complete key is the business complete key address information (also called the complete key address information). Therefore, this embodiment may further include the following steps: sending a threshold signature key acquisition request to a resource management server, so that the resource management server and the business terminal negotiate and generate a first key fragment stored in the first resource management client and a second key fragment stored in the resource management server based on a key fragmentation generation mechanism, and determining the key address information commonly corresponding to the first key fragment and the second key fragment as the threshold signature key address information; further, upon obtaining the threshold signature key address information, obtaining multiple registration management address information, including the threshold signature key address information and the business complete key address information; further, determining a registration transaction for contract registration based on the multiple registration management address information, sending the registration transaction to a blockchain node, so that the blockchain node registers the contract on the blockchain based on the registration transaction, obtaining the target business contract, and using the registration management address information as the contract management address information of the target business contract, the contract management address information being used to determine N signature management devices.
[0085] It can be understood that the second resource client is used to obtain business transactions to be signed and sign them using the stored key when the network connection between the business terminal and the resource management server is not established. The key stored in the second resource client can be the complete business key of the business object. Therefore, by using this complete key to sign the business transaction and obtaining the complete key signature, the second resource client can complete one transaction signature for the business transaction to be signed. It can also be understood that the second resource client can be a resource client that is not used for frequent transaction signing; it can also be called an offline resource client or a cold resource client. The terminal device where the second resource client is located can usually be in an offline state, or in other words, the second resource client is usually not logged in, to reduce the possibility of the complete business key being leaked. The second resource client only obtains the business transaction to be signed and signs it using the complete key stored in the second resource client when the first resource client of the business object is unavailable (e.g., the resource management server is unavailable). Since the second resource client stores the complete key, its leakage could significantly impact the assets on the target business contract. Therefore, the second resource client is not used for frequent transaction signing. When the network connection between the business terminal and the resource management server is connected, the first resource client can typically be used for transaction signing to ensure the security of the target business contract. The second resource client is only activated for transaction signing when the network connection between the business terminal and the resource management server is disconnected to ensure the availability of the target business contract.
[0086] The complete business key address information can be the key address information corresponding to the complete business key. This complete business key address information and the threshold signature key address information corresponding to the key fragments stored in the first resource client mentioned above are both contract management address information of the target business contract. The complete business key address information refers to the key address information corresponding to the complete business key, while the threshold signature key address information refers to the key address information commonly corresponding to multiple key fragments determined based on the threshold signature method.
[0087] This threshold signature key acquisition request can be used to request key fragments in the threshold signature method. The threshold signature acquisition request can carry the registration information of the business object, which may include facial information or other biometric features (such as fingerprints). The key fragment generation mechanism can be used for negotiation between the resource management server and the business terminal to obtain the key fragments corresponding to each device. For example, the key fragment generation mechanism can be the aforementioned MPC mechanism; no restrictions are placed here.
[0088] It is understood that the first key fragment can be a key fragment of the business object stored by the first resource client, and the second key fragment is a key fragment of the business object stored by the resource management server. The second key fragment can have one or more fragments. If the second key fragment has only one fragment, it can be stored by one resource management server in the resource management service cluster; if the second key fragment has multiple fragments, it can be stored by multiple resource management servers in the resource management service cluster. It is also understood that the threshold signature key address information refers to the key address information commonly corresponding to the first and second key fragments. This is because the first and second key fragments correspond to the same public key, thus allowing the determination of the threshold signature key address information, also known as the threshold signature key address information, which is the information shared by the first and second key fragments.
[0089] It is understood that the registration management address information can be the contract management address information corresponding to the resource management contract (also known as the business contract) to be registered. The registration management address information of a business contract to be registered can include the threshold signature key address information and the business complete key address information of the business object. Then, the business object can manage the registered business contract (i.e., sign the business transactions to be signed associated with the business contract) through the key fragment corresponding to the threshold signature key address information and the business complete key corresponding to the business complete key address information.
[0090] It is understood that the registration transaction can refer to a transaction used for contract registration. Optionally, the registration transaction can be sent to the blockchain node. This can be done either by the business terminal sending the registration transaction directly to the blockchain node, or by the business terminal sending the registration transaction to the resource management server, which then forwards the registration transaction to the blockchain node. There are no restrictions on this.
[0091] It is understandable that after a blockchain node obtains the target business contract through registration, it can use the management address information to be registered in the registration transaction as the contract management address information for the target business industry after registration.
[0092] It can be understood that the registration transaction may also include threshold information corresponding to the transaction signature strategy that needs to be deployed in the target business contract, such as the key sharding threshold indicated by the threshold signature strategy, and the multi-signature threshold indicated by the multi-signature strategy.
[0093] Specifically, determining the registration transaction for contract registration based on multiple management address information to be registered may include the following steps: obtaining the key fragmentation threshold indicated by the threshold signature policy and the multi-signature threshold indicated by the multi-signature policy; determining the registration transaction for contract registration based on multiple management address information to be registered, the key fragmentation threshold, and the multi-signature threshold.
[0094] It can be understood that the key fragmentation threshold indicated by the threshold signature strategy can be the number of signature fragments required to obtain an aggregated signature information. That is, the aggregated signature information can only be obtained by aggregating the signature fragments corresponding to key fragments that are greater than or equal to the key fragmentation threshold when the signature fragments corresponding to key fragments that are greater than or equal to the key fragmentation threshold are obtained.
[0095] It is understandable that the multi-signature threshold indicated by the multi-signature strategy means that a blockchain node needs to obtain remote signature management information that is greater than or equal to the multi-signature threshold, and successfully verify the remote signature management information that is greater than or equal to the multi-signature threshold before it can execute the corresponding business transaction.
[0096] It is understood that the registration management address information may include, in addition to the threshold signature key address information and complete business key address information of the business object initiating the registration transaction, the threshold signature key address information and complete business key address information of other business objects besides the business object initiating the registration transaction; this is not restricted here. It is also understood that the business terminal initiating the business transaction to be signed and the business terminal corresponding to the business object initiating the registration transaction can be the same terminal device or different terminal devices; this is not restricted here. For example, if business object A initiates a registration transaction for a business contract to be registered, the registration management address information in this registration transaction may include: the threshold signature key address information and complete business key address information of business object A, and the threshold signature key address information and complete business key address information of business object B; after the target business contract is successfully registered based on this registration transaction, the contract management address information of the target business contract may include: the threshold signature key address information and complete business key address information of business object A, and the threshold signature key address information and complete business key address information of business object B. Furthermore, business object A can initiate a pending-signature business transaction associated with the target business contract using its terminal device, and business object B can also initiate a pending-signature business transaction associated with the target business contract using its terminal device. This allows business object A and business object B to jointly manage the target business contract through their respective complete business keys and key shards. Both business object A and business object B can be referred to as business management objects of the target business contract. It is understood that the resource client used by any business management object to store key shards can be called the first resource client, and the resource client used to store the complete business key can be called the second resource client. For the same business contract, each business management object of the contract can act as a business object, initiating a transaction request through the business terminal. It then obtains the pending-signature business transaction associated with the contract address of the business contract through the resource client storing the key corresponding to the contract management address information, and uses the key corresponding to the resource client to sign the pending-signature business transaction. When the pending-signature business transaction is recognized as a signed business transaction, the signed business transaction and its associated signature information can be sent to the blockchain network.
[0097] Please see Figure 6 , Figure 6 This is a flowchart illustrating a business contract registration method provided in an embodiment of this application. Figure 6As shown, firstly, business object A can initiate a business contract registration request (step S61). Then, the business terminal can respond to this request and negotiate and determine key fragments based on the key fragmentation generation mechanism (step S62), thereby obtaining the first key fragment stored by the first resource client in the business terminal and the second key fragment stored by the resource management server. Next, the business terminal can obtain the management address information to be registered and generate a registration transaction TX3 based on this information (step S63), then send the registration transaction TX3 to the resource management server (step S64.1), so that the resource management server sends the registration transaction TX3 to the blockchain network (step S64.2). Optionally, the business terminal can also directly send the registration transaction TX3 to the blockchain node; this is not restricted. Then, the blockchain network can register the contract on the blockchain based on the registration transaction, obtain the target business contract, and determine the contract address of the target business contract (step S65). The blockchain network can return the contract address of the registered target business contract to business object A, and can also send it to other business management objects besides business object A.
[0098] S502. The first business transaction to be signed is determined by the first resource client and associated with the target contract address. When the first key fragment of the business object is obtained, the first business transaction to be signed is signed by the first key fragment to obtain the first signature fragment.
[0099] It is understood that the first business transaction to be signed can be a business contract associated with the target contract address determined by the first resource client. It is also understood that the first business transaction to be signed can be used to instruct the target business contract to perform corresponding functions, such as transferring digital resources within the target business contract, querying the quantity of digital resources within the target business contract, etc., without limitation.
[0100] It is understandable that the first key fragment of a business object can be determined by the first resource client. This first signature fragment can be the signature fragment obtained by signing the business transaction to be signed based on the first key fragment.
[0101] S503. Based on the multi-signature strategy, determine N signature management devices associated with the business object, and notify the N signature management devices to generate N remote signature management information associated with the first business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information.
[0102] It can be understood that the signature management device can be the terminal device running on the resource client corresponding to any of the keys in the contract management address information of the resource management contract, excluding the first key fragment stored by the first resource client. The N signature devices associated with the first transaction to be signed can be the terminal devices running on the resource client corresponding to the complete key address information in the contract management address information, or the terminal devices running on the resource client corresponding to the key fragment of the threshold signature key address information. For example, the contract management address information includes: the complete business key Q and key fragment F1 of business object A, and the complete business key R and key fragment P1 of business object B. If business object A determines the first transaction to be signed through the resource client corresponding to key fragment F1, then the N signature management devices determined based on the multi-signature strategy can be the terminal devices running on the resource client corresponding to the complete business key R of business object B, or the terminal devices running on the resource client corresponding to the key fragment P1 of business object B.
[0103] It is understandable that the same signature management device can be used to run only one resource client at a time, and the key address information corresponding to the key stored in the resource client belongs to the contract management address information of the target business contract. It is also understandable that one signature management device corresponds to one remote signature management information, which can be used to indicate that a signature management device can sign a transaction based on the resource client running on that device, thus obtaining a corresponding remote signature management information. Furthermore, it is understandable that a terminal device, when logging into different resource clients, can be used as different signature management devices. Therefore, identifying N signature management devices associated with a business object is equivalent to identifying N resource clients used for multi-signing transactions.
[0104] It is understandable that notifying N signature management devices to generate N remote signature management information associated with the first business transaction to be signed can be achieved by the resource management server sending a signature prompt message to the signature management devices, instructing them to use the corresponding resource clients to sign the business transaction to be signed. The signature management devices can then use the complete business key or key fragments stored in the running resource clients to sign the business transaction to be signed, ultimately generating the remote signature management information. Optionally, notifying N signature management devices to generate N remote signature management information associated with the first business transaction to be signed can also be achieved by notifying the signature management devices offline, thereby generating the remote signature management information through offline QR code scanning. For example, the business terminal generates a business transaction graphic code associated with the business transaction to be signed. The signature management device scans this graphic code to obtain the business transaction to be signed, then signs the transaction to obtain the remote signature management information, and generates a signature information graphic code based on the remote signature management information. The business terminal then scans this signature information graphic code to obtain the remote signature management information, which can then be sent to the blockchain node. Alternatively, the signature management device can sign the transaction to be signed, obtain the remote signature management information, and then directly send the remote signature management information to the blockchain node; there are no restrictions on this.
[0105] It is understandable that if the signature management device signs the business transaction to be signed using the complete business key, the obtained remote signature management information includes the complete key signature. If the signature management device signs the business transaction to be signed using key fragments, the obtained remote signature management information includes the aggregated signature information obtained by aggregating signature fragments obtained from multiple key fragment signatures.
[0106] S504. Based on the threshold signature strategy, the first signature fragment and the first business transaction to be signed are sent to the resource management server. This allows the resource management server to sign the first business transaction to be signed using the second key fragment of the business object, obtaining the second signature fragment. Then, by aggregating the second and first signature fragments, the resource management server obtains the first aggregated signature information. When the first business transaction to be signed is treated as the first signed business transaction, the resource management server sends the first aggregated signature information and the first signed business transaction to the blockchain node. The blockchain node, upon receiving the first aggregated signature information and K remote signature management information, calls the target business contract on the blockchain based on the target contract address. Using the first business transaction signature strategy indicated by the target business contract, the blockchain node verifies the first signed business transaction, obtaining the transaction verification result of the first signed business transaction. K is a positive integer less than or equal to N.
