A blockchain-based data processing method, device, and readable storage medium
Patent Information
- Application Number
- CN202211259133.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-14
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2042-10-14
AI Technical Summary
明显地,现有技术存在如下缺陷:1、平台应用将自己的原始数据(即第一业务数据)传输至广告商,故降低了数据的安全性;2,平台应用与广告商之间直接的数据流转,致使无法准确地追溯数据获取状态
[0088]在本申请实施例中,通过生成第一业务数据对应的第一位数组,可以确保第一业务数据可用不可见,故可以提高第一业务数据的安全性;进一步地,由于数据密钥是通过可信执行环境a中的数据交集应用所生成的,故其生成环境安全、应用环境安全以及存储环境安全,故通过数据密钥对第一位数组进行加密处理,可以提高第一位数组的安全性;进一步地,通过将密文位数组传输至区块链,可以准确地追溯第二设备针对密文位数组的获取状态;此外,本申请实施例是通过第一位数组以及第二业务数据对应的第二位数组,确定第一业务数据以及第二业务数据之间的业务交集数据,故不仅可以进行与业务交集数据相关联的业务处理,还进一步提高了第一业务数据的安全性。上述可知,采用本申请实施例,可以提高数据(包括第一业务数据以及第一位数组)的安全性,以及准确地追溯数据获取状态。
Smart Images

Figure CN117938406B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet technology, and in particular to a data processing method, device and readable storage medium based on blockchain. Background Technology
[0002] With the rapid development of mobile internet technology and various emerging technologies, platform applications have sprung up like mushrooms after rain. With the emergence of numerous platform applications, users have a wider range of choices. To improve user activity and retention, platform applications need to continuously promote themselves.
[0003] In existing technologies, platform applications, in order to promote themselves, collaborate with advertisers who possess strong platform promotion capabilities. Specifically, the platform application provides its initial business data to the advertiser, who then identifies common business data between its initial and secondary business data—the business intersection data—and performs promotional processing associated with this intersection data. Clearly, existing technologies have the following drawbacks: 1. The platform application transmits its raw data (i.e., the initial business data) to the advertiser, thus reducing data security; 2. The direct data flow between the platform application and the advertiser makes it impossible to accurately trace the data acquisition status. Summary of the Invention
[0004] This application provides a blockchain-based data processing method, device, and readable storage medium, which can improve data security and accurately trace the data acquisition status.
[0005] One embodiment of this application provides a blockchain-based data processing method, which is executed by a first device and includes:
[0006] If the first business data meets the data upload conditions, then the first element array corresponding to the first business data is generated;
[0007] The first bit array is encrypted using the data key generated by the second device in the data intersection application to obtain the ciphertext bit array; the data intersection application runs in the trusted execution environment a of the second device;
[0008] The ciphertext bit array is transmitted to a blockchain node in the blockchain so that the blockchain node stores the ciphertext bit array; the ciphertext bit array stored in the blockchain node is used by the blockchain node to forward to a second device; the second device is used in the data intersection application to decrypt the ciphertext bit array obtained from the blockchain node using a data key to obtain a first bit array; the first bit array is used to instruct the second device in the data intersection application to generate a second bit array corresponding to the second business data; the second bit array and the first bit array are used to instruct the second device in the data intersection application to determine the business intersection data between the first business data and the second business data; the business intersection data is used to instruct the second device to perform business processing associated with the business intersection data.
[0009] One embodiment of this application provides a blockchain-based data processing method, which is executed by a second device and includes:
[0010] Obtain the ciphertext bit array forwarded by the blockchain node in the blockchain; the ciphertext bit array is transmitted from the first device to the blockchain node, and the ciphertext bit array is obtained by the first device encrypting the first bit array with the data key generated by the second device in the data intersection application; the data intersection application runs in the trusted execution environment a of the second device; the first bit array is generated by the first device for the first business data when the first business data meets the data upload conditions;
[0011] In data intersection applications, the ciphertext bit array obtained from the blockchain node is decrypted using the data key to obtain the first bit array;
[0012] In the data intersection application, a second bit array corresponding to the second business data is generated. Based on the second bit array and the first bit array, the business intersection data between the first business data and the second business data is determined.
[0013] Perform business processing on data that intersects with business operations.
[0014] One embodiment of this application provides a blockchain-based data processing device, which operates on a first device and includes:
[0015] The first generation module is used to generate the first array corresponding to the first business data if the first business data meets the data upload conditions.
[0016] The first processing module is used to encrypt the first bit array using the data key generated by the second device in the data intersection application to obtain the ciphertext bit array; the data intersection application runs in the trusted execution environment a of the second device.
[0017] The encrypted transmission module transmits the encrypted bit array to the blockchain node in the blockchain so that the blockchain node stores the encrypted bit array. The encrypted bit array stored in the blockchain node is forwarded by the blockchain node to the second device. The second device is used to decrypt the encrypted bit array obtained from the blockchain node using a data key in the data intersection application to obtain the first bit array. The first bit array is used to instruct the second device to generate the second bit array corresponding to the second business data in the data intersection application. The second bit array and the first bit array are used to instruct the second device to determine the business intersection data between the first business data and the second business data in the data intersection application. The business intersection data is used to instruct the second device to perform business processing associated with the business intersection data.
[0018] The blockchain-based data processing device also includes:
[0019] The second generation module is used to generate a topic for the first business data and generate a topic publishing request that includes the topic and topic publishing object information.
[0020] The second processing module is used to sign the topic publishing request using the device private key corresponding to the first device to obtain a signed message z, and then call the topic publishing contract of the blockchain node based on the topic publishing request.
[0021] The request sending module is used to send a topic publishing request carrying a signature message z to the blockchain node through a topic publishing contract, so that the blockchain node calls the topic publishing contract when it passes the legality verification of the topic publishing request; the topic publishing contract is used to instruct the blockchain node to store the topic when it verifies that the topic publishing object information belongs to the registered object information and determines that the topic has the attribute to be published; the topic stored in the blockchain node is used to instruct the second device to send a topic subscription request to the blockchain node; the signature message z is used to instruct the blockchain node to verify the legality of the topic publishing request;
[0022] The request retrieval module is used to retrieve the topic subscription requests forwarded by the blockchain node when it determines that the topic subscription request has the attribute of a valid request;
[0023] The relationship determination module is used to determine the relationship between the first business data and the data upload conditions based on the topic subscription requests forwarded by the blockchain nodes. The relationship between the first business data and the data upload conditions includes whether the first business data meets the data upload conditions or whether the first business data does not meet the data upload conditions.
[0024] The relationship determination module includes:
[0025] The first generation unit is used to generate remote authentication requests based on the topic subscription requests forwarded by the blockchain nodes;
[0026] The request sending unit is used to send a remote authentication request to the second device, so that the second device generates an intermediate key pair g including an intermediate public key f according to the remote authentication request; the intermediate public key f is used to instruct the second device to call the trusted execution environment a to generate a remote authentication report for the data intersection application;
[0027] The first acquisition unit is used to acquire the remote authentication report returned by the second device, and determine the relationship between the first business data and the data upload conditions based on the remote authentication report.
[0028] The first acquisition unit includes:
[0029] The report verification subunit is used to call the authentication service, verify the remote authentication report through the authentication service, and obtain the first verification result;
[0030] The first determining subunit is used to determine that the first business data does not meet the data upload conditions if the first verification result indicates that the remote authentication report verification failed.
[0031] The second determining subunit is used to obtain the source code of the data intersection application if the first verification result indicates that the remote authentication report has passed verification, and determine the relationship between the first business data and the data upload conditions based on the source code.
[0032] The first acquisition unit further includes:
[0033] The third determining subunit is used to determine that the trusted execution environment a does not have environmental security attributes if the first verification result indicates that the remote authentication report verification failed.
[0034] The state sending subunit is used to generate a first update subscription state indicating that the trusted execution environment a does not have environment security attributes, and to send the first update subscription state to the blockchain node so that the blockchain node sets the first update subscription state for the topic subscription request.
[0035] The second determined subunit includes:
[0036] The first processing subunit is used to verify the source code and obtain the second verification result;
[0037] The second processing subunit is used to obtain the topic subscription object information for the data intersection application in the remote authentication report if the second verification result indicates that the source code verification is successful, perform verification processing on the topic subscription object information, and obtain the third verification result.
[0038] The third processing subunit is used to obtain the remote measurement value for the source code in the remote authentication report, perform verification processing on the remote measurement value, and obtain the fourth verification result.
[0039] The relationship determination subunit is used to determine the relationship between the first business data and the data upload conditions based on the third verification result and the fourth verification result;
[0040] The second processing subunit is also used to determine that the first business data does not meet the data upload conditions if the second verification result indicates that the source code verification failed.
[0041] The second determined subunit also includes:
[0042] The second processing subunit is also used to determine that the source code does not have code security attributes if the second verification result indicates that the source code verification failed.
[0043] The state generation subunit is used to generate a second update subscription state that indicates the source code does not have code security attributes, and sends the second update subscription state to the blockchain node so that the blockchain node sets the second update subscription state for the topic subscription request.
[0044] The second processing subunit is specifically used to obtain the application development object certificate for the data intersection application, obtain the application development object information from the application development object certificate, and compare the topic subscription object information with the application development object information.
[0045] The second processing subunit is also specifically used to generate a third verification result indicating that the verification of the topic subscription object information has failed if the topic subscription object information is different from the application development object information.
[0046] The second processing subunit is also specifically used to generate a third verification result indicating that the topic subscription object information has passed verification if the topic subscription object information is the same as the application development object information.
[0047] The second processing subunit is further specifically used to generate a third update subscription status to indicate that the topic subscription object information is unauthorized if the third verification result indicates that the verification of the topic subscription object information fails.
[0048] The second processing subunit is also specifically used to send the third update subscription state to the blockchain node so that the blockchain node sets the third update subscription state for the topic subscription request.
[0049] The third processing subunit is specifically used to compile the source code in the trusted execution environment b of the first device to obtain a trust measurement value.
[0050] The third processing subunit is also specifically used to compare the remote metric value with the trusted metric value. If the remote metric value and the trusted metric value are different, a fourth verification result is generated to indicate that the verification of the remote metric value has failed.
[0051] The third processing subunit is also specifically used to generate a fourth verification result to indicate that the remote metric value has passed verification if the remote metric value is the same as the trusted metric value.
[0052] The third processing subunit is also specifically used to generate a fourth update subscription state to indicate that the source code and the running code do not match if the fourth verification result indicates that the remote metric verification failed.
[0053] The third processing subunit is also specifically used to send the fourth update subscription state to the blockchain node so that the blockchain node sets the fourth update subscription state for the topic subscription request.
[0054] The relationship determination subunit is specifically used to determine that the first business data meets the data upload conditions if the third verification result indicates that the topic subscription object information has been verified and the fourth verification result indicates that the remote metric value has been verified.
[0055] The relationship determines the sub-unit, and is also specifically used to generate a fifth update subscription status to indicate that the topic subscription request has been verified if the first business data meets the data upload conditions;
[0056] The relationship determination subunit is also specifically used to send the fifth update subscription state to the blockchain node so that the blockchain node sets the fifth update subscription state for the topic subscription request.
[0057] The first generation unit includes:
[0058] The first generation subunit is used to generate an authentication challenge random number and an intermediate key pair j including an intermediate private key h and an intermediate public key i, based on the topic subscription request forwarded by the blockchain node.
[0059] The second generation subunit is used to generate a remote authentication request based on the intermediate public key i and the authentication challenge random number; the intermediate public key i is used to instruct the second device to generate a communication key based on the intermediate public key i, the authentication challenge random number and the intermediate private key k in the intermediate key pair g; the communication key is used to encrypt the data key to obtain an encrypted data key.
[0060] The first generating unit further includes:
[0061] The first acquisition subunit is used to acquire the intermediate public key f in the remote authentication report and generate a communication key based on the intermediate public key f, the authentication challenge random number and the intermediate private key h.
[0062] The second acquisition subunit is used to acquire the encrypted data key returned by the second device, and decrypt the encrypted data key using the communication key to obtain the data key.
[0063] The first generation module includes:
[0064] The second acquisition unit is used to acquire the initial bit array mapped with the first random number and the random mapping function, and input the first business data into the random mapping function;
[0065] The second generation unit is used to generate a second random number corresponding to the first business data through a random mapping function; the first random number includes the second random number.
[0066] The first determining unit is used to determine the bit array to be updated from the initial bit array; the bit array to be updated is mapped to a second random number;
[0067] The second determining unit is used to update the bit array to be updated in the initial bit array, and determine the updated initial bit array as the first bit array.
