A data processing method, device, apparatus, and readable storage medium
By generating decentralized authentication identifiers for IoT devices and uploading them to the blockchain, the problem of IoT device identifiers being easily tampered with is solved, achieving higher security and data credibility.
Patent Information
- Application Number
- CN202210487159.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-06
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2042-05-06
AI Technical Summary
Existing IoT devices use simple identification methods, which are easily tampered with, resulting in poor data security.
Assign unique authentication identifiers generated by a decentralized identity authentication system to IoT devices and upload them to the blockchain, leveraging the blockchain's unforgeability and tamper-proof nature to enhance the security of the identifiers.
By using decentralized authentication identifiers, the identity verification and data security of IoT devices can be significantly improved, ensuring the credibility and integrity of the data.
Smart Images

Figure CN117061134B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a data processing method, apparatus, device, and readable storage medium. Background Technology
[0002] The Internet of Things (IoT) refers to the use of various information sensing devices to collect information in real time about objects or processes that need to be connected and interacted with, and to achieve ubiquitous connectivity between things and between things and people through various possible network accesses, thereby enabling intelligent perception, identification and management of objects and processes.
[0003] IoT devices are used in various fields such as industry, consumer goods, and infrastructure, and these devices are closely related to people's work and life. For example, in indoor scenarios, there may be IoT devices such as smart coffee machines, smart treadmills, and smart refrigerators; while in outdoor scenarios, there may be IoT devices such as shared bicycles and shared phones.
[0004] For ease of management, each IoT device typically needs to be uniquely identified. Currently, most IoT devices are identified using barcodes or their MAC addresses. These existing methods of identifying IoT devices are very simple and have low barriers to counterfeiting. Consequently, the device data can be easily tampered with using these simple identifiers, resulting in poor data security. Summary of the Invention
[0005] This application provides a data processing method, apparatus, device, and readable storage medium, which can improve the security of IoT device identifiers and the data security of IoT devices.
[0006] One embodiment of this application provides a data processing method, including:
[0007] Obtain an identifier allocation request for the target IoT device; the identifier allocation request is used to request the allocation of a target decentralized authentication identifier as indicated by the target decentralized identity authentication system for the target IoT device; the target decentralized identity authentication system is the decentralized identity authentication system corresponding to the request initiating object; the request initiating object refers to the object that initiates the identifier allocation request;
[0008] Create a target decentralized authentication identifier corresponding to the target IoT device according to the character type and number of characters contained in the target identifier generation rule; the target identifier generation rule refers to the identifier generation rule indicated by the target decentralized identity authentication system;
[0009] Add the target decentralized authentication identifier to the blockchain; the target decentralized authentication identifier added to the blockchain is used by the device query object to obtain the shared operation data of the target IoT device from the blockchain based on the target decentralized authentication identifier; the device query object refers to the object that has the right to view the target IoT device.
[0010] One embodiment of this application provides a data processing apparatus, including:
[0011] The allocation request acquisition module is used to acquire the identifier allocation request for the target IoT device. The identifier allocation request is used to request the allocation of the target decentralized authentication identifier indicated by the target decentralized identity authentication system for the target IoT device. The target decentralized identity authentication system is the decentralized identity authentication system corresponding to the request initiating object. The request initiating object refers to the object that initiates the identifier allocation request.
[0012] The identifier creation module is used to create a target decentralized authentication identifier corresponding to the target IoT device according to the character type and number of characters contained in the target identifier generation rule; the target identifier generation rule refers to the identifier generation rule indicated by the target decentralized identity authentication system;
[0013] The on-chain identification module is used to add the target decentralized authentication identifier to the blockchain. The target decentralized authentication identifier added to the blockchain is used by the device query object to obtain the shared operation data of the target IoT device from the blockchain based on the target decentralized authentication identifier. The device query object refers to the object that has the right to view the target IoT device.
[0014] In one embodiment, the data processing apparatus further includes:
[0015] The registration request receiving module is used to receive identity registration requests initiated by the request initiating object and send the identity registration requests to the decentralized authentication server.
[0016] The authentication system determination module is used to determine the decentralized identity authentication system corresponding to the request initiator based on the request response information returned by the decentralized authentication server. The request response information includes the target decentralized authentication system assigned by the decentralized authentication server to the request initiator, and the target identifier generation rule indicated by the target decentralized authentication system.
[0017] In one embodiment, the character type includes a first character type and a second character type, and the character quantity includes the first character quantity corresponding to the first character and the second character quantity corresponding to the second character type;
[0018] The identifier creation module includes:
[0019] The string generation unit is used to obtain the first string generation algorithm corresponding to the first character type in the target identifier generation rule, and generate the first string based on the first string generation algorithm, the first character type, and the first character count; the character type of the first string is the first character type, and the number of characters contained in the first string is the first character count;
[0020] The string generation unit is also used to obtain the second string generation algorithm corresponding to the second character type in the target identifier generation rule, and generate the second string based on the second string generation algorithm, the second character type, and the number of second characters; the character type of the second string is the second character type, and the number of characters contained in the second string is the number of second characters;
[0021] The identifier generation unit is used to determine the target decentralized authentication identifier corresponding to the target IoT device based on the target identifier generation rules, the first string, and the second string.
[0022] In one embodiment, the identifier generation unit includes:
[0023] The characterization string acquisition subunit is used to retrieve the identity characterization string contained in the target identifier generation rule; the identity characterization string is used to uniquely identify the target decentralized identity authentication system;
[0024] Sequential acquisition sub-units are used to obtain the positional order of the identity representation string, the first string, and the second string as indicated by the target identifier generation rule;
[0025] The character arrangement subunit is used to arrange the identity representation string, the first string, and the second string in order according to their positions, and to determine the string sequence obtained by the arrangement as the target decentralized authentication identifier corresponding to the target IoT device.
[0026] In one embodiment, the identifier generation unit includes:
[0027] The associated identifier acquisition sub-unit is used to obtain the identity representation string contained in the target identifier generation rule; the identity representation string is used to uniquely identify the target decentralized identity authentication system;
[0028] The associated identifier acquisition subunit is also used to acquire the associated decentralized authentication identifier of associated IoT devices; associated IoT devices refer to IoT devices that have an operational dependency relationship with the target IoT device;
[0029] The associated identifier acquisition sub-unit is also used to obtain the dependency representation character in the associated decentralized authentication identifier; the dependency representation character is used to represent that there is an operational dependency relationship between the IoT device and the associated IoT device;
[0030] The identifier determination subunit is used to determine the target decentralized authentication identifier corresponding to the target IoT device based on the dependency representation character, the identity representation string, the first string, and the second string.
[0031] In one embodiment, the identifier determining subunit is further specifically used to obtain the positional arrangement order of the identity representation string, the first string, and the second string as indicated by the target identifier generation rule;
[0032] The identifier determines the subunit and is also specifically used to arrange the identity representation string, the first string, and the second string in order according to their position, and to determine the resulting string sequence as the initial decentralized authentication identifier.
[0033] The identifier determines the subunit and is also specifically used to obtain the character position of the dependent representation character in the associated decentralized authentication identifier, and to obtain the target position mapped by the character position in the initial decentralized authentication identifier;
[0034] The identifier determination subunit is also specifically used to obtain the mapping representation character corresponding to the dependency representation character, replace the character in the target position in the initial decentralized authentication identifier with the mapping representation character, and determine the replaced initial decentralized authentication identifier as the target decentralized authentication identifier; the mapping representation character in the target decentralized authentication identifier and the dependency representation character in the associated centralized authentication identifier are used to jointly represent the operational dependency relationship between the associated IoT device and the target IoT device; the device query object also has the right to view associated IoT devices.
[0035] In one embodiment, the identifier generation unit further includes:
[0036] The request retrieval subunit is used to retrieve exception handling requests initiated by the device user for the target IoT device; the device query object includes the device user, and the exception handling request includes the target decentralized authentication identifier;
[0037] The runtime data acquisition subunit is used to obtain shared runtime data from the blockchain based on the target decentralized authentication identifier;
[0038] The running data acquisition subunit is also used to acquire associated IoT devices that have a running dependency relationship with the target IoT device based on the mapping representation characters in the target decentralized authentication identifier, and to acquire associated running data of the associated IoT devices from the blockchain based on the associated decentralized authentication identifier of the associated IoT devices;
[0039] The abnormal maintenance subunit is used to identify abnormal IoT devices among the target IoT devices and associated IoT devices based on shared operational data and associated operational data, and to perform abnormal maintenance on the abnormal IoT devices; abnormal IoT devices refer to IoT devices whose operating status is abnormal.
[0040] In one embodiment, the data processing apparatus further includes:
[0041] The shared data acquisition module is used to acquire shared operational data sent by data nodes for the target IoT device; the data node is the business node corresponding to the device user, and the device user refers to the object using the target IoT device;
[0042] The block generation module generates target blocks based on shared runtime data.
[0043] The block on-chain module is used to add target blocks to the blockchain based on the target decentralized authentication identifier.
[0044] In one embodiment, the block on-chain module includes:
[0045] The block signing unit is used to sign the target block based on the private key corresponding to the target decentralized authentication identifier, thereby obtaining the block digital signature;
[0046] The signature verification unit is used to send the target block and the block digital signature to the consensus node of the blockchain, so that the consensus node can obtain the public key corresponding to the target decentralized authentication identifier, verify the block digital signature based on the public key corresponding to the target decentralized authentication identifier, and reach consensus on the target block after the signature verification is successful.
[0047] The block consensus unit is used to receive voting information returned by the consensus nodes; the voting information is determined by the consensus nodes when the digital signature of the block is verified.
[0048] The block consensus unit is also used to determine the consensus result of the target block based on voting information;
[0049] The block consensus unit is also used to add the target block to the blockchain when the consensus result of the target block is a consensus pass result.
[0050] In one embodiment, the number of consensus nodes is at least two, and the number of voting messages is at least two.
[0051] The block consensus unit includes:
[0052] The quantity statistics subunit is used to determine the voting information with the voting type of "pass" from at least two voting information messages as the passing voting information;
[0053] The quantity statistics subunit is also used to obtain the total number of nodes corresponding to consensus nodes, as well as the number of passes corresponding to the voting pass information;
[0054] The result determination sub-unit is used to determine the consensus result of the target block based on the number of passes and the total number of nodes.
[0055] In one embodiment, the request initiating object is the object that produces the target IoT device;
[0056] The data processing device also includes:
[0057] The status query request acquisition module is used to acquire status query requests initiated by the request initiator for the target IoT device during the device detection period; the status query request includes the target decentralized authentication identifier;
[0058] The device status determination module is used to obtain shared operational data of the target IoT device from the blockchain based on the target decentralized authentication identifier in the status query request;
[0059] The device status determination module is also used to determine the device operating status of the target IoT device based on shared operating data and send the device operating status to the request initiating object;
[0060] The maintenance processing module is used to receive device processing information returned by the request initiator based on the device's operating status;
[0061] The maintenance processing module is also used to perform device maintenance processing on the target IoT device based on the device processing information.