[0107] It is understood that when the threshold signature policy is a signature policy used to instruct the resource management server to perform aggregated signatures, step S504 can be executed. Performing aggregated signatures refers to the process of aggregating multiple signature fragments to obtain aggregated signature information. The transaction verification result refers to the result obtained by the blockchain node verifying the signature information associated with the signed business transaction.
[0108] The first aggregated signature information can be aggregated signature information obtained by aggregating multiple signature fragments (such as the first signature fragment and the second signature fragment) associated with the first business transaction to be signed, as determined by the threshold signature policy in the first business transaction signature policy. The second signature fragment can be obtained by the resource management server when signing the first business transaction to be signed using the second key fragment of the business object. It is understood that when there is only one second key fragment, this second key fragment can be deployed in one resource management server in the resource management service cluster. When there are multiple second key fragments, these multiple second key fragments can be deployed in multiple resource management servers in the resource management service cluster. Then, one selected resource management server in the resource management service cluster can notify other resource management servers to sign the first business transaction to be signed to obtain the second signature fragment, and obtain the second signature fragments returned by other resource management servers. Thus, when the total number of obtained first signature fragments and second signature fragments is greater than or equal to the key fragment threshold indicated by the threshold signature policy, the obtained first signature fragments and second signature fragments are aggregated to obtain aggregated signature information.
[0109] For example, if there is one second key fragment, and resource management server 120a in resource management service cluster 200a stores this second key fragment, then resource management server 120a can use this second key fragment to sign the first transaction to be signed, obtaining a second signature fragment. If the key fragment threshold indicated by the threshold signature policy is 2, then the resource management server can aggregate based on this one second signature fragment and the first signature fragment to obtain aggregated signature information.
[0110] For example, if there are multiple second key fragments (e.g., two), resource management servers 120a and 120b in the resource management service cluster each store one second key fragment. After receiving the first business transaction to be signed and the first signature fragment from the business terminal, one of the resource management servers (e.g., resource management server 120a) can use its stored second key fragment to sign the first business transaction to obtain a second signature fragment. It can also notify the other resource management server (e.g., resource management server 120b) to sign the first business transaction to obtain another second signature fragment. If the key fragment threshold indicated by this threshold signature policy is 3, then resource management server 120a needs to aggregate the two second signature fragments and the first signature fragment when it obtains them to obtain aggregated signature information. Optionally, if the key fragment threshold indicated by the threshold signature policy is 2, then the resource management server 120a needs to aggregate the first signature fragment and the second signature fragment when it obtains either of the two second signature fragments to obtain aggregated signature information.
[0111] It is understandable that after the resource management server obtains the aggregated signature information, it can send the first aggregated signature information and the first signed business transaction to the blockchain node when the first business transaction to be signed is regarded as the first signed business transaction; or, after the resource management server obtains the aggregated signature information, it can send the first aggregated signature information and the first signed business transaction to the blockchain node.
[0112] It is understandable that determining the second key fragment of a business object in the resource management server can determine the object access information based on the business object, so the business terminal can also send the object access information of the business object to the resource management server.
[0113] Specifically, the first business transaction to be signed is determined when the business object successfully accesses the first resource client through object access information; in the resource management server, the object access information of the business object is stored in association with the second key fragment; then, sending the first signature fragment and the first business transaction to be signed to the resource management server based on the threshold signature policy may include the following steps: obtaining the object access information of the business object; further, sending the object access information, the first signature fragment, and the first business transaction to be signed to the resource management server based on the threshold signature policy; the object access information is used to instruct the resource management server to determine the second key fragment of the business object based on the object access information.
[0114] It is understood that the object access information can be the facial information (also known as face information) or other biometric features (such as fingerprint information) of the business object. It is understood that if the object access information matches the object registration information corresponding to the first resource client, the business object is deemed to have successfully accessed the first resource client. It is understood that the first key fragment stored in the first resource client is determined based on the object registration information of the business object. Furthermore, in the resource management server, the object registration information of the business object is stored in association with the second key fragment. Therefore, after receiving the object access information, the resource management server can search for matching object registration information based on the object access information, and use the second key fragment associated with the matching object registration information as the second key fragment of the business object. This allows the resource management server to use the found second key fragment to sign the first business transaction to be signed, obtaining the second signature fragment.
[0115] Optionally, when the threshold signature policy is a signature policy used to instruct business terminals to perform aggregate signature, the first business transaction to be signed is sent to the resource management server, so that the resource management server signs the first business transaction to be signed using the second key fragment of the business object to obtain the second signature fragment; further, when the second signature fragment returned by the resource management server is obtained, the first aggregate signature information is obtained by aggregating the second signature fragment and the first signature fragment, and when the first business transaction to be signed is regarded as the first signed business transaction, the first aggregate signature information and the first signed business transaction are sent to the blockchain node.
[0116] It is understandable that if the business terminal performs the aggregated signature, the resource management server, after generating the second signature fragment, can return the second signature fragment to the business terminal that initiated the transaction. The business terminal then aggregates the obtained second and first signature fragments to obtain the first aggregated signature information. It is understandable that the method by which the business terminal aggregates the second and first signature fragments to obtain the aggregated signature information can refer to the relevant description of the resource management server aggregating the second and first signature fragments to obtain the aggregated signature information, which will not be repeated here. It is understandable that if there is only one second key fragment, the first business transaction to be signed is sent to the resource management server, that is, the first business transaction to be signed is sent to the resource management server storing the second key fragment. Then, after obtaining the second signature fragment, the single resource management server returns the second signature fragment to the business terminal. If there are multiple second key fragments, the first business transaction to be signed is sent to one of the resource management servers selected from the multiple resource management servers used to store the second key fragments. Then, the selected resource management server forwards the first business transaction to be signed to other resource management servers. Each resource management server storing the second key fragment can return a second signature fragment to the business terminal, or the selected resource management server can summarize the various second signature fragments and return them to the business terminal in a unified manner. There is no restriction here.
[0117] Understandably, having the business terminal perform signature aggregation and send the aggregated signature information and signed business transactions to the blockchain can prevent the resource management server from failing to send signed business transactions to the blockchain node due to configuration issues. This avoids the business terminal being unable to accurately determine whether the resource management server has sent signed business transactions to the blockchain node, thus improving the security and controllability of business transactions.
[0118] Understandably, the business terminal can also obtain remote signature management information generated by various signature management devices, and then send the obtained remote signature management information, the aggregated signature information obtained by the business object itself, and the signed business transactions to the blockchain node.
[0119] Specifically, when treating the first transaction to be signed as the first signed transaction, sending the first aggregated signature information and the first signed transaction to the blockchain node may include the following steps: receiving remote signature management information returned by the signature management devices among N signature management devices, and counting the number of received remote signature management information to obtain the number of received remote signatures; further, when the remote signature timestamp associated with the first transaction to be signed reaches the remote signature time threshold, and the number of received remote signatures is greater than or equal to the multi-signature threshold indicated by the multi-signature strategy, the first transaction to be signed is treated as the first signed transaction; further, the received K remote signature management information, the first aggregated signature information, and the first signed transaction are sent to the blockchain node.
[0120] It is understandable that the number of remote signatures received can be the number of remote signature management messages currently received that are associated with the first transaction to be signed. It is also understandable that for the business terminal, the number of received remote signatures can be incremented by one for each remote signature management message received.
[0121] Understandably, the remote signature timestamp can be associated with the timing information used by the signature management device to sign the transaction for the first transaction to be signed. This remote signature time threshold can be a preset maximum time threshold for waiting to receive remote signature management information. For example, if the remote signature time threshold is 20 minutes, then remote signature management information returned by the signature management device can be received within 20 minutes of receiving the first transaction to be signed. If the remote signature timestamp associated with the first transaction reaches 20 minutes, the counting of received remote signature management information will stop.
[0122] Understandably, if the remote signature timestamp associated with the first transaction awaiting signature reaches the remote signature time threshold, and the number of received remote signatures is less than the multi-signature threshold indicated by the multi-signature strategy, then the first transaction awaiting signature will not be considered the first signed transaction, and thus the transaction will not be sent to the blockchain node. This allows the business terminal to make a preliminary judgment on the number of multi-signatures obtained, avoiding sending transactions that are certain to fail verification to the blockchain node, thereby reducing the burden on the blockchain node.
[0123] For example, see Figure 7 , Figure 7 This is a schematic diagram of data interaction provided in an embodiment of this application. For example... Figure 7As shown, when business object A initiates a transaction request (step S71), the business terminal 70a, which integrates and runs the resource management client 1, can obtain the business transaction TX1 to be signed associated with the target contract address through the resource management client 1 (step S72); then, the business terminal 70a sends the business transaction TX1 to be signed to the resource management server (step S73); the resource management server 70b signs TX1 using key fragment F2 to obtain signature fragment M2 (step S74), and returns signature fragment M2 to the business terminal (step S75). Then, the business terminal 70a signs TX1 using key fragment F1 to obtain signature fragment M1. Based on signature fragment M1 and signature fragment M2, aggregated signature information is obtained (step S76). Furthermore, the business terminal 70a can notify the signature management device to sign the business transaction TX1 to be signed (step S77). The signature management device 70c integrates a resource client 2. The signature management device 70c can then use the key stored in the resource client 2 to sign the business transaction TX1 to be signed, obtaining remote signature management information (step S78). The signature management device 70c can then return the remote signature management information to the business terminal 70a (step S79). Further, when the remote signature timestamp associated with the business transaction TX1 reaches the remote signature time threshold, and the total number of received remote signature management information is greater than or equal to the multi-signature threshold indicated by the multi-signature strategy, the business terminal 70a sends the aggregated signature information, the remote signature management information, and the signed business transaction TX1 to the blockchain network (step S710). Further, the blockchain network can verify the signature of the business transaction TX1, and upon successful verification, execute the business transaction TX1 (step S711). It is understood that the process of the blockchain network signing and verifying business transactions and executing business transactions can refer to the above. Figure 2 The relevant descriptions shown are not repeated here.
[0124] In one embodiment, when the network connection status result indicates that the network connection status between the service terminal and the resource management server is connected, the transaction to be signed can be signed only by the threshold signature policy, which is equivalent to the multi-signature threshold indicated by the multi-signature policy being 0, and thus there is no need to notify other signature management devices to sign the transaction to be signed.
[0125] Specifically, when the network connection status result indicates that the network connection between the business terminal and the resource management server is in a connected state, the resource client used to participate in the transaction signing is determined as the first resource client based on the third business transaction signing strategy in the target transaction signing strategy; the second business transaction signing strategy is independent of the first business transaction signing strategy, and the second business transaction signing strategy is a threshold signing strategy; further, the third business transaction to be signed is determined through the first resource client and associated with the target contract address; when the first key fragment of the business object is obtained, the third business transaction to be signed is signed through the first key fragment to obtain the third signature fragment; further, the third signature fragment and the third business transaction to be signed are linked based on the threshold signing strategy. The business transaction is sent to the resource management server, so that the resource management server can sign the third business transaction to be signed using the second key fragment of the business object and obtain the fourth signature fragment. Then, the resource management server aggregates the third and fourth signature fragments to obtain the second aggregated signature information. When the third business transaction to be signed is regarded as the third signed business transaction, the resource management server sends the second aggregated signature information and the third signed business transaction to the blockchain node. When the blockchain node obtains the second aggregated signature information, it calls the target business contract on the blockchain based on the target contract address. The blockchain node verifies the third signed business transaction using the third business transaction signature strategy indicated by the target business contract and obtains the transaction verification result of the third signed business transaction.
[0126] It is understood that the first business transaction signature strategy is a threshold signature strategy, meaning that only transactions to be signed are signed using this strategy. The content of the third business transaction to be signed can be the same as or different from the content of the first business transaction; this is not restricted here. It is also understood that when the network connection status indicates that the network connection between the business terminal and the resource management server is active, only one business transaction strategy is determined from the third and first business transaction strategies to sign the transaction. The specific business transaction signature strategy used can be determined by actual business needs and is not restricted here.
[0127] The third signature fragment can be obtained by signing the third transaction to be signed using the first key fragment, and the fourth signature fragment can be obtained by signing the third transaction to be signed using the second key fragment. The second aggregated signature information can be obtained by aggregating the third and fourth signature fragments. It is understood that the method for generating the second aggregated signature information can refer to the method for generating the first aggregated signature information described above, and will not be repeated here. It is understood that the device used to generate the second aggregated signature information can be the resource management client or a business terminal; please refer to the relevant descriptions for generating the first aggregated signature information described above, and will not be repeated here.