[0068] One embodiment of this application provides a blockchain-based data processing device, which operates on a second device and includes:
[0069] The ciphertext acquisition module is used to acquire the ciphertext bit array forwarded by the blockchain nodes in the blockchain; the ciphertext bit array is transmitted from the first device to the blockchain node, and the ciphertext bit array is obtained by the first device encrypting the first bit array with the data key generated by the second device in the data intersection application; the data intersection application runs in the trusted execution environment a of the second device; the first bit array is generated by the first device for the first business data when the first business data meets the data upload conditions;
[0070] The first processing module is used in data intersection applications to decrypt the ciphertext bit array obtained from the blockchain node using the data key to obtain the first bit array;
[0071] The first generation module is used to generate a second bit array corresponding to the second business data in the data intersection application, and determine the business intersection data between the first business data and the second business data based on the second bit array and the first bit array.
[0072] The second processing module is used to perform business processing on the data that intersects with the business data.
[0073] The ciphertext acquisition module includes:
[0074] The request generation unit is used to generate a data download request for obtaining the ciphertext bit array based on the topic subscription object information;
[0075] The request sending unit is used to send data download requests to the blockchain node, so that the blockchain node can query the current subscription status corresponding to the topic subscription object information based on the data download request;
[0076] The ciphertext acquisition unit is used to acquire the ciphertext bit array returned by the blockchain node when it determines that the current subscription state is the fifth update subscription state; the fifth update subscription state is used to indicate that the first device has passed the verification of the topic subscription request; the topic subscription request is sent when the blockchain node stores the topic for the first business data.
[0077] The second business data includes second business data C. d d is a positive integer, and d is less than or equal to the total number of second business data; the second bit array includes the second business data C. d The corresponding second array E d ;
[0078] The first generation module is specifically used when the first array includes the second array E. d Then determine the second business data C d This refers to the business intersection data between the first business data and the second business data.
[0079] The second processing module is specifically used to obtain media data with application recommendation function provided by the first device and push the media data to the second service data C. d .
[0080] The blockchain-based data processing device also includes:
[0081] The second generation module is used to generate a topic subscription request for subscribing to a topic based on the topic subscription object information; the topic is generated by the first device for the first business data;
[0082] The contract invocation module is used to invoke the subscription topic contract of the blockchain node based on the topic subscription request;
[0083] The request sending module is used to send a topic subscription request to the blockchain node through the topic subscription contract. When the blockchain node verifies that the topic has the attribute to be subscribed and that the topic subscription object information belongs to the registered object information through the topic subscription contract, it stores the topic subscription request and sets a request pending verification status for the topic subscription request. The request pending verification status is used to instruct the blockchain node to forward the topic subscription request to the first device.
[0084] This application provides a computer device, including: a processor, a memory, and a network interface;
[0085] The processor is connected to the memory and the network interface, wherein the network interface is used to provide data communication functions, the memory is used to store computer programs, and the processor is used to call the computer programs so that the computer device executes the methods in the embodiments of this application.
[0086] One aspect of this application provides a computer-readable storage medium storing a computer program adapted for loading by a processor and executing the methods described in this application.
[0087] One aspect of this application provides a computer program product, which includes a computer program stored in a computer-readable storage medium; a processor of a computer device reads the computer program from the computer-readable storage medium and executes the computer program, causing the computer device to perform the method described in this application.
[0088] In this embodiment, by generating the first bit array corresponding to the first business data, the first business data can be ensured to be available but not visible, thus improving its security. Furthermore, since the data key is generated through the data intersection application in the trusted execution environment a, its generation environment, application environment, and storage environment are all secure. Therefore, encrypting the first bit array with the data key further enhances its security. Moreover, by transmitting the ciphertext bit array to the blockchain, the acquisition status of the second device for the ciphertext bit array can be accurately traced. In addition, this embodiment determines the business intersection data between the first and second business data using the first bit array and the second bit array corresponding to the second business data. Therefore, not only can business processing associated with the business intersection data be performed, but the security of the first business data is further improved. As can be seen from the above, by adopting this embodiment, the security of data (including the first business data and the first bit array) can be improved, and the data acquisition status can be accurately traced. Attached Figure Description
[0089] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0090] Figure 1 This is a schematic diagram of a system architecture provided in an embodiment of this application;
[0091] Figure 2a This application provides an example of a blockchain-based data processing scenario. Figure 1 ;
[0092] Figure 2b This is a flowchart illustrating a blockchain-based object registration method provided in an embodiment of this application;
[0093] Figure 2c This is a schematic diagram of a data processing scenario based on blockchain provided in an embodiment of this application;
[0094] Figure 3 This is a flowchart illustrating a blockchain-based data processing method provided in an embodiment of this application. Figure 1 ;
[0095] Figure 4a This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 1 ;
[0096] Figure 4b This is a second timing diagram of a blockchain-based data processing method provided in an embodiment of this application;
[0097] Figure 4c This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 3 ;
[0098] Figure 4d This is a timing diagram (4) illustrating a blockchain-based data processing method provided in this application embodiment;
[0099] Figure 4e This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 5 ;
[0100] Figure 5 This is a second flowchart illustrating a blockchain-based data processing method provided in an embodiment of this application.
[0101] Figure 6a This is a timing diagram (six) illustrating a blockchain-based data processing method provided in an embodiment of this application.
[0102] Figure 6b This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 7 ;
[0103] Figure 6c This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 8 ;
[0104] Figure 7 This is a flowchart illustrating a blockchain-based data processing method provided in an embodiment of this application. Figure 3 ;
[0105] Figure 8 This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 9 ;
[0106] Figure 9 This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 10 ;
[0107] Figure 10 This is a schematic diagram of the structure of a blockchain-based data processing device provided in an embodiment of this application. Figure 1 ;
[0108] Figure 11 This is a second schematic diagram of the structure of a blockchain-based data processing device provided in an embodiment of this application;
[0109] Figure 12 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0110] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0111] To facilitate understanding, the following brief explanations are provided for some of the terms:
[0112] 1. Blockchain: In a narrow sense, blockchain is a chain-like data structure with blocks as the basic unit. Blocks use digital digests to verify previously obtained transaction history, making it suitable for the tamper-proof and scalable requirements of distributed ledger scenarios. In a broader sense, blockchain also refers to the distributed ledger technology implemented using the blockchain structure, including distributed consensus, privacy and security protection, peer-to-peer communication technology, network protocols, and smart contracts. The goal of blockchain is to implement a distributed data record ledger that only allows additions, not deletions. The underlying basic structure of the ledger is a linear linked list. The linked list consists of a series of "blocks," with each subsequent block recording the hash value of the previous block. The validity of each block (and the transactions within it) can be quickly verified by calculating the hash value. If a node in the network proposes to add a new block, the block must be confirmed through a consensus mechanism.
[0113] 2. Hash Value: Also known as an information feature value or characteristic value, a hash value is generated by converting input data of arbitrary length into cryptographic data and producing a fixed output using a hash algorithm. The original input data cannot be retrieved by decrypting the hash value; it is a one-way cryptographic function. In a blockchain, each block (except the initial block) contains the hash values of its predecessor blocks. The hash value is a core foundation and the most important aspect of blockchain technology, preserving the authenticity of recorded and viewed data, as well as the integrity of the blockchain as a whole.
[0114] 3. Blockchain Nodes: Blockchain networks divide nodes into consensus nodes (also known as core nodes) and synchronization nodes (which can include data nodes and light nodes). Consensus nodes are responsible for the consensus process across the entire blockchain network; synchronization nodes are responsible for synchronizing the ledger information of the consensus nodes, i.e., synchronizing the latest block data. Both consensus and synchronization nodes include network communication components in their internal structure, because a blockchain network is essentially a peer-to-peer (P2P) network, requiring communication with other nodes in the blockchain network through P2P components. Resources and services in the blockchain network are distributed across various nodes; information transmission and service implementation occur directly between nodes, without the need for intermediaries or centralized servers (third parties).
[0115] 4. Public Key and Private Key: A public key and a private key are a key pair (one public key and one private key) obtained through an algorithm. The public key is the publicly known part of the key pair, while the private key is the private key. Public keys are typically used for encrypting data, verifying digital signatures, etc. This algorithm ensures that the resulting key pair is unique. When using this key pair, if data is encrypted with one key, it must be decrypted with the other key. For example, if data is encrypted with the public key, it must be decrypted with the private key, and vice versa; otherwise, decryption will fail.
[0116] 5. Asymmetric Signature: A signature algorithm uses two keys: a public key and a private key. The public and private keys are a pair; if data is signed with the private key, only the corresponding public key can verify the signature. Because the signing and verification processes use two different keys, this algorithm is called an asymmetric signature. The basic process of using asymmetric signatures to exchange confidential information can be as follows: Party A generates a key pair and publishes the public key. When Party A needs to send a message to another party (Party B), it signs the confidential message using its private key before sending it to Party B; Party B then uses Party A's public key to verify the signed message.
[0117] 6. Smart Contract: A smart contract is a computer protocol designed to disseminate, verify, or execute contracts in an information-based manner. In a blockchain system, a smart contract (or simply contract) is code that can be understood and executed by all nodes in the blockchain, capable of executing arbitrary logic and obtaining results. In practical applications, smart contracts are managed and tested through transactions on the blockchain. Each transaction is equivalent to a Remote Procedure Call (RPC) request to the blockchain system. If a smart contract is like an executable program, the blockchain is like an operating system providing the runtime environment. A blockchain can contain multiple contracts (such as the resource fusion function and resource issuance function in this application), distinguished by contract identity (ID), identifier, or name. In the embodiments of this application, both the topic publishing contract and the topic subscription contract are smart contracts.
[0118] 7. Trusted Execution Environment (TEE): A Trusted Execution Environment is a secure area built on a computing platform using hardware and software methods. It ensures the confidentiality and integrity of code and data loaded within this secure area. The goal of a Trusted Execution Environment is to ensure that a task executes as expected, guaranteeing the confidentiality and integrity of the initial state as well as the runtime state.
[0119] Please see Figure 1 , Figure 1 This is a schematic diagram of a system architecture provided in an embodiment of this application. For example... Figure 1 As shown, the system architecture may include a first device cluster, a second device cluster, a certificate device cluster, and a blockchain network.
[0120] It is understood that the above system may include one or more first devices, and the embodiments of this application do not limit the number of first devices. Figure 1 As shown, the first device cluster includes a first device 100a. The first device 100a refers to a device with a platform application installed. This platform application can be a video application, live streaming application, social application, instant messaging application, game application, music application, shopping application, novel application, browser, or other application that provides platform functionality. The application client corresponding to the platform application can be a standalone client or an embedded sub-client integrated into a client (e.g., a social client, an educational client, or a multimedia client), and is not limited here. In this embodiment, the first device 100a can provide the first business data of the aforementioned platform application. Based on privacy protection requirements, relevant technical means (e.g., Bloom filters) can be used to hide the original data (i.e., the first business data) and generate a first-order array to ensure the availability of the first business data.
[0121] It is understood that the above system may include one or more second devices, and the embodiments of this application do not limit the number of second devices. Figure 1 As shown, the second device cluster includes a second device 100b, which can provide a trusted execution environment, such as Software Guard Extensions (SGX). Based on its hardware technology, the second device 100b can run a data intersection application in the trusted execution environment, generate data keys in the data intersection application, and store the data keys in a secure enclave, thus ensuring the security of the data keys. Furthermore, the second device 100b can download the first array provided by the first device 100a from the blockchain network and run the data intersection application in the trusted execution environment to perform data intersection operations. That is, using the first array and its own second business data, it determines the common business data between the first and second business data, referred to as business intersection data in this embodiment. In addition, the second device 100b can perform business processing associated with the business intersection data. For example, if the business intersection data is used to represent intersection users, advertisements targeting the aforementioned platform application can be delivered to these users to attract them back to the platform application. The data intersection application can be any application that provides the function of determining the business intersection data, such as short video applications, live streaming applications, social applications, instant messaging applications, game applications, music applications, shopping applications, novel applications, and browsers. The application client corresponding to the data intersection application can be a standalone client or an embedded sub-client integrated into a client (e.g., a social client, an educational client, or a multimedia client), without any limitation.
[0122] It is understood that the above system may include one or more certificate devices, and this application embodiment does not limit the number of certificate devices. Figure 1 As shown, the certificate device cluster includes certificate device 100c. In this embodiment, certificate device 100c refers to a device that provides object information endorsement, such as the device corresponding to a Certificate Authority (CA). The certificate device cluster can provide object authentication for a first object corresponding to a first device cluster and a second object corresponding to a second device cluster, respectively, and provides object information endorsement for both the first and second objects. It also binds the object's public key to its object information for signature verification, ensuring the integrity and unforgeability of the object information, and ensuring the non-repudiation of the information sender.
[0123] in, Figure 1Any device within this framework (including the first device 100a, the second device 100b, and the certificate device 100c) includes, but is not limited to, terminal devices or business servers. The business server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud databases, cloud services, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. Terminal devices include, but are not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle terminals, and aircraft.
