A data processing method, device, apparatus, and computer-readable storage medium

By performing data signature verification and time range verification at the core account layer, the problem of low security of business accounts is solved, and efficient and accurate transaction data verification is achieved to prevent unauthorized transactions.

CN118917843BActive Publication Date: 2026-07-24TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TENCENT TECHNOLOGY (SHENZHEN) CO LTD
Filing Date
2023-05-08
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

In existing technologies, business accounts have low security, and the verification of transaction legitimacy and the processing of resource transfers are independent of each other, leading to security risks, as well as low verification efficiency and accuracy.

Method used

The transaction data is sent from the business server to the core account layer for signature verification. The legality is verified by combining the transaction time range. The data signature and transaction data are stored in the core account database. The verification device verifies the legality of the transaction data based on the data signature.

Benefits of technology

It improves the security of business accounts, enhances the efficiency and accuracy of transaction data verification, and prevents the execution of unauthorized transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118917843B_ABST
    Figure CN118917843B_ABST
Patent Text Reader

Abstract

The application discloses a data processing method, device and equipment and a computer readable storage medium. The method comprises the following steps: at a first time, sending transaction data initiated by a business account to a core account layer; performing signature verification on the data signature in the core account layer to obtain a verification result; if the verification result is a successful verification result, performing legality verification on the business transaction according to the first time and a verification transaction time range to obtain a verification result; if the verification result indicates that the business transaction is legal, storing the first time and the transaction data carrying the data signature in a core account database corresponding to the core account layer; the data signature and the transaction data stored in the core account database are used to be sent to a verification device; and the verification device is used to verify the legality of the transaction data according to the data signature. By using the application, the security of the business account can be improved, and the verification efficiency and accuracy of the transaction data can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet technology, and in particular to a data processing method, apparatus, device, and computer-readable storage medium. Background Technology

[0002] In today's era of information-based and electronic business systems, the security of business accounts has become one of the key areas of protection for various business organizations.

[0003] In existing technologies, business entities typically verify transaction passwords or signatures for their business accounts through a transaction layer or business layer. Then, the transaction layer or business layer sends a resource transfer instruction for the business transaction to the core account layer. Since the core account layer trusts the resource transfer instruction sent by the transaction layer or business layer, it processes the resource transfer. Clearly, in existing technologies, the verification of transaction legitimacy and the processing of resource transfers for business accounts are independent of each other, which can lead to security vulnerabilities for business accounts. For example, in scenarios where the business account is not authorized, the business entity or malicious actors could modify the account data or perform resource transfers. Therefore, existing technologies reduce the security of business accounts. Furthermore, in subsequent transaction verification, existing technologies require verification of all transactions of the business account, resulting in a long evidence-gathering chain, low verification efficiency, and low accuracy. Summary of the Invention

[0004] This application provides a data processing method, apparatus, device, and computer-readable storage medium, which can not only improve the security of business accounts, but also improve the verification efficiency and accuracy of transaction data.

[0005] One embodiment of this application provides a data processing method, which is executed by a business server, including:

[0006] In the first instant, the transaction data initiated by the business account is sent to the core account layer; the transaction data includes the business transaction and the corresponding verification transaction time range, and the transaction data carries a data signature;

[0007] In the core account layer, the data signature is verified to obtain the verification result. If the verification result is successful, the legality of the business transaction is verified based on the first moment and the time range of the verification transaction to obtain the verification result.

[0008] If the verification result indicates that the business transaction is legitimate, the transaction data along with the data signature will be stored in the core account database corresponding to the core account layer. The data signature and transaction data stored in the core account database are both sent to the verification device. The verification device is used to verify the legitimacy of the transaction data based on the data signature.

[0009] One embodiment of this application provides a data processing method, which is executed by a verification device, including:

[0010] Obtain the transaction verification request for the business account, and generate a transaction acquisition request for the business account based on the transaction verification request;

[0011] A transaction retrieval request is sent to the business server, which then retrieves the business account's data to be verified from the core account database corresponding to the core account layer. The data to be verified includes transaction data initiated by the business account. The transaction data includes the business transaction and the corresponding verification transaction time range. The verification transaction time range is used to instruct the business server to verify the legality of the business transaction.