[0128] For example, see Figure 8 , Figure 8 This is a data interaction diagram illustrating a third-party business transaction signature strategy provided in an embodiment of this application. For example... Figure 8 The service terminal 80a shown can be the above Figure 1 In the terminal device cluster of the corresponding embodiment, the service terminal 80a integrates and runs a resource management client 1, which is used for storage. Figure 8 The key fragment of business object A shown is (e.g., key fragment F1). Similarly, as... Figure 8 The resource management server 80b shown can be the above Figure 1 The corresponding embodiment includes a resource management service device that stores key fragments (e.g., key fragment F12) of the service object. Key fragment F1 and key fragment F2 both correspond to the same key address information. It can be seen that the network connection status between the service terminal 80a and the resource management server 80b is connected.
[0129] like Figure 8As shown, when business object A initiates a transaction request (step S81), the business terminal 80a, which integrates and runs the resource management client 1, can obtain the business transaction TX1 to be signed associated with the target contract address through the resource management client, and sign TX1 using key fragment F1 to obtain signature fragment M1 (step S82). Then, business terminal 80a sends the business transaction TX1 to be signed and signature fragment M1 to the resource management server (step S83). Resource management server 80b signs TX1 using key fragment F2 to obtain signature fragment M2, and aggregates the signature information based on signature fragment M1 and signature fragment M2 (step S84). Then, resource management server 80b sends the aggregated signature information and the signed business transaction TX1 to the blockchain network (step S85). Furthermore, the blockchain network can verify the signature of business transaction TX1, and execute business transaction TX1 when the verification is successful (step S86). Taking a blockchain node in a blockchain network as an example, the signature verification of business transaction TX1 by this blockchain node may include verifying aggregate signature information. Therefore, if the aggregate signature information is verified successfully, the signature verification of business transaction TX1 is determined to be successful. Furthermore, this blockchain node can collect signature verification results for business transaction TX1 from other blockchain nodes in the blockchain network. If, among the collected signature verification results, there are more than a certain threshold indicating that business transaction TX1 has been successfully verified, then business transaction TX1 is executed.
[0130] Please see Figure 9 , Figure 9 This is a flowchart illustrating a transaction processing method provided in an embodiment of this application. The method can be executed by a business terminal, such as the terminal device 110a described above. The method may include at least the following steps S901-S909.
[0131] S901. Detect the network connection status between the business terminal and the resource management server, and obtain the network connection status result.
[0132] It can be understood that this network connection status result can be the result of the network connection status between the business terminal and the resource management server. This network connection status result can be used to indicate that the network connection status between the business terminal and the resource management server is connected, or it can be used to indicate that the network connection status between the business terminal and the resource management server is not connected.
[0133] Specifically, embodiments of this application may include: detecting the network connection status between the service terminal and the resource management server, and obtaining a network connection status result; when the network connection status result indicates that the network connection status between the service terminal and the resource management server is a connected state, performing the step of determining the resource client used to participate in the transaction signature as the first resource client based on the first business transaction signature strategy in the target transaction signature strategy.
[0134] It is understandable that the step of determining the resource client used to participate in transaction signing as the first resource client based on the first business transaction signing policy in the target transaction signing policy can refer to the relevant description of step S501 above, and is not limited here. Subsequently, steps S502-S504 can be executed to achieve business transaction signing when the network connection between the business terminal and the resource management server is in a connected state.
[0135] When the network connection status result can be used to indicate that the network connection status between the business terminal and the resource management server is not connected, the relevant descriptions in subsequent steps S906-S909 can be referred to.
[0136] Understandably, the network connection status between the business terminal and the resource management server can be detected through a heartbeat mechanism. For example, the business terminal periodically sends heartbeat packets to the resource management server, and upon receiving the heartbeat packets, the resource management server can return a heartbeat packet to the business terminal. If the business terminal receives a heartbeat packet returned by the management server within a certain time range, the network connection status result indicates that the network connection between the business terminal and the resource management server is connected; if the business terminal does not receive a heartbeat packet returned by the resource management server within a certain time range, the network connection status result indicates that the network connection between the business terminal and the resource management server is disconnected.
[0137] S902. If the network connection status between the business terminal and the resource management server is connected, then the resource client used to participate in the transaction signing is determined as the first resource client based on the first business transaction signature strategy in the target transaction signature strategy; the first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy; the threshold signature strategy and the multi-signature strategy are deployed in the target business contract on the blockchain; the target business contract is obtained by the business object after registering the contract on the blockchain through the blockchain node; the contract address of the target business contract is the target contract address returned by the blockchain node to the business object.
[0138] S903. The first business transaction to be signed is determined by the first resource client and associated with the target contract address. When the first key fragment of the business object is obtained, the first business transaction to be signed is signed by the first key fragment to obtain the first signature fragment.
[0139] S904. Based on the multi-signature strategy, determine N signature management devices associated with the business object, and notify the N signature management devices to generate N remote signature management information associated with the first business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information.
[0140] S905. Based on the threshold signature strategy, the first signature fragment and the first business transaction to be signed are sent to the resource management server. This allows the resource management server to sign the first business transaction to be signed using the second key fragment of the business object, obtaining the second signature fragment. Then, by aggregating the second and first signature fragments, the resource management server obtains the first aggregated signature information. When the first business transaction to be signed is treated as the first signed business transaction, the resource management server sends the first aggregated signature information and the first signed business transaction to the blockchain node. The blockchain node, upon receiving the first aggregated signature information and K remote signature management information, calls the target business contract on the blockchain based on the target contract address. Using the first business transaction signature strategy indicated by the target business contract, the node verifies the first signed business transaction, obtaining the transaction verification result of the first signed business transaction. K is a positive integer less than or equal to N.
[0141] The relevant descriptions of steps S902-S905 can be found in the relevant descriptions of steps S501-S504, and will not be repeated here.
[0142] S906. When the network connection status result indicates that the network connection status between the business terminal and the resource management server is not connected, the resource client used to participate in the transaction signing is determined as the second resource client based on the second business transaction signing strategy in the target transaction signing strategy; the second business transaction signing strategy includes a full signature strategy and a multi-signature strategy; the full signature strategy and the multi-signature strategy are deployed in the target business contract.
[0143] It can be understood that the second resource client can be used to obtain the business transaction to be signed and sign it using the stored key when the network connection between the business terminal and the resource management server is not established. The key stored in the second resource client can be the complete business key of the business object. Therefore, by simply using this complete key to sign the business transaction to be signed, and obtaining the complete key signature, the second resource client can complete the transaction signing of the business transaction to be signed.
[0144] The full signature strategy can be a strategy that uses the complete business key to sign transactions. The multi-signature strategy can be described as above and will not be repeated here. It is understood that the full signature strategy and multi-signature strategy are deployed in the target business contract, and subsequently, blockchain nodes can verify the received signed business transactions (also known as signature verification) based on the full signature strategy and multi-signature strategy in the target business contract.
[0145] S907. The second business transaction to be signed is determined by the second resource client and associated with the target contract address. When the complete business key of the business object is obtained, the second business transaction to be signed is signed by the complete business key to obtain the complete key signature.
[0146] The second business transaction to be signed can be a business contract associated with the target contract address, determined by the second resource client. It is understood that the second business transaction to be signed can be used to instruct the target business contract to perform corresponding functions, such as transferring digital resources within the target business contract, querying the quantity of digital resources within the target business contract, etc., without limitation.
[0147] The complete key signature is the signature information obtained by signing transactions using the complete business key of the business object stored in the second resource client.
[0148] It is understood that the second resource client can run on the same terminal device as the first resource client, or it can run on a different terminal device; no restriction is placed here. It is also understood that if the second resource client runs on the same terminal device as the first resource client, then when the network connection status indicates that the network connection between the business terminal (i.e., the terminal device used by the business object to initiate the transaction request) and the resource management server is not connected, and a transaction request initiated by the business object is received, the second resource client is activated, and the contract address of the target business contract is set in the second resource client. Thus, the second business transaction to be signed, associated with the target contract address, is determined through the second resource client. If the second resource client and the first resource client run on different terminal devices, and the terminal device running the second resource client can be offline normally, then when the network connection status indicates that the network connection between the business terminal (i.e., the terminal device used by the business object to initiate the transaction request) and the resource management server is not connected, and a transaction request initiated by the business object is obtained, the business terminal can call the second resource client by scanning a code offline to obtain the complete key signature of the business transaction to be signed. For example, the business terminal that obtains the transaction request initiated by the business object generates a transaction request graphic code associated with the transaction request. The terminal device running the second resource client scans the transaction request graphic code to obtain the second business transaction to be signed associated with the target contract address. Then, the terminal device running the second resource client uses the stored complete key to sign the second business transaction to be signed, obtains the complete key signature, and returns the complete key signature and the second business transaction to be signed to the business terminal.
[0149] S908. Based on the multi-signature strategy, determine N signature management devices associated with the business object, and notify the N signature management devices to generate remote signature management information associated with the second business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information.
[0150] The process of determining the N signature management devices used to determine the remote signature management information of the second transaction to be signed can refer to the relevant description of the N signature management devices used to determine the remote signature management information of the first transaction to be signed, and will not be repeated here. In other words, these N signature management devices can be the terminal devices running on the resource clients corresponding to the complete keys other than the business complete key stored in the second resource client, which are the keys corresponding to the contract management address information of the resource management contract. In other words, the N signature devices associated with the second transaction to be signed are the terminal devices running on the resource clients corresponding to the complete keys corresponding to the complete key address information in the contract management address information. For example, the contract management address information includes: the business complete key Q and key fragment F1 of business object A, and the business complete key R and key fragment P1 of business object B. If business object A determines the second transaction to be signed through the resource client corresponding to the business complete key Q, then the N signature management devices determined based on the multi-signature strategy can be the terminal devices running on the resource clients corresponding to the business complete key R of business object B.
[0151] It is understandable that notifying N signature management devices to generate N remote signature management information associated with the first transaction to be signed can be achieved by the business terminal directly sending a signature prompt message to the signature management device, instructing the corresponding resource client to sign the transaction. The signature management device can then use the complete business key stored in the running resource client to sign the transaction, ultimately generating the remote signature management information. Alternatively, notifying N signature management devices to generate N remote signature management information associated with the first transaction to be signed can also be achieved by notifying the signature management devices offline, thereby generating the remote signature management information through offline QR code scanning. The method for generating remote signature management information through offline QR code scanning can refer to the description above regarding generating remote signature management information through offline QR code scanning when determining the signature management device associated with the first transaction to be signed, and will not be elaborated upon here.
[0152] S909. When the second business transaction to be signed is regarded as the second signed business transaction, the full key signature and the second signed business transaction are sent to the blockchain node based on the full key signature strategy. When the blockchain node obtains the full key signature and K remote signature management information, it calls the target business contract on the blockchain based on the target contract address. Through the second business transaction signature strategy indicated by the target business contract, the second signed business transaction is verified to obtain the transaction verification result of the second signed business transaction.
[0153] It is understandable that the K remote signature management information can be sent directly from the signature management device to the blockchain node, or it can be sent uniformly to the blockchain node by the business terminal after the signature management device returns the remote signature management information to the business terminal that initiated the second transaction to be signed. No restrictions are imposed here.
[0154] Specifically, if the K remote signature management information messages are sent to the blockchain node by the business terminal after the signature management device returns the remote signature management information to the business terminal that initiated the second business transaction to be signed, then when the second business transaction to be signed is treated as the second signed business transaction, sending the full key signature and the second signed business transaction to the blockchain node based on the full key signature strategy can include the following steps: Further, receiving remote signature management information returned by the signature management devices among the N signature management devices, and counting the number of received remote signature management information messages to obtain the number of received remote signatures; Further, when the remote signature timestamp associated with the second business transaction to be signed reaches the remote signature time threshold, and the number of received remote signatures is greater than or equal to the multi-signature threshold indicated by the multi-signature strategy, treating the second business transaction to be signed as the second signed business transaction; Further, sending the received K remote signature management information messages, the full key signature, and the second signed business transaction to the blockchain node based on the full signature strategy.
[0155] It is understood that the steps for determining whether a second transaction to be signed is a second signed transaction based on the number of remote signatures associated with the second transaction to be signed and the number of remote signatures received can refer to the above description of determining whether a first transaction to be signed is a first signed transaction based on the number of remote signatures associated with the first transaction to be signed and the number of remote signatures received. These steps will not be repeated here.