[0124] The blockchain network may include a blockchain node cluster 10, which may include blockchain nodes 10A, 10B, 10C, and 10N. Similarly, this application embodiment does not limit the number of blockchain nodes in the blockchain node cluster 10. It is understood that... Figure 1 The blockchain nodes include, but are not limited to, mobile terminals or servers. These servers can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. The mobile terminals include, but are not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, vehicle terminals, and aircraft. The mobile terminals and servers can be connected directly or indirectly via wired or wireless means; this embodiment does not impose any limitations on this.
[0125] Within this system, communication connections can exist between devices in the first device cluster. Furthermore, a first device in the first device cluster can communicate with a second device in the second device cluster; for example, first device 100a and second device 100b can communicate with each other. Additionally, a first device in the first device cluster can communicate with a certificate device in the certificate device cluster; for example, first device 100a and certificate device 100c can communicate with each other. Finally, a first device in the first device cluster can communicate with blockchain nodes in the blockchain node cluster 10; for example, first device 100a can communicate with blockchain node 10A.
[0126] Within this system, communication connections can exist between the second device clusters. Furthermore, a second device within a second device cluster can communicate with a certificate device within a certificate device cluster; for example, second device 100b can communicate with certificate device 100c. Additionally, a second device within a second device cluster can communicate with blockchain nodes within the blockchain node cluster 10; for example, second device 100b can communicate with blockchain node 10A.
[0127] Within this cluster, certificate devices can communicate with each other. Furthermore, certificate devices within a certificate device cluster can communicate with blockchain nodes in the blockchain node cluster 10; for example, certificate device 100c can communicate with blockchain node 10A.
[0128] Among them, there can be communication connections between blockchain node cluster 10, for example, there is a communication connection between blockchain node 10A and blockchain node 10C, and there is a communication connection between blockchain node 10A and blockchain node 10N.
[0129] The above-mentioned communication connection is not limited to a specific connection method. It can be connected directly or indirectly through wired communication, wireless communication, or other methods. This application does not impose any restrictions on these methods.
[0130] It is understood that in the specific implementation of this application, data related to user information (such as topic publishing object information and topic subscription object information) is involved. When the embodiments in this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0131] The data processing method based on blockchain provided in this application embodiment can be summarized as follows: Step 1: The first device 100a corresponding to the first object (e.g., a platform) generates a first asymmetric key pair for signing business messages; the second device 100b corresponding to the second object (e.g., an advertiser, a different platform from the first object) generates a second asymmetric key pair for signing business messages, and generates a third asymmetric key pair for signing data intersection applications, which can be used to determine that the application developer is the developer of the second object. Please also refer to... Figure 2a , Figure 2a This application provides an example of a blockchain-based data processing scenario. Figure 1 The first asymmetric key pair includes... Figure 2a The first private key and the first public key corresponding to the first private key; the second asymmetric key pair includes Figure 2aThe third asymmetric key pair includes the second private key and the corresponding second public key; Figure 2a The third private key and the third public key corresponding to the third private key.
[0132] Step 2, as follows Figure 2a As shown, the first device 100a generates a first certificate application request using a first public key and first object information representing a first object as parameters. Further, the first device 100a signs the first certificate application request using a first private key to obtain a first signed message, and sends the first certificate application request carrying the first signed message to the certificate device 100c. The second device 100b generates a second certificate application request using a second public key and second object information representing a second object as parameters. Further, the second device 100b signs the second certificate application request using a second private key to obtain a second signed message, and sends the second certificate application request carrying the second signed message to the certificate device 100c. Additionally, the second device 100b generates a third certificate application request using a third public key and second object information representing a second object as parameters. Further, the second device 100b signs the third certificate application request using a third private key to obtain a third signed message, and sends the third certificate application request carrying the third signed message to the certificate device 100c. Clearly, the second device 100b requests certificates from both parties from the certificate device 100c.
[0133] Step 3, as follows Figure 2a As shown, when certificate device 100c receives a first certificate application request, it first verifies the first signature message using the first public key. If the verification is successful, it reviews the first object information. If certificate device 100c confirms that the first object information is correct, it issues a first business certificate to first device 100a, which includes the first public key. Similarly, when receiving a second certificate application request, it first verifies the second signature message using the second public key. If the verification is successful, it reviews the second object information. If certificate device 100c confirms that the second object information is correct, it issues a second business certificate to second device 100b, which includes the second public key. Similarly, when receiving a third certificate application request, it first verifies the third signature message using the third public key. If the verification is successful, it reviews the second object information. If certificate device 100c confirms that the second object information is correct, it issues an application developer certificate to second device 100b, which includes the third public key.
[0134] Step 4, as follows Figure 2aAs shown, the first device 100a uses the first business certificate as a parameter to initiate a first object registration request to the blockchain network. It is understood that the first object registration request also carries a signature message, the generation process of which can be referred to the generation process of the first signature message, and will not be repeated here. In order to distinguish it from the signature message mentioned above, the signature message carried by the first object registration request is called the fourth signature message. Similarly, the second object registration request mentioned below carries a fifth signature message, and the third object registration request carries a sixth signature message.
[0135] When a blockchain node in the blockchain network receives a first object registration request, it first verifies the fourth signature message using the first public key. If the verification is successful, it then reviews the first business certificate. If the blockchain node approves the first business certificate, it calls the object contract in the smart contract. The object contract generates a first address corresponding to the first object information based on the first public key in the first business certificate, and uses this first address as the first object identifier. Then, it associates and stores the first object identifier, the first business certificate, and the first object information. The structure parameters and contract methods of the object contract are as follows: Figure 2b Object contracts within.
[0136] Similarly, when a blockchain node receives a second object registration request, it first verifies the fifth signature message using the second public key. If the verification is successful, it then reviews the second business certificate. If the blockchain node approves the second business certificate, it calls the object contract in the smart contract. The object contract generates a second address corresponding to the second object information based on the second public key in the second business certificate, and uses this second address as the second object identifier. Then, it associates and stores the second object identifier, the second business certificate, and the second object information. Likewise, when a blockchain node receives a third object registration request, it first verifies the sixth signature message using the third public key. If the verification is successful, it reviews the application developer certificate. If the blockchain node approves the application developer certificate, it calls the object contract in the smart contract. The object contract generates a third address corresponding to the second object information based on the third public key in the application developer certificate, and uses this third address as the third object identifier. Then, it associates and stores the third object identifier, the application developer certificate, and the second object information.
[0137] Please refer to steps 1-4 above together. Figure 2b , Figure 2b This is a flowchart illustrating a blockchain-based object registration method provided in an embodiment of this application. Figure 2bAs shown, in step 1a, the first device generates a first asymmetric key pair; in step 1b, the second device generates a second asymmetric key pair and a third asymmetric key pair; in step 2a, the first device applies for a certificate from the certificate device; in step 2b, the second device applies for a certificate from the certificate device; in step 3a, the certificate device issues a certificate to the first device; in step 3b, the certificate device issues a certificate to the second device; in step 4a, the first device registers an object with the blockchain node; in step 4b, the second device registers an object with the blockchain node. As can be seen from the above, the information of the participants (including the first object and the second object) in this embodiment is certified by a CA, and the keys are linked to the object information. The entire collaboration process is signed with a private key, ensuring that each process can be associated with the initiator. Therefore, it can prevent tampering and repudiation, facilitate traceability, aid in supervision, and reduce malicious activity.
[0138] Step 5: The first device needs to determine if the first service data meets the data upload conditions. The determination process can be summarized as follows: Please refer to [link / reference needed]. Figure 2c , Figure 2c This is a schematic diagram of a data processing scenario based on blockchain provided in an embodiment of this application. For example... Figure 2c As shown, the first device 100a performs security checks on the second device 100b, including object information, execution environment, and application security, through remote authentication. The specific implementation of this process will not be described in detail here; please refer to the following text. Figure 3 The description of step S101 in the corresponding embodiment, and the following... Figure 5 The description in the corresponding embodiment is as follows. Through the above security detection, if the first device 100a determines that the first service data meets the data upload conditions, it obtains the first array 20a corresponding to the first service data. It can be understood that the first array 20a can be the original data, i.e., the first service data, which is usable but not visible, thus improving the security of the first service data. For the specific implementation process of the first array 20a, please refer to the following text. Figure 3 The description of step S101 in the corresponding embodiment will not be elaborated here.
[0139] Step 6, as follows Figure 2c As shown, the first device 100a uses data key 20b to encrypt the first bit array 20a, obtaining the ciphertext bit array 20c. Data key 20b is generated by the second device 100b in the data intersection application within the Trusted Execution Environment 20e. Since data key 20b is generated in the TEE, its generation environment is secure, and therefore data key 20b will not be leaked. Using it to encrypt the first bit array 20a provides high security. Only the enclave that generated it (i.e., the data intersection application) can decrypt the ciphertext bit array 20c using data key 20b, thus ensuring the security of the first bit array 20a.
[0140] Step 7: The first device 100a uses the first private key mentioned above to sign the ciphertext bit array 20c, obtaining the seventh signed message, such as... Figure 2c As shown, the first device 100a transmits the ciphertext bit array 20c carrying the seventh signature message to the blockchain network. After receiving the ciphertext bit array 20c, the blockchain node in the blockchain network first verifies the seventh signature message using the first public key in the first asymmetric key pair. If the verification is successful, the blockchain node ensures that the ciphertext bit array 20c is intact and has not been tampered with, and therefore stores the ciphertext bit array 20c on the blockchain.
[0141] Step 8: The second device 100b sends a data download request to the blockchain network to obtain the encrypted bit array 20c. After receiving the data download request, the blockchain node decides whether to return the encrypted bit array 20c or refuse to process the data download request based on the current subscription status corresponding to the second object information (equivalent to the subject subscription object information of this application), and records this process on the blockchain for traceability. If the current subscription status of the second object information indicates that the second device 100b has the permission to obtain the encrypted bit array 20c, then the encrypted bit array 20c is returned to the second device 100b. It is understood that the blockchain network witnesses the process of the second device 100b obtaining the encrypted bit array 100c to ensure data traceability and prevent the second device 100b from failing to provide business services.
[0142] Step 9, as follows Figure 2c As shown, the second device 100b has a normal execution environment 20d and a trusted execution environment 20e. The normal execution environment 20d can run the second object platform corresponding to the second object (which is different from the platform corresponding to the first device 100a), such as an advertising platform; the data intersection application runs in the trusted execution environment 20e. In the second object platform running in the normal execution environment 20d, the second device 100b uses the ciphertext bit array 20c and the second business data as parameters to generate an intersection data lookup request; the intersection data lookup request is sent to the data intersection application running in the trusted execution environment 20e.
[0143] Step 10, as follows Figure 2c As shown, in the data intersection application, the second device 100b decrypts the ciphertext bit array 20c using the data key 20b to obtain the first bit array 20a. Further, the second device 100b generates a second bit array 20f corresponding to the second service data. Using the first bit array 20a and the second bit array 20f, the second device 100b can determine the common service data between the first and second service data, referred to as service intersection data in this embodiment.
[0144] Step 11, as follows Figure 2cAs shown, the second device 100b transmits the service intersection data determined in the trusted execution environment 20e to the second object platform. Furthermore, the second device 100b performs service processing associated with the service intersection data.
[0145] The embodiments of this application can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, smart transportation, and assisted driving. These embodiments are applicable to scenarios such as determining data intersections between platforms, platform recommendation scenarios, and platform evaluation scenarios; specific business scenarios will not be listed here.
[0146] Further, please see Figure 3 , Figure 3 This is a flowchart illustrating a blockchain-based data processing method provided in an embodiment of this application. Figure 1 This blockchain-based data processing method can be executed by a first device, a second device, a blockchain node, or interactively by at least two of the first device, second device, and blockchain node; no limitations are imposed here. For ease of description and understanding, this application's embodiments are described using a first device as an example, wherein the first device can be one of the aforementioned... Figure 1 The first device 100a in the corresponding embodiment. For example... Figure 3 As shown, the blockchain-based data processing method may include at least the following steps S101-S103.
[0147] Step S101: If the first business data meets the data upload conditions, then generate the first array corresponding to the first business data.
[0148] Specifically, a topic is generated for the first business data, and a topic publishing request is generated including the topic and the topic publishing object information; the topic publishing request is signed using the device private key corresponding to the first device to obtain a signature message z; based on the topic publishing request, the topic publishing contract of the blockchain node is invoked; the topic publishing request carrying the signature message z is sent to the blockchain node through the topic publishing contract, so that the blockchain node invokes the topic publishing contract when the topic publishing request passes the legality verification; the topic publishing contract is used to instruct the blockchain node to store the topic when verifying that the topic publishing object information belongs to the registered object information and determining that the topic has the attribute of being published; the topic stored in the blockchain node is used to instruct the second device to send a topic subscription request to the blockchain node; the signature message z is used to instruct the blockchain node to verify the legality of the topic publishing request; the topic subscription request forwarded by the blockchain node when it determines that the topic subscription request has the attribute of a valid request is obtained; based on the topic subscription request forwarded by the blockchain node, the relationship between the first business data and the data upload conditions is determined; the relationship between the first business data and the data upload conditions includes whether the first business data meets the data upload conditions or whether the first business data does not meet the data upload conditions.