[0012] Obtain the data to be verified returned by the business server. If the data to be verified does not include the data signature of the transaction data, then the transaction data is determined to be illegal transaction data.

[0013] If the data to be verified includes the data signature of the transaction data, then the legality of the transaction data is verified based on the data signature.

[0014] One embodiment of this application provides a data processing method, which is executed by a business terminal, including:

[0015] In the business account, respond to the completion operation for the business transaction and determine the time range for verifying the legality of the business transaction;

[0016] A data signature is generated for the transaction data. The transaction data includes the business transaction and the time range for verifying the transaction. The transaction data carrying the data signature is sent to the business server via the business account, so that the business server immediately sends the transaction data carrying the data signature to the core account layer. The core account layer verifies the data signature and obtains the verification result. The verification result includes a successful verification result. The verification result instructs the core account layer to verify the legality of the business transaction based on the immediate time and the time range for verifying the transaction, obtaining a verification result. The verification result includes a valid verification result. The valid verification result instructs the core account layer to associate and store the transaction data carrying the data signature in the core account database. Both the data signature and the transaction data stored in the core account database are sent to the verification device. The verification device verifies the legality of the transaction data based on the data signature.

[0017] One embodiment of this application provides a data processing apparatus, which operates on a business server and includes:

[0018] The data sending module is used to send transaction data initiated by the business account to the core account layer at the first moment; the transaction data includes the business transaction and the corresponding verification transaction time range, and the transaction data carries a data signature;

[0019] The transaction verification module is used to verify data signatures in the core account layer and obtain the verification result. If the verification result is successful, the legality of the business transaction is verified based on the first moment and the time range of the verification transaction, and the verification result is obtained.

[0020] The first storage module is used to associate and store the transaction data carrying the data signature with the transaction data at the first moment in the core account database corresponding to the core account layer if the verification result indicates that the business transaction is legitimate. The data signature and transaction data stored in the core account database are both sent to the verification device. The verification device is used to verify the legitimacy of the transaction data based on the data signature.

[0021] The transaction verification module includes:

[0022] The relationship identification unit is used to identify the relationship between the first moment and the transaction verification time range; the earliest moment of the transaction verification time range is equal to the second moment when the business terminal bound to the business account responds to the completion operation for the business transaction; the latest moment of the transaction verification time range is later than the second moment.

[0023] The first determining unit is used to determine the verification result as the verification result for the legality verification of the business transaction if the relationship between the first moment and the verification transaction time range is that the first moment is within the verification transaction time range; the verification result is used to indicate that the business transaction is legal.

[0024] The second determining unit is used to determine the invalid verification result as the verification result for the legality verification of the business transaction if the relationship between the first moment and the time range of the verification transaction is that the first moment is later than the latest moment; the invalid verification result is used to indicate that the business transaction is not legal.

[0025] The first storage module includes:

[0026] The first acquisition unit is used to acquire the current digital resources of the business account from the core account database corresponding to the core account layer.

[0027] The second acquisition unit is used to acquire the resource transfer value in the business transaction. If the current digital resource contains the digital resource to be transferred corresponding to the resource transfer value, the digital resource to be transferred in the current digital resource is processed for resource transfer, and the current digital resource after resource transfer is determined as the updated digital resource.

[0028] The data storage unit is used to associate and store real-time, updated digital resources and transaction data with data signatures into the core account database.

[0029] The transaction verification module includes:

[0030] The third acquisition unit is used to obtain the business public key of the business account from the core account database, and to perform signature verification processing on the data signature using the business public key to obtain the first digital digest;

[0031] The summary generation unit is used to generate a second digital summary of the transaction data, and compare the first digital summary with the second digital summary to obtain a comparison result;

[0032] The third determining unit is used to determine the signature success result as the signature verification result if the comparison result indicates that the first digital digest and the second digital digest are the same; the signature success result is also used to indicate that the data signature is obtained by a business terminal bound to a business account, which signs the transaction data using the business private key of the business account.

[0033] The fourth determining unit is used to determine the signature verification failure result as the signature verification result if the comparison result indicates that the first digital digest is different from the second digital digest.

