A data processing method, device, equipment and computer readable storage medium

By generating and processing voucher identification and resource transfer voucher identification of multiple digital resource collection identifications, the problem of low applicability of transaction resource transfer in the prior art is solved, cross-institutional resource transfer is realized, and transaction convenience and success rate are improved.

CN117057800BActive Publication Date: 2025-05-16TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210480874.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-05
Publication Date
2025-05-16
Estimated Expiration
2042-05-05

AI Technical Summary

Technical Problem

In the prior art, when mobile payment, the mobile terminal can only complete the transaction through a collection of digital resources of one payment institution. If the resources are insufficient, the payment institution needs to be switched frequently, resulting in low applicability of the transfer of transaction resources.

Method used

The transaction request of the application client is obtained through the business server, and the voucher identification and resource transfer voucher corresponding to multiple digital resource collection identifiers is generated, and sent to the institutional server cluster for resource transfer processing to ensure the transaction result of the transaction request.

Benefits of technology

Cross-institutional resource transfer is realized, the applicability and convenience of resource transfer in transactions is improved, and the possibility of transaction failure is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117057800B_ABST
    Figure CN117057800B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses a data processing method, apparatus, device and computer-readable storage medium, the method comprising: obtaining a transaction request; the transaction request comprises A digital resource collection identifiers all created by an application client, and resource transfer values ​​corresponding to the A digital resource collection identifiers; generating voucher identifiers corresponding to the A digital resource collection identifiers according to the transaction request, generating resource transfer vouchers corresponding to the A digital resource collection identifiers according to the A voucher identifiers and the A resource transfer values; sending the A resource transfer vouchers to an institutional server cluster; an institutional server is used to perform resource transfer processing on the resources to be transferred indicated by the resource transfer value according to the received resource transfer voucher; obtaining A resource transfer processing results, and determining the transaction result of the transaction request according to the A resource transfer processing results. The application can improve the applicability of resource transfer in transactions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technology, and in particular to a data processing method, apparatus, device, and computer-readable storage medium. Background Art

[0002] With the continuous improvement of Internet technology and the progress of society, mobile payment applications of mobile devices have been rapidly popularized. People use mobile devices (such as mobile phones) to buy the items they need every day. Obviously, mobile payment has become an important part of people's lives.

[0003] There are many payment institutions that implement mobile payments, but the payment institutions are independent and cannot communicate with each other; when a transaction is generated, in the prior art, the mobile terminal can only complete the transaction through a digital resource set in a payment institution; if the digital resource set in digital resource set a is not enough to complete the transaction, people need to select digital resource set b from the above-mentioned payment institution to complete the transaction. If the digital resources in digital resource set b are still not enough to complete the transaction, people have to continue to select another digital resource set from the above-mentioned payment institution, or select a digital resource set from another payment institution. If each digital resource set in each payment institution in the mobile terminal cannot complete the transaction, the resource transfer of the transaction fails. Obviously, the applicability of resource transfer in transactions in the prior art is low. Summary of the invention

[0004] Embodiments of the present application provide a data processing method, apparatus, device, and computer-readable storage medium, which can improve the applicability of resource transfer in transactions.

[0005] On the one hand, an embodiment of the present application provides a data processing method, including:

[0006] The business server obtains a transaction request for the application client; the transaction request includes A digital resource set identifiers and resource transfer values ​​corresponding to the A digital resource set identifiers; A is a positive integer greater than 1; the A digital resource set identifiers are all created by the application client;

[0007] Generate, according to the transaction request, voucher identifiers corresponding to the A digital resource set identifiers, and generate, according to the A voucher identifiers and the A resource transfer values, resource transfer vouchers corresponding to the A digital resource set identifiers;

[0008] A resource transfer vouchers are sent to an institutional server cluster; the institutional server cluster includes institutional servers corresponding to the A digital resource collection identifiers; an institutional server is used to receive a resource transfer voucher, and is used to perform resource transfer processing on the to-be-transferred resource indicated by the resource transfer value in the received resource transfer voucher according to the received resource transfer voucher;

[0009] Obtain resource transfer processing results respectively returned by A institution servers, and determine the transaction result of the transaction request according to the A resource transfer processing results.

[0010] On the one hand, an embodiment of the present application provides a data processing method, including:

[0011] The target institution server obtains the target resource transfer voucher sent by the business server; the target resource transfer voucher belongs to A resource transfer vouchers; the A resource transfer vouchers are generated by the business server according to the voucher identifiers corresponding to the A digital resource collection identifiers, and the resource transfer values ​​corresponding to the A digital resource collection identifiers; the A voucher identifiers are generated by the business server when obtaining the transaction request for the application client; the transaction request includes A digital resource collection identifiers and A resource transfer values; A is a positive integer greater than 1; the A digital resource collection identifiers are all created by the application client; the institution server to which the digital resource collection identifier corresponding to the target resource transfer voucher belongs is the target institution server;

[0012] According to the target resource transfer voucher, performing resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher to obtain a resource transfer processing result;

[0013] The resource transfer processing result is returned to the business server, so that the business server determines the transaction result of the transaction request based on the resource transfer processing result.

[0014] An embodiment of the present application provides a data processing device, which runs on a service server and includes:

[0015] The first acquisition module is used to acquire a transaction request for the application client; the transaction request includes A digital resource set identifiers and resource transfer values ​​corresponding to the A digital resource set identifiers; A is a positive integer greater than 1; the A digital resource set identifiers are all created by the application client;

[0016] A voucher generation module, used to generate voucher identifiers corresponding to A digital resource set identifiers according to a transaction request, and generate resource transfer vouchers corresponding to A digital resource set identifiers according to the A voucher identifiers and A resource transfer values;

[0017] A voucher acquisition module is used to send A resource transfer vouchers to an institutional server cluster; the institutional server cluster includes institutional servers corresponding to A digital resource collection identifiers; an institutional server is used to receive a resource transfer voucher, and is used to perform resource transfer processing on the to-be-transferred resource indicated by the resource transfer value in the received resource transfer voucher according to the received resource transfer voucher;

[0018] The second acquisition module is used to obtain the resource transfer processing results returned by A institution servers respectively, and determine the transaction result of the transaction request according to the A resource transfer processing results.

[0019] Among them, the credential generation module includes:

[0020] A first acquisition unit, used to acquire a transfer password to be verified in a transaction request;

[0021] The second acquisition unit is used to acquire a transfer password set corresponding to the application client; the transfer password set includes transfer passwords corresponding to B digital resource set identifiers respectively; wherein a transfer password refers to a password used for transactions set by the application client when creating a digital resource set identifier; the B digital resource set identifiers include A digital resource set identifiers; B is a positive integer equal to or greater than A;

[0022] A password verification unit, used for verifying the transfer password to be verified according to the transfer password set, and obtaining a verification result;

[0023] The first generating unit is used to generate credential identifiers corresponding to the A digital resource set identifiers respectively according to the verification result.

[0024] The password verification unit includes:

[0025] A password matching subunit, used for matching the transfer password to be verified with the transfer password in the transfer password set;

[0026] A result determination subunit, configured to determine that the verification result is a password error result if there is no transfer password identical to the transfer password to be verified in the transfer password set;

[0027] The result determination subunit is also used to determine that the verification result is a password correct result if there is a transfer password in the transfer password set that is the same as the transfer password to be verified.

[0028] Wherein, the first generation unit includes:

[0029] A first acquisition subunit is used to acquire object signatures corresponding to the A digital resource set identifiers in the transaction request respectively if the verification result indicates that there is a transfer password identical to the transfer password to be verified in the transfer password set;

[0030] The second acquisition subunit is used to obtain the object public key corresponding to the application client, and verify the A object signatures based on the object public key to obtain A verification results;

[0031] The identification generation subunit is used to generate credential identifications corresponding to the A digital resource set identifications respectively if the A signature verification results are all successful signature verification results.

[0032] Among them, A object signatures include digital resource collection identifier E d The corresponding object signature C d , d is a positive integer and d is less than or equal to A; digital resource collection identifier E d Belongs to A digital resource collection identifiers; A signature verification results include object signature C d The corresponding signature verification result;

[0033] The second acquisition subunit includes:

[0034] Signature decryption subunit, used to sign the object based on the object public key C d Decrypting to obtain a first digital summary;

[0035] The identification acquisition subunit is used to obtain the transaction identification in the transaction request, and obtain the digital resource collection identification E from the object identifications corresponding to the A digital resource collection identifications included in the transaction request. d The corresponding object identifier;

[0036] The first determination subunit is used to identify the transaction identifier and the digital resource set identifier E d The corresponding object identifier and the digital resource collection identifier E d The corresponding resource transfer value is determined as the data to be verified;

[0037] A summary comparison subunit, used to obtain a second digital summary of the data to be verified, and compare the first digital summary with the second digital summary;

[0038] The second determining subunit is used to determine the object signature C if the first digital summary is different from the second digital summary. d The corresponding signature verification result is a signature verification failure result;

[0039] The third determining subunit is used to determine the object signature C if the first digital summary is the same as the second digital summary. d The corresponding signature verification result is a successful signature verification result.

[0040] The transaction request also includes a transaction identifier, object signatures corresponding to the A digital resource collection identifiers, and object identifiers corresponding to the A digital resource collection identifiers; the A digital resource collection identifiers include the digital resource collection identifier Fg , g is a positive integer and g is less than or equal to A; the resource transfer vouchers corresponding to the A digital resource set identifiers respectively include the digital resource set identifier F g Corresponding resource transfer certificate;

[0041] Credential generation module, including:

[0042] The third acquisition unit is used to acquire the business private key, and based on the business private key, identify the digital resource set F g Corresponding voucher identifier, digital resource collection identifier F g Corresponding object identifier, digital resource collection identifier F g The corresponding resource transfer value and transaction identifier are signed to obtain the digital resource collection identifier F g The corresponding business signature;

[0043] The first determining unit is used to identify the digital resource set F g Corresponding voucher identifier, digital resource collection identifier F g Corresponding object identifier, digital resource collection identifier F g Corresponding resource transfer value, digital resource collection identifier F g The corresponding object signature, transaction identifier, and digital resource collection identifier F g The corresponding business signature is determined as the digital resource collection identifier F g The corresponding resource transfer certificate.

[0044] Wherein, the second acquisition module includes:

[0045] A second determining unit is configured to determine that the transaction result of the transaction request is a successful transaction result if all of the A resource transfer processing results are successful resource transfer results;

[0046] The third determining unit is configured to determine that the transaction result of the transaction request is a transaction failure result if there is a resource transfer failure result among the A resource transfer processing results.

[0047] Wherein, the second acquisition module further includes:

[0048] a fourth acquisition unit, configured to acquire, if the transaction result of the transaction request is a transaction failure result, a resource transfer processing result belonging to a resource transfer success result from the A resource transfer processing results as a target resource transfer processing result;

[0049] A fifth acquisition unit is used to acquire the digital resource set identifier corresponding to the target resource transfer processing result from the A digital resource set identifiers as the target digital resource set identifier;

[0050] A fourth determining unit, configured to determine the transferred resources corresponding to the target digital resource set identifier according to the resource transfer value corresponding to the target digital resource set identifier;

[0051] The resource return unit is used to return the transferred resources to the target digital resource collection identifier.