[0156] For example, see Figure 10 , Figure 10 This is a schematic diagram of data interaction provided in an embodiment of this application. For example... Figure 10As shown, when business object A initiates a transaction request (step S101), the business terminal 101a can activate resource client 3, obtain the business transaction TX2 to be signed associated with the target contract address through resource management client 3, and sign TX2 using the complete key P to obtain the complete key signature G (step S102). Furthermore, the business terminal 101a can notify the signature management device 101b to sign the business transaction TX2 to be signed (step S103). The signature management device 101b integrates and runs resource client 4, and thus the signature management device 101b can use the key stored in the resource client 4 to sign the business transaction TX2 to be signed, obtaining remote signature management information (step S104). Then, the signature management device 101b can return the remote management signature information to the business terminal (step S105). Furthermore, when the remote signature timestamp associated with business transaction TX2 reaches the remote signature time threshold, and the total number of received remote signature management messages is greater than or equal to the multi-signature threshold indicated by the multi-signature strategy, the business terminal 70a sends the remote management information, the complete key signature G, and the signed business transaction TX2 to the blockchain network (step S106). Furthermore, the blockchain network can verify the signature of business transaction TX2, and execute business transaction TX2 upon successful verification (step S107). It is understood that the steps for the blockchain network to verify the signature of business transaction TX2 and execute business transaction TX2 can be referred to the above. Figure 3 The relevant descriptions in the text will not be repeated here.
[0157] In one embodiment, when the network connection status result indicates that the network connection status between the service terminal and the resource management server is not connected, the transaction to be signed can be signed only by the full signature policy, which is equivalent to the multi-signature threshold indicated by the multi-signature policy being 0, and thus there is no need to notify other signature management devices to sign the transaction to be signed.
[0158] Specifically, when the network connection status result indicates that the network connection between the business terminal and the resource management server is in a connected state, the resource client used to participate in the transaction signing is determined as the second resource client based on the fourth business transaction signing strategy in the target transaction signing strategy; the third and fourth business transaction signing strategies are independent of the second business transaction signing strategy, and the fourth business transaction signing strategy is a complete signing strategy; further, the fourth business transaction to be signed is determined through the second resource client and associated with the target contract address. When the complete business key of the business object is obtained, the fourth business transaction to be signed is signed using the complete business key to obtain a complete key signature; further, when the second business transaction to be signed is used as the second signed business transaction, the complete key signature and the second signed business transaction are sent to the blockchain node based on the complete key signature strategy, so that when the blockchain node obtains the complete key signature, it calls the target business contract on the blockchain based on the target contract address, and verifies the fourth signed business transaction using the fourth business transaction signing strategy indicated by the target business contract to obtain the transaction verification result of the fourth signed business transaction.
[0159] It is understood that the fourth business transaction signature strategy is a complete signature strategy, meaning that only the complete signature strategy is used to sign the business transaction to be signed. The transaction content of this fourth business transaction to be signed can be the same as or different from the transaction content of the second business transaction to be signed; this is not restricted here. It is understood that when the network connection status indicates that the network connection between the business terminal and the resource management server is not connected, only one business transaction strategy is determined from the fourth and second business transaction strategies to sign the business transaction to be signed. The specific business transaction signature strategy used can be determined by actual business needs; this is not restricted here. The method for generating the complete key signature of the fourth business transaction to be signed can refer to the relevant description of generating the complete key signature of the second business transaction to be signed, and will not be repeated here. It is understood that when generating the complete key signature of the fourth business transaction to be signed, the fourth business transaction to be signed can be considered as the fourth signed business transaction.
[0160] For example, see Figure 11 , Figure 11 This is a data interaction diagram illustrating a fourth business transaction signature strategy provided in an embodiment of this application. For example... Figure 11 The service terminal 30a shown can be the above Figure 1 In the terminal device cluster of the corresponding embodiment, the service terminal 30a integrates and runs a resource management client 3, which is used for storage. Figure 3The complete key (e.g., complete key P) of business object A is shown. It can be seen that the network connection between business terminal 30a and the resource management server is not connected; therefore, the resource management server is not involved in this data transaction scenario diagram.
[0161] like Figure 11 As shown, when business object A initiates a transaction request (step S111), the business terminal 30a can activate resource client 3, obtain the business transaction TX2 to be signed associated with the target contract address through resource management client 3, and sign TX2 using the full key P to obtain the full key signature G (step S112). Then, the business terminal 20a sends the full key signature G and the signed business transaction TX2 to the blockchain network (step S113). Further, the blockchain network can verify the signature of business transaction TX2, and execute business transaction TX2 when the verification is successful (step S114). It can be understood that, taking a blockchain node in the blockchain network as an example, the signature verification of business transaction TX2 by the blockchain node may include verification of the full key signature, thereby determining that the verification of business transaction TX2 is successful when the full key signature verification is successful. Furthermore, the blockchain node can collect the signature verification results of other blockchain nodes in the blockchain network for the business transaction TX2. If there are signature verification results exceeding a certain threshold in the collected signature verification results, indicating that the business transaction TX2 has been successfully verified, then the business transaction TX2 will be executed.
[0162] Please see Figure 12 , Figure 12 This is a schematic flowchart of a transaction processing method provided in an embodiment of this application. The method can be executed by a blockchain node, such as the blockchain node 11a described above. The method may include at least the following steps S1201-S1203.
[0163] S1201. Obtain the first signed business transaction and the first aggregated signature information associated with the business terminal; the first signed business transaction is determined based on the first business transaction to be signed, which is determined by the first resource client running on the business terminal. The first resource client is a resource client used to participate in transaction signing, determined based on the first business transaction signature strategy in the target transaction signature strategy when the network connection between the business terminal and the resource management server is in a connected state; the first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy; the first aggregated signature information is obtained by aggregating the second signature fragment and the first signature fragment. The first signature fragment is obtained by the business terminal signing the first business transaction to be signed using the first key fragment of the business object. The second signature fragment is obtained by the resource management server signing the first business transaction to be signed using the second key fragment of the business object when it receives the first signature fragment and the first business transaction to be signed sent by the business terminal based on the threshold signature strategy.
[0164] It is understood that the descriptions of the first signed business transaction and the first aggregated signature information can be referenced above. Figure 5 The relevant descriptions in the illustrated embodiments will not be repeated here.
[0165] S1202. When K remote signature management information associated with the first signed business transaction is obtained, the target business contract on the blockchain is invoked based on the target contract address associated with the first signed business transaction. The K remote signature management information associated with the first signed business transaction is generated by K signature management devices based on the first business transaction to be signed. One signature management device corresponds to one remote signature management information. The K signature management devices are the signature management devices among the N signature management devices associated with the business object determined by the business terminal based on the multi-signature strategy. K and N are positive integers, and K is less than or equal to N.
[0166] It is understood that the K remote signature management information associated with the first signed business transaction can be sent to the blockchain node by the business terminal along with the first signed business transaction and the first aggregated signature information; or, the K remote signature management information associated with the first signed business transaction can be sent to the blockchain node by the resource management server along with the first signed business transaction and the first aggregated signature information; or, the K remote signature management information associated with the first signed business transaction can also be sent to the blockchain node by the K signature management devices themselves, without any restrictions.
[0167] It is understood that the embodiments of this application further include: receiving a first signed business transaction, a first aggregated signature information, and K remote signature management information sent by a business terminal; the K remote signature management information sent by the business terminal is returned to the business terminal by K signature management devices. It is understood that if the remote signature management information can be signature information generated based on a threshold signature method, the signature management device can sign the business transaction to be signed based on the first key fragment in the running resource client to obtain a first signature fragment, and then send the business transaction to be signed to the resource management server. The resource management server then determines the second key fragment corresponding to the object access information of the business object corresponding to the signature management device, generates a second signature fragment, and then returns the second signature fragment to the corresponding signature management device, so that the signature management device can aggregate the first signature fragment and the second signature fragment to obtain an aggregated signature information, determine a remote signature management information based on the aggregated signature information, and then send the remote signature management information to the business terminal. Understandably, if the remote signature management information can be signature information generated based on the complete signature method, the signature management device can sign the business transaction to be signed based on the complete business key in the running resource client to obtain the complete key signature. Then, the signature management device can determine a remote signature management information based on the complete business signature information and return the remote signature management information to the business terminal.
[0168] It is understood that the embodiments of this application further include: receiving a first signed business transaction, a first aggregated signature information, and K remote signature management information sent by the resource management server corresponding to the business terminal; the K remote signature management information sent by the resource management server is sent to the resource management server by K signature management devices. It is understood that if the remote signature management information can be signature information generated based on the threshold signature method, the signature management device can sign the business transaction to be signed based on the first key fragment in the running resource client to obtain a first signature fragment, and then send the first signature fragment and the business transaction to be signed to the resource management server. Then, the resource management server determines the second key fragment corresponding to the object access information of the business object corresponding to the signature management device, and generates a second signature fragment. Then, the resource management server aggregates the second signature fragment and the first signature fragment to obtain an aggregated signature information, and determines a remote signature management information based on the aggregated signature information. Subsequently, the resource management device can send the remote signature management information to the blockchain node. Understandably, if the remote signature management information can be signature information generated based on the complete signature method, the signature management device can sign the transaction to be signed based on the complete business key in the running resource client to obtain the complete key signature. Then, the signature management device can determine a remote signature management information based on the complete business signature information and send the remote signature management information to the resource management server so that the resource management server can send the remote signature management information to the blockchain node.
[0169] It is understood that the embodiments of this application also include: receiving K remote signature management messages sent by K signature management devices respectively. It is understood that if the remote signature management message can be signature information generated based on a threshold signature method, the signature management device can sign the transaction to be signed based on the first key fragment in the running resource client to obtain a first signature fragment, and then send the transaction to be signed to the resource management server. The resource management server then determines the second key fragment corresponding to the object access information of the business object corresponding to the signature management device, generates a second signature fragment, and then returns the second signature fragment to the corresponding signature management device. This allows the signature management device to aggregate the first and second signature fragments to obtain an aggregated signature message, determine a remote signature management message based on the aggregated signature message, and then directly send the remote signature management message to the blockchain node. Understandably, if the remote signature management information can be signature information generated based on the complete signature method, the signature management device can sign the transaction to be signed based on the complete business key in the running resource client to obtain the complete key signature. Then, the signature management device can determine a remote signature management information based on the complete business signature information and then send the remote signature management information directly to the blockchain node.
[0170] S1203. Using the first business transaction signature strategy indicated by the target business contract, perform transaction verification on the first signed business transaction to obtain the transaction verification result of the first signed business transaction.
[0171] It is understandable that the first business transaction signature strategy may include threshold signature strategy and multi-signature strategy, as detailed above. Figure 5 The relevant description in the illustrated embodiment. The transaction verification result can be used to indicate that the signed business transaction verification (also known as authentication) was successful, or to indicate that the signed business transaction verification failed. It is understood that a business transaction (such as transferring digital resources in a target business contract, querying the quantity of digital resources in a target business contract, etc.) can only be executed if the signed business transaction verification (also known as authentication) is successful. If the signed business transaction verification fails, the corresponding business transaction cannot be executed.
[0172] It is understandable that, by using the first business transaction signature strategy indicated by the target business contract to verify the first signed business transaction and obtain the transaction verification result of the first signed business transaction, it can be that the first signed business transaction is verified by using the threshold signature strategy and multi-signature strategy indicated by the target business contract, and the transaction verification result of the first signed business transaction is obtained.
[0173] Specifically, by using the first business transaction signature strategy indicated by the target business contract to verify the first signed business transaction and obtain the transaction verification result of the first signed business transaction, the process may include the following steps: Invoking the target business contract to determine a threshold signature strategy for verifying the first aggregated signature information; verifying the first aggregated signature information based on the threshold signature strategy to obtain the first signature verification result corresponding to the first aggregated signature information; further, invoking the target business contract to determine a multi-signature strategy for verifying the K remote signature management information; verifying the K remote signature management information based on the multi-signature strategy to obtain the first signature verification result corresponding to the K remote signature management information. The second signature verification result is associated with the information; the second signature verification result includes K signature verification results corresponding to K remote signature management information; M successful signature verification results among the K signature verification results are obtained by M signature management devices among the K signature management devices; in the M signature management devices, one signature management device corresponds to one successful signature verification result; M is a positive integer greater than the multi-signature threshold indicated by the multi-signature threshold policy; furthermore, if the first signature verification result is a successful signature verification result, and there are M successful signature verification results in the second signature verification result, then the transaction verification result of the first signed business transaction is determined to indicate that the first signed business transaction has been successfully verified.
[0174] It can be understood that the first signature verification result can be used to indicate whether the verification of the first aggregated signature information was successful. The second signature verification result may include K signature verification results, with one signature verification result corresponding to one remote signature management information, and the signature verification result corresponding to each remote signature management information is used to indicate whether the remote signature management information was successfully verified.