[0149] The specific process of determining the relationship between the first business data and the data upload conditions based on the topic subscription request forwarded by the blockchain node may include: generating a remote authentication request based on the topic subscription request forwarded by the blockchain node; sending the remote authentication request to the second device so that the second device generates an intermediate key pair g including an intermediate public key f based on the remote authentication request; the intermediate public key f is used to instruct the second device to call the trusted execution environment a to generate a remote authentication report for the data intersection application; obtaining the remote authentication report returned by the second device, and determining the relationship between the first business data and the data upload conditions based on the remote authentication report.
[0150] The specific process of generating a remote authentication request based on the topic subscription request forwarded by the blockchain node may include: generating an authentication challenge random number and an intermediate key pair j including an intermediate private key h and an intermediate public key i based on the topic subscription request forwarded by the blockchain node; generating a remote authentication request based on the intermediate public key i and the authentication challenge random number; the intermediate public key i is used to instruct the second device to generate a communication key based on the intermediate public key i, the authentication challenge random number, and the intermediate private key k in the intermediate key pair g; the communication key is used to encrypt the data key to obtain an encrypted data key; and may further include: obtaining the intermediate public key f in the remote authentication report, generating a communication key based on the intermediate public key f, the authentication challenge random number, and the intermediate private key h; obtaining the encrypted data key returned by the second device, and decrypting the encrypted data key using the communication key to obtain the data key.
[0151] Specifically, the process involves obtaining an initial bit array mapped with a first random number and a random mapping function, inputting the first business data into the random mapping function, generating a second random number corresponding to the first business data through the random mapping function, the first random number including the second random number, determining the bit array to be updated in the initial bit array, the bit array to be updated being mapped with the second random number, updating the bit array to be updated in the initial bit array, and determining the updated initial bit array as the first bit array.
[0152] In this embodiment, before publishing the encrypted bit array, the first device first publishes the topic corresponding to the first business data so that the data receiver (including the second device) can subscribe to the topic. Therefore, the first device can review the topic subscription request corresponding to the second device and return the review result to the blockchain network. If the review result is a pass, it is determined that the first business data meets the data upload conditions. Please also refer to... Figure 4a , Figure 4a This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 1 .like Figure 4a As shown, in step 4a1, the first device generates a topic; it is understood that this application embodiment does not limit the platform corresponding to the first device, and therefore does not limit the type of the first business data. In step 4a2, the first device generates a topic publishing request; wherein, the topic publishing request includes a topic and topic publishing object information (equivalent to the first object information mentioned above); in step 4a3, the first device generates a signature message z; the first device signs the topic publishing request using the device private key corresponding to the first device (equivalent to the first private key mentioned above), and obtains a signature message z; in step 4a4, the first device sends a topic publishing request carrying the signature message z to the blockchain node; specifically, the first device calls the topic publishing method of the topic contract on the blockchain (i.e., the topic publishing contract) to publish the topic to the blockchain network; the structure parameters of the topic contract and the contract method (including the topic publishing method) are as follows. Figure 4a The topic contract in the blockchain. Step 4a5: The blockchain node verifies the topic; specifically, after receiving the topic publishing request, the blockchain node verifies the signature message z using the device public key corresponding to the first device (equivalent to the first public key mentioned above). If the verification is successful, it ensures that the topic publishing request has not been tampered with. Further, the topic publishing method is called. Through the topic publishing method, the blockchain node can verify that the publisher (i.e., the topic publishing object information) belongs to the on-chain registered object information, equivalent to... Figure 4aThe bolded text indicates a valid object. Secondly, it ensures that the topic has not yet been registered, i.e., whether the topic already exists on the chain. After the above verification is successful, step 4a6 is executed. Step 4a6: The blockchain node stores the topic. Step 4a7: The blockchain node returns the result to the first device; the result can be information used to characterize the topic stored by the blockchain node. This application embodiment will not elaborate on the process of the second device sending a topic subscription request to the blockchain node; please refer to the following text. Figure 7 The description in the corresponding embodiments.
[0153] Upon determining that a topic subscription request possesses valid attributes, the blockchain node forwards the topic subscription request to the first device, or the first device queries the blockchain node for pending topic subscription requests, such as... Figure 4b As shown, Figure 4b This is a second timing diagram illustrating a blockchain-based data processing method provided in this application embodiment. Step 4b1: The first device queries the blockchain node for pending topic subscription requests; Step 4b2: The blockchain node returns the latest valid topic subscription request to the first device; The blockchain node can use the topic (equivalent to the topic name) as a parameter to call methods in the topic contract, such as... Figure 4b The bold text indicates "Get the latest valid subscription requests", which retrieves pending topic subscription requests.
[0154] The first device, based on the topic subscription request forwarded by the blockchain node, can determine the relationship between the first business data and the data upload conditions. Please refer to [link / reference needed]. Figure 4c , Figure 4c This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 3 .like Figure 4cAs shown, in step 4c1, the first device generates an authentication challenge random number and an intermediate key pair j(h, i), where h represents the intermediate public key in the intermediate key pair j, and i represents the intermediate private key in the intermediate key pair j; this is an asymmetric key pair. In step 4c2, the first device generates a remote authentication request; specifically, the first device uses the intermediate public key h and the authentication challenge random number as parameters to generate the remote authentication request. In step 4c3, the first device sends the remote authentication request. In step 4c4, the second device generates an intermediate key pair g(f, k), where f represents the intermediate public key in the intermediate key pair g, and k represents the intermediate private key in the intermediate key pair g; this is also an asymmetric key pair. In step 4c5, the second device generates a remote authentication report; specifically, the second device uses the intermediate public key f as a parameter to call the trusted execution environment a to generate a remote authentication report. Step 4c6: The second device generates a communication key. Specifically, the second device generates a communication key based on the intermediate public key i, the authentication challenge random number, and the intermediate private key k in the remote authentication request, and saves it. One feasible way is to generate the communication key through a key exchange algorithm. Among them, the intermediate private key h and the intermediate public key i of the intermediate key pair j can be represented by the following formula (1).
[0155] i=(G∧h)modp (1)
[0156] In formula (1), G is the base, p is a prime number, and both G and P are authentication challenge random numbers.
[0157] The intermediate private key k and intermediate public key f of the intermediate key pair g can be represented by the following formula (2).
[0158] f=(G∧k)modp (2)
[0159] The communication keys generated by the first device and the second device respectively can be represented by the following formula (3).
[0160] S=(i∧k)modp=(f∧h)modp (3)
[0161] Step 4c7: The second device returns the remote authentication report to the first device. Step 4c8: The first device verifies the remote authentication report; the first device calls the Provisioning Certification Service (PCS) to verify the remote authentication report. If the verification is successful, meaning the first business data meets the data upload conditions, then step 4c9 is executed. Step 4c9: The first device generates a communication key. Specifically, the first device generates a communication key based on the intermediate public key f, the authentication challenge random number, and the intermediate private key h in the remote authentication report, as shown in formula (3) above, and saves the communication key.
[0162] In this embodiment, to ensure the security of the first array, the first device encrypts the first array, and the data key used to encrypt the first array is generated by the second device in a trusted execution environment. Please refer to [link to relevant documentation]. Figure 4d , Figure 4d This is a timing diagram (fourth) illustrating a blockchain-based data processing method provided in an embodiment of this application. Figure 4d As shown, in step 4d1, the second device generates a data key; the second device can generate a data key in a trusted execution environment (TEE) upon receiving a remote authentication request, and run and store it in the TEE. In step 4d2, the second device generates an encrypted data key; specifically, the second device encrypts the data key using a communication key to obtain an encrypted data key. In step 4d3, the second device sends the encrypted data key to the first device. In step 4d4, the first device decrypts the encrypted data key using a communication key to obtain the data key. It is understood that other devices besides the first and second devices cannot generate a communication key because they do not possess the intermediate private key k or h.
[0163] If the first service data meets the data upload conditions, the first device generates the first bit array corresponding to the first service data. One feasible method for generating the first bit array is to use a Bloom filter. A Bloom filter consists of a long binary vector (which can be equivalent to an initial bit array, where each point of the original binary vector is 0) and a series of random mapping functions. The Bloom filter can be used to retrieve whether an element (e.g., the second service data in this embodiment) is in a set (e.g., the first service data in this embodiment). The principle is that when an element is added to the set, it is mapped to L points in the initial bit array through L random mapping functions (usually L is greater than 1), and the L points are set to 1. During retrieval, it is confirmed whether these L points in the first bit array are 1. If these L points in the first bit array are not all 1 or are all not 1, it can be determined that the element does not belong to the set. If these L points in the first bit array are all 1, then the element may be in the set. In this embodiment, the element is determined as the service intersection data.
[0164] Please see also Figure 4e , Figure 4e This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 5 .like Figure 4eAs shown, in step 4e1, the first device acquires the first service data. In step 4e2, the first device generates a first-order array; feasiblely, the first device generates a Bloom filter and stores the first service data into the Bloom filter. At this time, the first-order array is the Bloom filter containing the first service data. In this embodiment, the first device does not provide plaintext data, i.e., the first service data, but reads the first service data from the database and stores it into the Bloom filter. Without leaking data, it can ensure that the second device can filter out the service intersection data, achieving the purpose of data usability without visibility.
[0165] Step S102: The first bit array is encrypted using the data key generated by the second device in the data intersection application to obtain the ciphertext bit array; the data intersection application runs in the trusted execution environment a of the second device.
[0166] For details, please refer to [link / reference]. Figure 4e In step 4e3, the first device generates an encrypted bit array; the first device encrypts the first bit array using the data key to obtain the encrypted bit array.
[0167] Step S103: The ciphertext bit array is transmitted to the blockchain node in the blockchain so that the blockchain node stores the ciphertext bit array; the ciphertext bit array stored in the blockchain node is used by the blockchain node to forward to the second device; the second device is used to decrypt the ciphertext bit array obtained from the blockchain node using a data key in the data intersection application to obtain the first bit array; the first bit array is used to instruct the second device to generate the second bit array corresponding to the second business data in the data intersection application; the second bit array and the first bit array are used to instruct the second device to determine the business intersection data between the first business data and the second business data in the data intersection application; the business intersection data is used to instruct the second device to perform business processing associated with the business intersection data.
[0168] Specifically, in step 4e4, the first device sends the encrypted bit array to the blockchain node. In step 4e5, the blockchain node stores the encrypted bit array.
[0169] This application embodiment does not describe in detail the process of the second device obtaining the encrypted bit array, nor the process of determining the business intersection data. Please refer to the following text. Figure 7 The description in the corresponding embodiments.
[0170] In this embodiment, by generating the first bit array corresponding to the first business data, the first business data can be ensured to be available but not visible, thus improving its security. Furthermore, since the data key is generated through the data intersection application in the trusted execution environment a, its generation environment, application environment, and storage environment are all secure. Therefore, encrypting the first bit array with the data key further enhances its security. Moreover, by transmitting the ciphertext bit array to the blockchain, the acquisition status of the second device for the ciphertext bit array can be accurately traced. In addition, this embodiment determines the business intersection data between the first and second business data using the first bit array and the second bit array corresponding to the second business data. Therefore, not only can business processing associated with the business intersection data be performed, but the security of the first business data is further improved. As can be seen from the above, by adopting this embodiment, the security of data (including the first business data and the first bit array) can be improved, and the data acquisition status can be accurately traced.
[0171] Further, please see Figure 5 , Figure 5 This is a schematic flowchart of a data processing method provided in an embodiment of this application. Figure 5 As shown, the data processing method includes the following steps S1011-S1013, and steps S1011-S1013 are... Figure 3 A specific embodiment of step S101 in the corresponding embodiment.
[0172] Step S1011: Invoke the authentication service to verify the remote authentication report and obtain the first verification result.
[0173] Specifically, remote authentication occurs before the first device sends the ciphertext bit array to the blockchain network. It mainly verifies the data operating environment of the second device, the security of the application, and the correctness of the developer information (i.e., the subscriber), thereby ensuring that the ciphertext bit array is provided to the correct user and that the use of the ciphertext bit array is secure.
[0174] It should be emphasized that the embodiments of this application do not limit the order of verification of the data operating environment, application, and developer information. Verification can be performed in parallel or sequentially. If sequential verification is performed, the data operating environment can be verified first or last.
[0175] Step S1012: If the first verification result indicates that the remote authentication report verification failed, then it is determined that the first business data does not meet the data upload conditions.
[0176] Specifically, if the first verification result indicates that the remote authentication report verification failed, it is determined that the trusted execution environment a does not have the environment security attribute; a first update subscription state is generated to indicate that the trusted execution environment a does not have the environment security attribute, and the first update subscription state is sent to the blockchain node so that the blockchain node sets the first update subscription state for the topic subscription request.