[0052] On one hand, an embodiment of the present application provides a data processing device, which runs on a target organization server and includes:

[0053] A voucher acquisition module is used to acquire a target resource transfer voucher sent by a business server; the target resource transfer voucher belongs to A resource transfer vouchers; the A resource transfer vouchers are generated by the business server according to the voucher identifiers corresponding to the A digital resource collection identifiers, and the resource transfer values ​​corresponding to the A digital resource collection identifiers; the A voucher identifiers are generated by the business server when acquiring a transaction request for an application client; the transaction request includes A digital resource collection identifiers and A resource transfer values; A is a positive integer greater than 1; the A digital resource collection identifiers are all created by the application client; the institution server to which the digital resource collection identifier corresponding to the target resource transfer voucher belongs is the target institution server;

[0054] The resource transfer module is used to perform resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher according to the target resource transfer voucher, and obtain the resource transfer processing result;

[0055] The result returning module is used to return the resource transfer processing result to the business server, so that the business server determines the transaction result of the transaction request based on the resource transfer processing result.

[0056] Among them, the resource transfer module includes:

[0057] A first acquisition unit, used to acquire a target object signature in a target resource transfer voucher and a target service signature in a target resource transfer voucher;

[0058] The second acquisition unit is used to acquire the object public key corresponding to the application client, and verify the signature of the target object based on the object public key to obtain a first verification result;

[0059] The third acquisition unit is used to acquire the business public key corresponding to the organization server, and verify the target business signature based on the business public key to obtain a second verification result;

[0060] The resource transfer unit is used to perform resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher according to the first signature verification result and the second signature verification result to obtain the resource transfer processing result.

[0061] The resource transfer unit includes:

[0062] A first determining subunit is configured to determine that the resource transfer processing result is a resource transfer failure result if there is a signature verification failure result in the first signature verification result and the second signature verification result;

[0063] The second determination subunit is used to perform resource transfer processing on the resources to be transferred indicated by the resource transfer value in the target resource transfer voucher if both the first signature verification result and the second signature verification result are successful signature verification results; if the transfer of the resources to be transferred is successful, determine the resource transfer processing result as a successful resource transfer result.

[0064] On one hand, the present application provides a computer device, including: a processor, a memory, and a network interface;

[0065] The above-mentioned processor is connected to the above-mentioned memory and the above-mentioned network interface, wherein the above-mentioned network interface is used to provide a data communication function, the above-mentioned memory is used to store a computer program, and the above-mentioned processor is used to call the above-mentioned computer program so that the computer device executes the method in the embodiment of the present application.

[0066] On one hand, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. The computer program is suitable for being loaded by a processor and executing the method in the embodiment of the present application.

[0067] On the one hand, an embodiment of the present application provides a computer program product, which includes a computer program stored in a computer-readable storage medium; a processor of a computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the computer device executes the method in the embodiment of the present application.

[0068] In an embodiment of the present application, when a business server obtains a transaction request for an application client, it can generate, according to the transaction request, credential identifiers corresponding to the A digital resource set identifiers in the transaction request, wherein the A digital resource set identifiers are all created by the application client, that is, the application client of the present application can create at least two digital resource sets; further, the business server can generate resource transfer certificates corresponding to the A digital resource set identifiers according to the A credential identifiers and the resource transfer values ​​corresponding to the A digital resource set identifiers in the transaction request; the business server sends the A resource transfer certificates to an institution server cluster, wherein the institution server cluster includes institution servers corresponding to the A digital resource set identifiers; an institution server is used to receive a resource transfer certificate, and is used to perform resource transfer processing on the resources to be transferred indicated by the resource transfer value in the received resource transfer certificate according to the received resource transfer certificate; further, the business server obtains the resource transfer processing results returned by the A institution servers respectively, and can determine the transaction result of the transaction request according to the A resource transfer processing results. From the above, it can be seen that, for transaction requests, the embodiments of the present application can realize cross-institutional resource transfer, that is, the application client can complete a transaction through digital resources in at least two digital resource sets, thereby improving the applicability of resource transfer in transactions. BRIEF DESCRIPTION OF THE DRAWINGS

[0069] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0070] Figure 1 It is a schematic diagram of a system architecture provided by an embodiment of the present application;

[0071] Figure 2 This is a data processing scenario provided by an embodiment of the present application. Figure 1 ;

[0072] Figure 3 This is a data processing scenario provided by an embodiment of the present application. Figure 2 ;

[0073] Figure 4 This is a flow diagram of a data processing method provided in an embodiment of the present application. Figure 1 ;

[0074] Figure 5 This is a relationship structure diagram between an application client, a business server, and multiple operating organizations provided in an embodiment of the present application;

[0075] Figure 6 This is a data processing scenario provided by an embodiment of the present application. Figure 3 ;

[0076] Figure 7 This is a flow diagram of a data processing method provided in an embodiment of the present application. Figure 2 ;

[0077] Figure 8 This is a schematic diagram of the structure of a data processing device provided in an embodiment of the present application. Figure 1 ;

[0078] Fig. 9 This is a schematic diagram of the structure of a data processing device provided in an embodiment of the present application. Figure 2 ;

[0079] Fig.10 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. Figure 1 ;

[0080] Fig.11 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. Figure 2 . DETAILED DESCRIPTION

[0081] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0082] See also Figure 1 , Figure 1 Schematic diagram of a system architecture provided by an embodiment of the present application. Figure 1 As shown, the system architecture may include a business server 100, an organization server cluster and a terminal device cluster. It is understandable that the terminal device cluster may include one or more terminal devices, and the present application does not limit the number of terminal devices. Figure 1 As shown, the terminal device cluster may include: terminal device 101a, terminal device 101b, ..., terminal device 101n. Each terminal device in the terminal device cluster may include: smart phones, tablet computers, laptop computers, desktop computers, smart speakers, smart watches, car terminals, smart TVs and other smart terminals with digital resource transfer functions.

[0083] It should be understood that Figure 1Each terminal device in the terminal device cluster shown in FIG. 1 may be installed with an application client. When the application client runs in each terminal device, it may be respectively connected to the above-mentioned Figure 1 Data is exchanged between the business servers 100 shown. The application client may be an application client with a digital resource collection function, such as a video application, a convenient life application, a social application, a digital resource application, a financial application, a game application, a shopping application, a novel application, a browser, etc. The application client may be an independent client or an embedded sub-client integrated in a client (for example, a social client, an educational client, and a multimedia client, etc.), which is not limited here.

[0084] The business server 100 in the embodiment of the present application may be a server corresponding to the above-mentioned application client. Taking the application client as a digital resource application as an example, the business server 100 may be a collection of multiple servers including a background server corresponding to the digital resource application, a data processing server, etc. Therefore, each terminal device may transmit data with the business server 100 through the application client corresponding to the digital resource application. For example, each terminal device may upload a transaction request to the business server 100 through the application client of the digital resource application, and then the business server 100 may verify the transaction content according to the transaction request and request the institution server to transfer resources accordingly. The business server 100 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0085] It is understandable that the above-mentioned organization server cluster may include one or more organization servers, and this application does not limit the number of organization servers. Figure 1 As shown, the organization server cluster may include: organization server 102a, organization server 102b, ..., organization server 102n. Each organization server in the organization server cluster may be a server corresponding to an operating organization that has the function of providing digital resource collection services. For example, organization server 102a is a server corresponding to a first operating organization that provides digital resource collection services, organization server 102b is a server corresponding to a second operating organization that provides digital resource collection services, and organization server 102n is a server corresponding to a third operating organization that provides digital resource collection services; the first operating organization, the second operating organization, and the third operating organization are independent operating organizations. Each organization server in the organization server cluster may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services.

[0086] Among them, there may be communication connections between terminal device clusters, for example, there is a communication connection between terminal device 101a and terminal device 101b, and there is a communication connection between terminal device 101a and terminal device 101n. At the same time, any terminal device in the terminal device cluster may have a communication connection with the business server 100, for example, there is a communication connection between terminal device 101a and business server 100. At the same time, any terminal device in the terminal device cluster may have a communication connection with any institution server in the institution server cluster, for example, there is a communication connection between terminal device 101a and institution server 102a, and there is a communication connection between terminal device 101b and institution server 102a.

[0087] Among them, any institution server in the institution server cluster can have a communication connection with the business server 100, for example, there is a communication connection between the institution server 102a and the business server 100. At the same time, there can be a communication connection between institution server clusters, for example, there is a communication connection between the institution server 102a and the institution server 102b.

[0088] Among them, the present application does not limit the connection method for all the communication connections mentioned above. They can be directly or indirectly connected through wired communication methods, directly or indirectly connected through wireless communication methods, or through other methods.

[0089] To facilitate subsequent understanding and description, the embodiments of the present application can be Figure 1 A terminal device is selected as the target terminal device in the terminal device cluster shown, for example, the terminal device 101a is used as the target terminal device. When a transaction request including A digital resource set identifiers and resource transfer values ​​corresponding to the A digital resource set identifiers is generated in the application client, the terminal device 101a can send the transaction request carrying the object information to the business server 100, wherein A is a positive integer greater than 1; in the embodiment of the present application, the information used to identify the digital resource set is called the digital resource set identifier, and the embodiment of the present application does not limit the digital resource set identifier, and can be any information that can be used to identify the digital resource set in the business server 100; the digital resource set refers to a tool for managing digital resources, which can be understood as a digital wallet, which can realize the resource transfer of digital resources in online or offline transactions, and the application client provided by the embodiment of the present application can create a digital resource set provided by different operating institutions; the embodiment of the present application does not limit the digital resources, and all electronic resources with transaction value can be used; wherein, the object information can represent the object using the application client, and the embodiment of the present application does not limit the object information (the object is authorized), including but not limited to the mobile phone and identification number bound to the object in the application client, which can be set according to the actual application scenario.

[0090] Further, the business server 100 obtains the transaction request sent by the terminal device 101a to the application client. Obviously, the transaction request is used to request a transaction to be implemented through the resource transfer values ​​corresponding to the A digital resource collection identifiers. It can also be understood that the terminal device 101a requests a transaction to be implemented through the digital resource balances corresponding to the A digital resource collections. Further, according to the transaction request, the business server 100 can generate a voucher identifier corresponding to the A digital resource collection identifiers. The embodiment of the present application does not limit the method of generating the voucher identifier, and any method of generating a unique voucher identifier is acceptable. According to the A voucher identifiers and the A resource transfer values, the business server 100 can generate a resource transfer voucher corresponding to the A digital resource collection identifiers, that is, the resource transfer voucher corresponding to a digital resource collection identifier includes the voucher identifier corresponding to the digital resource collection identifier and the resource transfer value corresponding to the digital resource collection identifier.

[0091] The business server 100 sends A resource transfer certificates to the organization server cluster, wherein the organization server cluster includes organization servers corresponding to A digital resource set identifiers, for example, the A digital resource set identifiers include an identifier corresponding to a first digital resource set (referred to as the first digital resource set identifier), and the first digital resource set is provided by a first operating organization. Then, the business server 100 sends the resource transfer certificate corresponding to the first digital resource set identifier (referred to as the first resource transfer certificate) to the organization server corresponding to the first operating organization (such as Figure 1 The following description takes the institution server 102a as an example, and the processing process of other institution servers obtaining the resource transfer certificate is consistent with the processing process of the institution server 102a obtaining the first resource transfer certificate.