[0062] In one embodiment, the maintenance processing module includes:
[0063] The feedback notification unit is used to generate device feedback notification information and send it to the device user if the device is in normal operating status and the device processing information is the processing information returned by the request initiating object based on the normal operating status. The device feedback notification information is used to notify the device user to provide feedback to the request initiating object on improvement information for the target IoT device.
[0064] The equipment maintenance unit is used to generate equipment maintenance prompt information based on the maintenance time period if the equipment is in an abnormal operating state and the equipment processing information is the processing information returned by the request initiating object based on the abnormal operating state. The equipment maintenance prompt information is used to remind the target IoT device that it should be maintained within the maintenance time period.
[0065] In one embodiment, the request is initiated by an object that owns the target IoT device;
[0066] The data processing device also includes:
[0067] The transfer request acquisition module is used to acquire the ownership transfer request for the target IoT device initiated by the request initiating object; the ownership transfer request is used to request the transfer of the device's associated permissions to the target object, and the requesting object has the device usage rights of the target IoT device after the transfer of the device's associated permissions; the ownership transfer request carries the value of the requested virtual asset.
[0068] The request forwarding module is used to send ownership transfer requests to blockchain nodes in the blockchain; the blockchain nodes are used to assign access permissions for the target IoT device to the target object based on the ownership transfer request.
[0069] The message receiving module is used to receive the property transfer confirmation message sent by the blockchain node. The property transfer confirmation message is sent by the target object, which has been granted access to the target IoT device, to the blockchain node when the virtual asset valuation for the target IoT device is determined based on shared operational data and the virtual asset valuation is greater than or equal to the applied virtual asset value. The shared operational data is obtained by the target object from the blockchain through the target decentralized authentication identifier.
[0070] The asset transfer module is used to send asset transfer information to the target object based on the property transfer confirmation message. The asset transfer information is used to prompt the target object to transfer the virtual asset data corresponding to the requested virtual asset value to the account of the requesting object.
[0071] One embodiment of this application provides a computer device, including: a processor and a memory;
[0072] The memory stores a computer program, which, when executed by a processor, causes the processor to perform the method described in this application.
[0073] One aspect of this application provides a computer-readable storage medium storing a computer program, which includes program instructions. When executed by a processor, the program instructions perform the methods described in this application.
[0074] One aspect of this application provides a computer program product comprising a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium and executes the computer program, causing the computer device to perform the method provided in one aspect of the embodiments of this application.
[0075] In this embodiment, each IoT device (e.g., the target IoT device) can be assigned a decentralized authentication identifier (e.g., the target decentralized authentication identifier) indicated by its decentralized identity authentication system (e.g., the target decentralized identity authentication system). This decentralized authentication identifier can be used to uniquely identify each IoT device. After the decentralized authentication identifier is uploaded to the blockchain, the blockchain's unforgeability and tamper-proof nature can significantly improve the security of the decentralized authentication identifier. Furthermore, the shared operational data of IoT devices can only be uploaded to the blockchain through this decentralized authentication identifier, enhancing its credibility and security. Device query targets (objects with viewing permissions for IoT devices) can also query based on this decentralized authentication identifier, allowing for verification of data credibility from the source. In summary, this application, by combining IoT devices with a decentralized identity authentication system, assigning a decentralized authentication identifier to each IoT device through the identifier generation rules indicated by the decentralized identity authentication system, and then uploading the decentralized authentication identifier to the blockchain, can significantly improve the security of IoT device identifiers, thereby enhancing the security of IoT device data. Attached Figure Description
[0076] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0077] Figure 1 This is a network architecture diagram provided in an embodiment of this application;
[0078] Figure 2 This is a flowchart of a data processing method provided in an embodiment of this application;
[0079] Figure 3 This is a schematic diagram of the identifier structure of a decentralized authentication identifier provided in an embodiment of this application;
[0080] Figure 4 This is a schematic diagram of a process for generating a target decentralized authentication identifier provided in an embodiment of this application;
[0081] Figure 5 This is a system flowchart provided in an embodiment of this application;
[0082] Figure 6 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;
[0083] Figure 7This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0084] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0085] This application involves concepts related to the Internet of Things (IoT), IoT devices, and decentralized identity authentication systems. For ease of understanding, the relevant concepts of IoT, IoT devices, and decentralized identity authentication systems will be explained in a limited way below.
[0086] The Internet of Things (IoT) refers to the use of various devices and technologies, such as information sensors, RFID, GPS, infrared sensors, and laser scanners, to collect real-time information on any object or process that needs to be connected and interacted with. This information includes sound, light, heat, electricity, mechanics, chemistry, biology, and location data. Through various possible network access methods, it enables ubiquitous connectivity between things and between things and people, achieving intelligent sensing, identification, and management of objects and processes. An IoT device is an information carrier based on the internet and traditional telecommunications networks, allowing all independently addressable ordinary physical objects to form an interconnected network.
[0087] IoT devices are used in various fields such as consumer, industrial, and infrastructure, and these IoT devices are closely related to people's work and life. For example, there are many IoT devices in indoor application scenarios, such as smart coffee machines, smart treadmills, and smart refrigerators; there may also be IoT devices in outdoor application scenarios, such as shared bicycles and shared phones.
[0088] Decentralized ID (DID) is a digital identity system built on blockchain technology. It guarantees the authenticity and trustworthiness of identity data while protecting the privacy of individuals (such as users), ensuring that data related to personal identity belongs to the individual.
[0089] The solution provided in this application is mainly an identification scheme for IoT devices based on decentralized identity. By combining IoT devices with a decentralized identity authentication system, a unique decentralized authentication identifier is assigned to each IoT device. This decentralized authentication identifier is then registered in the blockchain. When the IoT device is running, it generates a large amount of operational data. This application can use the decentralized authentication identifier to put publicly available operational data (referred to as shared operational data) on the blockchain (i.e., store it in the blockchain). Then, various objects with viewing rights to the IoT device (such as device manufacturers, device users, etc.) can obtain the operational status of the IoT device based on the shared operational data on the blockchain, which facilitates corresponding device processing (such as device repair, maintenance, etc.).
[0090] For easier understanding, please refer to Figure 1 , Figure 1 This is a network architecture diagram provided in an embodiment of this application. For example... Figure 1 As shown, this network architecture may include server 1000 and a terminal device cluster. The terminal device cluster may include one or more terminal devices; the number of terminal devices is not limited here. Figure 1 As shown, multiple terminal devices may include terminal device 100a, terminal device 100b, terminal device 100c, ..., terminal device 100n; as Figure 1 As shown, terminal devices 100a, 100b, 100c, ..., 100n can each connect to server 1000 via a network so that each terminal device can interact with server 1000 through the network connection.
[0091] It is understandable that, such as Figure 1 Each terminal device shown can have the target application installed. When the target application runs on each terminal device, it can interact with... Figure 1 The servers 1000 shown interact with each other, enabling each server 1000 to receive business data from each terminal device. The target application may include applications capable of displaying text, images, audio, and video data. For example, the application may be a multimedia application (e.g., a video application), an entertainment application (e.g., a game application), a social application, an educational application, etc. It should be understood that the business data in this application may be application-related data corresponding to the application. For example, when the target application is a video application, the business data may refer to video-related data; when the target application is a game application, the business data may refer to game-related data. Examples will not be provided here.
[0092] It should be understood that the target application in this application can also be an application providing DID services (which may be referred to as a DID service application). Each terminal device in the terminal device cluster 100 can be the terminal device corresponding to any object that wishes to perform DID-related business (such as DID identifier registration business). The server 1000 can be the backend server corresponding to the DID service application and can provide computing services for the DID service application. In other words, when an object wishes to perform related business through the DID service application in the terminal device, the server 1000 can obtain its business data and provide related services based on the business data.
[0093] This application embodiment can select one terminal device from multiple terminal devices as the target terminal device. This terminal device may include: smartphones, tablets, laptops, desktop computers, smart TVs, smart speakers, desktop computers, smartwatches, smart voice interaction devices, in-vehicle devices, and other smart terminals with multimedia data processing functions (e.g., video data playback functions, music data playback functions), but is not limited to these. For example, this application embodiment can... Figure 1The terminal device 100a shown serves as the target terminal device. This target terminal device may integrate the aforementioned target application. In this case, the target terminal device can interact with the business server 1000 through the target application. For example, taking an object that produces an IoT device (which can be understood as the object that manufactures the IoT device, such as a company, hereinafter referred to as the device generation object) as an example, and wishing to register a DID identifier for the IoT device, the device generation object can initiate an identifier allocation request through the DID service application. Subsequently, the terminal device corresponding to the device production object (such as the target terminal device) can send the identifier allocation request to the DID backend server (such as server 1000 mentioned above). Server 1000 can obtain the decentralized identity authentication system corresponding to the device production object. (It should be understood that different device production objects can correspond to different decentralized identity authentication systems, and different decentralized identity authentication systems can correspond to different DID identifier generation rules. If the device production object is initiating an identifier allocation request for the first time, server 1000 can prioritize allocating a decentralized identity authentication system and identifier generation rules for the device production object. If the device production object is not initiating an identifier allocation request for the first time, it can indicate that the device...) If the production object already has a decentralized identity authentication system, it can be directly obtained. For the decentralized identity authentication system of this production object (hereinafter referred to as the target decentralized identity authentication system), server 1000 can obtain the identifier generation rule indicated by the target decentralized identity authentication system (hereinafter referred to as the target identifier generation rule). According to the character type and number of characters contained in the target identifier generation rule, a decentralized authentication identifier (i.e., a DID identifier, which can be referred to as the target decentralized authentication identifier) can be created for the IoT device. Subsequently, server 1000 can register (i.e., add) the target decentralized authentication identifier corresponding to the IoT device on the blockchain.
[0094] Furthermore, for the operational data generated by IoT devices during operation, the publicly available operational data (which can be called shared operational data) can be uploaded to the blockchain based on the target decentralized authentication identifier. Then, all objects with viewing rights to the IoT device (such as the device manufacturer, the device user, etc.) can learn about the operational status of the IoT device based on the shared operational data on the blockchain, which facilitates corresponding device processing (such as device repair, maintenance, etc.).
[0095] It is understood that the methods provided in this application embodiment can be executed by computer devices, including but not limited to terminal devices or servers. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0096] The terminal devices and servers can be connected directly or indirectly through wired or wireless communication, and this application does not impose any restrictions on this.