[0034] The data processing device also includes:

[0035] The request acquisition module is used to acquire a certificate application request initiated by the business terminal at a third time point earlier than the first time point. The certificate application request includes the business account and the business public key of the business account. The business public key is generated by the business terminal when applying for the business account.

[0036] The certificate generation module is used to generate a business certificate for a business account based on a certificate application request and return the business certificate to the business terminal; the business certificate is used to indicate to the business terminal that the business account application was successful.

[0037] The second storage module is used to associate and store business public keys and business accounts in the core account database.

[0038] One embodiment of this application provides a data processing apparatus, which operates on a verification device, including:

[0039] The request generation module is used to obtain transaction verification requests for business accounts and generate transaction acquisition requests for business accounts based on the transaction verification requests.

[0040] The request sending module is used to send a transaction retrieval request to the business server, so that the business server can retrieve the data to be verified of the business account from the core account database corresponding to the core account layer according to the transaction retrieval request; the data to be verified includes transaction data initiated by the business account; the transaction data includes the business transaction and the corresponding verification transaction time range; the verification transaction time range is used to instruct the business server to verify the legality of the business transaction;

[0041] The data determination module is used to obtain the data to be verified returned by the business server. If the data to be verified does not include the data signature of the transaction data, the transaction data is determined to be illegal transaction data.

[0042] The data verification module is used to verify the legality of transaction data based on the data signature if the data to be verified includes a data signature of transaction data.

[0043] The data verification module includes:

[0044] The public key acquisition unit is used to obtain the first business public key of the business account from the data to be verified, and to obtain the second business public key; the second business public key refers to the business public key provided by the business terminal bound to the business account, or the business public key obtained from the blockchain that is bound to the business account.

[0045] The public key comparison unit is used to compare the first business public key with the second business public key to obtain the comparison result;

[0046] The first determining unit is used to determine that the transaction data is illegal transaction data if the comparison result indicates that the first business public key is different from the second business public key;

[0047] The signature verification unit is used to perform signature verification processing on the transaction signature based on the first business public key if the comparison result indicates that the first business public key is the same as the second business public key, and to obtain the signature verification result.

[0048] The second determining unit is used to determine that the transaction data is illegal transaction data if the signature verification result is a signature verification failure result;

[0049] The third determining unit is used to determine that the transaction data is legitimate if the verification result is successful.

[0050] One embodiment of this application provides a data processing apparatus, which operates on a business terminal and includes:

[0051] The time determination module is used to respond to the completion operation of a business transaction in the business account and determine the time range of the verification transaction used to verify the legality of the business transaction;

[0052] The first generation module is used to generate data signatures for transaction data; the transaction data includes business transactions and the time range for verifying transactions.

[0053] The first sending module is used to send transaction data carrying a data signature to the business server through the business account, so that the business server sends the transaction data carrying the data signature to the core account layer at the first moment. The core account layer is used to verify the data signature and obtain the verification result. The verification result includes a successful verification result. The verification result is used to instruct the core account layer to perform legality verification on the business transaction according to the first moment and the verification transaction time range, and obtain a verification result. The verification result includes a legal verification result. The legal verification result is used to instruct the core account layer to associate and store the transaction data carrying the data signature at the first moment in the core account database. The data signature and transaction data stored in the core account database are both sent to the verification device. The verification device is used to verify the legality of the transaction data according to the data signature.

[0054] The time determination module includes:

[0055] The first determining unit is used to determine the second moment of the response to the completion operation of the business transaction as the earliest moment;

[0056] The first acquisition unit is used to acquire the verification transaction time threshold, and sum the earliest time and the verification transaction time threshold to obtain the latest time.

[0057] The first generation unit is used to generate a time range for verifying transactions, including the earliest and latest times.

[0058] The data processing device also includes:

[0059] The second generation module is used to generate business private keys and business public keys when applying for a business account.

[0060] The second sending module is used to generate a certificate application request including the business account and the business public key, and send the certificate application request to the business server so that the business server can generate a business certificate for the business account according to the certificate application request;

[0061] The certificate acquisition module is used to obtain the business certificate returned by the business server; the business certificate is used to indicate that the business terminal has successfully applied for a business account.

[0062] The first generation module includes:

[0063] The second generation unit is used to generate transaction data, including business transactions and the time range for verifying transactions.