[0092] After obtaining the first resource transfer certificate, the agency server 102a performs resource transfer processing on the resource to be transferred indicated by the resource transfer value in the first resource transfer certificate according to the first resource transfer certificate, obtains the resource transfer processing result, and returns the resource transfer processing result to the business server 100.

[0093] The business server 100 obtains the resource transfer processing results returned by the A institutional servers respectively. Further, based on the A resource transfer processing results, the business server 100 can determine the transaction result of the transaction request and return the transaction result to the terminal device 101a.

[0094] It is understandable that in the specific implementation of the present application, related data such as user information (such as object information and transaction requests) is involved. When the above embodiments of the present application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0095] Optionally, it is understandable that the system architecture may include multiple business servers, a terminal device may be connected to a business server, and each business server may obtain transaction requests uploaded by the terminal device connected thereto, thereby being able to process the obtained transaction requests.

[0096] It should be noted that the above-mentioned business server 100, terminal device 101a, terminal device 101b, ..., terminal device 101n, agency server 102a, agency server 102b, ..., agency server 102n can all be blockchain nodes in the blockchain network, and the data described in the full text (such as transaction requests and transaction results) can be stored. The storage method can be a method in which the blockchain node generates blocks based on the data and adds the blocks to the blockchain for storage.

[0097] Blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism and encryption algorithm. It is mainly used to organize data in chronological order and encrypt it into a ledger to make it impossible to be tampered with or forged. At the same time, it can verify, store and update data. Blockchain is essentially a decentralized database. Each node in the database stores the same blockchain. The blockchain network can divide nodes into core nodes, data nodes and light nodes. Core nodes, data nodes and light nodes together constitute blockchain nodes. Among them, the core node is responsible for the consensus of the entire blockchain network, that is, the core node is the consensus node in the blockchain network. The process of writing transaction data in the blockchain network into the ledger can be that the data node or light node in the blockchain network obtains the transaction data, and transmits the transaction data in the blockchain network (that is, the node transmits it in the form of a baton) until the consensus node receives the transaction data, and the consensus node then packs the transaction data into a block, executes consensus on the block, and writes the transaction data into the ledger after the consensus is completed. Here, transaction data is exemplified by transaction requests and transaction results. After reaching a consensus on the transaction data, the business server 100 (blockchain node) generates a block based on the transaction data and stores the block in the blockchain network. As for reading the transaction data (i.e., the transaction request and transaction result), the blockchain node can obtain the block containing the transaction data in the blockchain network, and further obtain the transaction data in the block.

[0098] It is understandable that the method provided in the embodiments of the present application can be executed by a computer device, which includes but is not limited to a terminal device or a business server or an institutional server. Among them, the business server and the institutional server can be independent physical servers, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud databases, cloud services, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal device includes but is not limited to mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, etc. Among them, the terminal device and the business server can be directly or indirectly connected by wire or wireless means, and the embodiments of the present application are not limited here.

[0099] It can be understood that the above system architecture can be applied to resource transfer scenarios of online transactions, as well as to business scenarios such as resource transfer scenarios of offline transactions. Specific business scenarios will not be listed one by one here.

[0100] For further information, see Figure 2 , Figure 2 This is a data processing scenario provided by an embodiment of the present application. Figure 1 The implementation process of the data processing scenario can be performed in a business server, in a terminal device, in any server in an institutional server cluster, or interactively in a terminal device, a business server, and an institutional server cluster. There is no limitation here. The terminal device can be the above-mentioned Figure 1 Any terminal device in the terminal device cluster of the corresponding embodiment, Figure 2 Taking the terminal device 101a as an example, the service server can be the above Figure 1 The business server 100 of the corresponding embodiment and the organization server cluster can be the above Figure 1 The server cluster of the corresponding embodiment. The embodiment of the present application can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, smart transportation, assisted driving, etc.

[0101] like Figure 2 As shown, the first object 20a has a binding relationship with the terminal device 101a. The application client of the present application has a digital resource collection function. For ease of understanding, Figure 2 Taking application a as an example of an application client, a wallet represents a digital resource set, and a wallet balance represents the digital resources corresponding to the digital resource set. As shown in the example of business page 201a, the first object 20a creates four digital resource sets in application a, namely, digital resource set 1 (such as Figure 2Wallet 1), digital resource collection 2 (such as Figure 2 wallet 2), digital resource collection 3 (such as Figure 2 wallet3), and digital resource collection4 (such as Figure 2 Wallet in 4).

[0102] like Figure 2 As shown, the first object 20a applies a to the second object ( Figure 2 The object "aa" in the first object 20 is transferred by 1000. At this time, the terminal device 101a queries the digital resources corresponding to each digital resource set in the application a of the first object 20, and displays the digital resources corresponding to each digital resource set in the business page 201a. As shown in the business page 201a, the balance of wallet 1 (that is, the digital resources corresponding to digital resource set 1) is 600, the balance of wallet 2 (that is, the digital resources corresponding to digital resource set 2) is 1000, the balance of wallet 3 (that is, the digital resources corresponding to digital resource set 3) is 500, and the balance of wallet 4 (that is, the digital resources corresponding to digital resource set 4) is 1200.

[0103] At this time, the terminal device 101a prompts the first object 20a to select a digital resource set (ie, a wallet) for resource transfer. The embodiment of the present application can provide two resource transfer modes. The first resource transfer mode is a single resource transfer, and the second resource transfer mode is a combined resource transfer. Figure 2 As shown, if the first object 20a selects single resource transfer and selects wallet 1, at this time, the terminal device 101a can display a digital resource lack prompt 201b on the business page 201a, such as Figure 2 In the example of "The balance of your wallet 1 is lower than the transfer value", when the display time of the digital resource shortage prompt 201b reaches the display time threshold, the terminal device 101a cancels the display of the digital resource shortage prompt 201b on the business page 201a. If the first object 20a selects a single resource transfer and selects wallet 4, at this time, the terminal device 101a can display a transfer password input prompt 201c, such as Figure 2 In the example of “Please enter the transfer password”, the embodiment of the present application does not limit the way in which the first object 20a enters the transfer password. Figure 2 Take a numeric password as an example.

[0104] If the first object 20a selects combined resource transfer, at this time, the terminal device 101a can display a combined setting page 201d, and the combined setting page 201d may include at least two combination areas to be input, and at least two resource areas to be input corresponding to the combination areas to be input, wherein the combination area to be input is used to input the digital resource collection (i.e., the wallet) in the combined resource transfer, and the resource area to be input is used to input the resource transfer value. Figure 2In the example, at least two combination areas to be input include a combination area to be input 201e, a combination area to be input 202e, and a combination area to be input 203e; at least two resource areas to be input include a resource area to be input 201f corresponding to the combination area to be input 201e, a resource area to be input 202f corresponding to the combination area to be input 202e, and a resource area to be input 203f corresponding to the combination area to be input 203e. The combination setting page 201d may also include an add combination control 204e. When the first object 20a triggers the add combination control 204e, the terminal device 101a may respond to the trigger operation for the add combination control 204e and add a new combination area to be input and a new resource area to be input in the combination setting page 201d.

[0105] like Figure 2 As shown, when the first object 20a triggers the to-be-input combination area 201e, the terminal device 101a can display a digital resource set list 201g, wherein the digital resource set list 201g includes all digital resource sets created by the first object 20a in application a, and the digital resources corresponding to each digital resource set, wherein: Figure 2 For the specific content of the digital resource collection list 201g, please refer to the description of the business page 201a above, which will not be repeated here. If the first object 20a selects digital resource collection 1 (i.e., wallet 1) in the digital resource collection list 201g, the terminal device 101a can update the combination setting page 201d to display the combination setting page 202d, such as Figure 2 As shown, the wallet 1 selected by the first object 20a is displayed in the to-be-input combination area 201e in the combination setting page 202d.

[0106] Figure 2 The example is that the first object 20a selects digital resource sets one by one. Optionally, the first object 20a can select multiple digital resource sets in the digital resource set list 201g, such as digital resource set 1 (such as Figure 2 Wallet 1), digital resource collection 2 (such as Figure 2 wallet 2) and digital resource collection 4 (such as Figure 2 4), the terminal device 101a responds to the selection operation of the digital resource set 1, the digital resource set 2 and the digital resource set 4, and updates the combination setting page 201d. Please refer to Figure 3 , Figure 3 This is a data processing scenario provided by an embodiment of the present application. Figure 2 .like Figure 3As shown, the terminal device 101a updates the combination setting page 201d to display the combination setting page 203d, wherein wallet 1 is displayed in the combination area 201e to be input in the combination setting page 203d, wallet 2 is displayed in the combination area 202e to be input in the combination setting page 203d, and wallet 4 is displayed in the combination area 203e to be input in the combination setting page 203d.

[0107] Further, the first object 20a sets each resource area to be input respectively. It can be understood that the setting process of the three resource areas to be input is the same. Therefore, the embodiment of the present application takes the resource area to be input 201f as an example of the setting process of the resource area to be input. Figure 3 As shown, when the first object 20a inputs 700 in the resource to be input area 201f, the terminal device 101a can display the digital resource lack prompt 201b according to the balance of the wallet 1. If the first object 20a triggers the digital resource lack prompt 201b, the terminal device 101a can cancel the display of the digital resource lack prompt 201b. If the first object 20a does not trigger the digital resource lack prompt 201b, the terminal device 101a continues to display the digital resource lack prompt 201b until the display time corresponding to the digital resource lack prompt 201b reaches the display time threshold, and then cancels the display of the digital resource lack prompt 201b; at this time, the first object 20a can reset the resource transfer value corresponding to the wallet 1, and the subsequent setting process is the same as above, so it will not be repeated.

[0108] The first object 20a sets three resource areas to be input, as shown in the example of the combination setting page 204d. The first object 20a sets the resource transfer value corresponding to wallet 1 to 300, the resource transfer value corresponding to wallet 2 to 500, and the resource transfer value corresponding to wallet 4 to 200, that is, the total number of resource transfer values ​​corresponding to the three digital resource sets is the total value of the transaction. If the first object 20a triggers the confirmation control 204f, the terminal device 101a responds to the triggering operation of the confirmation control 204f and displays the password input page 201h. If the first object 20a enters any transfer password in the transfer password set in the password input page 201h, the terminal device generates a transaction request based on the identifier corresponding to the digital resource set 1 (for example, digital resource set identifier 1), the identifier corresponding to the digital resource set 2 (for example, digital resource set identifier 2), the identifier corresponding to the digital resource set 4 (for example, digital resource set identifier 4), the resource transfer value corresponding to the digital resource set 1 (such as 300 in the combination setting page 204d), the resource transfer value corresponding to the digital resource set 2 (such as 500 in the combination setting page 204d), the resource transfer value corresponding to the digital resource set 4 (such as 200 in the combination setting page 204d), and the transfer password entered by the first object 20a (i.e., the transfer password to be verified).