[0177] The first device calls the Authentication Service (PCS) to verify the validity of the remote authentication report. If the verification fails, it means that the trusted execution environment of the second device is unreliable and the subscription request should be ignored. At this time, the first device updates the subscription status to "insecure environment", that is, updates the subscription status and terminates the subsequent process.
[0178] Step S1013: If the first verification result indicates that the remote authentication report has passed verification, then obtain the source code of the data intersection application, and determine the relationship between the first business data and the data upload conditions based on the source code.
[0179] Specifically, the source code is verified to obtain a second verification result; if the second verification result indicates that the source code verification passed, the topic subscription object information for the data intersection application in the remote authentication report is obtained, and the topic subscription object information is verified to obtain a third verification result; the remote metric value for the source code in the remote authentication report is obtained, and the remote metric value is verified to obtain a fourth verification result; based on the third and fourth verification results, the relationship between the first business data and the data upload conditions is determined; if the second verification result indicates that the source code verification failed, it is determined that the first business data does not meet the data upload conditions; it may also include: if the second verification result indicates that the source code verification failed, it is determined that the source code does not have code security attributes; a second update subscription state is generated to indicate that the source code does not have code security attributes, and the second update subscription state is sent to the blockchain node so that the blockchain node sets the second update subscription state for the topic subscription request.
[0180] The specific process of verifying the topic subscription object information to obtain a third verification result may include: obtaining the application development object certificate for the data intersection application; retrieving the application development object information from the application development object certificate; comparing the topic subscription object information with the application development object information; if the topic subscription object information and the application development object information are different, generating a third verification result indicating that the topic subscription object information verification failed; if the topic subscription object information and the application development object information are the same, generating a third verification result indicating that the topic subscription object information verification passed; and further including: if the third verification result indicates that the topic subscription object information verification failed, generating a third update subscription status indicating that the topic subscription object information is unauthorized object information; and sending the third update subscription status to the blockchain node so that the blockchain node sets the third update subscription status for the topic subscription request.
[0181] The specific process of verifying the remote metric value to obtain the fourth verification result may include: compiling the source code in the trusted execution environment b of the first device to obtain a trusted metric value; comparing the remote metric value with the trusted metric value; if the remote metric value and the trusted metric value are different, generating a fourth verification result to indicate that the remote metric value verification failed; if the remote metric value and the trusted metric value are the same, generating a fourth verification result to indicate that the remote metric value verification passed; and further including: if the fourth verification result indicates that the remote metric value verification failed, generating a fourth update subscription state to indicate that the source code and the running code do not match; and sending the fourth update subscription state to the blockchain node so that the blockchain node sets the fourth update subscription state for the topic subscription request.
[0182] The specific process of determining the relationship between the first business data and the data upload conditions based on the third and fourth verification results may include: if the third verification result indicates that the topic subscription object information has been verified and the fourth verification result indicates that the remote metric value has been verified, then the first business data is determined to meet the data upload conditions; it may also include: if the first business data meets the data upload conditions, then a fifth updated subscription state is generated to indicate that the topic subscription request has been verified; the fifth updated subscription state is sent to the blockchain node so that the blockchain node sets the fifth updated subscription state for the topic subscription request.
[0183] If any unprocessed remote authentication reports exist, the first device will verify the identity of the subscriber corresponding to the remote authentication report to ensure that it is a partner. Please refer to [link / reference needed]. Figure 6a , Figure 6a This is a timing diagram (six) illustrating a blockchain-based data processing method provided in an embodiment of this application. Figure 6aAs shown, in step 6a1, the first device requests an application developer certificate from the blockchain node. If the first device has not yet cached the subscriber's application developer certificate, it downloads it from the chain and caches it. If the subscriber's application developer certificate is already cached locally, step 6a1 is skipped, and step 6a2 is executed. In step 6a2, the blockchain node returns the application developer certificate to the first device. The blockchain node can call the method to obtain object information in the object contract based on the object identifier sent by the first device, thereby obtaining the application developer certificate requested by the first device. In step 6a3, the first device verifies the topic subscription object information and obtains a third verification result. Specifically, the first device compares the application development object information in the application developer certificate with the topic subscription object information in the remote authentication report to obtain a third verification result. In step 6a4, if the verification fails, the first device returns a third update subscription status to the blockchain node. It can be understood that if the verification passes, the first device does not execute this step; at this time, it either executes other verification steps or returns a fifth update subscription status to the blockchain node.
[0184] The second device provides the source code of the data intersection application to the first device, which then performs a manual review. If the source code contains security vulnerabilities, such as vulnerabilities or malicious use of data, the subscription status is updated to "program does not meet expectations," meaning the subscription status is updated again and the subsequent process is terminated.
[0185] In addition, please see also Figure 6b , Figure 6b This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 7 .like Figure 6b As shown, in step 6b1, the first device compiles the source code in the trusted execution environment to generate a trusted metric value; in step 6b2, the first device compares the trusted metric value with the remote metric value; if they are the same, it returns to the fifth update subscription state, or proceeds to the next step. In step 6b3, if they are different, the first device returns to the fourth update subscription state; if they are inconsistent, it indicates that the audit code provided by the second device is inconsistent with the code running on the second device in the TEE environment, which poses a potential risk. Therefore, the subscription state is updated to "audit code is inconsistent with running code", and the subsequent process is terminated.
[0186] As mentioned above, source code verification includes two aspects: verifying the source code and compiling the source code. Please refer to both for further details. Figure 6c , Figure 6c This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 8 .like Figure 6cAs shown, in step 6c1, the second device generates the source code for the data intersection application; in step 6c2, the second device compiles the source code in a trusted execution environment to obtain the data intersection application; in step 6c3, the second device runs the data intersection application in the trusted execution environment; in step 6c4, the second device transmits the source code to the first device. This embodiment does not limit the source code transmission method; it can be a point-to-point transmission between the second and first devices, or the second device can transmit the source code to a blockchain network, and then the first device retrieves it from the blockchain network. Furthermore, in scenarios where the second device updates the source code, the second device will transmit the updated source code to the first device again. This embodiment does not limit the execution order of steps 6c4 and 6c2; they can be executed simultaneously. In step 6c5, the second device reviews the source code; if the review fails, it sends the second update subscription status to the blockchain node; if the review passes, it executes step 6c6, where the first device compiles the source code in the trusted execution environment to obtain the data intersection application. Step 6c7: The first device generates a trust metric value for the data intersection application; the subsequent process is the same as above, so it will not be described again.
[0187] If all the above authentications (i.e., subscriber authentication, data runtime environment authentication, and application security authentication) pass, the first device updates the subscribers in the theme contract and updates the status of the contract subscription request to "completed," which is the fifth update of the subscription status. At the same time, the first device saves the remote authentication results.
[0188] In conjunction with the embodiments of this application and the above, Figure 3 In step S101 of the corresponding embodiment, after obtaining the topic subscription request to be processed, the first device will send a remote authentication request to the subscriber (i.e., the second device) according to the topic subscription request. The remote authentication request not only prompts the second device to return a remote authentication report, but also prompts the second device to generate a communication key and return an encrypted data key.
[0189] This application integrates blockchain, trusted execution environment (TEE), and Bloom filter technology to provide a hardware and software solution for finding the intersection of encrypted data. Blockchain provides object information authentication, ensuring process transparency and trustworthiness; TEE remote authentication ensures execution environment and application security; and Bloom filters enable data to be usable but not visible. This solution significantly reduces the time and space complexity of the program, ensures data security throughout its entire lifecycle of storage, transmission, and execution, and can quickly identify common samples from multiple parties without leaking business data, thus enabling joint business processing.
[0190] Please see Figure 7 , Figure 7 This is a flowchart illustrating a blockchain-based data processing method provided in an embodiment of this application. Figure 3This blockchain-based data processing method can be executed by a first device, a second device, a blockchain node, or interactively by at least two of the first device, second device, and blockchain node; no limitations are imposed here. For ease of description and understanding, this application embodiment will be described using a second device as an example, wherein the second device can be one of the aforementioned... Figure 1 The second device 100b in the corresponding embodiment. For example... Figure 7 As shown, the method may include at least the following steps.
[0191] Step S201: Obtain the ciphertext bit array forwarded by the blockchain node in the blockchain; the ciphertext bit array is transmitted from the first device to the blockchain node, and the ciphertext bit array is obtained by the first device encrypting the first bit array with the data key generated by the second device in the data intersection application; the data intersection application runs in the trusted execution environment a of the second device; the first bit array is generated by the first device for the first business data when the first business data meets the data upload conditions.
[0192] Specifically, based on the topic subscription object information, a topic subscription request is generated for subscribing to the topic; the topic is generated by the first device for the first business data; based on the topic subscription request, the topic subscription contract of the blockchain node is invoked; through the topic subscription contract, the topic subscription request is sent to the blockchain node, so that when the blockchain node verifies through the topic subscription contract that the topic has the attribute to be subscribed and that the topic subscription object information belongs to the registered object information, it stores the topic subscription request and sets a request pending verification status for the topic subscription request; the request pending verification status is used to instruct the blockchain node to forward the topic subscription request to the first device.
[0193] Specifically, based on the topic subscription object information, a data download request is generated to obtain the ciphertext bit array; the data download request is sent to the blockchain node so that the blockchain node can query the current subscription status corresponding to the topic subscription object information based on the data download request; the ciphertext bit array returned by the blockchain node when it determines that the current subscription status is the fifth update subscription status is obtained; the fifth update subscription status is used to indicate that the first device has passed the verification of the topic subscription request; the topic subscription request is sent when the blockchain node stores the topic for the first business data.
[0194] Please see also Figure 8 , Figure 8 This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 9 .like Figure 8As shown, step 81: The second device sends a topic subscription request to the blockchain node; the topic subscription request includes topic subscription object information. Step 82: The blockchain node verifies the topic subscription request; specifically, the blockchain node calls the topic subscription method (equivalent to a topic subscription contract) to ensure that the topic has not been subscribed to by other parties (such topics are only available for one-party subscription because the topic message is encrypted, and the communication key and data key cannot be shared among multiple parties to prevent data leakage), and also ensures that the subscriber is a registered object on the chain. Step 83: The blockchain node saves the topic subscription request; the blockchain node generates a subscription request identifier based on the topic name, subscriber (i.e., topic subscription object information), block height, and transaction index, saves the topic subscription request, and marks the request processing status of the topic subscription request as "object not registered / subscribed to by other objects / pending authorization" according to the above verification. If the topic subscription request is valid, the request identifier of the latest valid subscription request for the topic is updated to the latest subscription request identifier. Step 84: The blockchain node returns the result to the second device; the result can be used to characterize the blockchain network's processing result for the topic subscription request.
[0195] In step S202, in the data intersection application, the ciphertext bit array obtained from the blockchain node is decrypted using the data key to obtain the first bit array.
[0196] Please see also Figure 9 , Figure 9 This is a timing diagram of a blockchain-based data processing method provided in an embodiment of this application. Figure 10 .like Figure 9 As shown, in step 91, the second device downloads the ciphertext bit array from the blockchain node. In step 92, the second device decrypts the ciphertext bit array using the data key to obtain the first bit array.
[0197] Step S203: In the data intersection application, a second bit array corresponding to the second business data is generated. Based on the second bit array and the first bit array, the business intersection data between the first business data and the second business data is determined.
[0198] Specifically, the second business data includes second business data C. d d is a positive integer, and d is less than or equal to the total number of second business data; the second bit array includes the second business data C. d The corresponding second array E d If the first array includes the second array E d Then determine the second business data C d This refers to the business intersection data between the first business data and the second business data.
[0199] Please see again. Figure 9 Step 93: The second device generates the second bit array of the second service data. Specifically, the process of the first device generating the first bit array is the same as the process of the second device generating the second bit array, so it will not be described again here. Step 94: The second device compares the second bit array and the first bit array to determine the service intersection data. Among them, Figure 9 Steps 92-94 are all executed in a trusted execution environment. This embodiment does not limit the number of second service data points; there can be one or more. If multiple second service data points exist, the second device iterates through each second service data point to determine the existence of a second bit array corresponding to a second service data point in the first bit array. If it exists, the second service data point is determined to be service intersection data. Step 95: The second device performs service processing associated with the service intersection data.
[0200] For ease of understanding, the example here uses the mobile phone number held by the platform application corresponding to the first device. This mobile phone number can be the contact information of a silent object of the platform application. The platform application wants to promote the silent object to attract it back to the platform. Therefore, it cooperates with a promoter with strong promotion capabilities. However, to ensure the security of the silent object's mobile phone number, the first device cannot disclose the mobile phone number to the outside world. At this time, the first device can use the method provided in this application, that is, firstly generate the first element array corresponding to the mobile phone number (i.e., the first business data), specifically, the mobile phone number can be stored in a Bloom filter; then, the Bloom filter containing the mobile phone number is encrypted using the data key generated by the second device in the trusted execution environment, to obtain an encrypted Bloom filter; and then the encrypted Bloom filter is transmitted to the blockchain.