[0175] It is understandable that, based on a threshold signature strategy, signing and verifying the first aggregated signature information to obtain a first signature verification result can be achieved by determining the public key corresponding to the first aggregated signature information based on the threshold signature strategy, and then verifying the first aggregated signature information based on the public key to obtain the first signature verification result. Similarly, based on a multi-signature strategy, signing and verifying K remote signature management information to obtain a second signature verification result associated with the K remote signature management information can be achieved by determining the public key corresponding to each remote signature management information based on the multi-signature strategy, and then verifying the transaction of the corresponding remote signature management information based on the public key of each remote signature management information, thereby obtaining the second signature verification result based on the signature verification results of the K remote signature management information.
[0176] It is understandable that a successful signature verification result means that the corresponding signature information has been successfully verified.
[0177] It is understandable that the presence of M successful signature verification results in the second signature verification result is equivalent to the successful verification of remote signature management information exceeding the multi-signature threshold indicated by the multi-signature threshold policy. It is also understandable that the first signature verification result is a successful signature verification result, and the presence of M successful signature verification results in the second signature verification result is equivalent to the successful verification of signature information generated by keys corresponding to M+1 contract management address information, thus confirming the successful verification of the first signed business transaction.
[0178] Understandably, before a business terminal obtains the first business transaction to be signed associated with the target business contract, it needs to register the contract on the blockchain.
[0179] Specifically, the blockchain deploys a business management contract for managing business contracts and a business template contract for defining business contract templates. Therefore, this application embodiment may further include the following steps: when a registration transaction for contract registration is obtained, the registration management address information corresponding to the contract to be registered is determined from the registration transaction; further, when the business management contract is invoked to deploy the contract to be registered on the blockchain based on the business template contract, the contract to be registered already deployed on the blockchain is used as the target business contract, and the registration management address information is used as the contract management address information of the target business contract; further, when the contract address of the target business contract is obtained, the contract address of the target business contract is sent to the business terminal.
[0180] It is understandable that the registration transaction and the management address information to be registered in the registration transaction can refer to the above. Figure 5 The relevant descriptions in the illustrated embodiments will not be repeated here.
[0181] Specifically, the business management contract can be a smart contract used to manage resource management contracts (also known as business contracts) deployed on the blockchain. The business template contract can be a smart contract used to define templates for resource management contracts deployed on the blockchain. It is understood that after receiving a registration transaction, a blockchain node can invoke the business management contract to deploy the contract to be registered on the blockchain based on the business template contract, thus using the already deployed contract to be registered as the target business contract.
[0182] Understandably, a blockchain node can generate the contract address (i.e., the target contract address) of a registered target business contract, and then return the target contract address to the business terminal that initiated the registration transaction. This means sending it to the business object that initiated the registration transaction, allowing the business object to subsequently initiate a pending-signature business transaction associated with the target contract address of that target business contract. Furthermore, the blockchain node can also send the target contract address to the terminal device running the resource client corresponding to the key of the contract management address information, in addition to other terminal devices besides the business terminal that initiated the registration transaction. In other words, the blockchain node can send the target contract address to the business object that initiated the registration transaction, and also to other business management objects of the target business contract, so that these other business management objects can initiate pending-signature business transactions associated with the target contract address of the target business contract.
[0183] It is understood that the registration transaction may also include the key fragmentation threshold indicated by the threshold signature policy and the multi-signature threshold indicated by the multi-signature policy, thereby determining the key fragmentation threshold of the threshold signature policy and the multi-signature threshold of the multi-signature policy in the business transaction signature policy deployed in the target business contract.
[0184] For example, see Figure 13 , Figure 13 This is a schematic diagram of a business management contract deployment process provided in an embodiment of this application. For example... Figure 13 As shown, a development object (such as development object B) can send a deployment transaction for a business management contract and a business template contract to the blockchain network (step S1301), thereby deploying the business management contract 1301a and the business template contract 1301b on the blockchain node. Furthermore, upon receiving a registration transaction for registering a business contract, the blockchain node can invoke the business management contract 1301a and the business template contract 1301b to deploy a business contract exclusively owned by the business object corresponding to the set contract management address information.
[0185] Understandably, business template contracts can be used to define the functionality of the business contracts to be deployed. A business template contract can define functions including: transferring digital resources, adding or removing contract management address information, querying the quantity of digital resources in the business contract, and setting thresholds corresponding to signature transaction strategies (such as key sharding thresholds for threshold signature strategies and multi-signature thresholds for multi-signature strategies). For example, if the multi-signature threshold corresponding to the device's multi-signature strategy is 0, then the business object only needs to use its own key (such as a full key or key shards) to sign the transaction and obtain signature information (such as aggregate signature information corresponding to a full key signature or key shards) to invoke the business contract.
[0186] For example, see Figure 14 , Figure 14 This is a functional diagram corresponding to a business contract provided in an embodiment of this application. For example... Figure 14 As shown, the functions corresponding to a business contract can be defined by a business template contract. This business contract may include functions such as transferring digital resources (1401a), querying the quantity of digital resources in the business contract (1402a), adding or removing contract management address information (1403a), and setting the threshold corresponding to the signature transaction strategy (1404a). It is understood that the various functions corresponding to this business contract can all be initiated by the business management object through a business transaction, which is then sent to the blockchain network. When the blockchain network successfully verifies the signed business transaction, it can invoke the business contract to execute the corresponding function. For example, the business management object of the target business contract can send a transaction request indicating the transfer of numerical resources to determine the signed business transaction associated with the target business contract for transferring numerical resources through the business terminal, and then send the signed business transaction to the blockchain network. The blockchain network can then invoke the target business contract to execute the business transaction.
[0187] Understandably, embodiments of this application also include: upon obtaining the third signed business transaction and the second aggregated signature information, invoking the target business contract on the blockchain based on the target contract address associated with the third signed business transaction; the third signed business transaction is determined based on the third business transaction to be signed, and the third business transaction to be signed is determined by a first resource client running on the business terminal; the first resource client is a resource client determined based on the third business transaction signature strategy in the target transaction signature strategy when the network connection between the business terminal and the resource management server is in a connected state; the third business transaction signature strategy is a threshold signature strategy; the third... The aggregated signature information is obtained by the resource management server through the aggregation of the third signature fragment and the fourth signature fragment. The third signature fragment is obtained by the business terminal signing the third business transaction to be signed using the first key fragment of the business object. The fourth signature fragment is obtained by the resource management server signing the third business transaction to be signed using the second key fragment of the business object when it receives the third signature fragment and the third business transaction to be signed sent by the business terminal based on the threshold signature policy. Furthermore, the third signed business transaction is verified by the third business transaction signature policy indicated by the target business contract to obtain the transaction verification result of the third signed business transaction.
[0188] It is understandable that the process of generating the third signed business transaction and the second aggregated signature information can refer to the above. Figure 5 The relevant descriptions in the illustrated embodiments will not be repeated here.
[0189] It is understandable that the third signed business transaction is verified by using the third business transaction signature strategy indicated by the target business contract to obtain the transaction verification result of the third signed business transaction. That is, the public key corresponding to the second aggregated signature information is obtained by using the threshold signature strategy indicated by the target business contract, and the third signed business transaction is verified by using the public key corresponding to the second aggregated signature information to obtain the transaction verification result of the third signed business transaction.
[0190] Please see Figure 15 , Figure 15 This is a schematic flowchart of a transaction processing method provided in an embodiment of this application. The method can be executed by a blockchain node, such as the blockchain node 11a described above. The method may include at least the following steps S1501-S1503.
[0191] S1501. Obtain the second signed business transaction and the full key signature sent by the business terminal; the second signed business transaction is determined based on the second business transaction to be signed, which is determined by the second resource client running on the business terminal. The second resource client is a resource client used to participate in transaction signing, determined based on the second business transaction signing strategy in the target transaction signing strategy when the network connection between the business terminal and the resource management server is not connected; the second business transaction signing strategy includes a full signature strategy and a multi-signature strategy; the second signed business transaction and the full key signature are sent by the business terminal based on the full signature strategy, and the full key signature is obtained by the business terminal signing the second business transaction to be signed using the full key of the business object.
[0192] It is understood that the descriptions of the second signed business transaction and the full key signature can be referred to above. Figure 9 The relevant descriptions in the illustrated embodiments will not be repeated here.
[0193] S1502. When K remote signature management information associated with the second signed business transaction is obtained, the target business contract on the blockchain is invoked based on the target contract address associated with the second signed business transaction. The K remote signature management information associated with the second signed business transaction is generated by K signature management devices based on the second business transaction to be signed, and one signature management device corresponds to one remote signature management information. The K signature management devices are the signature management devices among the N signature management devices associated with the business object determined by the business terminal based on the multi-signature strategy. K is a positive integer, and K is a positive integer less than or equal to N.
[0194] It is understood that the K remote signature management information associated with the second signed business transaction can be sent to the blockchain node by the business terminal along with the second signed business transaction and the complete key signature; or the K remote signature management information associated with the second signed business transaction can be sent to the blockchain node by the K signature management devices themselves, without any restrictions.
[0195] It is understood that the embodiments of this application further include: receiving a second signed business transaction, a complete key signature, and K remote signature management information sent by a business terminal; the K remote signature management information sent by the business terminal is returned to the business terminal by K signature management devices. It is understood that when the resource management server is unavailable, the remote signature management information can be signature information generated based on the complete signature method. In this case, the signature management device can sign the business transaction to be signed based on the complete business key in the running resource client to obtain a complete key signature. Then, the signature management device can determine a remote signature management information based on this complete business signature information and return the remote signature management information to the business terminal. The business terminal then sends the remote signature management information, the second signed business transaction, and the complete key signature to the blockchain node.
[0196] It is understood that the embodiments of this application also include: receiving K remote signature management messages sent by K signature management devices respectively. It is understood that when the resource management server is unavailable, the remote signature management message can be signature information generated based on a complete signature method. In this case, the signature management device can sign the transaction to be signed based on the complete business key in the running resource client to obtain a complete key signature. Then, the signature management device can determine a remote signature management message based on this complete business signature information and directly send the remote signature management message to the blockchain node.
[0197] It is understandable that if K remote signature management information is directly sent to the blockchain node, then any of the K signature management devices can use the business complete key in the signature management device to sign the second business transaction to be signed, obtain the corresponding complete key signature, and treat the second business transaction to be signed as the second signed business transaction. Then, the second business transaction to be signed and the corresponding complete key signature are used as remote signature management information to send the remote signature management information to the blockchain node.
[0198] Understandably, when a blockchain node obtains the first second signed business transaction and the associated complete business key, it determines the signature waiting timer information associated with the second signed business transaction; receives remote signature management information associated with the second signed business transaction, and counts the number of remote signature management messages received associated with the second signed business transaction; when the signature waiting timer information reaches the signature waiting timer threshold, and the number of remote signature management messages received is greater than or equal to the multi-signature threshold indicated by the multi-signature strategy, it calls the target business contract on the blockchain based on the target contract address associated with the second signed business transaction.
[0199] S1503. Using the second business transaction signature strategy indicated by the target business contract, perform transaction verification on the second signed business transaction to obtain the transaction verification result of the second signed business transaction.
[0200] It is understood that the second business transaction signature strategy can include a full signature strategy and a multi-signature strategy, as detailed above. Figure 9 The relevant descriptions in the illustrated embodiments.
[0201] It is understandable that, by using the second business transaction signature strategy indicated by the target business contract to verify the second signed business transaction and obtain the transaction verification result of the second signed business transaction, it can be that the transaction verification of the second signed business transaction is performed using the full signature strategy and multi-signature strategy indicated by the target business contract, and the transaction verification result of the second signed business transaction is obtained.
[0202] Specifically, by using the second business transaction signature strategy indicated by the target business contract to verify the second signed business transaction and obtain the transaction verification result of the second signed business transaction, the following steps may be included: Invoking the target business contract to determine a complete signature strategy for verifying the signature of the complete key signature; performing signature verification on the complete key signature based on the complete signature strategy to obtain a third signature verification result corresponding to the complete key signature; further, invoking the target business contract to determine a multi-signature strategy for verifying the signature of K remote signature management information; performing signature verification on the K remote signature management information based on the multi-signature strategy to obtain a result related to the K remote signature management information. The fourth signature verification result of the connection; the fourth signature verification result includes K signature verification results corresponding to K remote signature management information; M successful signature verification results among the K signature verification results are obtained by M signature management devices among the K signature management devices; in the M signature management devices, one signature management device corresponds to one successful signature verification result; M is a positive integer greater than the multi-signature threshold indicated by the multi-signature threshold policy; furthermore, if the third signature verification result is a successful signature verification result, and there are M successful signature verification results in the fourth signature verification result, then the transaction verification result of the second signed business transaction is determined to indicate that the second signed business transaction verification is successful.