[0097] Optionally, and understandably, the aforementioned computer devices (such as server 1000, terminal device 100a, terminal device 100b, etc.) can be nodes in a distributed system. This distributed system can be a blockchain system, formed by connecting multiple nodes through network communication. The nodes can form a peer-to-peer (P2P) network, where the P2P protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP). In this distributed system, any type of computer device, such as servers, terminal devices, or other electronic devices, can become a node in the blockchain system by joining this peer-to-peer network. For ease of understanding, the concept of blockchain is explained below: Blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. It is mainly used to organize data in chronological order and encrypt it into a ledger, making it tamper-proof and forgery-proof, while also enabling data verification, storage, and updating. When a computer device is a blockchain node, the immutability and anti-counterfeiting characteristics of the blockchain ensure that the data in this application (such as the DID identifier of IoT devices, the shared operation data of IoT devices, etc.) has authenticity and security, thereby making the results obtained after data processing based on this data more reliable.
[0098] It should be noted that, in the specific embodiments of this application, data related to user information and user data (such as the DID identifier of IoT devices, operational data of IoT devices, etc.) can only be obtained with the user's authorization. In other words, when the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions.
[0099] For ease of understanding, please refer to the following: Figure 2 , Figure 2 This is a flowchart illustrating a data processing method provided in an embodiment of this application. The data processing method can be executed by a computer device, which may refer to a server (e.g., the one described above). Figure 1 The server in the corresponding embodiment can also refer to a terminal device (such as the one mentioned above). Figure 1 The term "any terminal device in the terminal device cluster" in the corresponding embodiment can also refer to a node in a blockchain. For example... Figure 2 As shown, the data processing method may include at least the following steps S101-S103:
[0100] Step S101: Obtain an identifier allocation request for the target IoT device; the identifier allocation request is used to request the target IoT device to be allocated a target decentralized authentication identifier indicated by the target decentralized identity authentication system; the target decentralized identity authentication system is the decentralized identity authentication system corresponding to the request initiating object; the request initiating object refers to the object that initiates the identifier allocation request.
[0101] In this application, an Internet of Things (IoT) device is an information carrier based on the Internet and traditional telecommunications networks, enabling all independently addressable ordinary physical objects to form an interconnected network. Smart coffee machines, smart treadmills, smart refrigerators, shared bicycles, and shared telephones can all be considered IoT devices. Any IoT device can be the target IoT device in this application. The decentralized identity authentication system (Decentralized ID, DID) in this application is a digital identity system built on blockchain technology. It can guarantee the authenticity and trustworthiness of identity data while protecting the privacy of identity objects (such as users), ensuring that data related to personal identity belongs to the individual. This application can combine the decentralized identity authentication system with IoT devices, assigning a DID identifier to each IoT device (a DID identifier is a specific format string used to represent the digital identity of an entity, which can be a person, machine, or object; here, the DID identifier can be referred to as a decentralized authentication identifier). For a clearer understanding of the DID identifier, please refer to [link to relevant documentation]. Figure 3 , Figure 3 This is a schematic diagram of the identifier structure of a decentralized authentication identifier provided in an embodiment of this application. For example... Figure 3As shown, a DID identifier can include a prefix, a DID method, and a specific string. The prefix for each DID identifier is fixed and can be "DID:". The example for each DID identifier represents the DID method, indicating which DID method is used. This DID method can be customized and registered on a relevant website (such as the W3C website). Finally, each DID identifier can contain a specific string, which is unique and can uniquely identify an object (such as a person, item, or machine). The DID method in a DID identifier refers to the method for generating the specific string. This string can be composed of strings of different character types (such as numeric, alphanumeric, or other types), and different character types can be generated by their corresponding DID methods.
[0102] If an object wishes to assign a DID (Distributed Identifier) to an IoT device, it can initiate an identifier assignment request for that IoT device through a target application (such as a DID service application) on the terminal device. This IoT device can also be referred to as the target IoT device, and the object initiating the identifier assignment request can be called the request initiating object. This request initiating object can be an object that owns the IoT device, such as the object that produced the IoT device (referred to as the device manufacturer), the object that purchased the IoT device (referred to as the device purchaser or device user), and so on.
[0103] It should be understood that different objects (such as enterprises) may correspond to different decentralized identity authentication systems, and each object registers a corresponding decentralized identity authentication system. Taking the above example of a request initiating object registering a target decentralized identity authentication system, the specific method is as follows: The request initiating object can initiate an identity registration request to a computer device (such as a terminal device or a server) through a target application (such as a DID service application). The computer device can receive the identity registration request initiated by the request initiating object and can send the identity registration request to a decentralized authentication server (the backend server corresponding to the DID service application). Subsequently, the decentralized authentication server can allocate a decentralized identity authentication system (referred to as the target decentralized identity authentication system) for the request initiating object and allocate an identifier generation rule (referred to as the target identifier generation rule) for the target decentralized identity authentication system. The decentralized authentication server can generate a request-response information based on the target decentralized identity authentication system and the target identifier generation rule, and return the request-response information to the computer device. Subsequently, the computer device can determine the decentralized identity authentication system corresponding to the request initiator based on the request response information returned by the decentralized authentication server; wherein, the request response information includes the target decentralized authentication system assigned by the decentralized authentication server to the request initiator, and the target identifier generation rule indicated by the target decentralized authentication system.
[0104] Step S102: Create a target decentralized authentication identifier corresponding to the target IoT device according to the character type and number of characters contained in the target identifier generation rule; the target identifier generation rule refers to the identifier generation rule indicated by the target decentralized identity authentication system.
[0105] As can be seen from the above, a DID identifier can be composed of strings of different character types. Therefore, this application can also create a target decentralized authentication identifier for a target IoT device according to the character types and number of characters contained in the target identifier generation rules. Taking the example of a character type containing a first character type and a second character type, and a character quantity containing the first character quantity corresponding to the first character type and the second character quantity corresponding to the second character type, the specific implementation method for creating a target decentralized authentication identifier corresponding to a target IoT device can be as follows: The first string generation algorithm corresponding to the first character type in the target identifier generation rules can be obtained. Based on the first string generation algorithm, the first character type, and the first character quantity, a first string can be generated; wherein, the character type of the first string is the first character type, and the number of characters contained in the first string is the first character quantity. Subsequently, the second string generation algorithm corresponding to the second character type in the target identifier generation rules can be obtained. Based on the second string generation algorithm, the second character type, and the second character quantity, a second string can be generated; wherein, the character type of the second string is the second character type, and the number of characters contained in the second string is the second character quantity. Based on the target identifier generation rules, the first string, and the second string, the target decentralized authentication identifier corresponding to the target IoT device can be determined.
[0106] The specific implementation method for determining the target decentralized authentication identifier corresponding to the target IoT device based on the target identifier generation rule, the first string, and the second string can be as follows: The identity representation string contained in the target identifier generation rule can be obtained; wherein, the identity representation string is used to uniquely identify the target decentralized identity authentication system; subsequently, the positional arrangement order of the identity representation string, the first string, and the second string as indicated by the target identifier generation rule can be obtained; according to the positional arrangement order, the identity representation string, the first string, and the second string can be arranged in sequence, and the resulting string sequence can be determined as the target decentralized authentication identifier corresponding to the target IoT device.
[0107] It is understandable that a DID identifier can be composed of strings of different character types. Therefore, an identifier generation rule can include string generation algorithms corresponding to different character types (such as string generation algorithms for numeric characters, alphanumeric characters, pattern characters, etc.). These string generation algorithms can be any algorithm with string generation capabilities (such as a random algorithm). Based on these string generation algorithms, strings of corresponding character types can be generated. For example, taking a numeric character type as the first character type and the number of the first character as 8, the string generation algorithm corresponding to the numeric character type can generate a numeric string containing 8 digits, such as "34587697". This numeric string "34587697" can then be used as the first string. It should be understood that this string generation algorithm can correspond to the above... Figure 3 The DID method in the corresponding embodiment means that the DID method in a DID identifier can include different string generation algorithms for different character types. Based on different string generation algorithms, strings of different character types can be generated. Combining and concatenating these strings yields the aforementioned result. Figure 3 The specific string used to uniquely identify an object in the corresponding embodiment.
[0108] Furthermore, it should be understood that the identifier generation rules of a decentralized identity authentication system may also include an identity representation string used to uniquely identify the decentralized identity authentication system, and may also include the positional order of strings of different character types. For example, the target identifier generation rules indicated by the target decentralized identity authentication system may include an identity representation string used to uniquely identify the target decentralized identity authentication system, and may include the positional order of strings of numeric character type and strings of alphanumeric character type (e.g., strings of numeric character type are arranged before strings of alphanumeric character type). After generating the numeric string corresponding to the numeric character type and the alphanumeric string corresponding to the alphanumeric character type, the identity representation string, numeric string and alphanumeric string can be arranged in order according to their positional order. The resulting string sequence can be determined as the target decentralized authentication identifier (such as DID identifier) of the target IoT device. For example, for a target decentralized identity system, its target identifier generation rule can include a representation string "12" to uniquely identify the target decentralized identity system, a string generation algorithm corresponding to numeric character types, and a string generation algorithm corresponding to alphanumeric character types. After generating the numeric string (assuming the numeric string is "347659") and the alphanumeric string (assuming the alphanumeric string is "aabhdj"), the representation string "12", the numeric string "347659", and the alphanumeric string "aabhdj" can be arranged in order according to their positions. Assuming the order is representation string + numeric string + alphanumeric string (i.e., the representation string precedes the numeric string, and the numeric string precedes the alphanumeric string), the resulting string sequence is "12347659aabhdj". This string sequence "12347659aabhdj" can then serve as the target decentralized authentication identifier for the target IoT device.
[0109] Step S103: Add the target decentralized authentication identifier to the blockchain; the target decentralized authentication identifier added to the blockchain is used by the device query object to obtain the shared operation data of the target IoT device from the blockchain based on the target decentralized authentication identifier; the device query object refers to the object that has the right to view the target IoT device.
[0110] In this application, after assigning a target decentralized authentication identifier (DID) to a target IoT device, the DID can be registered on the blockchain (e.g., added to the blockchain). It should also be understood that for a DID identifier, the DID document is a detailed description of the DID, and there is a one-to-one relationship between the DID document and the DID. The DID document can consist of two parts: DID metadata and the DID public key, which can be used for digital signatures or encryption operations. Typically, the DID can be stored by an object (such as a user), while the DID document is stored on the blockchain. It should be noted that when generating a DID identifier for a target IoT device, this application can generate the DID identifier and the associated DID document through a smart contract on the blockchain, and the DID document can then be stored on the blockchain.