[0064] The second acquisition unit is used to acquire the business private key, and then use the business private key to sign the transaction data to obtain the data signature of the transaction data.

[0065] This application provides a computer device, including: a processor, a memory, and a network interface;

[0066] The processor is connected to the memory and the network interface, wherein the network interface is used to provide data communication functions, the memory is used to store computer programs, and the processor is used to call the computer programs so that the computer device executes the methods in the embodiments of this application.

[0067] One aspect of this application provides a computer-readable storage medium storing a computer program adapted for loading by a processor and executing the methods described in this application.

[0068] One aspect of this application provides a computer program product, which includes a computer program stored in a computer-readable storage medium; a processor of a computer device reads the computer program from the computer-readable storage medium and executes the computer program, causing the computer device to perform the method described in this application.

[0069] In this embodiment, the business server sends transaction data initiated by the business account to the core account layer at a first moment. The transaction data includes the business transaction and the corresponding verification transaction time range, and carries a data signature. In the core account layer, the business server can verify the data signature to obtain a verification result. If the verification result is successful, the business transaction is validated for legality based on the first moment and the verification transaction time range, yielding a verification result. Further, if the verification result indicates that the business transaction is legal, the business server associates and stores the transaction data with the data signature at the first moment in the core account database corresponding to the core account layer. Both the data signature and the transaction data stored in the core account database are sent to the verification device. The verification device verifies the legality of the transaction data based on the data signature. As can be seen, the business server directly sends the transaction data with the data signature to the core account layer, and the core account layer verifies the legality of the business transaction through the data signature and the verification transaction time range. Therefore, in scenarios without business account authorization, the core account layer will not recognize the business transaction and will not execute it, thus improving the security of the business account. In addition, by using data signatures, verification devices can verify the legality of transaction data, thus improving the efficiency and accuracy of transaction data verification. Attached Figure Description

[0070] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0071] Figure 1 This is a schematic diagram of a system architecture provided in an embodiment of this application;

[0072] Figure 2 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 1 ;

[0073] Figure 3 This is a schematic diagram of a data processing scenario provided in an embodiment of this application. Figure 1 ;

[0074] Figure 4 This is a schematic diagram of a data processing scenario provided in an embodiment of this application. Figure 2 ;

[0075] Figure 5 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 2 ;

[0076] Figure 6 This is an interactive illustration of a data processing method provided in an embodiment of this application. Figure 1 ;

[0077] Figure 7 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 3 ;

[0078] Figure 8 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 4 ;

[0079] Figure 9 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 5 ;

[0080] Figure 10 This is an interactive illustration of a data processing method provided in an embodiment of this application. Figure 2 ;

[0081] Figure 11 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 1 ;

[0082] Figure 12This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 2 ;

[0083] Figure 13 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 3 ;

[0084] Figure 14 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0085] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0086] Please see Figure 1 , Figure 1 This is a schematic diagram of a system architecture provided in an embodiment of this application. For example... Figure 1 As shown, the system architecture may include a business server 100, a verification device cluster, and a terminal device cluster. It is understood that the aforementioned terminal device cluster may include one or more terminal devices; this application does not limit the number of terminal devices. Figure 1 As shown, the terminal device cluster may include: terminal device 101a, terminal device 101b, ..., terminal device 101n. Each terminal device in this cluster may include: a smartphone, tablet computer, laptop computer, desktop computer, smart speaker, smartwatch, in-vehicle terminal, smart TV, or other smart terminal with the function of sending transaction data.

[0087] It should be understood that, such as Figure 1 Each terminal device in the terminal device cluster shown can have an application client installed. When the application client runs on each terminal device, it can interact with the aforementioned... Figure 1 The business servers 100 shown interact with each other. The application client can be a video application, a convenient lifestyle application, a payment application, a financial management application, a game application, a shopping application, a novel application, a browser, or other application client with the function of binding a business account. This application client can be a standalone client or an embedded sub-client integrated into another client (e.g., a payment client, an education client, or a multimedia client), and there is no limitation here.