[0109] The above transfer code set includes the first object 20a creating each digital resource set (such as Figure 2 as well as Figure 3 It is understandable that the first object 20a needs to set the transfer password corresponding to each digital resource set when creating each digital resource set. For example, in application a, through the digital resource collection (wallet) service provided by operating organization 1, the first object 20a can create digital resource collection 1 (such as wallet 1) and set the transfer password 1 corresponding to digital resource collection 1; through the digital resource collection service provided by operating organization 1, the first object 20a can create digital resource collection 2 (such as wallet 2) and set the transfer password 2 corresponding to digital resource collection 2; the application client (i.e., application a) in the embodiment of the present application supports multiple operating organizations to provide digital resource collection services, so through the digital resource collection service provided by operating organization 2, the first object 20a can create digital resource collection 3 (such as wallet 3) and set the transfer password 3 corresponding to digital resource collection 3; through the digital resource collection service provided by operating organization 3, the first object 20a can create digital resource collection 4 (such as wallet 4) and set the transfer password 4 corresponding to digital resource collection 4; therefore, the transfer password set may include transfer password 1, transfer password 2, transfer password 3 and transfer password 4, wherein each transfer password in the transfer password set is determined by the first object 20a, so they may be different from each other or the same.

[0110] Please see again Figure 3 , the terminal device 101a sends the transaction request for application a to the business server 100. When the transaction request for application a sent by the terminal device 101a is obtained, the business server 100 can generate resource transfer vouchers corresponding to the three digital resource set identifiers (such as the above-mentioned digital resource set identifier 1, digital resource set identifier 2 and digital resource set identifier 4) in the transaction request according to the transaction request, such as Figure 3 The resource transfer voucher 1 corresponding to the digital resource collection identifier 1, the resource transfer voucher 2 corresponding to the digital resource collection identifier 2, and the resource transfer voucher 3 corresponding to the digital resource collection identifier 4 are shown in the example. The specific process of generating the resource transfer voucher by the business server 100 is not described in detail in the embodiment of the present application. Please refer to the following Figure 4 The description of step S102 in the corresponding embodiment.

[0111] Furthermore, since the digital resource set 1 is created by the digital resource set service function provided by the operating organization 1, the service server 100 sends the resource transfer certificate 1 to the server corresponding to the operating organization 1, for example Figure 3Similarly, since the digital resource set 2 is created by the digital resource set service function provided by the operating organization 1, the business server 100 sends the resource transfer certificate 2 to the server corresponding to the operating organization 1, for example Figure 3 Similarly, since the digital resource collection 4 is created by the digital resource collection service function provided by the operating organization 3, the business server 100 sends the resource transfer certificate 3 to the server corresponding to the operating organization 3, for example Figure 3 The institution server 102b in the example. Among them, an institution server is used to perform resource transfer processing on the resource to be transferred indicated by the resource transfer value in the received resource transfer certificate according to the received resource transfer certificate. This embodiment of the application does not describe this process in detail. Please refer to the following Figure 7 The description in the corresponding embodiment.

[0112] Please see again Figure 3 , the organization server 102a returns the resource transfer processing result 1 corresponding to the resource transfer voucher 1, and the resource transfer processing result 2 corresponding to the resource transfer voucher 2 to the business server 100, and the organization server 102b returns the resource transfer processing result 3 corresponding to the resource transfer voucher 3 to the business server 100. The business server 100 determines the transaction result of the transaction request according to the three resource transfer processing results, such as a successful transaction result or a failed transaction result. Further, the business server 100 returns the transaction result to the terminal device 101a, so that the first object 20a understands the resource transfer result.

[0113] Understandably, Figure 2 as well as Figure 3 The interfaces and controls shown are only some forms of expression for reference. In actual business scenarios, developers can make relevant designs according to product requirements. The embodiments of the present application do not limit the specific forms of the interfaces and controls involved.

[0114] From the above, it can be seen that the embodiment of the present application is based on the digital resource collection (i.e., digital wallet) mechanism to connect the digital resource collections corresponding to different operating institutions. For example, the above-mentioned application a supports operating institution 1 to provide digital resource collection service functions, and operating institution 2 to provide digital resource collection service functions; therefore, for a transaction request, the embodiment of the present application can realize the simultaneous deduction of multiple digital resource collections, that is, the digital resources can be connected.

[0115] For further information, see Figure 4 , Figure 4 This is a flow diagram of a data processing method provided in an embodiment of the present application. Figure 1 The data processing method may be implemented by a business server (for example, Figure 1 The service server 100 shown in the figure may also be executed by a terminal device (for example, the above Figure 1 The terminal device 101a) shown in the figure can also be executed by the service server and the terminal device interactively. For ease of understanding, the embodiment of the present application takes the method executed by the service server as an example for explanation. Figure 4 As shown, the data processing method may at least include the following steps S101 to S104.

[0116] Step S101, obtaining a transaction request for an application client; the transaction request includes A digital resource set identifiers, and resource transfer values ​​corresponding to the A digital resource set identifiers respectively; A is a positive integer greater than 1; the A digital resource set identifiers are all created by the application client.

[0117] Specifically, the transaction request in the embodiment of the present application may include multiple digital resource set identifiers, and resource transfer values ​​corresponding to the multiple digital resource set identifiers. That is, the embodiment of the present application can simultaneously perform resource transfer processing on digital resources in multiple digital resource sets for one transaction. Therefore, when the digital resources in one digital resource set are not sufficient to complete the resource transfer of a transaction, a transaction can be completed by the digital resources corresponding to two or more digital resource sets. Therefore, the applicability and convenience of resource transfer in the transaction can be improved.

[0118] It is understandable that the embodiment of the present application also supports completing a transaction through digital resources in a digital resource set, and the process is the same as described below, so it will not be repeated.

[0119] The application client of the embodiment of the present application supports the digital resource collection service functions provided by multiple operating organizations. Figure 5 , Figure 5 1 is a diagram showing the relationship between an application client, a service server and multiple operating organizations provided in an embodiment of the present application. Figure 5 As shown, the business server can provide multiple operating agencies for the application client, such as operating agency 1, operating agency 2, operating agency 3, ..., operating agency n, each of which can provide digital resource collection service functions. Figure 5In the figure, through the digital resource collection service function provided by operating organization 1, the application client creates digital resource collection 1 and digital resource collection 2; through the digital resource collection service function provided by operating organization 3, the application client creates digital resource collection 3 and digital resource collection 4; it can be understood that through the digital resource collection service functions provided by operating organization 1 and operating organization 3 respectively, the application client can still create a new digital resource collection, such as digital resource collection 5. Similarly, through the digital resource collection service functions provided by operating organization 2 and operating organization 4 respectively, the application client can create another new digital resource collection, such as digital resource collection 6.

[0120] Step S102: Generate voucher identifiers corresponding to the A digital resource set identifiers according to the transaction request, and generate resource transfer vouchers corresponding to the A digital resource set identifiers according to the A voucher identifiers and the A resource transfer values.

[0121] Specifically, obtain the transfer password to be verified in the transaction request; obtain the transfer password set corresponding to the application client; the transfer password set includes the transfer passwords corresponding to B digital resource collection identifiers; wherein, a transfer password refers to the password set for transactions when the application client creates a digital resource collection identifier; the B digital resource collection identifiers include A digital resource collection identifiers; B is a positive integer equal to or greater than A; according to the transfer password set, verify the transfer password to be verified to obtain a verification result; according to the verification result, generate credential identifiers corresponding to the A digital resource collection identifiers.

[0122] Among them, according to the transfer password set, the transfer password to be verified is verified, and the specific process of obtaining the verification result may include: matching the transfer password to be verified with the transfer passwords in the transfer password set; if there is no transfer password identical to the transfer password to be verified in the transfer password set, determining that the verification result is a password error result; if there is a transfer password identical to the transfer password to be verified in the transfer password set, determining that the verification result is a password correct result.

[0123] Among them, according to the verification result, the specific process of generating credential identifiers corresponding to A digital resource collection identifiers respectively may include: if the verification result indicates that there is a transfer password identical to the transfer password to be verified in the transfer password set, then obtaining the object signatures corresponding to the A digital resource collection identifiers in the transaction request; obtaining the object public key corresponding to the application client, and verifying the A object signatures based on the object public key to obtain A verification results; if the A verification results are all successful verification results, then generating credential identifiers corresponding to the A digital resource collection identifiers respectively.

[0124] Among them, A object signatures include digital resource collection identifier E dThe corresponding object signature C d , d is a positive integer and d is less than or equal to A; digital resource collection identifier E d Belongs to A digital resource collection identifiers; A signature verification results include object signature C d Corresponding signature verification results; based on the object public key, the A object signatures are respectively verified, and the specific process of obtaining the A signature verification results may include: based on the object public key, the object signature C d Decrypt to obtain the first digital summary; obtain the transaction identifier in the transaction request, and obtain the digital resource collection identifier E from the object identifiers corresponding to the A digital resource collection identifiers included in the transaction request. d Corresponding object identifier; transaction identifier, digital resource collection identifier E d The corresponding object identifier and the digital resource collection identifier E d The corresponding resource transfer value is determined as the data to be verified; the second digital summary of the data to be verified is obtained, and the first digital summary is compared with the second digital summary; if the first digital summary is different from the second digital summary, the object signature C is determined d The corresponding verification result is a verification failure result; if the first digital summary is the same as the second digital summary, the object signature C is determined d The corresponding signature verification result is a successful signature verification result.

[0125] Specifically, the transaction request also includes a transaction identifier, object signatures corresponding to the A digital resource set identifiers, and object identifiers corresponding to the A digital resource set identifiers; the A digital resource set identifiers include the digital resource set identifier F g , g is a positive integer and g is less than or equal to A; the resource transfer vouchers corresponding to the A digital resource set identifiers respectively include the digital resource set identifier F g Corresponding resource transfer certificate; obtain the business private key, and based on the business private key, identify the digital resource collection F g Corresponding voucher identifier, digital resource collection identifier F g Corresponding object identifier, digital resource collection identifier F g The corresponding resource transfer value and transaction identifier are signed to obtain the digital resource collection identifier F g Corresponding business signature; the digital resource collection identifier F g Corresponding voucher identifier, digital resource collection identifier F g Corresponding object identifier, digital resource collection identifier F g Corresponding resource transfer value, digital resource collection identifier F g The corresponding object signature, transaction identifier, and digital resource collection identifier F g The corresponding business signature is determined as the digital resource collection identifier F gThe corresponding resource transfer certificate.

[0126] like Figure 2 as well as Figure 3 As shown, when the first object 20a conducts a transaction through the application a of the terminal device 101a, it needs to enter a transfer password. The terminal device 101a adds the transfer password entered by the first object 20a as the transfer password to be verified to the transaction request. Therefore, after the business server 100 obtains the transaction request, it needs to verify the transfer password to be verified in the transaction request. Please refer to Figure 6 , Figure 6 This is a data processing scenario provided by an embodiment of the present application. Figure 3 .like Figure 3 As shown, the service server 100 obtains the transfer password set 40a corresponding to the application client, and the transfer password set 40a may include transfer password 1 (equivalent to the above Figure 2 The corresponding embodiment of the transfer password 1), transfer password 2 (equivalent to the above Figure 2 The corresponding embodiment of the transfer password 2), transfer password 3 (equivalent to the above Figure 2 The corresponding embodiment of the transfer password 3), and the transfer password 4 (equivalent to the above Figure 2 The transfer password 4 in the corresponding embodiment). Further, the service server 100 matches the transfer password to be verified with the four transfer passwords in the transfer password set 40a; if there is no transfer password identical to the transfer password to be verified in the transfer password set 40a, it can be determined that the verification result is a password error result. At this time, the service server 100 can generate a first prompt information, such as Figure 6 The prompt information 401a shown in the example, namely "transfer password is wrong, transaction failed", returns the second prompt information to the terminal device 101a, so that the first object 20a can enter the correct transfer password.