[0111] It should be understood that after assigning a target decentralized authentication identifier to the target IoT device, this application can embed the private key (corresponding to the public key) corresponding to the target decentralized authentication identifier into the target IoT device. Then, after registering the target decentralized authentication identifier into the blockchain, the operational data generated by the target IoT device during operation can be signed using the private key embedded in the target IoT device, and the signed data can be added to the blockchain for storage. The blockchain can obtain the corresponding public key based on the target decentralized authentication identifier and verify the signature based on the public key to verify the correctness of the data. After successful verification, the operational data can be stored on the blockchain.
[0112] To facilitate understanding, the specific implementation method of adding operational data to the blockchain will be described below. Taking the example of a device user (an object that uses the target IoT device and generates operational data) wanting to put the operational data corresponding to the target IoT device on the blockchain, the specific method is as follows: Obtain the shared operational data corresponding to the target IoT device sent by the data node (shared operational data can refer to publicly available data in the operational data of the target IoT device); where the data node is the business node corresponding to the device user (e.g., specifically the terminal device of the device user), and the device user refers to the object using the target IoT device; subsequently, the computer device can generate the target block based on the shared operational data, and the target block can be added to the blockchain based on the target decentralized authentication identifier.
[0113] One specific implementation for adding a target block to the blockchain based on a target decentralized authentication identifier is as follows: The target block can be signed using the private key corresponding to the target decentralized authentication identifier, resulting in a digital signature. Subsequently, the target block and its digital signature can be sent to the consensus node of the blockchain, allowing the consensus node to obtain the public key corresponding to the target decentralized authentication identifier. The consensus node then verifies the digital signature based on this public key and reaches consensus on the target block upon successful verification. The consensus node can return its voting information (including votes that pass consensus and votes that reject consensus) to the computer device, which can receive this information. The voting information is determined by the consensus node upon successful verification of the digital signature. Based on the voting information, the consensus result for the target block is determined. When the consensus result for the target block is successful, the target block is added to the blockchain.
[0114] The specific implementation method for determining the consensus result of the target block based on voting information is as follows: the voting information with the voting type of "pass" (e.g., voting information that passes consensus) from at least two voting information can be determined as the voting pass information; then, the total number of nodes corresponding to the consensus nodes and the number of passes corresponding to the voting pass information can be obtained; based on the number of passes and the total number of nodes, the consensus result of the target block can be determined.
[0115] The specific implementation method for determining the consensus result of the target block based on the number of passes and the total number of nodes can be as follows: the ratio between the number of passes and the total number of nodes can be determined. If the ratio is greater than or equal to the ratio threshold, the consensus result of the target block can be determined as a consensus pass result; if the ratio is less than the ratio threshold, the consensus result of the target block can be determined as a consensus failure result.
[0116] It should be understood that the ratio threshold can be a manually defined value (such as 2 / 3, 3 / 4, etc., which will not be listed here). When there are consensus nodes with a ratio threshold (such as 2 / 3) that all vote in favor, the consensus result of the target block can be considered a consensus pass, and the target block can be added to the blockchain.
[0117] Understandably, once the shared operational data of a target IoT device is uploaded to the blockchain, its use and management become more convenient. For example, the manufacturer of the target IoT device (which can be referred to as the device manufacturer) can quickly and easily learn about the device's operational status based on the shared operational data on the blockchain. This facilitates better after-sales and maintenance services (such as repairing the target IoT device). For ease of understanding, the following example uses the request initiator as the device production object (i.e., the object that produces the target IoT device). The application of shared operational data on the blockchain can be as follows: During the device testing period (which can be a periodic period, such as testing once a month, once every two months, etc.), a status query request for the target IoT device initiated by the request initiator is obtained. This status query request may include the target decentralized authentication identifier. Based on the target decentralized authentication identifier in the status query request, shared operational data of the target IoT device can be obtained from the blockchain. Based on the shared operational data, the device's operational status can be determined, and then sent to the request initiator. The request initiator can then return device processing information for the target IoT device based on its operational status. The computer device can receive this device processing information and perform device maintenance on the target IoT device based on the device processing information.
[0118] The aforementioned device operating status can include normal operating status and abnormal operating status. A specific implementation method for maintaining the target IoT device based on device processing information is as follows: If the device is in normal operating status and the device processing information is the processing information returned by the request initiating object based on the normal operating status, the computer device can generate device feedback prompt information and send it to the device user. This device feedback prompt information is used to remind the device user to provide improvement information for the target IoT device to the request initiating object. In other words, within the device detection period, if the target IoT device is in normal operating status, the device user can still be consulted for improvement suggestions to better improve the target IoT device. Conversely, if the device is in abnormal operating status and the device processing information is the processing information returned by the request initiating object based on the abnormal operating status, a device maintenance prompt information can be generated based on the maintenance period (e.g., within one month, one year, etc.) and sent to the device user. This device maintenance prompt information is used to remind the target IoT device to undergo device maintenance within the maintenance period. In other words, if an abnormality is detected in the target IoT device during the device detection period, and its operating status is abnormal, the user can be prompted to have the target IoT device repaired during the maintenance period.
[0119] It is understandable that the use and management of the target IoT device can also be as follows: If an object that owns the target IoT device (such as the device manufacturer; when the device manufacturer sells the target IoT device to another object, the object that purchases the target IoT device (which can be called the device purchaser) acquires ownership of the target IoT device, while the device manufacturer no longer owns the target IoT device), and wishes to transfer the ownership of the target IoT device (such as transferring the item-related permissions of the target IoT device to the target object) in order to obtain the corresponding virtual asset data, the target object can conveniently and quickly learn about the relevant situation of the target IoT device based on the shared operational data on the blockchain. This facilitates a better evaluation and decision on whether to accept the object's request for ownership transfer. For ease of understanding, the following example uses an entity that owns the target IoT device as the initiating object. The specific implementation of transferring ownership of a target IoT device based on shared operational data on a blockchain can be as follows: An ownership transfer request for the target IoT device initiated by the requesting entity can be obtained. This request requests the transfer of device-related permissions of the target IoT device to the target entity, granting the requesting entity the device usage rights after the transfer. The ownership transfer request carries the requested virtual asset value. Subsequently, the computer device can send the ownership transfer request to a blockchain node. The blockchain node, based on the ownership transfer request, assigns the target entity access rights to the target IoT device. Once the target entity has access rights to the target IoT device, it can retrieve the shared operational data from the blockchain based on the target's decentralized authentication identifier and access it. The virtual asset valuation for the target IoT device is determined based on shared operational data. When this valuation is greater than the requested virtual asset value, the target object can return a property transfer confirmation message (confirming acceptance of the property transfer request). The computer device can receive the property transfer confirmation message sent by the blockchain node. The property transfer confirmation message is sent by the target object, which has been granted access to the target IoT device, to the blockchain node when the virtual asset valuation for the target IoT device is determined based on shared operational data and is greater than or equal to the requested virtual asset value. The shared operational data is obtained by the target object from the blockchain through the target decentralized authentication identifier. Based on the property transfer confirmation message, the computer device can send asset transfer information to the target object. The asset transfer information prompts the target object to transfer the virtual asset data corresponding to the requested virtual asset value to the account corresponding to the requesting object.
[0120] It is understandable that the device-related permissions can refer to device mortgage permissions. When an object that owns a target IoT device (referred to as the device ownership object) wishes to transfer the device-related permissions of the target IoT device to the target object in order to obtain the virtual asset data corresponding to the applied virtual asset value from the target object, the target object can obtain the shared operating data of the target IoT device from the blockchain based on the target decentralized authentication identifier. Based on the shared operating data and the endorsement of the device ownership object (the endorsement can be used to prove that the target IoT device does indeed belong to the device ownership object), an asset valuation is performed to obtain a virtual asset valuation value. If the virtual asset valuation value is greater than the applied virtual asset value, and the target object agrees to transfer the virtual asset data corresponding to the applied virtual asset value to the device ownership object, a property transfer confirmation message can be generated, and the virtual asset data corresponding to the applied virtual asset value can be transferred to the account of the device ownership object on schedule.
[0121] Of course, the above examples of applications based on shared operational data only illustrate two scenarios: after-sales maintenance and property transfer. In reality, this solution, based on decentralized authentication identifiers and shared operational data, can also be applied to other scenarios, such as product traceability, connected vehicles, intelligent manufacturing, and smart cities. These will not be described in detail here.
[0122] In this embodiment, each IoT device (e.g., the target IoT device) can be assigned a decentralized authentication identifier (e.g., the target decentralized authentication identifier) indicated by its decentralized identity authentication system (e.g., the target decentralized identity authentication system). This decentralized authentication identifier can be used to uniquely identify each IoT device. After the decentralized authentication identifier is uploaded to the blockchain, the blockchain's unforgeability and tamper-proof nature can significantly improve the security of the decentralized authentication identifier. Furthermore, the shared operational data of IoT devices can only be uploaded to the blockchain through this decentralized authentication identifier, enhancing its credibility and security. Device query targets (objects with viewing permissions for IoT devices) can also query based on this decentralized authentication identifier, allowing for verification of data credibility from the source. In summary, this application, by combining IoT devices with a decentralized identity authentication system, assigning a decentralized authentication identifier to each IoT device through the identifier generation rules indicated by the decentralized identity authentication system, and then uploading the decentralized authentication identifier to the blockchain, can significantly improve the security of IoT device identifiers, thereby enhancing the security of IoT device data.
[0123] Optionally, and understandably, as described above, after generating the first string corresponding to the first character type and the second string corresponding to the second character type, the target decentralized authentication identifier corresponding to the target IoT device can be determined based on the target identifier generation rules, the first string, and the second string. In a feasible embodiment, this application can determine the target decentralized authentication identifier of the target IoT device based on the decentralized authentication identifier (referred to as the associated decentralized authentication identifier) corresponding to IoT devices that have an operational dependency relationship with the target IoT device (referred to as associated IoT devices). That is, the target decentralized authentication identifier of the target IoT device and the associated decentralized authentication identifier of the associated IoT devices can be mutually associated, i.e., they are related on the blockchain. If the target IoT device malfunctions during operation, the shared operational data of the target IoT device and the associated shared operational data of the associated IoT devices (hereinafter referred to as associated operational data) can be obtained from the blockchain based on the correlation between the target IoT device's decentralized authentication identifier and the associated decentralized authentication identifier of the associated IoT devices. This shared operational data can then be analyzed to determine which IoT device is malfunctioning (due to the operational dependency between the target IoT device and the associated IoT devices, when the target IoT device malfunctions, it may not actually be that the target IoT device itself is malfunctioning). For better understanding, please refer to [link to relevant documentation]. Figure 4 , Figure 4 This is a schematic diagram illustrating a process for generating a target decentralized authentication identifier, provided in an embodiment of this application. This process can be as described above. Figure 2 In the corresponding embodiment, after generating the first string and the second string, the process of determining the target decentralized authentication identifier of the target IoT device is based on the target identifier generation rule, the first string, and the second string. In other words, Figure 4 The corresponding method flow can also be executed by computer devices, where computer devices can refer to servers (such as those mentioned above). Figure 1 The server in the corresponding embodiment can also refer to a terminal device (such as the one mentioned above). Figure 1 The term "any terminal device in the terminal device cluster" in the corresponding embodiment can also refer to a node in a blockchain. For example... Figure 4 As shown, the process may include at least the following steps S201-S204:
[0124] Step S201: Obtain the identity representation string contained in the target identifier generation rule; the identity representation string is used to uniquely identify the target decentralized identity authentication system.