[0203] It is understood that the third signature verification result can be used to indicate whether the signature of the complete key was successfully verified. The fourth signature verification result can include K signature verification results, with one signature verification result corresponding to one remote signature management information, and the signature verification result corresponding to each remote signature management information is used to indicate whether the remote signature management information was successfully verified.
[0204] It is understandable that verifying a full key signature based on a full signature strategy to obtain a third signature verification result corresponding to the first full key signature can be achieved by determining the public key corresponding to the full key signature based on the full signature strategy, and then verifying the full key signature based on the public key corresponding to the full key signature to obtain a third signature verification result. Verifying the signatures of K remote signature management messages based on a multi-signature strategy to obtain a fourth signature verification result associated with the K remote signature management messages can be referred to the relevant description of obtaining the second signature verification result above, and will not be repeated here.
[0205] Understandably, the embodiments of this application also include: when the fourth signed business transaction and the full key signature are obtained, the target business contract on the blockchain is invoked based on the target contract address associated with the fourth signed business transaction; the fourth signed business transaction is determined based on the fourth business transaction to be signed, which is determined by a second resource client running on the business terminal. The second resource client is a resource client used to participate in transaction signing, determined based on the fourth business transaction signing strategy in the target transaction signing strategy when the network connection between the business terminal and the resource management server is not connected; the fourth business transaction signing strategy is a full signature strategy; the fourth signed business transaction and the full key signature are sent by the business terminal based on the full signature strategy, and the full key signature is obtained by the business terminal signing the second business transaction to be signed using the full key of the business object; furthermore, the fourth signed business transaction is verified by the fourth business transaction signing strategy indicated by the target business contract to obtain the transaction verification result of the fourth signed business transaction.
[0206] It is understandable that the fourth signed business transaction and the full key signature can be referenced as described above. Figure 9 The relevant descriptions in the illustrated embodiments will not be repeated here.
[0207] Understandably, the fourth signed business transaction is verified by using the fourth business transaction signature strategy indicated by the target business contract to obtain the transaction verification result of the fourth signed business transaction. That is, the public key corresponding to the full key signature is obtained by using the full signature strategy indicated by the target business contract, and the transaction verification is performed on the fourth signed business transaction based on the public key corresponding to the full key signature to obtain the transaction verification result of the fourth signed business transaction.
[0208] Please see Figure 16 , Figure 16 This is a schematic diagram of the structure of a transaction processing device provided in an embodiment of this application. Figure 16 As shown, the transaction processing device 1 can be a computer program (including program code) running on a business terminal (e.g., the terminal device 110a mentioned above), for example, the transaction processing device 1 is an application software; it is understood that the transaction processing device 1 can be used to execute the corresponding steps in the transaction processing method provided in the embodiments of this application. Figure 16 As shown, the transaction processing device 1 may include: a resource client determination module 11, a threshold signature module 12, a multi-signature module 13, and a sending module 14;
[0209] The resource client determination module 11 is used to determine the resource client participating in transaction signing as the first resource client based on the first business transaction signature strategy in the target transaction signature strategy if the network connection status between the business terminal and the resource management server is connected. The first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy. The threshold signature strategy and the multi-signature strategy are deployed in the target business contract on the blockchain. The target business contract is obtained by the business object after registering the contract on the blockchain through the blockchain node. The contract address of the target business contract is the target contract address returned by the blockchain node to the business object.
[0210] The threshold signature module 12 is used to determine the first business transaction to be signed associated with the target contract address through the first resource client, and when the first key fragment of the business object is obtained, to sign the first business transaction to be signed through the first key fragment to obtain the first signature fragment.
[0211] The multi-signature module 13 is used to determine N signature management devices associated with the business object based on the multi-signature strategy, and to notify the N signature management devices to generate N remote signature management information associated with the first business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information;
[0212] The sending module 14 is used to send the first signature fragment and the first business transaction to be signed to the resource management server based on the threshold signature strategy. This allows the resource management server to sign the first business transaction to be signed using the second key fragment of the business object and obtain the second signature fragment. Then, it aggregates the second signature fragment and the first signature fragment to obtain the first aggregated signature information. When the first business transaction to be signed is regarded as the first signed business transaction, the resource management server sends the first aggregated signature information and the first signed business transaction to the blockchain node. The blockchain node, upon obtaining the first aggregated signature information and K remote signature management information, calls the target business contract on the blockchain based on the target contract address. It then verifies the first signed business transaction using the first business transaction signature strategy indicated by the target business contract to obtain the transaction verification result of the first signed business transaction. K is a positive integer less than or equal to N.
[0213] Among them, the first business transaction to be signed is determined when the business object successfully accesses the first resource client through the object access information;
[0214] The sending module 14 may include: an information acquisition unit 141 and an information sending unit 142;
[0215] Information acquisition unit 141 is used to acquire object access information of business objects;
[0216] The information sending unit 142 is used to send object access information, the first signature fragment, and the first business transaction to be signed to the resource management server based on the threshold signature policy; the object access information is used to instruct the resource management server to determine the second key fragment of the business object based on the object access information.
[0217] Among them, the business object is associated with a second resource client, and the second resource client stores the complete business key of the business object. The key address information of the complete business key is the complete business key address information.
[0218] Transaction processing device 1 includes: contract registration module 15; contract registration module 15 includes: key negotiation unit 151, management address acquisition unit 152, and registration transaction sending unit 153;
[0219] The key negotiation unit 151 is used to send a threshold signature key acquisition request to the resource management server so that the resource management server and the business terminal negotiate and generate the first key fragment stored by the first resource management client and the second key fragment stored by the resource management server based on the key fragment generation mechanism, and determine the key address information that the first key fragment and the second key fragment correspond to as the threshold signature key address information.
[0220] The management address acquisition unit 152 is used to acquire multiple management address information to be registered when the threshold signature key address information is acquired. The multiple management address information to be registered includes: threshold signature key address information and business complete key address information.
[0221] The registration transaction sending unit 153 is used to determine the registration transaction for contract registration based on multiple registration management address information, and send the registration transaction to the blockchain node so that the blockchain node can register the contract on the blockchain based on the registration transaction to obtain the target business contract. The registration management address information is used as the contract management address information of the target business contract, and the contract management address information is used to determine N signature management devices.
[0222] The contract registration module 15 also includes a threshold acquisition unit 154;
[0223] The threshold acquisition unit 154 is also used to acquire the key fragmentation threshold indicated by the threshold signature policy and the multi-signature threshold indicated by the multi-signature policy.
[0224] The registration transaction sending unit 153 is also used to determine the registration transaction for contract registration based on multiple management address information to be registered, key fragmentation threshold and multi-signature threshold.
[0225] Among them, the information sending unit 142 is used to send the first business transaction to be signed to the resource management server when the threshold signature policy is a signature policy used to instruct the business terminal to perform aggregate signature, so that the resource management server performs transaction signature on the first business transaction to be signed through the second key fragment of the business object and obtains the second signature fragment;
[0226] The threshold signature module 12 is used to obtain the first aggregated signature information by aggregating the second signature fragment and the first signature fragment when the second signature fragment returned by the resource management server is obtained, and to send the first aggregated signature information and the first signed business transaction to the blockchain node when the first business transaction to be signed is regarded as the first signed business transaction.
[0227] The multi-signature module 13 includes: a remote signature receiving unit 131, a signature transaction unit 132, and a transaction sending unit 133;
[0228] The remote signature receiving unit 131 is used to receive remote signature management information returned by the signature management devices among N signature management devices, and to count the number of remote signature management information received to obtain the number of remote signatures received.
[0229] The signature transaction unit 132 is used to treat the first business transaction to be signed as the first signed business transaction when the remote signature timestamp associated with the first business transaction to be signed reaches the remote signature time threshold and the number of remote signatures received is greater than or equal to the multi-signature threshold indicated by the multi-signature strategy.
[0230] The transaction sending unit 133 is used to send the received K remote signature management information, the first aggregated signature information and the first signed business transaction to the blockchain node.
[0231] The transaction processing device 1 further includes: a network status detection module 16;
[0232] Network status detection module 16 is used to detect the network connection status between the business terminal and the resource management server and obtain the network connection status result;
[0233] The resource client determination module 11 is used to perform the step of determining the resource client used to participate in transaction signing as the first resource client based on the first business transaction signing strategy in the target transaction signing strategy when the network connection status result indicates that the network connection status between the business terminal and the resource management server is connected.
[0234] The transaction processing device 1 further includes: a complete signature module 17;
[0235] The network status detection module 16 is used to determine the resource client used to participate in transaction signing as the second resource client based on the second business transaction signing strategy in the target transaction signing strategy when the network connection status result indicates that the network connection status between the business terminal and the resource management server is not connected; the second business transaction signing strategy includes a full signature strategy and a multi-signature strategy; the full signature strategy and the multi-signature strategy are deployed in the target business contract;
[0236] The complete signature module 17 is used to determine the second business transaction to be signed associated with the target contract address through the second resource client. When the complete business key of the business object is obtained, the complete business key is used to sign the second business transaction to be signed to obtain the complete key signature.
[0237] The multi-signature module 13 is used to determine N signature management devices associated with the business object based on the multi-signature strategy, and to notify the N signature management devices to generate remote signature management information associated with the second business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information.
[0238] The sending module 14 is used to send the complete key signature and the second signed business transaction to the blockchain node based on the complete key signature strategy when the second business transaction to be signed is regarded as the second signed business transaction. This enables the blockchain node to call the target business contract on the blockchain based on the target contract address when it obtains the complete key signature and K remote signature management information. The blockchain node then verifies the second signed business transaction through the second business transaction signature strategy indicated by the target business contract and obtains the transaction verification result of the second signed business transaction.
[0239] The remote signature receiving unit 131 is used to receive remote signature management information returned by the signature management devices among N signature management devices, and to count the number of received remote signature management information to obtain the number of received remote signatures.
[0240] The signature transaction unit 132 is used to treat the second business transaction to be signed as the second signed business transaction when the remote signature timestamp associated with the second business transaction to be signed reaches the remote signature time threshold and the number of remote signatures received is greater than or equal to the multi-signature threshold indicated by the multi-signature strategy.
[0241] The transaction sending unit 133 is used to send the received K remote signature management information, the complete key signature, and the second signed business transaction to the blockchain node based on the complete signature policy.
[0242] Among them, the resource client determination module 11 is used to determine the resource client used to participate in transaction signing as the first resource client based on the third business transaction signing strategy in the target transaction signing strategy when the network connection status result indicates that the network connection status between the business terminal and the resource management server is connected. The third business transaction signing strategy is independent of the third business transaction signing strategy and is a threshold signing strategy.
[0243] Threshold signature module 12 is used to determine the third business transaction to be signed associated with the target contract address through the first resource client. When the first key fragment of the business object is obtained, the third business transaction to be signed is signed through the first key fragment to obtain the third signature fragment.
[0244] The sending module 14 is used to send the third signature fragment and the third business transaction to be signed to the resource management server based on the threshold signature strategy. This allows the resource management server to sign the third business transaction to be signed using the second key fragment of the business object and obtain the fourth signature fragment. Then, it aggregates the third and fourth signature fragments to obtain the second aggregated signature information. When the third business transaction to be signed is treated as the third signed business transaction, the second aggregated signature information and the third signed business transaction are sent to the blockchain node. The blockchain node, upon obtaining the second aggregated signature information, calls the target business contract on the blockchain based on the target contract address. Using the third business transaction signature strategy indicated by the target business contract, it verifies the third signed business transaction and obtains the transaction verification result of the third signed business transaction.
[0245] Please see Figure 17 , Figure 17 This is a schematic diagram of the structure of a transaction processing device provided in an embodiment of this application. Figure 17 As shown, the transaction processing device 2 can be a computer program (including program code) running on a blockchain node (e.g., the aforementioned blockchain node 11a), for example, the transaction processing device 1 is an application software; it is understood that the transaction processing device 2 can be used to execute the corresponding steps in the transaction processing method provided in the embodiments of this application. Figure 17 As shown, the transaction processing device 2 may include: an acquisition module 21, a contract invocation module 22, and a transaction verification module 23;
[0246] The acquisition module 21 is used to acquire the first signed business transaction and the first aggregated signature information associated with the business terminal. The first signed business transaction is determined based on the first business transaction to be signed. The first business transaction to be signed is determined by the first resource client running on the business terminal. The first resource client is a resource client used to participate in transaction signing, determined based on the first business transaction signature strategy in the target transaction signature strategy when the network connection between the business terminal and the resource management server is in a connected state. The first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy. The first aggregated signature information is obtained by aggregating the second signature fragment and the first signature fragment. The first signature fragment is obtained by the business terminal signing the first business transaction to be signed using the first key fragment of the business object. The second signature fragment is obtained by the resource management server signing the first business transaction to be signed using the second key fragment of the business object when it receives the first signature fragment and the first business transaction to be signed sent by the business terminal based on the threshold signature strategy.