[0088] In this embodiment, the business server 100 can be the server corresponding to the aforementioned application client. Taking a payment application as an example, the business server 100 can be a collection of multiple servers, including a backend server and a data processing server corresponding to the payment application. Therefore, each terminal device can transmit data with the business server 100 through the application client corresponding to the payment application. For example, each terminal device can send locally generated transaction data for a business account to the business server 100 at a first moment through the application client of the payment application. The business server 100 can then send the transaction data to the core account layer at that first moment. The core account layer verifies the transaction data, and after successful verification, executes the transaction data to obtain the transaction execution result. The transaction execution result is then returned to the terminal device and stored in the core account database along with the transaction data at the first moment. The business server 100 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0089] It is understood that the aforementioned verification device cluster may include one or more verification devices, and this application does not limit the number of verification devices, such as... Figure 1 As shown, the verification device cluster may include: verification device 102a, verification device 102b, ..., verification device 102n. Each verification device in the cluster has the function of verifying transaction data stored in the core account database of the business server 100. This function can be provided by a verification application, which can be a video application, a convenient lifestyle application, a payment application, a financial management application, a game application, a shopping application, a novel application, a browser, or other applications with transaction data verification capabilities. The application client corresponding to the verification application can be a standalone client or an embedded sub-client integrated into a client (e.g., a financial management client, an education client, or a multimedia client, etc.), without limitation here.

[0090] in, Figure 1 Each verification device in the verification device cluster includes, but is not limited to, terminal devices or business servers. The business server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud databases, cloud services, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. Terminal devices include, but are not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle terminals, and aircraft.

[0091] Within this cluster of terminal devices, communication connections can exist between each other. For example, terminal device 101a can communicate with terminal device 101b, and terminal device 101a can communicate with terminal device 101n. Simultaneously, any terminal device in the cluster can communicate with the service server 100, for example, terminal device 101a can communicate with the service server 100. Furthermore, any terminal device in the cluster can communicate with any verification device in the verification device cluster, for example, terminal device 101a can communicate with verification device 102a, and terminal device 101b can communicate with verification device 102a.

[0092] In this system, any verification device in the verification device cluster can have a communication connection with the business server 100. For example, verification device 102a can have a communication connection with the business server 100. At the same time, there can be communication connections between verification devices in the cluster. For example, verification device 102a can have a communication connection with verification device 102b.

[0093] In this application, the connection method for all the communication connections mentioned above is not limited. The connection can be made directly or indirectly through wired communication, wireless communication, or other methods.

[0094] It is understood that the collection and processing of relevant data (such as transaction data) in this application should strictly comply with the requirements of relevant national laws and regulations, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the personal information subject.

[0095] For ease of subsequent understanding and explanation, the embodiments of this application may be... Figure 1In the illustrated terminal device cluster, one terminal device is selected as an example, such as terminal device 101a. When responding to the completion operation of a business transaction for a business account at the second time point, terminal device 101a can determine the verification transaction time range used to verify the legality of the business transaction. It defines the verification transaction time range and the business transaction as transaction data, and uses the business account's private key to sign the transaction data, obtaining a data signature. The transaction data carrying the data signature is then transmitted to the business server 100. This application embodiment does not limit the specific content of the business transaction, including but not limited to business transactions of banking institutions and financial institutions. At a first time point later than the second time point, the business server 100 receives the transaction data sent by terminal device 101a and synchronously sends the transaction data carrying the data signature to the core account layer. It is understood that the time when terminal device 101a determines the verification transaction time range is very close to the time when the data signature is generated; therefore, this application embodiment refers to both very close times as the second time point. Similarly, the moment when the business server 100 obtains the transaction data sent by the terminal device 101a is very close to the moment when the business server 100 sends the obtained transaction data to the core account database. Therefore, in this embodiment, both very close moments are referred to as the first moment.

[0096] Furthermore, within the core account layer, the business server 100 can perform signature verification processing on the data signature to obtain a verification result. If the verification result is successful, the business transaction's legality can be verified based on the initial moment and the transaction time range, yielding a verification result. Further, if the verification result indicates that the business transaction is legal, the business server 100 associates and stores the initial moment and the transaction data carrying the data signature in the core account database corresponding to the core account layer. Both the data signature and the transaction data stored in the core account database are used to send to the verification device (e.g., [missing information]). Figure 1 The verification device 102a) is used to verify the legality of transaction data based on the data signature. The business account is provided by the business server 100. In this embodiment, the business account refers to a tool used to manage digital resources, enabling the transfer of digital resources in online or offline transactions. This embodiment does not limit the scope of the business account; any account with transaction functionality is acceptable.