[0125] Specifically, as can be seen from the above, the identifier generation rules of a decentralized identity authentication system can include an identity representation string used to uniquely identify the decentralized identity authentication system. Therefore, for a target decentralized identity authentication system, the identity representation string included in the target identifier generation rules can be obtained.
[0126] Step S202: Obtain the associated decentralized authentication identifier of the associated IoT device; the associated IoT device refers to an IoT device that has an operational dependency relationship with the target IoT device.
[0127] Specifically, associated IoT devices refer to IoT devices that have an operational dependency relationship with the target IoT device. For example, IoT device A needs the operational data of IoT device B to operate, or IoT device B needs the operational data of IoT device A to operate; or IoT devices A and B need each other's operational data to operate. In this case, IoT devices A and B can be identified as two IoT devices with an operational dependency relationship. The associated decentralized authentication identifier of the associated IoT devices can be obtained. If an associated decentralized authentication identifier for the associated IoT devices does not exist at this time, it can be generated according to priority.
[0128] Step S203: Obtain the dependency representation character from the associated decentralized authentication identifier; the dependency representation character is used to represent that there is an operational dependency relationship between the existing IoT device and the associated IoT device.
[0129] Specifically, dependency representation characters can be used to indicate that there is an operational dependency relationship between existing IoT devices and associated IoT devices. The character position of this dependency representation character can be a preset special position (such as the third character position in the identifier), or the dependency representation character can be a preset special character. When the identifier of an IoT device contains this special character, it can indicate that there is an operational dependency relationship between existing IoT devices and associated IoT devices. In other words, this special character can be used exclusively to indicate that there is an operational dependency relationship between existing IoT devices and associated IoT devices. The identifier of IoT devices that do not have an operational dependency relationship may not contain this special character.
[0130] Step S204: Determine the target decentralized authentication identifier corresponding to the target IoT device based on the dependency representation character, the identity representation string, the first string, and the second string.
[0131] Specifically, based on the dependency representation character, identity representation string, first string, and second string, the target decentralized authentication identifier corresponding to the target IoT device can be determined. The specific implementation method is as follows: The positional order of the identity representation string, first string, and second string as indicated by the target identifier generation rule can be obtained; according to the positional order, the identity representation string, first string, and second string can be arranged sequentially, and the resulting string sequence can be determined as the initial decentralized authentication identifier; subsequently, the character position of the dependency representation character in the associated decentralized authentication identifier can be obtained, and the target position mapped by the character position in the initial decentralized authentication identifier can be obtained; the mapping representation character corresponding to the dependency representation character can be obtained, and then the character at the target position in the initial decentralized authentication identifier is replaced with the mapping representation character, and the replaced initial decentralized authentication identifier can be determined as the target decentralized authentication identifier; wherein, the mapping representation character in the target decentralized authentication identifier and the dependency representation character in the associated centralized authentication identifier can be used to jointly represent the operational dependency relationship between the associated IoT device and the target IoT device; the device query object also has viewing permissions for associated IoT devices.
[0132] Understandably, taking the associated decentralized authentication identifier of the linked IoT device as "12Y4567iuyu" as an example, the string "12" in the first two character positions is the representation string corresponding to the target decentralized identity authentication system; the character "Y" in the third character position is the dependent representation character, and its corresponding mapping representation character is "L"; for the target IoT device, assuming the generated initial decentralized authentication identifier is "12574675iuyi", the character in the third character position is "5"; in this initial decentralized authentication identifier, in the associated decentralized authentication identifier "12Y4567iuyu", the third... The character position corresponds to the character position of the dependency representation character. In the initial decentralized authentication identifier "12574675iuyi", the target position mapped to this character position should also be the third character position (that is, the character position of the dependency representation character in the associated decentralized authentication identifier should be the same as the character position of the mapped representation character in the initial decentralized authentication identifier). Therefore, the character "5" at the third character position in the initial decentralized authentication identifier "12574675iuyi" can be replaced with the mapped representation character "L", thus obtaining the final target decentralized authentication identifier "12L74675iuyi". It can be understood that the "L" at the third character position in the target decentralized authentication identifier "12L74675iuyi" and the "Y" at the third character position in the associated decentralized authentication identifier "12Y4567iuyu" can jointly represent that the corresponding target IoT device and the associated IoT device have an operational dependency relationship.
[0133] It should be noted that the dependency representation character and the mapping representation character mentioned above can be the same character. The dependency representation character "Y" and the mapping representation character "L" illustrated above are different characters, but they are only examples and do not have any practical reference significance. At the same time, the character position of the dependency representation character in the associated decentralized authentication identifier and the character position of the mapping representation character in the initial decentralized authentication identifier "12574675iuyi" can also be different characters. The two character positions illustrated above are the same and are only examples for ease of understanding.
[0134] Furthermore, when an IoT device malfunctions, its decentralized authentication identifier can be used to obtain associated decentralized authentication identifiers, and then the shared operational data of associated IoT devices can be obtained. Based on the shared operational data of the IoT device and the associated IoT devices, the specific IoT device that malfunctioned can be identified. Taking the malfunction of a target IoT device as an example, the specific application process is described below. The specific method may include: obtaining an anomaly handling request initiated by the device user for the target IoT device; wherein the device query object includes the device user, and the anomaly handling request includes the target decentralized authentication identifier; based on the target decentralized authentication identifier, shared operational data can be obtained from the blockchain; based on the mapping representation characters in the target decentralized authentication identifier, associated IoT devices with operational dependencies on the target IoT device can be obtained; based on the associated decentralized authentication identifiers of the associated IoT devices, associated operational data of the associated IoT devices can be obtained from the blockchain; based on the shared operational data and associated operational data, the abnormal IoT device can be identified among the target IoT device and associated IoT devices, and abnormal maintenance processing can be performed on the abnormal IoT device; an abnormal IoT device refers to an IoT device whose operating state is abnormal.
[0135] In this embodiment, each IoT device (e.g., the target IoT device) can be assigned a decentralized authentication identifier (e.g., the target decentralized authentication identifier) indicated by its decentralized identity authentication system (e.g., the target decentralized identity authentication system). This decentralized authentication identifier can be used to uniquely identify each IoT device. After the decentralized authentication identifier is uploaded to the blockchain, the blockchain's unforgeability and tamper-proof nature can significantly improve the security of the decentralized authentication identifier. Furthermore, the shared operational data of IoT devices can only be uploaded to the blockchain through this decentralized authentication identifier, enhancing its credibility and security. Device query targets (objects with viewing permissions for IoT devices) can also query based on this decentralized authentication identifier, allowing for verification of data credibility from the source. In summary, this application, by combining IoT devices with a decentralized identity authentication system, assigning a decentralized authentication identifier to each IoT device through the identifier generation rules indicated by the decentralized identity authentication system, and then uploading the decentralized authentication identifier to the blockchain, can significantly improve the security of IoT device identifiers, thereby enhancing the security of IoT device data. Meanwhile, identifying and associating IoT devices with operational dependencies allows for rapid detection of these IoT devices through decentralized authentication identifiers when an IoT device malfunctions, thus improving detection efficiency.
[0136] Further, please see Figure 5 , Figure 5 This is a system flowchart provided in an embodiment of this application. For example... Figure 5 As shown, the process may include at least the following steps S21-S30:
[0137] Step S21: The device production object sends a request to the DID backend server to register the device.
[0138] Specifically, taking the above request initiator as the device generation object as an example, in reality, the request to send the device registration request to the DID backend server can be initiated by an object that owns the IoT device.
[0139] Step S22: The DID backend server assigns cid and identifier generation rules to the device production object.
[0140] Specifically, CID here can refer to a decentralized identity authentication system, which may include information used to identify the system, such as the system name and system number.
[0141] Step S23: The device production object assigns a DID identifier to the device according to the cid and the identifier generation rules, and embeds the private key corresponding to the DID identifier into the IoT device.
[0142] Specifically, the device corresponding to the device production object (such as a terminal device) can be assigned a DID identifier according to the CID and identifier generation rules, and the private key corresponding to the DID identifier can be embedded into the IoT device. For details on its implementation, please refer to the above. Figure 2 The descriptions in the corresponding embodiments will not be repeated here.
[0143] Step S24: The device manufacturer initiates a registration request for the DID identifier of the IoT device to the DID backend server.
[0144] Specifically, the registration request for this DID identifier is mainly used to request that the DID identifier be registered on the blockchain.
[0145] Step S25: The DID backend server initiates a registration request to the blockchain for the DID identifier of the IoT device.
[0146] Specifically, the DID backend server can forward the registration request to the blockchain, which can then register the DID identifier and save the DID document for that identifier.
[0147] Step S26: The blockchain sends a notification to the DID backend server that the DID identifier has been successfully added to the blockchain.
[0148] Step S27: The DID backend server returns a notification to the device production object that the DID identifier has been successfully added to the blockchain.
[0149] In step S28, the device manufacturer sends publicly available operational data of the IoT device, along with a digital signature, to the blockchain.
[0150] Specifically, the device manufacturer can sign the publicly available operational data of the IoT device based on the private key corresponding to the DID identifier, and send the publicly available operational data and digital signature to the blockchain together.
[0151] Step S29: After the blockchain successfully verifies the digital signature, it clears the publicly available data of the IoT device to the SPV of the designated physical network device.
[0152] Specifically, the SPV here can refer to a light node (or data node) in the blockchain, primarily used to provide business services to device application objects (or device query objects, which can be understood as objects with access rights to physical network devices, including device users, device manufacturers, etc.). The SPV here can also refer to a node in the blockchain primarily used to store data for a specific physical network device.
[0153] In step S30, the backend server of the device application object pulls the running data from the SPV.
[0154] Specifically, when a device application wants to obtain the operating data of an IoT device, it can obtain the operating data from the SPV node through the backend server (such as the backend server corresponding to the target application, which can also be the data node corresponding to the device application) and perform statistics on the device's operating status.