[0247] Contract invocation module 22 is used to invoke the target business contract on the blockchain based on the target contract address associated with the first signed business transaction when it obtains K remote signature management information associated with the first signed business transaction; the K remote signature management information associated with the first signed business transaction are generated by K signature management devices based on the first business transaction to be signed; one signature management device corresponds to one remote signature management information; the K signature management devices are the signature management devices among the N signature management devices associated with the business object determined by the business terminal based on the multi-signature strategy; K and N are positive integers, and K is less than or equal to N;
[0248] The transaction verification module 23 is used to verify the first signed business transaction through the first business transaction signature strategy indicated by the target business contract, and obtain the transaction verification result of the first signed business transaction.
[0249] The transaction signature verification module 23 includes: a threshold signature verification unit 231, a multi-signature verification unit 232, and a verification result unit 233.
[0250] The threshold signature verification unit 231 is used to call the target business contract to determine the threshold signature strategy for signing and verifying the first aggregate signature information, and to perform signature verification on the first aggregate signature information based on the threshold signature strategy to obtain the first signature verification result corresponding to the first aggregate signature information.
[0251] The multi-signature verification unit 232 is used to call the target business contract to determine the multi-signature strategy for signing and verifying K remote signature management information, and to perform signature verification on the K remote signature management information based on the multi-signature strategy to obtain a second signature verification result associated with the K remote signature management information; the second signature verification result includes K signature verification results corresponding to the K remote signature management information; M successful signature verification results among the K signature verification results are obtained by M signature management devices among the K signature management devices; in the M signature management devices, one signature management device corresponds to one successful signature verification result; M is a positive integer greater than the multi-signature threshold indicated by the multi-signature threshold strategy;
[0252] The verification result unit 233 is used to determine the transaction verification result of the first signed business transaction to indicate that the first signed business transaction has been successfully verified if the first signature verification result is a successful signature verification result and there are M successful signature verification results in the second signature verification result.
[0253] Among them, the blockchain deploys business management contracts for managing business contracts, and business template contracts for defining business contract templates;
[0254] The transaction processing device 2 further includes: a business contract deployment module 24; the business contract deployment module 24 includes: a transaction registration and acquisition unit 241, a contract management and invocation unit 242, and an address generation unit 243;
[0255] The registration transaction acquisition unit 241 is used to determine the registration management address information corresponding to the contract to be registered from the registration transaction when it obtains the registration transaction used for contract registration;
[0256] The management contract invocation unit 242 is used to, when invoking the business management contract to deploy the contract to be registered on the blockchain based on the business template contract, take the contract to be registered already deployed on the blockchain as the target business contract, and take the management address information to be registered as the contract management address information of the target business contract;
[0257] Address generation unit 243 is used to send the contract address of the target business contract to the business terminal when the contract address of the target business contract is obtained.
[0258] The acquisition module 21 is further configured to acquire the second signed business transaction and the complete key signature sent by the business terminal. The second signed business transaction is determined based on the second business transaction to be signed. The second business transaction to be signed is determined by the second resource client running on the business terminal. The second resource client is a resource client used to participate in transaction signing, determined based on the second business transaction signing strategy in the target transaction signing strategy when the network connection between the business terminal and the resource management server is not connected. The second business transaction signing strategy includes a complete signature strategy and a multi-signature strategy. The second signed business transaction and the complete key signature are sent by the business terminal based on the complete signature strategy. The complete key signature is obtained by the business terminal signing the second business transaction to be signed using the complete key of the business object.
[0259] The contract invocation module 22 is also used to invoke the target business contract on the blockchain based on the target contract address associated with the second signed business transaction when it obtains K remote signature management information associated with the second signed business transaction; the K remote signature management information associated with the second signed business transaction are generated by K signature management devices based on the second business transaction to be signed, and one signature management device corresponds to one remote signature management information; the K signature management devices are the signature management devices among the N signature management devices associated with the business object determined by the business terminal based on the multi-signature strategy; K is a positive integer, and K is a positive integer less than or equal to N;
[0260] The transaction verification module 23 is also used to verify the second signed business transaction through the second business transaction signature strategy indicated by the target business contract, and obtain the transaction verification result of the second signed business transaction.
[0261] The acquisition module 21 is further configured to, upon acquiring the third signed business transaction and the second aggregated signature information, invoke the target business contract on the blockchain based on the target contract address associated with the third signed business transaction. The third signed business transaction is determined based on the third business transaction to be signed. The third business transaction to be signed is determined by the first resource client running on the business terminal. The first resource client is a resource client used to participate in transaction signing, determined based on the third business transaction signature strategy in the target transaction signature strategy when the network connection between the business terminal and the resource management server is in a connected state. The third business transaction signature strategy is a threshold signature strategy. The second aggregated signature information is obtained by the resource management server through the aggregation of the third signature fragment and the fourth signature fragment. The third signature fragment is obtained by the business terminal signing the third business transaction to be signed using the first key fragment of the business object. The fourth signature fragment is obtained by the resource management server signing the third business transaction to be signed using the second key fragment of the business object when it receives the third signature fragment and the third business transaction to be signed from the business terminal based on the threshold signature strategy.
[0262] The transaction verification module 23 is also used to verify the third signed business transaction through the third business transaction signature strategy indicated by the target business contract, and obtain the transaction verification result of the third signed business transaction.
[0263] Please see Figure 18 , Figure 18 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 18 As shown, the computer device 1000 may include a processor 1001, a network interface 1004, and a memory 1005. Furthermore, the computer device 1000 may also include a user interface 1003 and at least one communication bus 1002. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen and a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be a high-speed RAN memory or a non-volatile memory, such as at least one disk storage device. Optionally, the memory 1005 may also be at least one storage device located remotely from the processor 1001. Figure 18 As shown, the memory 1005, which is a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a device control application.
[0264] In such Figure 18 In the computer device 1000 shown, the network interface 1004 provides network communication functionality; the user interface 1003 is mainly used to provide an input interface for the user; and the processor 1001 can be used to call the device control application stored in the memory 1005 to execute the transaction processing method described in any of the corresponding embodiments above, which will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.
[0265] Furthermore, it should be noted that this application also provides a computer-readable storage medium storing a computer program executed by the transaction processing apparatus 1 and transaction processing apparatus 2 mentioned above. The computer program includes program instructions, and when the processor executes the program instructions, it can perform the transaction processing method described in the preceding embodiments; therefore, it will not be repeated here. Additionally, the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the embodiments of the computer-readable storage medium involved in this application, please refer to the description of the method embodiments of this application.
[0266] The aforementioned computer-readable storage medium can be an internal storage unit of the transaction processing apparatus provided in any of the foregoing embodiments or the computer device described above, such as a hard disk or memory of the computer device. The computer-readable storage medium can also be an external storage device of the computer device, such as a plug-in hard disk, smart memory card (SNC), secure digital card (SD), flash card, etc., provided on the computer device. Furthermore, the computer-readable storage medium can include both internal storage units and external storage devices of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.
[0267] Furthermore, it should be noted that this application also provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. The processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method provided in any of the preceding corresponding embodiments. Additionally, the beneficial effects of using the same method will not be repeated here. For technical details not disclosed in the embodiments of the computer program product or computer program involved in this application, please refer to the description of the method embodiments of this application.
[0268] The terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other step units inherent to these processes, methods, apparatuses, products, or devices.
[0269] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0270] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.
Claims
1. A transaction processing method, characterized in that, The method is executed by the service terminal; the method includes: If the network connection between the business terminal and the resource management server is in a connected state, then the resource client used to participate in the transaction signing is determined as the first resource client based on the first business transaction signature strategy in the target transaction signature strategy; the first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy; the threshold signature strategy and the multi-signature strategy are deployed in the target business contract on the blockchain; the target business contract is obtained by the business object after registering the contract on the blockchain through the blockchain node; the contract address of the target business contract is the target contract address returned by the blockchain node to the business object; The first resource client determines the first business transaction to be signed associated with the target contract address. When the first key fragment of the business object is obtained, the first business transaction to be signed is signed using the first key fragment to obtain the first signature fragment. Based on the multi-signature strategy, N signature management devices are determined to be associated with the business object, and the N signature management devices are notified to generate N remote signature management information associated with the first business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information. Based on the threshold signature strategy, the first signature fragment and the first business transaction to be signed are sent to the resource management server. This allows the resource management server to sign the first business transaction to be signed using the second key fragment of the business object, obtaining a second signature fragment. Then, by aggregating the second signature fragment and the first signature fragment, the resource management server obtains first aggregated signature information. When the first business transaction to be signed is considered the first signed business transaction, the resource management server sends the first aggregated signature information and the first signed business transaction to the blockchain node. The blockchain node, upon receiving the first aggregated signature information and K remote signature management information, invokes the target business contract on the blockchain based on the target contract address. Using the first business transaction signature strategy indicated by the target business contract, the node verifies the first signed business transaction, obtaining the transaction verification result of the first signed business transaction. K is a positive integer less than or equal to N.
2. The method according to claim 1, characterized in that, The first business transaction to be signed is determined when the business object successfully accesses the first resource client through object access information; Sending the first signature fragment and the first transaction to be signed to the resource management server based on the threshold signature policy includes: Obtain the object access information of the business object; Based on the threshold signature policy, the object access information, the first signature fragment, and the first business transaction to be signed are sent to the resource management server; the object access information is used to instruct the resource management server to determine the second key fragment of the business object based on the object access information.
3. The method according to claim 1, characterized in that, The business object is associated with a second resource client, which stores the complete business key of the business object. The key address information of the complete business key is the complete business key address information. The method further includes: A threshold signature key acquisition request is sent to the resource management server so that the resource management server and the business terminal negotiate and generate the first key fragment stored in the first resource management client and the second key fragment stored in the resource management server based on the key fragment generation mechanism, and determine the key address information that the first key fragment and the second key fragment jointly correspond to as the threshold signature key address information. When the threshold signature key address information is obtained, multiple registration management address information is obtained, including the threshold signature key address information and the complete business key address information. Based on the multiple registration management address information, a registration transaction for contract registration is determined, and the registration transaction is sent to the blockchain node so that the blockchain node can register the contract on the blockchain based on the registration transaction to obtain the target business contract. The registration management address information is used as the contract management address information of the target business contract, and the contract management address information is used to determine the N signature management devices.
4. The method according to claim 3, characterized in that, The step of determining the registration transaction for contract registration based on the multiple management address information to be registered includes: Obtain the key fragmentation threshold indicated by the threshold signature policy and the multi-signature threshold indicated by the multi-signature policy; Based on the multiple management address information to be registered, the key sharding threshold, and the multi-signature threshold, a registration transaction for contract registration is determined.
5. The method according to claim 1, characterized in that, The method further includes: When the threshold signature policy is a signature policy used to instruct the business terminal to perform aggregate signature, the first business transaction to be signed is sent to the resource management server, so that the resource management server performs transaction signing on the first business transaction to be signed through the second key fragment of the business object, and obtains the second signature fragment; Upon receiving the second signature fragment returned by the resource management server, the first aggregated signature information is obtained by aggregating the second signature fragment and the first signature fragment. When the first business transaction to be signed is regarded as the first signed business transaction, the first aggregated signature information and the first signed business transaction are sent to the blockchain node.
6. The method according to claim 5, characterized in that, When the first transaction to be signed is designated as the first signed transaction, sending the first aggregated signature information and the first signed transaction to the blockchain node includes: Receive remote signature management information returned by the signature management devices among the N signature management devices, and count the number of remote signature management information received to obtain the number of remote signatures received; When the remote signature timestamp associated with the first transaction to be signed reaches the remote signature time threshold, and the number of received remote signatures is greater than or equal to the multi-signature threshold indicated by the multi-signature strategy, the first transaction to be signed is regarded as the first signed transaction. The received K remote signature management messages, the first aggregated signature message, and the first signed business transaction are sent to the blockchain node.