[0127] Please see again Figure 6 If there is a transfer password in the transfer password set that is the same as the transfer password to be verified, for example, the transfer password to be verified is the same as transfer password 1, then the business server 100 can determine that the verification result is a correct password result. At this time, the business server 100 obtains the object signatures corresponding to the A digital resource set identifiers in the transaction request. Figure 6 by Figure 3The digital resource collection identifier 1, digital resource collection identifier 2, and digital resource collection identifier 4 mentioned above are examples of A digital resource collection identifiers, so the A object signatures may include object signature 1 corresponding to digital resource collection identifier 1, object signature 2 corresponding to digital resource collection identifier 2, and object signature 3 corresponding to digital resource collection identifier 4. Among them, object signature 1 is a signature generated by terminal device 101a based on the object private key, for object identifier 1, transaction identifier, and resource transfer value 1 (such as Figure 3 300 in the figure, object identifier 1 refers to the object information authorized when the first object 20a creates the digital resource set 1, and the transaction identifier refers to the information of the transaction, such as the transaction number, etc.; object signature 2 is generated by the terminal device 101a based on the object private key, the object identifier 2, the transaction identifier and the resource transfer value 2 (such as Figure 3 500 in the figure), object identifier 2 refers to the object information authorized when the first object 20a creates the digital resource set 2; object signature 3 is generated by the terminal device 101a based on the object private key, the object identifier 3, the transaction identifier and the resource transfer value 3 (such as Figure 3 200) in the figure, the object identifier 3 refers to the object information authorized when the first object 20a creates the digital resource set 4.

[0128] The object public key and object private key mentioned in the embodiments of the present application, as well as the business public key and business private key are all asymmetric key pairs. The public key in the asymmetric key pair is the public part of the key pair, and the private key is the non-public part. The public key is usually used to encrypt data, verify digital signatures, etc. This algorithm can ensure that the obtained key pair is unique. When using this key pair, if one of the keys is used to encrypt a piece of data, it must be decrypted with another key. For example, if the data is encrypted with the public key, it must be decrypted with the private key. If it is encrypted with the private key, it must also be decrypted with the public key, otherwise the decryption will not be successful.

[0129] Further, the business server 100 obtains the object public key 40b corresponding to the application client, and verifies A (in the example of the present embodiment, A is equal to 3) object signatures based on the object public key 40b, and obtains A verification results. It can be understood that the process of the business server 100 verifying each object signature based on the object public key 40b is the same, so the present embodiment of the application is described by an example of verifying the object signature 1 based on the object public key 40b. Figure 6As shown, the business server 100 decrypts the object signature 1 based on the object public key 40b to obtain the first digital summary 1, and performs hash calculation on the object identifier 1, the transaction identifier and the resource transfer value 1 to obtain the second digital summary 1; the business server 100 compares the first digital summary 1 and the second digital summary 1. If the two are the same, it is determined that the verification result of the object signature 1 is a successful verification result; if the first digital summary 1 is different from the second digital summary 1, the business server 100 can determine that the verification result of the object signature 1 is a failed verification result. At this time, the business server 100 can generate a second prompt message, such as Figure 6 The prompt information “the object status is abnormal” in the example is returned to the terminal device 101a, so that the first object 20a can understand that its object status is in an abnormal state.

[0130] When the three verification results are all successful, the service server 100 generates credential identifiers corresponding to the three digital resource set identifiers, such as Figure 6 The example credential identifier 1, credential identifier 2 and credential identifier 3. Further, the business server 100 obtains the business private key 40d, and based on the business private key 40d, signs the credential identifier 1, object identifier 1, transaction identifier and resource transfer value 1 to obtain the business signature 1 corresponding to the digital resource set identifier 1; based on the business private key 40d, the business server 100 signs the credential identifier 2, object identifier 2, transaction identifier and resource transfer value 2 to obtain the business signature 2 corresponding to the digital resource set identifier 2; based on the business private key 40d, signs the credential identifier 3, object identifier 3, transaction identifier and resource transfer value 3 to obtain the business signature 3 corresponding to the digital resource set identifier 4.

[0131] Further, the business server 100 combines the credential identifier 1, object identifier 1, transaction identifier, resource transfer value 1, business signature 1 and object signature 1 into a resource transfer credential 1 corresponding to the digital resource collection identifier 1; combines the credential identifier 2, object identifier 2, transaction identifier, resource transfer value 2, business signature 2 and object signature 2 into a resource transfer credential 2 corresponding to the digital resource collection identifier 2; and combines the credential identifier 3, object identifier 3, transaction identifier, resource transfer value 3, business signature 3 and object signature 3 into a resource transfer credential 3 corresponding to the digital resource collection identifier 4.

[0132] The above-mentioned uses the asymmetric key pair of the business server 100 to ensure the trust relationship between it and the institutional server cluster, that is, the business server 100 signs the relevant data based on the business private key 40d to obtain a business signature, so that the institutional server that receives the resource transfer certificate can verify the business signature based on the business public key corresponding to the business private key 40d. According to the verification result, the institutional server determines the credibility of the transaction. Optionally, the business server 100 and the institutional server negotiate a symmetric key pair in advance (that is, the symmetric key pair is one-time, and the public key and private key in the symmetric key pair are the same), and then the business server 100 encrypts the credential identifier 1, object identifier 1, transaction identifier, and resource transfer value 1 according to the negotiated symmetric key pair to obtain encrypted data 1; encrypts the credential identifier 2, object identifier 2, transaction identifier, and resource transfer value 2 according to the negotiated symmetric key pair to obtain encrypted data 2; encrypts the credential identifier 3, object identifier 3, transaction identifier, and resource transfer value 2 according to the negotiated symmetric key pair. Value 3 is encrypted to obtain encrypted data 3; then the credential identifier 1, object identifier 1, transaction identifier, resource transfer value 1, encrypted data 1 and object signature 1 are combined into a resource transfer credential 1 corresponding to the digital resource collection identifier 1; the credential identifier 2, object identifier 2, transaction identifier, resource transfer value 2, encrypted data 2 and object signature 2 are combined into a resource transfer credential 2 corresponding to the digital resource collection identifier 2; the credential identifier 3, object identifier 3, transaction identifier, resource transfer value 3, encrypted data 3 and object signature 3 are combined into a resource transfer credential 3 corresponding to the digital resource collection identifier 4.

[0133] Step S103, sending A resource transfer certificates to an institutional server cluster; the institutional server cluster includes institutional servers corresponding to A digital resource collection identifiers; an institutional server is used to receive a resource transfer certificate, and is used to perform resource transfer processing on the resources to be transferred indicated by the resource transfer value in the received resource transfer certificate according to the received resource transfer certificate.

[0134] Specifically, the embodiment of the present application does not limit the operating organizations to which the A digital resource set identifiers respectively belong, that is, it does not limit the operating organizations to which the A digital resource sets respectively belong, and the operating organizations corresponding to each digital resource set may be different. Assume that the A digital resource sets include digital resource set a, digital resource set b, and digital resource set c. In the application client, if the first object creates digital resource set a according to the service functions provided by operating organization a, creates digital resource set b according to the service functions provided by operating organization b, and creates digital resource set c according to the service functions provided by operating organization c, then the business server sends the resource transfer certificate corresponding to the digital resource set a to the organization server corresponding to operating organization a, sends the resource transfer certificate corresponding to the digital resource set b to the organization server corresponding to operating organization b, and sends the resource transfer certificate corresponding to the digital resource set c to the organization server corresponding to operating organization c.

[0135] Optionally, there are two or more digital resource sets in A digital resource sets, and the corresponding operating organizations are the same, as described above. Figure 5 The digital resource set 1 and digital resource set 2 in the example both belong to operating organization 1, and the digital resource set 3 and digital resource set 4 both belong to operating organization 3. In this scenario, the business server sends the resource transfer certificate corresponding to digital resource set 1 and the resource transfer certificate corresponding to digital resource set 2 to the organization server corresponding to operating organization 1, and sends the resource transfer certificate corresponding to digital resource set 3 and the resource transfer certificate corresponding to digital resource set 4 to the organization server corresponding to operating organization 3.

[0136] Step S104, obtaining the resource transfer processing results returned by the A institution servers respectively, and determining the transaction result of the transaction request according to the A resource transfer processing results.

[0137] Specifically, if all A resource transfer processing results are successful resource transfer results, the transaction result of the transaction request is determined to be a successful transaction result; if there is a failed resource transfer result among the A resource transfer processing results, the transaction result of the transaction request is determined to be a failed transaction result.

[0138] Specifically, if the transaction result of the transaction request is a transaction failure result, the resource transfer processing result belonging to the successful resource transfer result is obtained from A resource transfer processing results as the target resource transfer processing result; the digital resource set identifier corresponding to the target resource transfer processing result is obtained from A digital resource set identifiers as the target digital resource set identifier; according to the resource transfer value corresponding to the target digital resource set identifier, the transferred resources corresponding to the target digital resource set identifier are determined; and the transferred resources are returned to the target digital resource set identifier.

[0139] The embodiment of the present application implements a summarized personal digital resource collection mechanism. When a transaction occurs, the terminal device does not need to switch digital resource collections multiple times, and resource transfer can be completed based on multiple digital resource collections, which can improve the convenience of transactions and the convenience of digital resource management.

[0140] In an embodiment of the present application, when a business server obtains a transaction request for an application client, it can generate, according to the transaction request, credential identifiers corresponding to the A digital resource set identifiers in the transaction request, wherein the A digital resource set identifiers are all created by the application client, that is, the application client of the present application can create at least two digital resource sets; further, the business server can generate resource transfer certificates corresponding to the A digital resource set identifiers according to the A credential identifiers and the resource transfer values ​​corresponding to the A digital resource set identifiers in the transaction request; the business server sends the A resource transfer certificates to an institution server cluster, wherein the institution server cluster includes institution servers corresponding to the A digital resource set identifiers; an institution server is used to receive a resource transfer certificate, and is used to perform resource transfer processing on the resources to be transferred indicated by the resource transfer value in the received resource transfer certificate according to the received resource transfer certificate; further, the business server obtains the resource transfer processing results returned by the A institution servers respectively, and can determine the transaction result of the transaction request according to the A resource transfer processing results. From the above, it can be seen that, for transaction requests, the embodiments of the present application can realize cross-institutional resource transfer, that is, the application client can complete a transaction through digital resources in at least two digital resource sets, thereby improving the applicability of resource transfer in transactions.

[0141] See also Figure 7 , Figure 7 This is a flow diagram of a data processing method provided in an embodiment of the present application. Figure 2 The method may be performed by a business server (eg, Figure 1 The business server 100 shown in the figure may also be executed by the target organization server (for example, the above Figure 1 The method may be executed by the organization server 102a) shown in the figure, or may be executed interactively by the business server and the target organization server. For ease of understanding, the present application embodiment takes the method executed by the target organization server as an example for explanation. Figure 7 As shown, the method may include at least the following steps.