[0097] It should be noted that the aforementioned business server 100, terminal device 101a, terminal device 101b, ..., terminal device 101n, verification device 102a, verification device 102b, ..., verification device 102n can all be blockchain nodes in the blockchain network. The data described in the entire text (such as the first moment and transaction data) can be stored. The storage method can be that the blockchain node generates blocks based on the data and adds the blocks to the blockchain for storage.

[0098] Blockchain is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. It is primarily used to organize data chronologically and encrypt it into a ledger, making it tamper-proof and forgery-proof. It also allows for data verification, storage, and updating. Essentially, a blockchain is a decentralized database where each node stores the same blockchain. A blockchain network can distinguish nodes as core nodes, data nodes, and light nodes. These three types of nodes together constitute the blockchain node. The core node is responsible for the consensus of the entire blockchain network; in other words, the core node is the consensus node in the blockchain network. The process of writing transaction data into the ledger in a blockchain network can be as follows: data nodes or light nodes in the blockchain network obtain the data to be added to the chain and pass it through the blockchain network (i.e., nodes pass it like a relay) until the consensus node receives the data. The consensus node then packages the data into a block, performs consensus on the block, and writes the data into the ledger after consensus is achieved. Here, we take the first moment and transaction data as examples of data to be uploaded to the blockchain. After the business server 100 (blockchain node) reaches a consensus on the data to be uploaded to the blockchain, it generates a block based on the data to be uploaded to the blockchain and stores the block in the blockchain network. As for reading the data that has already been uploaded to the blockchain (such as the first moment and transaction data), the blockchain node can obtain the block containing the data that has already been uploaded to the blockchain network, and further, retrieve the data that has already been uploaded to the blockchain from the block.

[0099] It is understood that the methods provided in this application embodiment can be executed by computer devices, including but not limited to terminal devices, business servers, or verification devices. The terminal devices, business servers, and verification devices can be directly or indirectly connected via wired or wireless means, and this application embodiment does not impose any limitations on this connection.

[0100] The above system architecture is applicable to resource transfer query and resource transfer verification scenarios, as well as business scenarios such as account status query, account status identification, and account status analysis. Specific business scenarios will not be listed here.

[0101] Further, please see Figure 2, Figure 2 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 1 The embodiments of this application can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, smart transportation, and assisted driving. This data processing method can be provided by a business server (e.g., the one described above). Figure 1 The business server 100 shown can execute the service, or it can be executed by a terminal device (i.e., a business terminal, such as the one described above). Figure 1 The terminal device 101a shown can be used to execute the test, or it can be used by a verification device (such as the one described above). Figure 1 The verification device 102a) shown can be executed, but it can also be executed interactively by at least two of the following entities: the business server, the terminal device, and the verification device. No limitation is made here. For ease of understanding, this embodiment uses the execution by the business server as an example for illustration. Figure 2 As shown, the data processing method may include at least the following steps S101-S103.

[0102] Step S101: At the first moment, the transaction data initiated by the business account is sent to the core account layer; the transaction data includes the business transaction and the corresponding verification transaction time range, and the transaction data carries a data signature.

[0103] Specifically, this application embodiment does not describe the process of generating transaction data on a terminal device bound to a business account; please refer to the following text. Figure 5 or Figure 9 The description in the corresponding embodiments.

[0104] In a business information system (such as a financial information system), there may be a multi-layered design, such as a business layer, an order layer, and a core account layer. Please refer to the relevant documentation for further details. Figure 3 , Figure 3 This is a schematic diagram of a data processing scenario provided in an embodiment of this application. Figure 1 .like Figure 3 As shown, the business server 100 includes a business layer, a transaction layer, and a core account layer. The core account layer is the lowest-level module, carrying the real financial data of the business accounts. Every borrowing and lending transaction record in the core account reflects the actual financial changes of the business accounts. In other words, the core account layer primarily carries the real cash flow of the business accounts. The key information in the core account database of the core account layer includes the business account, transaction amount, account balance, transaction time, transaction type (transfer out or transfer in, etc.), and database signature.