7. The method according to claim 1, characterized in that, The method further includes: Detect the network connection status between the service terminal and the resource management server, and obtain the network connection status result; When the network connection status result indicates that the network connection status between the service terminal and the resource management server is connected, the step of determining the resource client used to participate in the transaction signature as the first resource client based on the first business transaction signature strategy in the target transaction signature strategy is executed.
8. The method according to claim 7, characterized in that, The method further includes: When the network connection status result indicates that the network connection between the business terminal and the resource management server is not connected, the resource client used to participate in the transaction signing is determined as the second resource client based on the second business transaction signature strategy in the target transaction signature strategy; the second business transaction signature strategy includes a full signature strategy and the multi-signature strategy; the full signature strategy and the multi-signature strategy are deployed in the target business contract; The second resource client determines the second business transaction to be signed associated with the target contract address. When the complete business key of the business object is obtained, the complete business key is used to sign the second business transaction to be signed to obtain the complete key signature. Based on the multi-signature strategy, N signature management devices are identified that are associated with the business object, and the N signature management devices are notified to generate remote signature management information associated with the second business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information. When the second business transaction to be signed is used as the second signed business transaction, the full key signature and the second signed business transaction are sent to the blockchain node based on the full key signature strategy. When the blockchain node obtains the full key signature and K remote signature management information, it calls the target business contract on the blockchain based on the target contract address. Through the second business transaction signature strategy indicated by the target business contract, the second signed business transaction is verified to obtain the transaction verification result of the second signed business transaction.
9. The method according to claim 8, characterized in that, When the second transaction to be signed is treated as the second signed transaction, sending the full key signature and the second signed transaction to the blockchain node based on the full key signature strategy includes: Receive remote signature management information returned by the signature management devices among the N signature management devices, and count the number of remote signature management information received to obtain the number of remote signatures received; When the remote signature timestamp associated with the second transaction to be signed reaches the remote signature time threshold, and the number of received remote signatures is greater than or equal to the multi-signature threshold indicated by the multi-signature strategy, the second transaction to be signed is treated as the second signed transaction. Based on the complete signature policy, the received K remote signature management messages, the complete key signature, and the second signed business transaction are sent to the blockchain node.
10. The method according to claim 7, characterized in that, The method further includes: When the network connection status result indicates that the network connection status between the service terminal and the resource management server is connected, the resource client used to participate in the transaction signature is determined to be the first resource client based on the third business transaction signature strategy in the target transaction signature strategy; the third business transaction signature strategy is independent of the third business transaction signature strategy, and the third business transaction signature strategy is the threshold signature strategy; The first resource client determines the third business transaction to be signed associated with the target contract address. When the first key fragment of the business object is obtained, the third business transaction to be signed is signed using the first key fragment to obtain the third signature fragment. Based on the threshold signature strategy, the third signature fragment and the third business transaction to be signed are sent to the resource management server. This allows the resource management server to sign the third business transaction to be signed using the second key fragment of the business object, obtaining a fourth signature fragment. Then, the resource management server aggregates the third signature fragment and the fourth signature fragment to obtain second aggregated signature information. When the third business transaction to be signed is considered the third signed business transaction, the resource management server sends the second aggregated signature information and the third signed business transaction to the blockchain node. Upon receiving the second aggregated signature information, the blockchain node invokes the target business contract on the blockchain based on the target contract address. Using the third business transaction signature strategy indicated by the target business contract, the node verifies the third signed business transaction to obtain the transaction verification result.
11. A transaction processing method, characterized in that, The method is executed by a blockchain node; the method includes: The system acquires a first signed business transaction and a first aggregated signature information associated with a business terminal. The first signed business transaction is determined based on a first business transaction to be signed. The first business transaction to be signed is determined by a first resource client running on the business terminal. The first resource client is a resource client used to participate in transaction signing, determined based on a first business transaction signature strategy in the target transaction signature strategy, when the network connection between the business terminal and the resource management server is in a connected state. The first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy. The first aggregated signature information is obtained by aggregating a second signature fragment and a first signature fragment. The first signature fragment is obtained by the business terminal signing the first business transaction to be signed using a first key fragment of a business object. The second signature fragment is obtained by the resource management server signing the first business transaction to be signed using a second key fragment of the business object when it receives the first signature fragment and the first business transaction to be signed from the business terminal based on the threshold signature strategy. When K remote signature management information associated with the first signed business transaction is obtained, the target business contract on the blockchain is invoked based on the target contract address associated with the first signed business transaction; the K remote signature management information associated with the first signed business transaction is generated by K signature management devices based on the first business transaction to be signed; one signature management device corresponds to one remote signature management information; the K signature management devices are the signature management devices among the N signature management devices associated with the business object determined by the business terminal based on the multi-signature strategy; K and N are positive integers, and K is less than or equal to N; The first signed business transaction is verified using the first business transaction signature strategy indicated by the target business contract to obtain the transaction verification result of the first signed business transaction.
12. The method according to claim 11, characterized in that, The step of verifying the first signed business transaction using the first business transaction signature strategy indicated by the target business contract to obtain the transaction verification result of the first signed business transaction includes: The target business contract is invoked to determine a threshold signature strategy for signing and verifying the first aggregated signature information. Based on the threshold signature strategy, the first aggregated signature information is signed and verified to obtain a first signature verification result corresponding to the first aggregated signature information. The target business contract is invoked to determine a multi-signature strategy for verifying the signatures of the K remote signature management information. Based on the multi-signature strategy, the K remote signature management information is verified to obtain a second signature verification result associated with the K remote signature management information. The second signature verification result includes K signature verification results corresponding to the K remote signature management information. M successful signature verification results among the K signature verification results are obtained from M signature management devices among the K signature management devices. In the M signature management devices, one signature management device corresponds to one successful signature verification result. M is a positive integer greater than the multi-signature threshold indicated by the multi-signature threshold strategy. If the first signature verification result is a successful signature verification result, and there are M successful signature verification results in the second signature verification result, then the transaction verification result of the first signed business transaction is determined to indicate that the first signed business transaction has been successfully verified.
13. The method according to claim 11, characterized in that, The blockchain is deployed with a business management contract for managing business contracts and a business template contract for defining business contract templates; The method further includes: When a registration transaction for contract registration is obtained, the registration management address information corresponding to the contract to be registered is determined from the registration transaction; When the business management contract is invoked to deploy the contract to be registered on the blockchain based on the business template contract, the contract to be registered that has been deployed on the blockchain is used as the target business contract, and the management address information to be registered is used as the contract management address information of the target business contract. Upon obtaining the contract address of the target business contract, the contract address of the target business contract is sent to the business terminal.
14. The method according to claim 11, characterized in that, The method further includes: The system obtains a second signed business transaction and a complete key signature sent by the business terminal. The second signed business transaction is determined based on a second business transaction to be signed. The second business transaction to be signed is determined by a second resource client running on the business terminal. The second resource client is a resource client used to participate in transaction signing, determined based on the second business transaction signing strategy in the target transaction signing strategy when the network connection between the business terminal and the resource management server is not connected. The second business transaction signing strategy includes a complete signature strategy and the multi-signature strategy. The second signed business transaction and the complete key signature are sent by the business terminal based on the complete signature strategy. The complete key signature is obtained by the business terminal signing the second business transaction to be signed using the complete key of the business object. Upon obtaining K remote signature management information associated with the second signed business transaction, the target business contract on the blockchain is invoked based on the target contract address associated with the second signed business transaction. The K remote signature management information associated with the second signed business transaction is generated by K signature management devices based on the second business transaction to be signed, with one signature management device corresponding to one remote signature management information. The K signature management devices are the signature management devices among the N signature management devices associated with the business object determined by the business terminal based on the multi-signature strategy. K is a positive integer, and K is a positive integer less than or equal to N. The second signed business transaction is verified using the second business transaction signature strategy indicated by the target business contract to obtain the transaction verification result of the second signed business transaction.
15. The method according to claim 11, characterized in that, The method further includes: Upon obtaining the third signed business transaction and the second aggregated signature information, the target business contract on the blockchain is invoked based on the target contract address associated with the third signed business transaction. The third signed business transaction is determined based on the third pending signature business transaction, which is determined by the first resource client running on the business terminal. The first resource client is a resource client used to participate in transaction signing, determined based on the third business transaction signature strategy in the target transaction signature strategy, when the network connection between the business terminal and the resource management server is in a connected state. The third business transaction signature strategy is a threshold signature strategy. The second aggregated signature information is obtained by the resource management server through the aggregation of the third signature fragment and the fourth signature fragment. The third signature fragment is obtained by the business terminal signing the third pending signature business transaction through the first key fragment of the business object. The fourth signature fragment is obtained by the resource management server signing the third pending signature business transaction through the second key fragment of the business object when it receives the third signature fragment and the third pending signature business transaction sent by the business terminal based on the threshold signature strategy. The third signed business transaction is verified using the third business transaction signature strategy indicated by the target business contract to obtain the transaction verification result of the third signed business transaction.
16. A transaction processing apparatus, characterized in that, The device is operated by a service terminal; the device includes: The resource client determination module is used to determine, if the network connection status between the business terminal and the resource management server is connected, the resource client used to participate in transaction signing as the first resource client based on the first business transaction signing strategy in the target transaction signing strategy; the first business transaction signing strategy includes a threshold signature strategy and a multi-signature strategy; the threshold signature strategy and the multi-signature strategy are deployed in the target business contract on the blockchain; the target business contract is obtained by the business object after registering the contract on the blockchain through the blockchain node; the contract address of the target business contract is the target contract address returned by the blockchain node to the business object; The threshold signature module is used to determine the first business transaction to be signed associated with the target contract address through the first resource client, and when the first key fragment of the business object is obtained, to sign the first business transaction to be signed through the first key fragment to obtain the first signature fragment. The multi-signature module is used to determine N signature management devices associated with the business object based on the multi-signature strategy, and to notify the N signature management devices to generate N remote signature management information associated with the first business transaction to be signed; N is a positive integer; one signature management device corresponds to one remote signature management information; The sending module is configured to send the first signature fragment and the first business transaction to be signed to the resource management server based on the threshold signature strategy. This allows the resource management server to sign the first business transaction to be signed using the second key fragment of the business object, obtaining a second signature fragment. Then, it aggregates the second signature fragment and the first signature fragment to obtain first aggregated signature information. When the first business transaction to be signed is considered the first signed business transaction, the resource management server sends the first aggregated signature information and the first signed business transaction to the blockchain node. The blockchain node, upon receiving the first aggregated signature information and K remote signature management information, invokes the target business contract on the blockchain based on the target contract address. Using the first business transaction signature strategy indicated by the target business contract, it verifies the first signed business transaction to obtain the transaction verification result of the first signed business transaction. K is a positive integer less than or equal to N.
17. A transaction processing apparatus, characterized in that, The device is executed by a blockchain node; the device includes: The acquisition module is used to acquire a first signed business transaction and a first aggregated signature information associated with a business terminal. The first signed business transaction is determined based on a first business transaction to be signed. The first business transaction to be signed is determined by a first resource client running on the business terminal. The first resource client is a resource client determined to participate in transaction signing based on a first business transaction signature strategy in the target transaction signature strategy when the network connection between the business terminal and the resource management server is in a connected state. The first business transaction signature strategy includes a threshold signature strategy and a multi-signature strategy. The first aggregated signature information is obtained by aggregating a second signature fragment and a first signature fragment. The first signature fragment is obtained by the business terminal signing the first business transaction to be signed using a first key fragment of a business object. The second signature fragment is obtained by the resource management server signing the first business transaction to be signed using a second key fragment of the business object when it receives the first signature fragment and the first business transaction to be signed sent by the business terminal based on the threshold signature strategy. The contract invocation module is used to invoke the target business contract on the blockchain based on the target contract address associated with the first signed business transaction when K remote signature management information associated with the first signed business transaction are obtained. The K remote signature management information associated with the first signed business transaction are generated by K signature management devices based on the first business transaction to be signed. One signature management device corresponds to one remote signature management information. The K signature management devices are the signature management devices among the N signature management devices associated with the business object determined by the business terminal based on the multi-signature strategy. K and N are positive integers, and K is less than or equal to N. The transaction verification module is used to verify the first signed business transaction through the first business transaction signature strategy indicated by the target business contract, and obtain the transaction verification result of the first signed business transaction.
18. A computer device, characterized in that, Including memory and processor; The memory is connected to the processor, the memory is used to store computer programs, and the processor is used to invoke the computer programs so that the computer device performs the method according to any one of claims 1-15.
19. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded and executed by a processor to cause a computer device having the processor to perform the method of any one of claims 1-15.
20. A computer program product, characterized in that, Includes a computer program / instruction that, when executed by a processor, implements the method according to any one of claims 1-15.