[0142] Step S201, obtain the target resource transfer certificate sent by the business server; the target resource transfer certificate belongs to A resource transfer certificates; the A resource transfer certificates are generated by the business server according to the certificate identifiers corresponding to the A digital resource collection identifiers, and the resource transfer values ​​corresponding to the A digital resource collection identifiers; the A certificate identifiers are generated by the business server when obtaining the transaction request for the application client; the transaction request includes A digital resource collection identifiers and A resource transfer values; A is a positive integer greater than 1; the A digital resource collection identifiers are all created by the application client; the institution server to which the digital resource collection identifier corresponding to the target resource transfer certificate belongs is the target institution server.

[0143] Specifically, the target institution server is the above Figure 4 An institutional server in an institutional server cluster in the corresponding embodiment can be understood that each institutional server in the institutional server cluster has the same processing process for the received resource transfer certificate. Therefore, the embodiment of the present application is described using the target institutional server as an example. The target institutional server can be any institutional server in the institutional server cluster.

[0144] Among them, the target resource transfer certificate is the above Figure 4 For the generation process of the A resource transfer vouchers in the corresponding embodiment, please refer to the above Figure 4 The corresponding step S102 in the embodiment is not described in detail here.

[0145] Step S202: According to the target resource transfer voucher, a resource transfer process is performed on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher to obtain a resource transfer process result.

[0146] Specifically, obtain the target object signature in the target resource transfer certificate and the target business signature in the target resource transfer certificate; obtain the object public key corresponding to the application client, verify the target object signature based on the object public key, and obtain a first verification result; obtain the business public key corresponding to the organization server, verify the target business signature based on the business public key, and obtain a second verification result; based on the first verification result and the second verification result, perform resource transfer processing on the resources to be transferred indicated by the resource transfer value in the target resource transfer certificate to obtain a resource transfer processing result.

[0147] Among them, according to the first signature verification result and the second signature verification result, resource transfer processing is performed on the resources to be transferred indicated by the resource transfer value in the target resource transfer voucher, and the specific process of obtaining the resource transfer processing result may include: if there is a signature verification failure result in the first signature verification result and the second signature verification result, then the resource transfer processing result is determined to be a resource transfer failure result; if the first signature verification result and the second signature verification result are both signature verification success results, then resource transfer processing is performed on the resources to be transferred indicated by the resource transfer value in the target resource transfer voucher, and if the transfer of the resources to be transferred is successful, then the resource transfer processing result is determined to be a resource transfer success result.

[0148] The target organization server verifies the signature of the target object. Figure 4 In the corresponding embodiment, the process of the business server verifying the object signature is the same, so it is not repeated here. It can be understood that the process of the target organization server verifying the target business signature is the same as the process of the target organization server verifying the target object signature, the only difference is that the public key used is different, so it is not repeated here.

[0149] The target organization server performs resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher, that is, obtains the resource to be transferred indicated by the resource transfer value in the digital resource collection corresponding to the target resource transfer voucher, and transfers it to the digital resource collection corresponding to the second object, such as Figure 2 In the example, the first object 20a transfers 300 in the digital resource set 1 to the digital resource set corresponding to the object "aa". If the transfer of the resources to be transferred is successful, the target institution server can determine that the resource transfer processing result is a successful resource transfer result. If the transfer of the resources to be transferred fails, for example, the target institution server determines that the digital resources in the digital resource set corresponding to the target resource transfer voucher are lower than the resource transfer value in the target resource transfer voucher, or the target institution server determines that the collection state of the digital resource set corresponding to the second object is an abnormal collection state, the transfer will fail, so the target institution server can determine that the resource transfer processing result is a failed resource transfer result.

[0150] Step S203: Return the resource transfer processing result to the business server, so that the business server determines the transaction result of the transaction request based on the resource transfer processing result.

[0151] For the specific implementation process of step S203, please refer to the above Figure 4 The corresponding step S104 in the embodiment is not described in detail here.

[0152] In an embodiment of the present application, after receiving the target resource transfer certificate sent by the business server, the target institution server ignores the transfer password set by the first object for the digital resource set of the target resource transfer certificate, but verifies whether the various data of the target resource transfer certificate are valid, that is, verifies the signature of the target business, and verifies the signature of the target object; if the various data of the target resource transfer certificate are valid, the target institution server performs resource transfer processing on the resources to be transferred indicated by the resource transfer value in the target resource transfer certificate, and returns the resource transfer processing result to the business server. Using this application, the institution server cluster can process a transaction request at the same time, that is, perform resource transfer processing of the resource transfer value associated with itself respectively, so the convenience and applicability of resource transfer in transactions can be improved.

[0153] For further information, see Figure 8 , Figure 8 This is a schematic diagram of the structure of a data processing device provided in an embodiment of the present application. Figure 1 The above-mentioned data processing device may be a computer program (including program code) running in a computer device, for example, the data processing device is an application software; the device may be used to execute the corresponding steps of the method provided in the embodiment of the present application. Figure 8 As shown, the data processing device 1 may include: a first acquisition module 11 , a credential generation module 12 , a credential acquisition module 13 and a second acquisition module 14 .

[0154] The first acquisition module 11 is used to acquire a transaction request for the application client; the transaction request includes A digital resource set identifiers and resource transfer values ​​corresponding to the A digital resource set identifiers; A is a positive integer greater than 1; the A digital resource set identifiers are all created by the application client;

[0155] The voucher generation module 12 is used to generate voucher identifiers corresponding to the A digital resource set identifiers according to the transaction request, and generate resource transfer vouchers corresponding to the A digital resource set identifiers according to the A voucher identifiers and the A resource transfer values;

[0156] The certificate acquisition module 13 is used to send A resource transfer certificates to the organization server cluster; the organization server cluster includes organization servers corresponding to A digital resource collection identifiers; an organization server is used to receive a resource transfer certificate, and is used to perform resource transfer processing on the to-be-transferred resource indicated by the resource transfer value in the received resource transfer certificate according to the received resource transfer certificate;

[0157] The second acquisition module 14 is used to obtain the resource transfer processing results returned by A institution servers respectively, and determine the transaction result of the transaction request according to the A resource transfer processing results.

[0158] The specific functional implementation of the first acquisition module 11, the credential generation module 12, the credential acquisition module 13 and the second acquisition module 14 can be referred to in the above Figure 4 Steps S101 to S104 in the corresponding embodiment will not be described in detail here.

[0159] See also Figure 8 The credential generation module 12 may include: a first acquisition unit 121 , a second acquisition unit 122 , a password verification unit 123 and a first generation unit 124 .

[0160] The first acquisition unit 121 is used to acquire the transfer password to be verified in the transaction request;

[0161] The second acquisition unit 122 is used to acquire a transfer password set corresponding to the application client; the transfer password set includes transfer passwords corresponding to B digital resource set identifiers respectively; wherein a transfer password refers to a password set by the application client for conducting transactions when creating a digital resource set identifier; the B digital resource set identifiers include A digital resource set identifiers; B is a positive integer equal to or greater than A;

[0162] The password verification unit 123 is used to verify the transfer password to be verified according to the transfer password set to obtain a verification result;

[0163] The first generating unit 124 is used to generate credential identifiers corresponding to the A digital resource set identifiers according to the verification result.

[0164] The specific functional implementation of the first acquisition unit 121, the second acquisition unit 122, the password verification unit 123 and the first generation unit 124 can be referred to above. Figure 4 The step S102 in the corresponding embodiment will not be described in detail here.

[0165] See also Figure 8 The password verification unit 123 may include: a password matching subunit 1231 and a result determination subunit 1232.

[0166] The password matching subunit 1231 is used to match the transfer password to be verified with the transfer password in the transfer password set;

[0167] The result determination subunit 1232 is used to determine that the verification result is a password error result if there is no transfer password identical to the transfer password to be verified in the transfer password set;

[0168] The result determination subunit 1232 is further used to determine that the verification result is a password correct result if there is a transfer password in the transfer password set that is the same as the transfer password to be verified.

[0169] The specific functional implementation of the password matching subunit 1231 and the result determination subunit 1232 can be found in the above Figure 4 The step S102 in the corresponding embodiment will not be described in detail here.

[0170] See also Figure 8 The first generation unit 124 may include: a first acquisition subunit 1241, a second acquisition subunit 1242 and an identification generation subunit 1243.

[0171] The first acquisition subunit 1241 is configured to acquire object signatures corresponding to the A digital resource set identifiers in the transaction request if the verification result indicates that there is a transfer password identical to the transfer password to be verified in the transfer password set;

[0172] The second acquisition subunit 1242 is used to obtain the object public key corresponding to the application client, and verify the A object signatures based on the object public key to obtain A verification results;

[0173] The identifier generation subunit 1243 is used to generate credential identifiers corresponding to the A digital resource set identifiers respectively if the A signature verification results are all successful signature verification results.

[0174] The specific functional implementation of the first acquisition subunit 1241, the second acquisition subunit 1242 and the identification generation subunit 1243 can be found in the above Figure 4 The step S102 in the corresponding embodiment will not be described in detail here.

[0175] See also Figure 8 , A object signature includes a digital resource collection identifier E d The corresponding object signature C d , d is a positive integer and d is less than or equal to A; digital resource collection identifier E d Belongs to A digital resource collection identifiers; A signature verification results include object signature C d The corresponding signature verification result;

[0176] The second acquisition subunit 1242 may include: a signature decryption subunit 12421 , an identification acquisition subunit 12422 , a first determination subunit 12423 , a digest comparison subunit 12424 , a second determination subunit 12425 , and a third determination subunit 12426 .

[0177] Signature decryption subunit 12421, used to sign the object based on the object public key C dDecrypting to obtain a first digital summary;

[0178] The identification acquisition subunit 12422 is used to acquire the transaction identification in the transaction request, and acquire the digital resource collection identification E from the object identifications corresponding to the A digital resource collection identifications included in the transaction request. d The corresponding object identifier;

[0179] The first determining subunit 12423 is used to convert the transaction identifier and the digital resource set identifier E d The corresponding object identifier and the digital resource collection identifier E d The corresponding resource transfer value is determined as the data to be verified;

[0180] The summary comparison subunit 12424 is used to obtain a second digital summary of the data to be verified, and compare the first digital summary with the second digital summary;

[0181] The second determining subunit 12425 is used to determine the object signature C if the first digital summary is different from the second digital summary. d The corresponding signature verification result is a signature verification failure result;

[0182] The third determining subunit 12426 is used to determine the object signature C if the first digital summary is the same as the second digital summary. d The corresponding signature verification result is a successful signature verification result.

[0183] The specific functional implementation of the signature decryption subunit 12421, the identification acquisition subunit 12422, the first determination subunit 12423, the summary comparison subunit 12424, the second determination subunit 12425 and the third determination subunit 12426 can be referred to above. Figure 4 The step S102 in the corresponding embodiment will not be described in detail here.

[0184] See also Figure 8 The transaction request also includes a transaction identifier, an object signature corresponding to each of the A digital resource collection identifiers, and an object identifier corresponding to each of the A digital resource collection identifiers; the A digital resource collection identifiers include a digital resource collection identifier F g , g is a positive integer and g is less than or equal to A; the resource transfer vouchers corresponding to the A digital resource set identifiers respectively include the digital resource set identifier F g Corresponding resource transfer certificate;

[0185] The credential generating module 12 may include: a third obtaining unit 125 and a first determining unit 126 .