[0201] The blockchain first reviews the encrypted Bloom filter. If the review is successful, the encrypted Bloom filter is stored. When a data download request is received from a second device, the blockchain first reviews the second device. If the review is successful, the encrypted Bloom filter is forwarded to the second device.
[0202] In a data intersection application running in a trusted execution environment, the second device first decrypts the encrypted Bloom filter using a data key to obtain a Bloom filter containing phone numbers (referred to as the first Bloom filter for distinction). Then, it transmits its own phone numbers to the trusted execution environment, storing each phone number separately in a Bloom filter (referred to as the second Bloom filter for distinction). If the second Bloom filter matches the first Bloom filter, it determines that the phone numbers in the second Bloom filter belong to both the promoter and the platform application, i.e., business intersection data. Subsequently, the second device pushes advertisements with promotional effects provided by the first device to the business intersection data, which represents the contact information of a silent object within the platform application.
[0203] To protect plaintext data, i.e., the first business data, this application embodiment incorporates privacy set intersection. Privacy set intersection (PSI) refers to the ability of two parties holding data to calculate the intersection of their data sets without exposing any data set information outside the intersection. PSI typically has the following three characteristics:
[0204] (1) Semi-trusted scenario: Both parties to the data are unwilling to expose all the data, and only want to find the intersection of the data sets;
[0205] (2) Data minimization: Data other than the intersection of data sets should not be disclosed to any party;
[0206] (3) Secure two-party computation: The two parties involved in the computation need to jointly implement a secure computation protocol to ensure data security.
[0207] Step S204: Perform business processing on the business intersection data.
[0208] Specifically, the system acquires media data with application recommendation functionality provided by the first device and pushes the media data to the second business data C. d .
[0209] By storing the first business data through a Bloom filter, the embodiments of this application can not only protect the privacy of the object, but also reduce the amount of data, reduce the number of communications, and reduce the time and space complexity of the system.
[0210] By generating and managing data keys in the TEE, the embodiments of this application can ensure the security of data keys during storage, transmission and use, thereby guaranteeing data security.
[0211] By using blockchain, this application embodiment puts the code on the chain, improving the credibility of the application. When the data user (i.e., the second device) updates the code without the consent of the data provider (i.e., the first device), the data provider can stop providing the first business data and record this process on the chain to preserve evidence of the service status change. Furthermore, participating parties (including the data user and the data provider) can record each service / data provided on the chain to provide a basis for subsequent services. Additionally, recording object identity information on the chain can verify data integrity; recording workflows on the chain can ensure process transparency and facilitate supervision.
[0212] In this embodiment, by generating the first bit array corresponding to the first business data, the first business data can be ensured to be available but not visible, thus improving its security. Furthermore, since the data key is generated through the data intersection application in the trusted execution environment a, its generation environment, application environment, and storage environment are all secure. Therefore, encrypting the first bit array with the data key further enhances its security. Moreover, by transmitting the ciphertext bit array to the blockchain, the acquisition status of the second device for the ciphertext bit array can be accurately traced. In addition, this embodiment determines the business intersection data between the first and second business data using the first bit array and the second bit array corresponding to the second business data. Therefore, not only can business processing associated with the business intersection data be performed, but the security of the first business data is further improved. As can be seen from the above, by adopting this embodiment, the security of data (including the first business data and the first bit array) can be improved, and the data acquisition status can be accurately traced.
[0213] Further, please see Figure 10 , Figure 10 This is a schematic diagram of the structure of a blockchain-based data processing device provided in an embodiment of this application. Figure 1 The blockchain-based data processing device 1 can operate on the first device, and can be used to execute the corresponding steps in the methods provided in the embodiments of this application. For example... Figure 10 As shown, the blockchain-based data processing device 1 may include: a first generation module 11, a first processing module 12, and a encrypted transmission module 13.
[0214] The first generation module 11 is used to generate the first array corresponding to the first business data if the first business data meets the data upload conditions.
[0215] The first processing module 12 is used to encrypt the first bit array using the data key generated by the second device in the data intersection application to obtain the ciphertext bit array; the data intersection application runs in the trusted execution environment a of the second device.
[0216] The encrypted transmission module 13 is used to transmit the encrypted bit array to the blockchain node in the blockchain so that the blockchain node stores the encrypted bit array; the encrypted bit array stored in the blockchain node is used by the blockchain node to forward to the second device; the second device is used to decrypt the encrypted bit array obtained from the blockchain node using a data key in the data intersection application to obtain the first bit array; the first bit array is used to instruct the second device to generate the second bit array corresponding to the second business data in the data intersection application; the second bit array and the first bit array are used to instruct the second device to determine the business intersection data between the first business data and the second business data in the data intersection application; the business intersection data is used to instruct the second device to perform business processing associated with the business intersection data.
[0217] The specific functional implementation of the first generation module 11, the first processing module 12, and the encrypted transmission module 13 can be found in the above description. Figure 3 Steps S101-S103 in the corresponding embodiment will not be described again here.
[0218] Please see again Figure 10 The blockchain-based data processing device 1 may further include: a second processing module 15, a request sending module 16, a request obtaining module 17, and a relationship determination module 18.
[0219] The second generation module 14 is used to generate a topic for the first business data and generate a topic publishing request that includes the topic and topic publishing object information.
[0220] The second processing module 15 is used to sign the topic publishing request using the device private key corresponding to the first device to obtain a signed message z, and to call the topic publishing contract of the blockchain node based on the topic publishing request.
[0221] The request sending module 16 is used to send a topic publishing request carrying a signature message z to the blockchain node through a topic publishing contract, so that the blockchain node calls the topic publishing contract when it passes the legality verification of the topic publishing request; the topic publishing contract is used to instruct the blockchain node to store the topic when it verifies that the topic publishing object information belongs to the registered object information and determines that the topic has the attribute to be published; the topic stored in the blockchain node is used to instruct the second device to send a topic subscription request to the blockchain node; the signature message z is used to instruct the blockchain node to verify the legality of the topic publishing request;
[0222] The request acquisition module 17 is used to acquire the topic subscription request forwarded by the blockchain node when it is determined that the topic subscription request has the attribute of a valid request;
[0223] The relationship determination module 18 is used to determine the relationship between the first business data and the data upload conditions based on the topic subscription request forwarded by the blockchain node; the relationship between the first business data and the data upload conditions includes whether the first business data meets the data upload conditions or whether the first business data does not meet the data upload conditions.
[0224] The specific functional implementation methods of the second processing module 15, the request sending module 16, the request obtaining module 17, and the relationship determination module 18 can be found in the above description. Figure 3 Step S101 in the corresponding embodiment will not be described again here.
[0225] Please see again Figure 10 The relationship determination module 18 may include: a first generation unit 181, a request sending unit 182, and a first acquisition unit 183.
[0226] The first generation unit 181 is used to generate a remote authentication request based on the topic subscription request forwarded by the blockchain node;
[0227] The request sending unit 182 is used to send a remote authentication request to the second device, so that the second device generates an intermediate key pair g including an intermediate public key f according to the remote authentication request; the intermediate public key f is used to instruct the second device to call the trusted execution environment a to generate a remote authentication report for the data intersection application;
[0228] The first acquisition unit 183 is used to acquire the remote authentication report returned by the second device and determine the relationship between the first business data and the data upload conditions based on the remote authentication report.
[0229] The specific functional implementation of the first generation unit 181, the request sending unit 182, and the first acquisition unit 183 can be found in the above description. Figure 3 Step S101 in the corresponding embodiment will not be described again here.
[0230] Please see again Figure 10 The first acquisition unit 183 may include: a report verification subunit 1831, a first determination subunit 1832, and a second determination subunit 1833.
[0231] The report verification subunit 1831 is used to call the authentication service, verify the remote authentication report through the authentication service, and obtain the first verification result;
[0232] The first determining subunit 1832 is used to determine that the first business data does not meet the data upload conditions if the first verification result indicates that the remote authentication report verification failed.
[0233] The second determining subunit 1833 is used to obtain the source code of the data intersection application if the first verification result indicates that the remote authentication report has been verified, and determine the relationship between the first business data and the data upload conditions based on the source code.
[0234] The first acquisition unit 183 may further include: a third determination subunit 1834 and a status sending subunit 1835.
[0235] The third determining subunit 1834 is used to determine that the trusted execution environment a does not have environmental security attributes if the first verification result indicates that the remote authentication report verification failed.
[0236] The status sending subunit 1835 is used to generate a first update subscription state indicating that the trusted execution environment a does not have environment security attributes, and send the first update subscription state to the blockchain node so that the blockchain node sets the first update subscription state for the topic subscription request.
[0237] The specific functional implementation methods of the report verification subunit 1831, the first determination subunit 1832, the second determination subunit 1833, the third determination subunit 1834, and the status transmission subunit 1835 can be found in the above description. Figure 5 Step S1013 in the corresponding embodiment will not be described again here.
[0238] Please see again Figure 10 The second determining subunit 1833 may include: a first processing subunit 18331, a second processing subunit 18332, a third processing subunit 18333, and a relationship determining subunit 18334.
[0239] The first processing subunit 18331 is used to verify the source code and obtain the second verification result;
[0240] The second processing subunit 18332 is used to obtain the topic subscription object information for the data intersection application in the remote authentication report if the second verification result indicates that the source code verification is successful, perform verification processing on the topic subscription object information, and obtain the third verification result.
[0241] The third processing subunit 18333 is used to obtain the remote measurement value for the source code in the remote authentication report, perform verification processing on the remote measurement value, and obtain the fourth verification result.
[0242] The relationship determination subunit 18334 is used to determine the relationship between the first business data and the data upload conditions based on the third verification result and the fourth verification result.
[0243] The second processing subunit 18332 is also used to determine that the first business data does not meet the data upload conditions if the second verification result indicates that the source code verification failed.
[0244] The second determining subunit 1833 may further include: a state generation subunit 18335.
[0245] The second processing subunit 18332 is further configured to determine that the source code does not have code security attributes if the second verification result indicates that the source code verification has failed.
[0246] The state generation subunit 18335 is used to generate a second update subscription state indicating that the source code does not have code security attributes, and to send the second update subscription state to the blockchain node so that the blockchain node sets the second update subscription state for the topic subscription request.
[0247] The specific functional implementation methods of the first processing subunit 18331, the second processing subunit 18332, the third processing subunit 18333, the relationship determination subunit 18334, and the state generation subunit 18335 can be found above. Figure 5 Step S1013 in the corresponding embodiment will not be described again here.
[0248] Please see again Figure 10 The second processing subunit 18332 is specifically used to obtain the application development object certificate for the data intersection application, obtain the application development object information from the application development object certificate, and compare the topic subscription object information with the application development object information.
[0249] The second processing subunit 18332 is also specifically used to generate a third verification result indicating that the verification of the topic subscription object information has failed if the topic subscription object information is different from the application development object information.
[0250] The second processing subunit 18332 is also specifically used to generate a third verification result indicating that the topic subscription object information has passed verification if the topic subscription object information is the same as the application development object information.
[0251] The second processing subunit 18332 is also specifically used to generate a third update subscription status to indicate that the topic subscription object information is unauthorized object information if the third verification result indicates that the verification of the topic subscription object information fails.
[0252] The second processing subunit 18332 is also specifically used to send the third update subscription state to the blockchain node so that the blockchain node sets the third update subscription state for the topic subscription request.
[0253] The specific functional implementation of the second processing subunit 18332 can be found in the above description. Figure 5 Step S1013 in the corresponding embodiment will not be described again here.
[0254] Please see again Figure 10 The third processing subunit 18333 is specifically used to compile the source code in the trusted execution environment b of the first device to obtain a trust measurement value;
[0255] The third processing subunit 18333 is also specifically used to compare the remote metric value with the trusted metric value. If the remote metric value and the trusted metric value are different, a fourth verification result is generated to indicate that the verification of the remote metric value has failed.
[0256] The third processing subunit 18333 is also specifically used to generate a fourth verification result indicating that the remote metric value has passed verification if the remote metric value is the same as the trusted metric value.
[0257] The third processing subunit 18333 is also specifically used to generate a fourth update subscription state to indicate that the source code and the running code do not match if the fourth verification result indicates that the remote metric verification failed.
[0258] The third processing subunit 18333 is also specifically used to send the fourth update subscription state to the blockchain node so that the blockchain node sets the fourth update subscription state for the topic subscription request.
[0259] The specific functional implementation of the third processing subunit 18333 can be found in the above description. Figure 5 Step S1013 in the corresponding embodiment will not be described again here.
[0260] Please see again Figure 10 The relationship determination subunit 18334 is specifically used to determine that the first business data meets the data upload conditions if the third verification result indicates that the topic subscription object information has been verified and the fourth verification result indicates that the remote metric value has been verified.