[0155] For the specific implementation of steps S21-S30, please refer to the above. Figures 2-4 The descriptions in the corresponding embodiments will not be repeated here.
[0156] In this embodiment, each IoT device (e.g., the target IoT device) can be assigned a decentralized authentication identifier (e.g., the target decentralized authentication identifier) indicated by its decentralized identity authentication system (e.g., the target decentralized identity authentication system). This decentralized authentication identifier can be used to uniquely identify each IoT device. After the decentralized authentication identifier is uploaded to the blockchain, the blockchain's unforgeability and tamper-proof nature can significantly improve the security of the decentralized authentication identifier. Furthermore, the shared operational data of IoT devices can only be uploaded to the blockchain through this decentralized authentication identifier, enhancing its credibility and security. Device query targets (objects with viewing permissions for IoT devices) can also query based on this decentralized authentication identifier, allowing for verification of data credibility from the source. In summary, this application, by combining IoT devices with a decentralized identity authentication system, assigning a decentralized authentication identifier to each IoT device through the identifier generation rules indicated by the decentralized identity authentication system, and then uploading the decentralized authentication identifier to the blockchain, can significantly improve the security of IoT device identifiers, thereby enhancing the security of IoT device data. Meanwhile, identifying and associating IoT devices with operational dependencies allows for rapid detection of these IoT devices through decentralized authentication identifiers when an IoT device malfunctions, thus improving detection efficiency.
[0157] Further, please see Figure 6 , Figure 6 This is a schematic diagram of the structure of a data processing apparatus provided in an embodiment of this application. The data processing apparatus can be a computer program (including program code) running on a computer device; for example, the data processing apparatus is an application software. The data processing apparatus can be used to execute... Figure 3 The method shown. (As illustrated) Figure 6 As shown, the data processing device 1 may include: an allocation request acquisition module 11, an identifier creation module 12, and an identifier uploading module 13.
[0158] The allocation request acquisition module 11 is used to acquire an identifier allocation request for a target IoT device. The identifier allocation request is used to request the allocation of a target decentralized authentication identifier indicated by the target decentralized identity authentication system for the target IoT device. The target decentralized identity authentication system is the decentralized identity authentication system corresponding to the request initiating object. The request initiating object refers to the object that initiates the identifier allocation request.
[0159] The identifier creation module 12 is used to create a target decentralized authentication identifier corresponding to the target IoT device according to the character type and number of characters contained in the target identifier generation rule; the target identifier generation rule refers to the identifier generation rule indicated by the target decentralized identity authentication system;
[0160] The on-chain identification module 13 is used to add the target decentralized authentication identifier to the blockchain; the target decentralized authentication identifier added to the blockchain is used by the device query object to obtain the shared operation data of the target IoT device from the blockchain based on the target decentralized authentication identifier; the device query object refers to the object that has the right to view the target IoT device.
[0161] The specific implementation methods of the allocation request acquisition module 11, the identifier creation module 12, and the identifier on-chain module 13 can be found in the above description. Figure 2 The descriptions of steps S101-S103 in the corresponding embodiments will not be repeated here.
[0162] In one embodiment, the data processing device 1 may further include: a registration request receiving module 14 and an authentication system determination module 15.
[0163] The registration request receiving module 14 is used to receive the identity registration request initiated by the request initiating object and send the identity registration request to the decentralized authentication server;
[0164] The authentication system determination module 15 is used to determine the decentralized identity authentication system corresponding to the request initiator based on the request response information returned by the decentralized authentication server. The request response information includes the target decentralized authentication system assigned by the decentralized authentication server to the request initiator, and the target identifier generation rule indicated by the target decentralized authentication system.
[0165] The specific implementation methods of the registration request receiving module 14 and the authentication system determination module 15 can be found in the above description. Figure 2 The description of step S101 in the corresponding embodiment will not be repeated here.
[0166] In one embodiment, the character type includes a first character type and a second character type, and the character quantity includes the first character quantity corresponding to the first character and the second character quantity corresponding to the second character type;
[0167] The identifier creation module 12 may include a string generation unit 121 and an identifier generation unit 122.
[0168] The string generation unit 121 is used to obtain the first string generation algorithm corresponding to the first character type in the target identifier generation rule, and generate the first string based on the first string generation algorithm, the first character type, and the first character count; the character type of the first string is the first character type, and the number of characters contained in the first string is the first character count;
[0169] The string generation unit 121 is also used to obtain the second string generation algorithm corresponding to the second character type in the target identifier generation rule, and generate the second string based on the second string generation algorithm, the second character type and the number of second characters; the character type of the second string is the second character type, and the number of characters contained in the second string is the number of second characters;
[0170] The identifier generation unit 122 is used to determine the target decentralized authentication identifier corresponding to the target IoT device based on the target identifier generation rule, the first string, and the second string.
[0171] The specific implementation methods of the string generation unit 121 and the identifier generation unit 122 can be found in the above description. Figure 2 The description of step S102 in the corresponding embodiment will not be repeated here.
[0172] In one embodiment, the identifier generation unit 122 may include: a character string acquisition subunit 1221, a sequence acquisition subunit 1222, and a character arrangement subunit 1223.
[0173] The characterization string acquisition subunit 1221 is used to obtain the identity characterization string contained in the target identifier generation rule; the identity characterization string is used to uniquely identify the target decentralized identity authentication system;
[0174] Sequential acquisition subunit 1222 is used to obtain the positional order of the identity representation string, the first string, and the second string as indicated by the target identifier generation rule;
[0175] The character arrangement subunit 1223 is used to arrange the identity representation string, the first string, and the second string in order according to their positions, and to determine the string sequence obtained by the arrangement as the target decentralized authentication identifier corresponding to the target IoT device.
[0176] The specific implementation methods of the string acquisition subunit 1221, the sequential acquisition subunit 1222, and the character arrangement subunit 1223 can be found in the above description. Figure 2 The description of step S102 in the corresponding embodiment will not be repeated here.
[0177] In one embodiment, the identifier generation unit 122 may include an associated identifier acquisition subunit 1224 and an identifier determination subunit 1225.
[0178] The associated identifier acquisition sub-unit 1224 is used to obtain the identity representation string contained in the target identifier generation rule; the identity representation string is used to uniquely identify the target decentralized identity authentication system;
[0179] The associated identifier acquisition subunit 1224 is also used to acquire the associated decentralized authentication identifier of the associated IoT device; the associated IoT device refers to an IoT device that has an operational dependency relationship with the target IoT device;
[0180] The associated identifier acquisition subunit 1224 is also used to obtain the dependency representation character in the associated decentralized authentication identifier; the dependency representation character is used to represent that there is an operational dependency relationship between the IoT device and the associated IoT device;
[0181] The identifier determination subunit 1225 is used to determine the target decentralized authentication identifier corresponding to the target IoT device based on the dependency representation character, the identity representation string, the first string, and the second string.
[0182] The specific implementation methods of the associated identifier acquisition subunit 1224 and the identifier determination subunit 1225 can be found in the above description. Figure 4 The descriptions of steps S201-S204 in the corresponding embodiments will not be repeated here.
[0183] In one embodiment, the identifier determination subunit 1225 is further specifically used to obtain the positional arrangement order of the identity representation string, the first string, and the second string as indicated by the target identifier generation rule;
[0184] The identifier determination subunit 1225 is also specifically used to arrange the identity representation string, the first string and the second string in order according to the position arrangement order, and determine the string sequence obtained by the arrangement as the initial decentralized authentication identifier;
[0185] The identifier determination subunit 1225 is also specifically used to obtain the character position of the dependent representation character in the associated decentralized authentication identifier, and to obtain the target position mapped by the character position in the initial decentralized authentication identifier;
[0186] The identifier determination subunit 1225 is also specifically used to obtain the mapping representation character corresponding to the dependency representation character, replace the character in the target position in the initial decentralized authentication identifier with the mapping representation character, and determine the replaced initial decentralized authentication identifier as the target decentralized authentication identifier; the mapping representation character in the target decentralized authentication identifier and the dependency representation character in the associated centralized authentication identifier are used to jointly represent the operational dependency relationship between the associated IoT device and the target IoT device; the device query object also has the right to view the associated IoT device.
[0187] In one embodiment, the identifier generation unit 122 may further include: a request processing acquisition subunit 1226, a running data acquisition subunit 1227, and an exception maintenance subunit 1228.
[0188] The request acquisition subunit 1226 is used to acquire the exception handling request initiated by the device user for the target IoT device; the device query object includes the device user, and the exception handling request includes the target decentralized authentication identifier;
[0189] The runtime data acquisition subunit 1227 is used to acquire shared runtime data from the blockchain based on the target decentralized authentication identifier;
[0190] The running data acquisition subunit 1227 is also used to acquire associated IoT devices that have a running dependency relationship with the target IoT device based on the mapping representation characters in the target decentralized authentication identifier, and to acquire associated running data of the associated IoT devices from the blockchain based on the associated decentralized authentication identifier of the associated IoT devices.
[0191] The abnormal maintenance subunit 1228 is used to identify abnormal IoT devices among the target IoT devices and associated IoT devices based on shared operation data and associated operation data, and to perform abnormal maintenance on the abnormal IoT devices; abnormal IoT devices refer to IoT devices whose operating status is abnormal.
[0192] The specific implementation methods of the request acquisition subunit 1226, the runtime data acquisition subunit 1227, and the exception maintenance subunit 1228 can be found in the above description. Figure 4 The description of step S204 in the corresponding embodiment will not be repeated here.
[0193] In one embodiment, the data processing device 1 may further include: a shared data acquisition module 16, a block generation module 17, and a block on-chain module 18.
[0194] The shared data acquisition module 16 is used to acquire shared operational data sent by the data node for the target IoT device; the data node is the business node corresponding to the device user, and the device user refers to the object using the target IoT device.
[0195] Block generation module 17 generates target blocks based on shared runtime data;
[0196] Block-on-chain module 18 is used to add target blocks to the blockchain based on the target decentralized authentication identifier.
[0197] The specific implementation methods of the shared data acquisition module 16, the block generation module 17, and the block on-chain module 18 can be found in the above description. Figure 2 The description of step S103 in the corresponding embodiment will not be repeated here.
[0198] In one embodiment, the block on-chain module 18 may include: a block signature unit 181, a signature verification unit 182, and a block consensus unit 183.
[0199] Block signing unit 181 is used to sign the target block based on the private key corresponding to the target decentralized authentication identifier to obtain the block digital signature;
[0200] The signature verification unit 182 is used to send the target block and the block digital signature to the consensus node of the blockchain, so that the consensus node can obtain the public key corresponding to the target decentralized authentication identifier, verify the block digital signature based on the public key corresponding to the target decentralized authentication identifier, and reach consensus on the target block after the signature verification is successful.