[0186] The third acquisition unit 125 is used to acquire the business private key, and based on the business private key, identify the digital resource set Fg Corresponding voucher identifier, digital resource collection identifier F g Corresponding object identifier, digital resource collection identifier F g The corresponding resource transfer value and transaction identifier are signed to obtain the digital resource collection identifier F g The corresponding business signature;

[0187] The first determining unit 126 is used to identify the digital resource set F g Corresponding voucher identifier, digital resource collection identifier F g Corresponding object identifier, digital resource collection identifier F g Corresponding resource transfer value, digital resource collection identifier F g The corresponding object signature, transaction identifier, and digital resource collection identifier F g The corresponding business signature is determined as the digital resource collection identifier F g The corresponding resource transfer certificate.

[0188] The specific functional implementation of the third acquisition unit 125 and the first determination unit 126 can be found in the above Figure 4 The step S102 in the corresponding embodiment will not be described in detail here.

[0189] See also Figure 8 The second acquisition module 14 may include: a second determination unit 141 and a third determination unit 142.

[0190] The second determining unit 141 is configured to determine that the transaction result of the transaction request is a successful transaction result if all A resource transfer processing results are successful resource transfer results;

[0191] The third determining unit 142 is configured to determine that the transaction result of the transaction request is a transaction failure result if there is a resource transfer failure result among the A resource transfer processing results.

[0192] The specific functional implementation of the second determining unit 141 and the third determining unit 142 can refer to the above Figure 4 The step S104 in the corresponding embodiment will not be described in detail here.

[0193] See also Figure 8 The second acquisition module 14 may further include: a fourth acquisition unit 143 , a fifth acquisition unit 144 , a fourth determination unit 145 and a resource withdrawal unit 146 .

[0194] The fourth acquisition unit 143 is configured to acquire a resource transfer processing result that is a successful resource transfer result from the A resource transfer processing results as a target resource transfer processing result if the transaction result of the transaction request is a transaction failure result;

[0195] A fifth acquisition unit 144 is used to acquire the digital resource set identifier corresponding to the target resource transfer processing result from the A digital resource set identifiers as the target digital resource set identifier;

[0196] The fourth determining unit 145 is used to determine the transferred resources corresponding to the target digital resource set identifier according to the resource transfer value corresponding to the target digital resource set identifier;

[0197] The resource returning unit 146 is used to return the transferred resources to the target digital resource set identifier.

[0198] The specific functional implementation of the fourth acquisition unit 143, the fifth acquisition unit 144, the fourth determination unit 145 and the resource return unit 146 can be found in the above Figure 4 The step S104 in the corresponding embodiment will not be described in detail here.

[0199] From the above, it can be seen that, for transaction requests, the embodiments of the present application can realize cross-institutional resource transfer, that is, the application client can complete a transaction through digital resources in at least two digital resource sets, thereby improving the applicability of resource transfer in transactions.

[0200] For further information, see Fig. 9 , Fig. 9 This is a schematic diagram of the structure of a data processing device provided in an embodiment of the present application. Figure 2 The above-mentioned data processing device may be a computer program (including program code) running in a computer device, for example, the data processing device is an application software; the device may be used to execute the corresponding steps of the method provided in the embodiment of the present application. Fig. 9 As shown, the data processing device 2 may include: a credential acquisition module 21, a resource transfer module 22 and a result return module 23.

[0201] The certificate acquisition module 21 is used to acquire the target resource transfer certificate sent by the business server; the target resource transfer certificate belongs to A resource transfer certificates; the A resource transfer certificates are generated by the business server according to the certificate identifiers corresponding to the A digital resource collection identifiers, and the resource transfer values ​​corresponding to the A digital resource collection identifiers; the A certificate identifiers are generated by the business server when acquiring the transaction request for the application client; the transaction request includes A digital resource collection identifiers and A resource transfer values; A is a positive integer greater than 1; the A digital resource collection identifiers are all created by the application client; the institution server to which the digital resource collection identifier corresponding to the target resource transfer certificate belongs is the target institution server;

[0202] The resource transfer module 22 is used to perform resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher according to the target resource transfer voucher, and obtain a resource transfer processing result;

[0203] The result returning module 23 is used to return the resource transfer processing result to the business server, so that the business server determines the transaction result of the transaction request based on the resource transfer processing result.

[0204] The specific functional implementation of the credential acquisition module 21, the resource transfer module 22 and the result return module 23 can be found in the above Figure 7 Steps S201 to S203 in the corresponding embodiment are not described in detail here.

[0205] See also Fig. 9 The resource transfer module 22 may include: a first acquisition unit 221, a second acquisition unit 222, a third acquisition unit 223 and a resource transfer unit 224.

[0206] The first acquisition unit 221 is used to acquire the target object signature in the target resource transfer certificate and the target service signature in the target resource transfer certificate;

[0207] The second acquisition unit 222 is used to obtain the object public key corresponding to the application client, and verify the signature of the target object based on the object public key to obtain a first verification result;

[0208] The third acquisition unit 223 is used to obtain the business public key corresponding to the organization server, and verify the target business signature based on the business public key to obtain a second verification result;

[0209] The resource transfer unit 224 is used to perform resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher according to the first signature verification result and the second signature verification result to obtain a resource transfer processing result.

[0210] The specific functional implementation of the first acquisition unit 221, the second acquisition unit 222, the third acquisition unit 223 and the resource transfer unit 224 can be referred to above. Figure 7 The step S202 in the corresponding embodiment will not be described in detail here.

[0211] See also Fig. 9 , the resource transfer unit 224 may include: a first determining subunit 2241 and a second determining subunit 2242.

[0212] The first determining subunit 2241 is configured to determine that the resource transfer processing result is a resource transfer failure result if there is a signature verification failure result in the first signature verification result and the second signature verification result;

[0213] The second determination subunit 2242 is used to perform resource transfer processing on the resources to be transferred indicated by the resource transfer value in the target resource transfer voucher if both the first signature verification result and the second signature verification result are successful signature verification results; if the transfer of the resources to be transferred is successful, determine the resource transfer processing result as a successful resource transfer result.

[0214] The specific functional implementation of the first determining subunit 2241 and the second determining subunit 2242 can refer to the above Figure 7 The step S202 in the corresponding embodiment will not be described in detail here.

[0215] From the above, it can be seen that, for transaction requests, the embodiments of the present application can realize cross-institutional resource transfer, that is, the application client can complete a transaction through digital resources in at least two digital resource sets, thereby improving the applicability of resource transfer in transactions.

[0216] For further information, see Fig.10 , Fig.10 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. Figure 1 .like Fig.10 As shown, the computer device 1000 may include: at least one processor 1001, such as a CPU, at least one network interface 1004, a user interface 1003, a memory 1005, and at least one communication bus 1002. The communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display) and a keyboard (Keyboard), and the network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory, or a non-volatile memory (non-volatile memory), such as at least one disk storage. The memory 1005 may optionally also be at least one storage device located away from the aforementioned processor 1001. As shown in FIG. Fig.10 As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a device control application.

[0217] exist Fig.10 In the computer device 1000 shown, the network interface 1004 can provide a network communication function; the user interface 1003 is mainly used to provide an input interface for the user; and the processor 1001 can be used to call the device control application stored in the memory 1005 to achieve:

[0218] Obtaining a transaction request for an application client; the transaction request includes A digital resource set identifiers and resource transfer values ​​corresponding to the A digital resource set identifiers; A is a positive integer greater than 1; the A digital resource set identifiers are all created by the application client;

[0219] Generate, according to the transaction request, voucher identifiers corresponding to the A digital resource set identifiers, and generate, according to the A voucher identifiers and the A resource transfer values, resource transfer vouchers corresponding to the A digital resource set identifiers;

[0220] A resource transfer vouchers are sent to an institutional server cluster; the institutional server cluster includes institutional servers corresponding to the A digital resource collection identifiers; an institutional server is used to receive a resource transfer voucher, and is used to perform resource transfer processing on the to-be-transferred resource indicated by the resource transfer value in the received resource transfer voucher according to the received resource transfer voucher;

[0221] Obtain resource transfer processing results returned by A institution servers respectively, and determine the transaction result of the transaction request according to the A resource transfer processing results.

[0222] It should be understood that the computer device 1000 described in the embodiment of the present application can execute the above Figure 4 as well as Figure 7 The description of the data processing method in the corresponding embodiment can also be performed as described above. Figure 8 The description of the data processing device 1 in the corresponding embodiment will not be repeated here. In addition, the description of the beneficial effects of the same method will not be repeated here either.

[0223] For further information, see Fig.11 , Fig.11 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. Figure 2 .like Fig.11As shown, the above-mentioned computer device 2000 may include: a processor 2001, a network interface 2004 and a memory 2005. In addition, the above-mentioned computer device 2000 may also include: a user interface 2003, and at least one communication bus 2002. Among them, the communication bus 2002 is used to realize the connection and communication between these components. Among them, the user interface 2003 may include a display screen (Display), a keyboard (Keyboard), and the optional user interface 2003 may also include a standard wired interface and a wireless interface. The network interface 2004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 2005 may be a high-speed RAM memory, or it may be a non-volatile memory (non-volatile memory), such as at least one disk storage. The memory 2005 may optionally also be at least one storage device located away from the aforementioned processor 2001. As Fig.11 As shown, the memory 2005 as a computer-readable storage medium may include an operating system, a network communication module, a user interface module, and a device control application program.

[0224] exist Fig.11 In the computer device 2000 shown, the network interface 2004 can provide a network communication function; the user interface 2003 is mainly used to provide an input interface for the user; and the processor 2001 can be used to call the device control application stored in the memory 2005 to achieve:

[0225] Obtain the target resource transfer voucher sent by the business server; the target resource transfer voucher belongs to A resource transfer vouchers; the A resource transfer vouchers are generated by the business server according to the voucher identifiers corresponding to the A digital resource collection identifiers, and the resource transfer values ​​corresponding to the A digital resource collection identifiers; the A voucher identifiers are generated by the business server when obtaining the transaction request for the application client; the transaction request includes A digital resource collection identifiers and A resource transfer values; A is a positive integer greater than 1; the A digital resource collection identifiers are all created by the application client; the institution server to which the digital resource collection identifier corresponding to the target resource transfer voucher belongs is the target institution server;

[0226] According to the target resource transfer voucher, performing resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher to obtain a resource transfer processing result;

[0227] The resource transfer processing result is returned to the business server, so that the business server determines the transaction result of the transaction request based on the resource transfer processing result.

[0228] It should be understood that the computer device 2000 described in the embodiment of the present application can execute the above Figure 4 as well as Figure 7 The description of the data processing method in the corresponding embodiment can also be performed as described above. Fig. 9 The description of the data processing device 2 in the corresponding embodiment will not be repeated here. In addition, the description of the beneficial effects of the same method will not be repeated here either.

[0229] The present application also provides a computer-readable storage medium storing a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, Figure 4 as well as Figure 7 For details on the data processing methods provided in each step, please refer to the above Figure 4 as well as Figure 7 The implementation methods provided by each step will not be described in detail here. In addition, the description of the beneficial effects of adopting the same method will not be described in detail here either.