[0105] The embodiments of this application are based on the zero-trust concept, which is mainly based on the various module units of the information system (e.g., Figure 3This invention employs a system design method that assumes no trust between the business layer, transaction layer, and core account layer. In this invention, resource transfer at the core account layer does not depend on trust in the layer above it. Therefore, when the business server 100 receives transaction data 30b carrying data signature 30d from the terminal device 101a at the first moment, it will simultaneously send the acquired data signature 30d and transaction data 30b to the core account layer.

[0106] This application does not limit the real-time nature of business transactions; they can be real-time business transactions, for example... Figure 3 The business transaction in the example transaction data 30b shown is a real-time business transaction. For instance, business object 30a triggers selection control 303a, and at 12:00 on February 2, 2023, enters the correct resource transfer password. Terminal device 101a responds to the input operation for the resource transfer password, and generates a real-time business transaction upon verifying that the resource transfer password is correct. The business transaction in this embodiment can also be a non-real-time business transaction, such as... Figure 3 As shown in the example, when business object 30a triggers selection control 302a, meaning business object 30a selects automatic renewal, then terminal device 101a, upon verifying that the resource transfer password is correct, can generate a non-real-time business transaction. For example, it can set 9:00 AM on March 2, 2023, as the completion time of this non-real-time business transaction, which is the second time mentioned below. As can be seen from the above, the determination of the second time is not fixed and can be set according to the actual application scenario.

[0107] Please see again. Figure 3 Transaction data 30b includes verification of the transaction time range, i.e. Figure 3 The period from 12:00 PM to 12:02 PM on February 2, 2023, also includes business transactions. Figure 3 Business accounts in Figure 3 (using aaaaaaaaa as an example) and digital resources to be transferred out ( Figure 3 (See example 5). It should be emphasized that the transaction verification time range refers to the time range used to verify the legality of business transactions, which is different from the time range displayed by terminal device 101a prompting business object 30a to enter the resource transfer password.

[0108] Understandable Figure 3 The interfaces and controls shown are merely some forms of representation for reference. In actual business scenarios, developers can make relevant designs according to product requirements. This application does not limit the specific forms of the interfaces and controls involved.

[0109] Step S102: In the core account layer, the data signature is verified to obtain the verification result. If the verification result is successful, the legality of the business transaction is verified based on the first moment and the time range of the verification transaction to obtain the verification result.

[0110] Specifically, in the core account database, the business public key of the business account is obtained, and the data signature is verified using the business public key to obtain a first digital digest; a second digital digest of the transaction data is generated, and the first digital digest and the second digital digest are compared to obtain a comparison result; if the comparison result indicates that the first digital digest and the second digital digest are the same, then the signature verification success result is determined as the signature verification result; the signature verification success result is also used to indicate that the data signature was obtained by the business terminal bound to the business account, which signed the transaction data using the business private key of the business account; if the comparison result indicates that the first digital digest and the second digital digest are different, then the signature verification failure result is determined as the signature verification result.

[0111] Specifically, the relationship between the first moment and the transaction verification time range is identified; the earliest moment of the transaction verification time range is equal to the second moment when the business terminal bound to the business account responds to the completion operation for the business transaction; the latest moment of the transaction verification time range is later than the second moment; if the relationship between the first moment and the transaction verification time range is that the first moment is within the transaction verification time range, then the verification result is determined as the verification result for the legality verification of the business transaction; the verification result is used to indicate that the business transaction is legal; if the relationship between the first moment and the transaction verification time range is that the first moment is later than the latest moment, then the verification result is determined as the verification result for the legality verification of the business transaction; the verification result is used to indicate that the business transaction is not legal.

[0112] Understandably, if the transaction data received by the core account layer does not carry a data signature, the core account layer can determine that the transaction data is illegitimate, and therefore will not only execute this step but also subsequent steps. If the transaction data received by the core account layer carries a data signature, please refer to [the relevant documentation / reference]. Figure 4 , Figure 4 This is a schematic diagram of a data processing scenario provided in an embodiment of this application. Figure 2 .like Figure 4 As shown, the business server 100 retrieves the business public key 40b associated with the business account from the core account database 40a corresponding to the core account layer. Figure 4 Example business account: aaaaaaaa.