[0201] Block consensus unit 183 is used to receive voting information returned by consensus nodes; the voting information is determined by the consensus nodes when the digital signature of the block is verified.
[0202] Block consensus unit 183 is also used to determine the consensus result of the target block based on voting information;
[0203] Block consensus unit 183 is also used to add the target block to the blockchain when the consensus result of the target block is a consensus pass result.
[0204] The specific implementation methods of the block signature unit 181, the signature verification unit 182, and the block consensus unit 183 can be found in the above. Figure 2 The description of step S103 in the corresponding embodiment will not be repeated here.
[0205] In one embodiment, the number of consensus nodes is at least two, and the number of voting messages is at least two.
[0206] Block consensus unit 183 may include: quantity statistics subunit 1831 and result determination subunit 1832.
[0207] The quantity statistics subunit 1831 is used to determine the voting information with the voting type of "pass" from at least two voting information as the voting pass information;
[0208] The quantity statistics subunit 1831 is also used to obtain the total number of nodes corresponding to the consensus nodes, as well as the number of passes corresponding to the voting pass information;
[0209] The result determination subunit 1832 is used to determine the consensus result of the target block based on the number of passes and the total number of nodes.
[0210] The specific implementation methods of the quantity statistics subunit 1831 and the result determination subunit 1832 can be found in the above. Figure 2The description of step S103 in the corresponding embodiment will not be repeated here.
[0211] In one embodiment, the request initiating object is the object that produces the target IoT device;
[0212] The data processing device 1 may further include: a query request acquisition module 19, a device status determination module 21, and a maintenance processing module 22.
[0213] The request retrieval module 19 is used to retrieve status retrieval requests initiated by the request initiator for the target IoT device during the device detection time period; the status retrieval request includes the target decentralized authentication identifier;
[0214] Device status determination module 21 is used to obtain shared operating data of the target IoT device from the blockchain based on the target decentralized authentication identifier in the status query request;
[0215] The device status determination module 21 is also used to determine the device operating status of the target IoT device based on shared operating data and send the device operating status to the request initiating object;
[0216] Maintenance processing module 22 is used to receive device processing information returned by the request initiator based on the device operating status;
[0217] The maintenance processing module 22 is also used to perform device maintenance processing on the target IoT device based on the device processing information.
[0218] For details on the implementation of the query request acquisition module 19, the device status determination module 21, and the maintenance processing module 22, please refer to the above. Figure 2 The description of step S103 in the corresponding embodiment will not be repeated here.
[0219] In one embodiment, the maintenance processing module 22 may include a feedback prompting unit 221 and an equipment repair unit 222.
[0220] The feedback prompting unit 221 is used to generate device feedback prompting information and send it to the device user if the device is in normal operating state and the device processing information is the processing information returned by the request initiating object based on the normal operating state. The device feedback prompting information is used to prompt the device user to provide feedback to the request initiating object on improvement information for the target IoT device.
[0221] The equipment maintenance unit 222 is used to generate equipment maintenance prompt information based on the maintenance time period if the equipment is in an abnormal operating state and the equipment processing information is the processing information returned by the request initiating object based on the abnormal operating state, and send the equipment maintenance prompt information to the device user; the equipment maintenance prompt information is used to remind the target IoT device that it should be maintained within the maintenance time period.
[0222] The specific implementation methods of the feedback prompting unit 221 and the equipment maintenance unit 222 can be found in the above description. Figure 2 The description of step S103 in the corresponding embodiment will not be repeated here.
[0223] In one embodiment, the request is initiated by an object that owns the target IoT device;
[0224] The data processing device 1 may further include: a transfer request acquisition module 23, a request forwarding module 24, a message receiving module 25, and an asset transfer module 26.
[0225] The transfer request acquisition module 23 is used to acquire the ownership transfer request for the target IoT device initiated by the request initiating object; the ownership transfer request is used to request the transfer of the device-related permissions of the target IoT device to the target object, and the request initiating object has the device usage rights of the target IoT device after the transfer of device-related permissions; the ownership transfer request carries the value of the requested virtual asset.
[0226] The request forwarding module 24 is used to send a property transfer request to the blockchain node in the blockchain; the blockchain node is used to assign access permissions for the target IoT device to the target object based on the property transfer request.
[0227] The message receiving module 25 is used to receive the property transfer confirmation message sent by the blockchain node. The property transfer confirmation message is sent by the target object, which has been granted access to the target IoT device, to the blockchain node when the virtual asset valuation of the target IoT device is determined based on the shared operation data and the virtual asset valuation is greater than or equal to the applied virtual asset value. The shared operation data is obtained by the target object from the blockchain through the target decentralized authentication identifier.
[0228] The asset transfer module 26 is used to send asset transfer information to the target object based on the property transfer confirmation message; the asset transfer information is used to prompt the target object to transfer the virtual asset data corresponding to the applied virtual asset value to the account corresponding to the requesting object.
[0229] The specific implementation methods of the transfer request acquisition module 23, request forwarding module 24, message receiving module 25, and asset transfer module 26 can be found in the above description. Figure 2 The description of step S103 in the corresponding embodiment will not be repeated here.
[0230] In this embodiment, by combining IoT devices with a decentralized identity authentication system, and assigning a decentralized authentication identifier to each IoT device according to the identifier generation rules indicated by the decentralized identity authentication system, and then uploading the decentralized authentication identifier to the blockchain, the security of the IoT device's identity identifier can be significantly improved, thereby enhancing the security of the IoT device's data. Simultaneously, associating IoT devices with operational dependencies with their identifiers allows for rapid detection of these IoT devices when an anomaly occurs in an IoT device, improving detection efficiency.
[0231] Further, please see Figure 7 , Figure 7 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 7 As shown above, Figure 6 The data processing device 1 in the corresponding embodiment can be applied to the aforementioned computer device 8000. The computer device 8000 may include a processor 8001, a network interface 8004, and a memory 8005. Furthermore, the computer device 8000 also includes a user interface 8003 and at least one communication bus 8002. The communication bus 8002 is used to enable communication between these components. The user interface 8003 may include a display screen and a keyboard; optionally, the user interface 8003 may also include a standard wired interface or a wireless interface. The network interface 8004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 8005 may be high-speed RAM or non-volatile memory, such as at least one disk storage device. Optionally, the memory 8005 may also be at least one storage device located remotely from the aforementioned processor 8001. Figure 7 As shown, the memory 8005, which is a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a device control application program.
[0232] exist Figure 7 In the computer device 8000 shown, the network interface 8004 provides network communication functionality; the user interface 8003 is mainly used to provide an input interface for the user; and the processor 8001 can be used to call the device control application program stored in the memory 8005 to achieve:
[0233] Obtain an identifier allocation request for the target IoT device; the identifier allocation request is used to request the allocation of a target decentralized authentication identifier as indicated by the target decentralized identity authentication system for the target IoT device; the target decentralized identity authentication system is the decentralized identity authentication system corresponding to the request initiating object; the request initiating object refers to the object that initiates the identifier allocation request;
[0234] Create a target decentralized authentication identifier corresponding to the target IoT device according to the character type and number of characters contained in the target identifier generation rule; the target identifier generation rule refers to the identifier generation rule indicated by the target decentralized identity authentication system;
[0235] Add the target decentralized authentication identifier to the blockchain; the target decentralized authentication identifier added to the blockchain is used by the device query object to obtain the shared operation data of the target IoT device from the blockchain based on the target decentralized authentication identifier; the device query object refers to the object that has the right to view the target IoT device.
[0236] It should be understood that the computer device 8000 described in the embodiments of this application can execute the foregoing text. Figures 3 to 4 The description of the data processing method in the corresponding embodiment can also be performed as described above. Figure 6 The description of the data processing apparatus 1 in the corresponding embodiments will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated here.
[0237] Furthermore, it should be noted that this application embodiment also provides a computer-readable storage medium, which stores a computer program executed by the aforementioned data processing computer device 8000. The computer program includes program instructions, and when the processor executes the program instructions, it can execute the aforementioned... Figures 3 to 4 The description of the data processing method in the corresponding embodiments is already provided and will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the computer-readable storage medium embodiments related to this application, please refer to the description of the method embodiments of this application.
[0238] The aforementioned computer-readable storage medium can be an internal storage unit of the data processing apparatus or computer device provided in any of the foregoing embodiments, such as a hard disk or memory of the computer device. The computer-readable storage medium can also be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device. Furthermore, the computer-readable storage medium can include both internal and external storage units of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.
[0239] One aspect of this application provides a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method provided in one aspect of the embodiments of this application.
[0240] The terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other step units inherent to these processes, methods, apparatuses, products, or devices.
[0241] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0242] The methods and related apparatus provided in this application are described with reference to the method flowcharts and / or structural diagrams provided in this application. Specifically, each block of the method flowchart and / or structural diagram, as well as combinations of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to create a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing device, generate instructions for implementing the process. Figure 1 A schematic diagram of one or more processes and / or structures. Figure 1 The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process. Figure 1 A schematic diagram of one or more processes and / or structures. Figure 1 The functions specified in one or more boxes. These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable apparatus for implementing the process. Figure 1 A process or multiple processes and / or structures illustrate the steps of the functions specified in one or more boxes.
[0243] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.
Claims
1. A data processing method, characterized in that, include: Obtain an identifier allocation request for a target IoT device; the identifier allocation request is used to request the allocation of a target decentralized authentication identifier indicated by a target decentralized identity authentication system for the target IoT device; the target decentralized identity authentication system is the decentralized identity authentication system corresponding to the request initiating object; The request initiating object refers to the object that initiates the identifier allocation request; According to the character types and character counts included in the target identifier generation rule, a target decentralized authentication identifier corresponding to the target IoT device is created; the target identifier generation rule refers to the identifier generation rule indicated by the target decentralized identity authentication system; wherein, the character type includes a first character type and a second character type, and the character count includes the first character count corresponding to the first character type and the second character count corresponding to the second character type; the step of creating the target decentralized authentication identifier corresponding to the target IoT device according to the character types and character counts included in the target identifier generation rule includes: obtaining a first string generation algorithm corresponding to the first character type in the target identifier generation rule, and generating an identifier based on the first string. The algorithm, the first character type, and the first character count are used to generate a first string; the character type of the first string is the first character type, and the number of characters contained in the first string is the first character count; the algorithm for generating a second string corresponding to the second character type in the target identifier generation rule is obtained, and a second string is generated based on the second string generation algorithm, the second character type, and the second character count; the character type of the second string is the second character type, and the number of characters contained in the second string is the second character count; the target decentralized authentication identifier corresponding to the target IoT device is determined according to the target identifier generation rule, the first string, and the second string; The target decentralized authentication identifier is added to the blockchain; the target decentralized authentication identifier added to the blockchain is used by the device query object to obtain the shared operation data of the target IoT device from the blockchain based on the target decentralized authentication identifier; the device query object refers to the object that has the right to view the target IoT device; The step of determining the target decentralized authentication identifier corresponding to the target IoT device based on the target identifier generation rule, the first string, and the second string includes: obtaining an identity representation string contained in the target identifier generation rule; the identity representation string is used to uniquely identify the target decentralized identity authentication system; obtaining an associated decentralized authentication identifier of an associated IoT device; the associated IoT device refers to an IoT device that has an operational dependency relationship with the target IoT device; obtaining a dependency representation character from the associated decentralized authentication identifier; the dependency representation character is used to indicate that there is an operational dependency relationship between the IoT device and the associated IoT device; and determining the target decentralized authentication identifier corresponding to the target IoT device based on the dependency representation character, the identity representation string, the first string, and the second string.