[0230] The computer-readable storage medium may be the data processing device provided in any of the aforementioned embodiments or the internal storage unit of the computer device, such as the hard disk or memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a smart memory card (smart media card, SMC), a secure digital (secure digital, SD) card, a flash card (flash card), etc. equipped on the computer device. Further, the computer-readable storage medium may also include both the internal storage unit of the computer device and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium may also be used to temporarily store data that has been output or is to be output.

[0231] The present application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. The processor of the computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the computer device can execute the description of the data processing method or device in the above embodiments, which will not be repeated here. In addition, the description of the beneficial effects of the same method will not be repeated.

[0232] The terms "first", "second", etc. in the description, claims, and drawings of the embodiments of the present application are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, device, product, or equipment that includes a series of steps or units is not limited to the listed steps or modules, but optionally includes steps or modules that are not listed, or optionally includes other step units inherent to these processes, methods, devices, products, or equipment.

[0233] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0234] The above disclosure is only the preferred embodiment of the present application, which certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.

Claims

1. A data processing method, characterized in that: include: The business server obtains a transaction request for the application client; the transaction request includes A digital resource set identifiers and resource transfer values ​​corresponding to the A digital resource set identifiers; A is a positive integer greater than 1; the A digital resource set identifiers are all created by the application client; Generate, according to the transaction request, voucher identifiers corresponding to the A digital resource set identifiers respectively, and generate, according to the A voucher identifiers and the A resource transfer values, resource transfer vouchers corresponding to the A digital resource set identifiers respectively; A resource transfer vouchers are sent to an institutional server cluster; the institutional server cluster includes institutional servers corresponding to the A digital resource set identifiers; an institutional server is used to receive a resource transfer voucher, and is used to perform resource transfer processing on the to-be-transferred resource indicated by the resource transfer value in the received resource transfer voucher according to the received resource transfer voucher; Obtain resource transfer processing results respectively returned by A institution servers, and determine the transaction result of the transaction request based on the A resource transfer processing results.

2. The method according to claim 1, characterized in that The generating, according to the transaction request, credential identifiers corresponding to the A digital resource set identifiers respectively comprises: Obtaining the transfer password to be verified in the transaction request; Obtaining a transfer password set corresponding to the application client; the transfer password set includes transfer passwords corresponding to B digital resource set identifiers respectively; wherein a transfer password refers to a password used for transactions set by the application client when creating a digital resource set identifier; the B digital resource set identifiers include the A digital resource set identifiers; B is a positive integer equal to or greater than A; Verifying the transfer password to be verified according to the transfer password set to obtain a verification result; According to the verification result, credential identifiers corresponding to the A digital resource set identifiers are generated.

3. The method according to claim 2, characterized in that The step of verifying the transfer password to be verified according to the transfer password set to obtain a verification result includes: Matching the transfer password to be verified with the transfer passwords in the transfer password set; If there is no transfer password identical to the transfer password to be verified in the transfer password set, determining that the verification result is a password error result; If there is a transfer password in the transfer password set that is the same as the transfer password to be verified, then the verification result is determined to be a password correct result.

4. The method according to claim 2, characterized in that: The generating, according to the verification result, credential identifiers corresponding to the A digital resource set identifiers respectively comprises: If the verification result indicates that there is a transfer password identical to the transfer password to be verified in the transfer password set, obtaining object signatures corresponding to the A digital resource set identifiers in the transaction request respectively; Obtain the object public key corresponding to the application client, and verify A object signatures based on the object public key to obtain A verification results; If the A signature verification results are all successful signature verification results, then credential identifiers corresponding to the A digital resource set identifiers are generated.

5. The method according to claim 4, characterized in that The A object signatures include a digital resource collection identifier E d The corresponding object signature C d , d is a positive integer and d is less than or equal to A; the digital resource set identifier E d Belongs to the A digital resource collection identifiers; the A signature verification results include the object signature C d The corresponding signature verification result; The verifying the A object signatures based on the object public key to obtain A verification results includes: Sign the object based on the object public key C d Decrypting to obtain a first digital summary; Obtain the transaction identifier in the transaction request, and obtain the digital resource set identifier E from the object identifiers corresponding to the A digital resource set identifiers included in the transaction request. d The corresponding object identifier; The transaction identifier and the digital resource collection identifier E d The corresponding object identifier and the digital resource collection identifier E d The corresponding resource transfer value is determined as the data to be verified; Obtaining a second digital summary of the data to be verified, and comparing the first digital summary with the second digital summary; If the first digital summary is different from the second digital summary, the object signature C is determined d The corresponding signature verification result is a signature verification failure result; If the first digital summary is the same as the second digital summary, the object signature C is determined d The corresponding signature verification result is a successful signature verification result.

6. The method according to claim 1, characterized in that The transaction request also includes a transaction identifier, object signatures corresponding to the A digital resource set identifiers, and object identifiers corresponding to the A digital resource set identifiers; the A digital resource set identifiers include a digital resource set identifier F g , g is a positive integer and g is less than or equal to A; the resource transfer vouchers corresponding to the A digital resource set identifiers respectively include the digital resource set identifier F g Corresponding resource transfer certificate; The generating, according to the A voucher identifiers and the A resource transfer values, resource transfer vouchers corresponding to the A digital resource set identifiers respectively comprises: Obtain a business private key, and based on the business private key, identify the digital resource set F g The corresponding voucher identifier and the digital resource collection identifier F g The corresponding object identifier, the digital resource collection identifier F g The corresponding resource transfer value and the transaction identifier are signed to obtain the digital resource collection identifier F g The corresponding business signature; The digital resource collection identifier F g The corresponding voucher identifier and the digital resource collection identifier F g The corresponding object identifier, the digital resource collection identifier F g The corresponding resource transfer value, the digital resource set identifier F g The corresponding object signature, the transaction identifier, and the digital resource collection identifier F g The corresponding business signature is determined as the digital resource set identifier F g The corresponding resource transfer certificate.

7. The method according to claim 1, characterized in that The determining the transaction result of the transaction request according to the A resource transfer processing results includes: If the A resource transfer processing results are all successful resource transfer results, determining the transaction result of the transaction request as a successful transaction result; If there is a resource transfer failure result among the A resource transfer processing results, it is determined that the transaction result of the transaction request is a transaction failure result.

8. The method according to claim 7, characterized in that The method further comprises: If the transaction result of the transaction request is the transaction failure result, obtaining the resource transfer processing result belonging to the resource transfer success result from the A resource transfer processing results as the target resource transfer processing result; From the A digital resource set identifiers, obtaining the digital resource set identifier corresponding to the target resource transfer processing result as the target digital resource set identifier; Determining the transferred resources corresponding to the target digital resource set identifier according to the resource transfer value corresponding to the target digital resource set identifier; The transferred resource is returned to the target digital resource collection identifier.

9. A data processing method, characterized in that: include: The target organization server obtains the target resource transfer certificate sent by the business server; The target resource transfer voucher belongs to A resource transfer vouchers; The A resource transfer vouchers are generated by the business server according to the voucher identifiers corresponding to the A digital resource set identifiers, and the resource transfer values ​​corresponding to the A digital resource set identifiers; the A voucher identifiers are generated by the business server when obtaining a transaction request for the application client; the transaction request includes the A digital resource set identifiers and the A resource transfer values; A is a positive integer greater than 1; the A digital resource set identifiers are all created by the application client; The institution server to which the digital resource collection identifier corresponding to the target resource transfer voucher belongs is the target institution server; According to the target resource transfer voucher, performing resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher to obtain a resource transfer processing result; The resource transfer processing result is returned to the business server, so that the business server determines the transaction result of the transaction request based on the resource transfer processing result.

10. The method according to claim 9, characterized in that The step of performing resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher according to the target resource transfer voucher to obtain a resource transfer processing result includes: Obtaining a target object signature in the target resource transfer voucher and a target service signature in the target resource transfer voucher; Obtaining the object public key corresponding to the application client, and verifying the signature of the target object based on the object public key to obtain a first verification result; Obtaining the business public key corresponding to the institution server, and verifying the target business signature based on the business public key to obtain a second verification result; According to the first signature verification result and the second signature verification result, resource transfer processing is performed on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher to obtain a resource transfer processing result.

11. The method according to claim 10, characterized in that The performing resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher according to the first signature verification result and the second signature verification result to obtain the resource transfer processing result includes: If there is a signature verification failure result in the first signature verification result and the second signature verification result, determining that the resource transfer processing result is a resource transfer failure result; If the first signature verification result and the second signature verification result are both successful signature verification results, resource transfer processing is performed on the resources to be transferred indicated by the resource transfer value in the target resource transfer voucher. If the transfer of the resources to be transferred is successful, the resource transfer processing result is determined to be a successful resource transfer result.

12. A data processing device, characterized in that: The data processing device runs on the service server and includes: Obtaining a transaction request for an application client; the transaction request includes A digital resource set identifiers and resource transfer values ​​corresponding to the A digital resource set identifiers; A is a positive integer greater than 1; the A digital resource set identifiers are all created by the application client; Generate, according to the transaction request, voucher identifiers corresponding to the A digital resource set identifiers respectively, and generate, according to the A voucher identifiers and the A resource transfer values, resource transfer vouchers corresponding to the A digital resource set identifiers respectively; A resource transfer vouchers are sent to an institutional server cluster; the institutional server cluster includes institutional servers corresponding to the A digital resource set identifiers; an institutional server is used to receive a resource transfer voucher, and is used to perform resource transfer processing on the to-be-transferred resource indicated by the resource transfer value in the received resource transfer voucher according to the received resource transfer voucher; Obtain resource transfer processing results respectively returned by A institution servers, and determine the transaction result of the transaction request based on the A resource transfer processing results.

13. A data processing device, characterized in that: The data processing device runs on the target institution server and includes: Obtain a target resource transfer voucher sent by a business server; the target resource transfer voucher belongs to A resource transfer vouchers; the A resource transfer vouchers are generated by the business server according to the voucher identifiers corresponding to the A digital resource set identifiers, and the resource transfer values ​​corresponding to the A digital resource set identifiers; the A voucher identifiers are generated by the business server when obtaining a transaction request for an application client; the transaction request includes the A digital resource set identifiers and the A resource transfer values; A is a positive integer greater than 1; the A digital resource set identifiers are all created by the application client; the institution server to which the digital resource set identifier corresponding to the target resource transfer voucher belongs is the target institution server; According to the target resource transfer voucher, performing resource transfer processing on the resource to be transferred indicated by the resource transfer value in the target resource transfer voucher to obtain a resource transfer processing result; The resource transfer processing result is returned to the business server, so that the business server determines the transaction result of the transaction request based on the resource transfer processing result.

14. A computer device, characterized in that: include: A processor, a memory and a network interface; the processor is connected to the memory and the network interface, wherein the network interface is used to provide a data communication function, the memory is used to store a computer program, and the processor is used to call the computer program so that the computer device executes the method described in any one of claims 1 to 11.

15. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program is suitable for being loaded and executed by a processor, so that a computer device having the processor executes the method according to any one of claims 1 to 11.

16. A computer program product, characterized in that The computer program product comprises a computer program, which is stored in a computer-readable storage medium. The computer program is suitable for being read and executed by a processor, so that a computer device having the processor executes the method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Data transfer processing method and device and computer readable storage medium

    CN111062717A

  • Digital resource transfer control method and device, computer equipment and storage medium

    CN114119012A