[0261] The relationship determination subunit 18334 is also specifically used to generate a fifth update subscription status to indicate that the topic subscription request has passed verification if the first business data meets the data upload conditions;
[0262] The relation determination subunit 18334 is also specifically used to send the fifth update subscription state to the blockchain node so that the blockchain node sets the fifth update subscription state for the topic subscription request.
[0263] The specific functional implementation of the relationship-determining subunit 18334 can be found in the above. Figure 5 Step S1013 in the corresponding embodiment will not be described again here.
[0264] Please see again Figure 10 The first generation unit 181 may include a first generation subunit 1811 and a second generation subunit 1812.
[0265] The first generation subunit 1811 is used to generate an authentication challenge random number and an intermediate key pair j including an intermediate private key h and an intermediate public key i, based on the topic subscription request forwarded by the blockchain node.
[0266] The second generation subunit 1812 is used to generate a remote authentication request based on the intermediate public key i and the authentication challenge random number; the intermediate public key i is used to instruct the second device to generate a communication key based on the intermediate public key i, the authentication challenge random number and the intermediate private key k in the intermediate key pair g; the communication key is used to encrypt the data key to obtain an encrypted data key.
[0267] The first generation unit 181 may include a first acquisition subunit 1813 and a second acquisition subunit 1814.
[0268] The first acquisition subunit 1813 is used to acquire the intermediate public key f in the remote authentication report and generate a communication key based on the intermediate public key f, the authentication challenge random number and the intermediate private key h.
[0269] The second acquisition subunit 1814 is used to acquire the encrypted data key returned by the second device, and to decrypt the encrypted data key using the communication key to obtain the data key.
[0270] The specific functional implementation of the first generation subunit 1811, the second generation subunit 1812, the first acquisition subunit 1813, and the second acquisition subunit 1814 can be found above. Figure 3 Step S101 in the corresponding embodiment will not be described again here.
[0271] Please see again Figure 10 The first generation module 11 may include: a second acquisition unit 111, a second generation unit 112, a first determination unit 113, and a second determination unit 114.
[0272] The second acquisition unit 111 is used to acquire the initial bit array mapped with the first random number and the random mapping function, and input the first business data into the random mapping function;
[0273] The second generation unit 112 is used to generate a second random number corresponding to the first business data through a random mapping function; the first random number includes the second random number.
[0274] The first determining unit 113 is used to determine the bit array to be updated from the initial bit array; the bit array to be updated is mapped with a second random number;
[0275] The second determining unit 114 is used to update the bit array to be updated in the initial bit array and determine the updated initial bit array as the first bit array.
[0276] The specific functional implementation of the second acquisition unit 111, the second generation unit 112, the first determination unit 113, and the second determination unit 114 can be found in the above description. Figure 3 Step S101 in the corresponding embodiment will not be described again here.
[0277] In this embodiment, by generating the first bit array corresponding to the first business data, the first business data can be ensured to be available but not visible, thus improving its security. Furthermore, since the data key is generated through the data intersection application in the trusted execution environment a, its generation environment, application environment, and storage environment are all secure. Therefore, encrypting the first bit array with the data key further enhances its security. Moreover, by transmitting the ciphertext bit array to the blockchain, the acquisition status of the second device for the ciphertext bit array can be accurately traced. In addition, this embodiment determines the business intersection data between the first and second business data using the first bit array and the second bit array corresponding to the second business data. Therefore, not only can business processing associated with the business intersection data be performed, but the security of the first business data is further improved. As can be seen from the above, by adopting this embodiment, the security of data (including the first business data and the first bit array) can be improved, and the data acquisition status can be accurately traced.
[0278] Further, please see Figure 11 , Figure 11 This is a second schematic diagram of the structure of a blockchain-based data processing device provided in an embodiment of this application. The aforementioned blockchain-based data processing device 2 can operate on a second device, and this device can be used to execute the corresponding steps in the method provided in the embodiments of this application. For example... Figure 11 As shown, the blockchain-based data processing device 2 may include: a ciphertext acquisition module 21, a first processing module 22, a first generation module 23, and a second processing module 24.
[0279] The ciphertext acquisition module 21 is used to acquire the ciphertext bit array forwarded by the blockchain node in the blockchain; the ciphertext bit array is transmitted from the first device to the blockchain node, and the ciphertext bit array is obtained by the first device encrypting the first bit array with the data key generated by the second device in the data intersection application; the data intersection application runs in the trusted execution environment a of the second device; the first bit array is generated by the first device for the first business data when the first business data meets the data upload conditions;
[0280] The first processing module 22 is used to decrypt the ciphertext bit array obtained from the blockchain node using the data key in the data intersection application to obtain the first bit array;
[0281] The first generation module 23 is used to generate a second bit array corresponding to the second business data in the data intersection application, and determine the business intersection data between the first business data and the second business data based on the second bit array and the first bit array.
[0282] The second processing module 24 is used to perform business processing on the business intersection data.
[0283] The specific functional implementation of the ciphertext acquisition module 21, the first processing module 22, the first generation module 23, and the second processing module 24 can be found in the above description. Figure 7 Steps S201-S204 in the corresponding embodiment will not be described again here.
[0284] Please see again Figure 11 The ciphertext acquisition module 21 may include: a request generation unit 211, a request sending unit 212, and a ciphertext acquisition unit 213.
[0285] The request generation unit 211 is used to generate a data download request for obtaining the ciphertext bit array based on the topic subscription object information;
[0286] The request sending unit 212 is used to send a data download request to the blockchain node so that the blockchain node can query the current subscription status corresponding to the topic subscription object information based on the data download request.
[0287] The ciphertext acquisition unit 213 is used to acquire the ciphertext bit array returned by the blockchain node when it determines that the current subscription state is the fifth update subscription state; the fifth update subscription state is used to indicate that the first device has passed the verification of the topic subscription request; the topic subscription request is sent when the blockchain node stores the topic for the first business data.
[0288] The specific functional implementation of the request generation unit 211, the request sending unit 212, and the ciphertext acquisition unit 213 can be found in the above description. Figure 7 Step S201 in the corresponding embodiment will not be described again here.
[0289] Please see again Figure 11 The second business data includes the second business data C. d d is a positive integer, and d is less than or equal to the total number of second business data; the second bit array includes the second business data C. d The corresponding second array E d ;
[0290] The first generation module 23 is specifically used if the first array includes the second array E. d Then determine the second business data C d This refers to the business intersection data between the first business data and the second business data.
[0291] The second processing module 24 is specifically used to obtain media data with application recommendation function provided by the first device and push the media data to the second service data C. d .
[0292] The specific functional implementation of the first generation module 23 and the second processing module 24 can be found in the above description. Figure 7 Steps S203-S204 in the corresponding embodiment will not be described again here.
[0293] Please see again Figure 11 The blockchain-based data processing device 2 may also include: a second generation module 25, a contract invocation module 26, and a request sending module 27.
[0294] The second generation module 25 is used to generate a topic subscription request for subscribing to a topic based on the topic subscription object information; the topic is generated by the first device for the first business data;
[0295] Contract invocation module 26 is used to invoke the subscription topic contract of the blockchain node based on the topic subscription request;
[0296] The request sending module 27 is used to send a topic subscription request to the blockchain node through the topic subscription contract, so that when the blockchain node verifies that the topic has the attribute to be subscribed and that the topic subscription object information belongs to the registered object information through the topic subscription contract, it stores the topic subscription request and sets the topic subscription request to a request pending verification status; the request pending verification status is used to instruct the blockchain node to forward the topic subscription request to the first device.
[0297] The specific functional implementations of the second generation module 25, the contract invocation module 26, and the request sending module 27 can be found above. Figure 7 Step S201 in the corresponding embodiment will not be described again here.
[0298] In this embodiment, by generating the first bit array corresponding to the first business data, the first business data can be ensured to be available but not visible, thus improving its security. Furthermore, since the data key is generated through the data intersection application in the trusted execution environment a, its generation environment, application environment, and storage environment are all secure. Therefore, encrypting the first bit array with the data key further enhances its security. Moreover, by transmitting the ciphertext bit array to the blockchain, the acquisition status of the second device for the ciphertext bit array can be accurately traced. In addition, this embodiment determines the business intersection data between the first and second business data using the first bit array and the second bit array corresponding to the second business data. Therefore, not only can business processing associated with the business intersection data be performed, but the security of the first business data is further improved. As can be seen from the above, by adopting this embodiment, the security of data (including the first business data and the first bit array) can be improved, and the data acquisition status can be accurately traced.
[0299] Further, please see Figure 12 , Figure 12 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 12 As shown, the computer device 1000 may include: at least one processor 1001, such as a CPU; at least one network interface 1004; a user interface 1003; a memory 1005; and at least one communication bus 1002. The communication bus 1002 is used to enable communication between these components. In some embodiments, the user interface 1003 may include a display screen and a keyboard, and the network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be high-speed RAM or non-volatile memory, such as at least one disk storage device. Optionally, the memory 1005 may also be at least one storage device located remotely from the aforementioned processor 1001. Figure 12 As shown, the memory 1005, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a device control application program.
[0300] exist Figure 12 In the computer device 1000 shown, the network interface 1004 provides network communication functionality; the user interface 1003 is mainly used to provide an input interface for the user; and the processor 1001 can be used to call the device control application stored in the memory 1005 to achieve:
[0301] If the first business data meets the data upload conditions, then the first element array corresponding to the first business data is generated;
[0302] The first bit array is encrypted using the data key generated by the second device in the data intersection application to obtain the ciphertext bit array; the data intersection application runs in the trusted execution environment a of the second device;
[0303] The ciphertext bit array is transmitted to a blockchain node in the blockchain so that the blockchain node stores the ciphertext bit array; the ciphertext bit array stored in the blockchain node is used by the blockchain node to forward to a second device; the second device is used in the data intersection application to decrypt the ciphertext bit array obtained from the blockchain node using a data key to obtain a first bit array; the first bit array is used to instruct the second device in the data intersection application to generate a second bit array corresponding to the second business data; the second bit array and the first bit array are used to instruct the second device in the data intersection application to determine the business intersection data between the first business data and the second business data; the business intersection data is used to instruct the second device to perform business processing associated with the business intersection data.
[0304] Alternatively, processor 1001 can be used to call the device control application stored in memory 1005 to achieve:
[0305] Obtain the ciphertext bit array forwarded by the blockchain node in the blockchain; the ciphertext bit array is transmitted from the first device to the blockchain node, and the ciphertext bit array is obtained by the first device encrypting the first bit array with the data key generated by the second device in the data intersection application; the data intersection application runs in the trusted execution environment a of the second device; the first bit array is generated by the first device for the first business data when the first business data meets the data upload conditions;
[0306] In data intersection applications, the ciphertext bit array obtained from the blockchain node is decrypted using the data key to obtain the first bit array;
[0307] In the data intersection application, a second bit array corresponding to the second business data is generated. Based on the second bit array and the first bit array, the business intersection data between the first business data and the second business data is determined.
[0308] Perform business processing on data that intersects with business operations.
[0309] It should be understood that the computer device 1000 described in the embodiments of this application can perform the data processing methods or apparatus based on blockchain described in the preceding embodiments, and will not be repeated here. In addition, the beneficial effects of using the same method will also not be repeated.
[0310] This application also provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the blockchain-based data processing methods or apparatus described in the preceding embodiments, which will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.
[0311] The aforementioned computer-readable storage medium can be the internal storage unit of the blockchain-based data processing apparatus provided in any of the foregoing embodiments or the computer device, such as the hard drive or memory of the computer device. The computer-readable storage medium can also be an external storage device of the computer device, such as a plug-in hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device. Furthermore, the computer-readable storage medium can include both internal and external storage units of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.
[0312] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium and executes the computer program, enabling the computer device to perform the blockchain-based data processing methods or apparatus described in the preceding embodiments, which will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.
[0313] The terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other step units inherent to these processes, methods, apparatuses, products, or devices.
[0314] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0315] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.
Claims
1. A data processing method based on blockchain, characterized in that, The method is performed by a first device, and the method includes: Generate a topic for the first business data, and generate a topic publishing request that includes the topic and topic publishing object information; Using the device private key corresponding to the first device, the topic publishing request is signed to obtain a signed message z. Based on the topic publishing request, the topic publishing contract of the blockchain node is invoked. The topic publishing contract sends the topic publishing request carrying the signature message z to the blockchain node, so that the blockchain node invokes the topic publishing contract when it passes the legality verification of the topic publishing request. The topic publishing contract instructs the blockchain node to store the topic when it verifies that the topic publishing object information belongs to the registered object information and determines that the topic has the attribute to be published. The topic stored in the blockchain node is used to instruct the second device to send a topic subscription request to the blockchain node. The signature message z instructs the blockchain node to perform legality verification on the topic publishing request. Obtain the topic subscription request forwarded by the blockchain node when it determines that the topic subscription request has a valid request attribute; Based on the topic subscription request forwarded by the blockchain node, determine the relationship between the first business data and the data upload conditions; If the first business data meets the data upload conditions, then the first element array corresponding to the first business data is generated; The first bit array is encrypted using the data key generated by the second device in the data intersection application to obtain a ciphertext bit array; the data intersection application runs in the trusted execution environment a of the second device. The ciphertext bit array is transmitted to a blockchain node in the blockchain so that the blockchain node stores the ciphertext bit array; the ciphertext bit array stored in the blockchain node is used by the blockchain node to forward to the second device; the second device is used in the data intersection application to decrypt the ciphertext bit array obtained from the blockchain node using the data key to obtain the first bit array; the first bit array is used to instruct the second device in the data intersection application to generate a second bit array corresponding to the second business data; the second bit array and the first bit array are used to instruct the second device in the data intersection application to determine the business intersection data between the first business data and the second business data; the business intersection data is used to instruct the second device to perform business processing associated with the business intersection data.