2. The method according to claim 1, characterized in that, The method further includes: Receive the identity registration request initiated by the request initiating object, and send the identity registration request to the decentralized authentication server; Based on the request response information returned by the decentralized authentication server, the decentralized identity authentication system corresponding to the request initiating object is determined; the request response information includes the target decentralized authentication system assigned by the decentralized authentication server to the request initiating object, and the target identifier generation rule indicated by the target decentralized authentication system.
3. The method according to claim 1, characterized in that, The step of determining the target decentralized authentication identifier corresponding to the target IoT device based on the target identifier generation rule, the first string, and the second string includes: Obtain the identity representation string contained in the target identifier generation rule; the identity representation string is used to uniquely identify the target decentralized identity authentication system; Obtain the positional order of the identity representation string, the first string, and the second string as indicated by the target identifier generation rule; The identity representation string, the first string, and the second string are arranged in order according to their positions, and the resulting string sequence is determined as the target decentralized authentication identifier corresponding to the target IoT device.
4. The method according to claim 1, characterized in that, The step of determining the target decentralized authentication identifier corresponding to the target IoT device based on the dependency representation character, the identity representation string, the first string, and the second string includes: Obtain the positional order of the identity representation string, the first string, and the second string as indicated by the target identifier generation rule; According to the positional order, the identity representation string, the first string, and the second string are arranged in sequence, and the resulting string sequence is determined as the initial decentralized authentication identifier. Obtain the character position of the dependent representation character in the associated decentralized authentication identifier, and obtain the target position mapped by the character position in the initial decentralized authentication identifier; Obtain the mapping representation character corresponding to the dependency representation character, replace the character in the initial decentralized authentication identifier at the target position with the mapping representation character, and determine the replaced initial decentralized authentication identifier as the target decentralized authentication identifier; the mapping representation character in the target decentralized authentication identifier and the dependency representation character in the associated decentralized authentication identifier are used to jointly represent the operational dependency relationship between the associated IoT device and the target IoT device; the device query object also has the right to view the associated IoT device.
5. The method according to claim 4, characterized in that, The method further includes: Obtain the exception handling request initiated by the device user for the target IoT device; the device query object includes the device user, and the exception handling request includes the target decentralized authentication identifier; Based on the target decentralized authentication identifier, the shared operational data is obtained from the blockchain; Based on the mapping character in the target decentralized authentication identifier, obtain the associated IoT device that has an operational dependency relationship with the target IoT device; based on the associated decentralized authentication identifier of the associated IoT device, obtain the associated operational data of the associated IoT device from the blockchain. Based on the shared operational data and the associated operational data, abnormal IoT devices are identified among the target IoT devices and the associated IoT devices, and abnormal maintenance is performed on the abnormal IoT devices; the abnormal IoT devices refer to IoT devices whose operating status is abnormal.
6. The method according to claim 1, characterized in that, The method further includes: Acquire the shared operational data sent by the data node for the target IoT device; the data node is a business node corresponding to the device user, and the device user refers to the object using the target IoT device. A target block is generated based on the shared runtime data, and the target block is added to the blockchain based on the target decentralized authentication identifier.
7. The method according to claim 6, characterized in that, Adding the target block to the blockchain based on the target decentralized authentication identifier includes: Based on the private key corresponding to the target decentralized authentication identifier, the target block is signed to obtain the block digital signature; The target block and its digital signature are sent to the consensus node of the blockchain, so that the consensus node can obtain the public key corresponding to the target decentralized authentication identifier, verify the digital signature of the block based on the public key corresponding to the target decentralized authentication identifier, and reach a consensus on the target block after the verification is successful. Receive voting information returned by the consensus node; the voting information is determined by the consensus node when the digital signature verification of the block is passed; Based on the voting information, the consensus result of the target block is determined. When the consensus result of the target block is a consensus pass, the target block is added to the blockchain.
8. The method according to claim 7, characterized in that, The number of consensus nodes is at least two, and the number of voting information is at least two. The consensus result for determining the target block based on the voting information includes: Among at least two sets of voting information, those with the voting type "pass" are identified as passing voting information; Obtain the total number of nodes corresponding to the consensus node, and the number of passes corresponding to the vote pass information; The consensus result of the target block is determined based on the number of passes and the total number of nodes.
9. The method according to claim 1, characterized in that, The request is initiated by the object that produces the target IoT device. The method further includes: During the device detection period, obtain the status query request initiated by the request initiator for the target IoT device; the status query request includes the target decentralized authentication identifier; Based on the target decentralized authentication identifier in the status query request, the shared operating data of the target IoT device is obtained from the blockchain; Based on the shared operational data, the device operating status of the target IoT device is determined, and the device operating status is sent to the request initiating object; The system receives device processing information returned by the request initiator based on the device's operating status, and performs device maintenance on the target IoT device based on the device processing information.
10. The method according to claim 9, characterized in that, The step of performing device maintenance on the target IoT device based on the device processing information includes: If the device is in normal operating status, and the device processing information is the processing information returned by the request initiating object based on the normal operating status, then device feedback prompt information is generated and sent to the device user; the device feedback prompt information is used to prompt the device user to provide feedback to the request initiating object on improvement information for the target IoT device; If the device is in an abnormal operating state, and the device processing information is the processing information returned by the request initiating object based on the abnormal operating state, then a device maintenance prompt message is generated according to the maintenance time period, and the device maintenance prompt message is sent to the device user; the device maintenance prompt message is used to remind the target IoT device that it should be maintained within the maintenance time period.
11. The method according to claim 1, characterized in that, The request is initiated by an object that owns the target IoT device. The method further includes: The system retrieves a property transfer request for the target IoT device initiated by the request initiating object; the property transfer request is used to request the transfer of device-related permissions of the target IoT device to the target object, and the request initiating object has the device usage permissions of the target IoT device after the transfer of device-related permissions; the property transfer request carries the value of the requested virtual asset. The ownership transfer request is sent to a blockchain node in the blockchain; the blockchain node is used to assign access permissions for the target IoT device to the target object based on the ownership transfer request; The system receives a property transfer confirmation message sent by the blockchain node. This message is sent by the target object, which has been granted access to the target IoT device, after determining the virtual asset valuation for the target IoT device based on the shared operational data, and when the virtual asset valuation is greater than or equal to the requested virtual asset value. The shared operational data is obtained by the target object from the blockchain using the target decentralized authentication identifier. Based on the property transfer confirmation message, asset transfer information is sent to the target object; the asset transfer information is used to prompt the target object to transfer the virtual asset data corresponding to the applied virtual asset value to the account corresponding to the request initiator.
12. A data processing apparatus, characterized in that, include: The allocation request acquisition module is used to acquire an identifier allocation request for a target IoT device; the identifier allocation request is used to request the allocation of a target decentralized authentication identifier indicated by a target decentralized identity authentication system for the target IoT device; the target decentralized identity authentication system is the decentralized identity authentication system corresponding to the request initiating object; The request initiating object refers to the object that initiates the identifier allocation request; An identifier creation module is used to create a target decentralized authentication identifier corresponding to the target IoT device according to the character type and character quantity contained in the target identifier generation rule; the target identifier generation rule refers to the identifier generation rule indicated by the target decentralized identity authentication system; wherein, the character type includes a first character type and a second character type, and the character quantity includes the first character quantity corresponding to the first character type and the second character quantity corresponding to the second character type; the step of creating the target decentralized authentication identifier corresponding to the target IoT device according to the character type and character quantity contained in the target identifier generation rule includes: obtaining a first string generation algorithm corresponding to the first character type in the target identifier generation rule, and based on the first... A first string is generated based on a string generation algorithm, the first character type, and the first character count; the character type of the first string is the first character type, and the number of characters contained in the first string is the first character count; a second string is generated based on the second string generation algorithm, the second character type, and the second character count; the character type of the second string is the second character type, and the number of characters contained in the second string is the second character count; and the target decentralized authentication identifier corresponding to the target IoT device is determined according to the target identifier generation rule, the first string, and the second string. The on-chain identification module is used to add the target decentralized authentication identifier to the blockchain; the target decentralized authentication identifier added to the blockchain is used by the device query object to obtain the shared operation data of the target IoT device from the blockchain based on the target decentralized authentication identifier; the device query object refers to the object with viewing permission for the target IoT device; The step of determining the target decentralized authentication identifier corresponding to the target IoT device based on the target identifier generation rule, the first string, and the second string includes: obtaining an identity representation string contained in the target identifier generation rule; the identity representation string is used to uniquely identify the target decentralized identity authentication system; obtaining an associated decentralized authentication identifier of an associated IoT device; the associated IoT device refers to an IoT device that has an operational dependency relationship with the target IoT device; obtaining a dependency representation character from the associated decentralized authentication identifier; the dependency representation character is used to indicate that there is an operational dependency relationship between the IoT device and the associated IoT device; and determining the target decentralized authentication identifier corresponding to the target IoT device based on the dependency representation character, the identity representation string, the first string, and the second string.
13. A computer device, characterized in that, include: Processor, memory, and network interface; The processor is connected to the memory and the network interface, wherein the network interface is used to provide network communication functions, the memory is used to store computer programs, and the processor is used to call the computer programs to cause the computer device to execute the method according to any one of claims 1-11.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded by a processor and to execute the method according to any one of claims 1-11.
15. A computer program product, characterized in that, The computer program product includes a computer program stored in a computer-readable storage medium, the computer program being adapted to be read and executed by a processor to cause a computer device having the processor to perform the method of any one of claims 1-11.
Citation Information
Patent Citations
Method for realizing Internet of Things service, application server, Internet of Things device and medium
CN110086755A
Method and device for allocating identifiers based on smart contract
CN112270160A