2. The method according to claim 1, characterized in that, Determining the relationship between the first business data and the data upload conditions based on the topic subscription request forwarded by the blockchain node includes: A remote authentication request is generated based on the topic subscription request forwarded by the blockchain node; The remote authentication request is sent to the second device, so that the second device generates an intermediate key pair g including an intermediate public key f according to the remote authentication request; the intermediate public key f is used to instruct the second device to invoke the trusted execution environment a to generate a remote authentication report for the data intersection application; Obtain the remote authentication report returned by the second device, and determine the relationship between the first business data and the data upload conditions based on the remote authentication report.
3. The method according to claim 2, characterized in that, Determining the relationship between the first business data and the data upload conditions based on the remote authentication report includes: The authentication service is invoked, and the remote authentication report is verified through the authentication service to obtain a first verification result; If the first verification result indicates that the remote authentication report verification failed, then it is determined that the first business data does not meet the data upload conditions; If the first verification result indicates that the remote authentication report has passed verification, then obtain the source code of the data intersection application, and determine the relationship between the first business data and the data upload conditions based on the source code; The method further includes: If the first verification result indicates that the remote authentication report verification failed, then it is determined that the trusted execution environment a does not have environmental security attributes; A first update subscription state is generated to indicate that the trusted execution environment a does not have the environment security attribute, and the first update subscription state is sent to the blockchain node so that the blockchain node sets the first update subscription state for the topic subscription request.
4. The method according to claim 3, characterized in that, Determining the relationship between the first business data and the data upload conditions based on the source code includes: The source code is verified to obtain a second verification result; If the second verification result indicates that the source code verification is successful, then obtain the topic subscription object information for the data intersection application in the remote authentication report, perform verification processing on the topic subscription object information, and obtain the third verification result; Obtain the remote metric value for the source code from the remote authentication report, perform verification processing on the remote metric value, and obtain the fourth verification result; Based on the third verification result and the fourth verification result, determine the relationship between the first business data and the data upload conditions; If the second verification result indicates that the source code verification failed, then it is determined that the first business data does not meet the data upload conditions; The method further includes: If the second verification result indicates that the source code verification failed, then it is determined that the source code does not have code security attributes; A second update subscription state is generated to indicate that the source code does not have the code security attribute, and the second update subscription state is sent to the blockchain node so that the blockchain node sets the second update subscription state for the topic subscription request.
5. The method according to claim 4, characterized in that, The verification process for the topic subscription object information, to obtain a third verification result, includes: Obtain the application development object certificate for the data intersection application, retrieve the application development object information from the application development object certificate, and compare the topic subscription object information with the application development object information; If the topic subscription object information is different from the application development object information, a third verification result is generated to indicate that the verification of the topic subscription object information has failed. If the topic subscription object information is the same as the application development object information, a third verification result is generated to indicate that the topic subscription object information has passed verification; The method further includes: If the third verification result indicates that the verification of the topic subscription object information fails, a third update subscription status is generated to indicate that the topic subscription object information is unauthorized object information; The third update subscription status is sent to the blockchain node so that the blockchain node sets the third update subscription status for the topic subscription request.
6. The method according to claim 4, characterized in that, The verification process for the remote metric value, resulting in a fourth verification result, includes: The source code is compiled in the trusted execution environment b of the first device to obtain a trust metric value; The remote metric value is compared with the trusted metric value. If the remote metric value is different from the trusted metric value, a fourth verification result is generated to indicate that the verification of the remote metric value has failed. If the remote metric value is the same as the trusted metric value, a fourth verification result is generated to indicate that the remote metric value has passed verification. The method further includes: If the fourth verification result indicates that the remote metric verification failed, a fourth update subscription state is generated to indicate that the source code and the running code do not match. The fourth update subscription status is sent to the blockchain node so that the blockchain node sets the fourth update subscription status for the topic subscription request.
7. The method according to claim 4, characterized in that, Determining the relationship between the first business data and the data upload conditions based on the third verification result and the fourth verification result includes: If the third verification result indicates that the topic subscription object information has been verified successfully, and the fourth verification result indicates that the remote metric has been verified successfully, then it is determined that the first business data meets the data upload conditions. The method further includes: If the first business data meets the data upload conditions, a fifth update subscription status is generated to indicate that the topic subscription request has passed verification; The fifth update subscription status is sent to the blockchain node so that the blockchain node sets the fifth update subscription status for the topic subscription request.
8. The method according to claim 2, characterized in that, The step of generating a remote authentication request based on the topic subscription request forwarded by the blockchain node includes: Based on the topic subscription request forwarded by the blockchain node, an authentication challenge random number is generated, as well as an intermediate key pair j including an intermediate private key h and an intermediate public key i; A remote authentication request is generated based on the intermediate public key i and the authentication challenge random number; the intermediate public key i is used to instruct the second device to generate a communication key based on the intermediate public key i, the authentication challenge random number, and the intermediate private key k in the intermediate key pair g; the communication key is used to encrypt the data key to obtain an encrypted data key. The method further includes: Obtain the intermediate public key f from the remote authentication report, and generate the communication key based on the intermediate public key f, the authentication challenge random number, and the intermediate private key h; Obtain the encrypted data key returned by the second device, and decrypt the encrypted data key using the communication key to obtain the data key.
9. The method according to claim 1, characterized in that, The step of generating the first array corresponding to the first business data includes: Obtain an initial bit array with a first random number and a random mapping function, and input the first business data into the random mapping function; The random mapping function generates a second random number corresponding to the first business data; the first random number includes the second random number. A bit array to be updated is determined from the initial bit array; the bit array to be updated is mapped to the second random number. The bit array to be updated in the initial bit array is updated, and the updated initial bit array is determined as the first bit array.
10. A data processing method based on blockchain, characterized in that, The method is performed by a second device, and the method includes: Based on the topic subscription object information, generate a data download request to obtain the ciphertext bit array; The data download request is sent to the blockchain node, so that the blockchain node can query the current subscription status corresponding to the topic subscription object information based on the data download request; The method involves obtaining the ciphertext bit array returned by the blockchain node when it determines that the current subscription state is the fifth update subscription state; the fifth update subscription state is used to indicate that the first device has passed the verification of the topic subscription request; the topic subscription request is sent when the blockchain node stores the topic for the first business data; the ciphertext bit array is transmitted from the first device to the blockchain node, and the ciphertext bit array is obtained by the first device encrypting the first bit array using the data key generated by the second device in the data intersection application; the data intersection application runs in the trusted execution environment a of the second device; the first bit array is generated by the first device for the first business data when the first business data meets the data upload conditions; In the data intersection application, the ciphertext bit array obtained from the blockchain node is decrypted using the data key to obtain the first bit array; In the data intersection application, a second bit array corresponding to the second business data is generated, and the business intersection data between the first business data and the second business data is determined based on the second bit array and the first bit array. Perform business processing on the data that intersects with the business data.
11. The method according to claim 10, characterized in that, The second business data includes second business data C d d is a positive integer, and d is less than or equal to the total number of the second business data; the second bit array includes the second business data C. d The corresponding second array E d ; The step of determining the business intersection data between the first business data and the second business data based on the second bit array and the first bit array includes: If the first bit array includes the second bit array E d Then determine the second business data C d This refers to the business intersection data between the first business data and the second business data; The business processing of the business intersection data includes: Obtain media data with application recommendation function provided by the first device, and push the media data to the second service data C. d .
12. The method according to claim 10, characterized in that, The method further includes: Based on the topic subscription object information, a topic subscription request is generated for subscribing to the topic; the topic is generated by the first device in response to the first service data. Based on the topic subscription request, the topic subscription contract of the blockchain node is invoked; The topic subscription request is sent to the blockchain node through the topic subscription contract. When the blockchain node verifies that the topic has a subscribed attribute and that the topic subscription object information belongs to the registered object information, it stores the topic subscription request and sets a request pending verification status for the topic subscription request. The request pending verification status is used to instruct the blockchain node to forward the topic subscription request to the first device.
13. A data processing device based on blockchain, characterized in that, The device operates in the first device, and the device includes: The first generation module is used to generate a topic for the first business data and generate a topic publishing request that includes the topic and topic publishing object information. The first generation module is further configured to sign the topic publishing request using the device private key corresponding to the first device to obtain a signed message z, and to call the topic publishing contract of the blockchain node based on the topic publishing request; The first generation module is further configured to send the topic publishing request carrying the signature message z to the blockchain node through the topic publishing contract, so that the blockchain node invokes the topic publishing contract when verifying the legality of the topic publishing request; the topic publishing contract is configured to instruct the blockchain node to store the topic when verifying that the topic publishing object information belongs to the registered object information and determining that the topic has a publishing attribute; the topic stored in the blockchain node is configured to instruct the second device to send a topic subscription request to the blockchain node; the signature message z is configured to instruct the blockchain node to perform legality verification on the topic publishing request; The first generation module is further configured to obtain the topic subscription request forwarded by the blockchain node when it determines that the topic subscription request has a valid request attribute; The first generation module is further configured to determine the relationship between the first business data and the data upload conditions based on the topic subscription request forwarded by the blockchain node; The first generation module is further configured to generate the first bit array corresponding to the first business data if the first business data meets the data upload conditions; The first processing module is used to encrypt the first bit array using the data key generated by the second device in the data intersection application to obtain a ciphertext bit array; the data intersection application runs in the trusted execution environment a of the second device. A ciphertext transmission module is used to transmit the ciphertext bit array to a blockchain node in the blockchain, so that the blockchain node stores the ciphertext bit array; the ciphertext bit array stored in the blockchain node is used to be forwarded by the blockchain node to the second device; the second device is used to decrypt the ciphertext bit array obtained from the blockchain node using the data key in the data intersection application to obtain the first bit array; the first bit array is used to instruct the second device to generate a second bit array corresponding to the second business data in the data intersection application; the second bit array and the first bit array are used to instruct the second device to determine the business intersection data between the first business data and the second business data in the data intersection application; the business intersection data is used to instruct the second device to perform business processing associated with the business intersection data.
14. A data processing device based on blockchain, characterized in that, The device operates in a second device, and the device includes: The ciphertext acquisition module is used to generate a data download request for obtaining the ciphertext bit array based on the topic subscription object information; The encrypted acquisition module is also used to send the data download request to the blockchain node, so that the blockchain node can query the current subscription status corresponding to the topic subscription object information according to the data download request; The ciphertext acquisition module is further configured to acquire the ciphertext bit array returned by the blockchain node when it determines that the current subscription state is the fifth update subscription state; the fifth update subscription state is used to indicate that the first device has passed the verification of the topic subscription request; the topic subscription request is sent when the blockchain node stores the topic for the first business data; the ciphertext bit array is transmitted from the first device to the blockchain node, and the ciphertext bit array is obtained by the first device encrypting the first bit array using the data key generated by the second device in the data intersection application; the data intersection application runs in the trusted execution environment a of the second device; the first bit array is generated by the first device for the first business data when the first business data meets the data upload conditions; The first processing module is used to decrypt the ciphertext bit array obtained from the blockchain node using the data key in the data intersection application to obtain the first bit array. The first generation module is used to generate a second bit array corresponding to the second business data in the data intersection application, and determine the business intersection data between the first business data and the second business data based on the second bit array and the first bit array. The second processing module is used to perform business processing on the business intersection data.
15. A computer device, characterized in that, include: Processor, memory, and network interface; The processor is connected to the memory and the network interface, wherein the network interface is used to provide data communication functions, the memory is used to store computer programs, and the processor is used to invoke the computer programs to cause the computer device to perform the method according to any one of claims 1 to 12.
16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded and executed by a processor to cause a computer device having the processor to perform the method of any one of claims 1-12.
17. A computer program product, characterized in that, The computer program product includes a computer program stored in a computer-readable storage medium, the computer program being adapted to be read and executed by a processor to cause a computer device having the processor to perform the method of any one of claims 1-12.
Citation Information
Patent Citations
Data processing method, device and equipment and storage medium
CN112711774A
Privacy set intersection method and device based on bloom filter and storage medium
CN114444124A