[0113] Furthermore, within the core account layer, the business server 100, using the business public key 40b, can verify the data signature 30d carried by the transaction data 30b, obtaining a first digital digest. Simultaneously, within the core account layer, the business server 100 can generate a second digital digest of the transaction data 30b. It is understood that both the first and second digital digests are hash values. The business server 100 compares the first and second digital digests to obtain a comparison result. If the comparison result indicates that the first and second digital digests are identical, the verification success result can be confirmed as the verification result. It is understood that a successful verification result indicates that the data signature 30d was generated by a business terminal bound to a business account (e.g., [missing information]). Figure 3 Terminal device 101a in the middle), through the business account's business private key (e.g. Figure 3 The example uses the business private key 30c) to sign the transaction data 30b. The business private key and business public key are an asymmetric key pair. The business private key is not publicly disclosed; it is stored and used locally on the business terminal. The business public key is publicly disclosed. If the comparison result indicates that the first digital digest and the second digital digest are different, the business server 100 can determine the signature failure result as the signature verification result. The signature failure result indicates that transaction data 30b is illegal transaction data, therefore no further processing is required, and the transaction is stopped.

[0114] Furthermore, if the verification result of data signature 30d is a successful verification result, then the business server 100 identifies the relationship between the first moment and the verification transaction time range, wherein the earliest moment of the verification transaction time range is equal to the second moment when the business terminal bound to the business account responds to the completion operation for the business transaction, and the latest moment of the verification transaction time range is later than the second moment. According to Figure 3 And the description of step S101, in this embodiment of the application, the second moment is 12:00 on 2023.2.2. The duration of the transaction verification time range can be set according to the needs of the actual application scenario. This embodiment of the application does not limit this, but in order to ensure the security of transaction data, it should not be too long. In this embodiment of the application, the duration of the transaction verification time range is set to 2 minutes, that is, the transaction verification time range is 2023.2.2 12:00-2023.2.2 12:02.

[0115] Furthermore, if the relationship between the first moment and the verification transaction time range is that the first moment falls within the verification transaction time range, then the business server 100 can determine the verification result as the verification result for the legality of the business transaction; the verification result is used to indicate that the business transaction is legal; for example, if the first moment is 2023.2.2 12:00:05, it is clear that the first moment falls within the verification transaction time range. Figure 4The example demonstrates the verification transaction time range. If the relationship between the first moment and the verification transaction time range is that the first moment is later than the latest moment, then the business server 100 can determine the invalid verification result as the verification result for the legality verification of the business transaction; the invalid verification result is used to indicate that the business transaction is not legal. For example, if the first moment is 12:05 on February 2, 2023, it is clear that the first moment is later than... Figure 4 The latest time in the example verification transaction time range is 2023.2.2 12:02.

[0116] Step S103: If the verification result indicates that the business transaction is legitimate, the transaction data with the data signature carried at the first moment is associated and stored in the core account database corresponding to the core account layer; the data signature and transaction data stored in the core account database are both sent to the verification device; the verification device is used to verify the legitimacy of the transaction data based on the data signature.

[0117] Specifically, in the core account database corresponding to the core account layer, the current digital resources of the business account are obtained; the resource transfer value in the business transaction is obtained; if the current digital resources contain the digital resources to be transferred corresponding to the resource transfer value, the digital resources to be transferred in the current digital resources are processed for resource transfer, and the current digital resources after resource transfer processing are determined as the updated digital resources; the first moment, the updated digital resources, and the transaction data carrying the data signature are associated and stored in the core account database.

[0118] Understandably, if the verification result also indicates invalidity, the business server will not execute this step. If the verification result indicates that the business transaction is valid, then the current digital resources of the business account are retrieved from the core account database, and the resource transfer value in the business transaction is obtained, for example... Figure 4 The example shown is digital resource 5 to be transferred. Further, the business server compares the resource transfer value with the current digital resource. If the current digital resource is equal to or greater than the resource transfer value, for example, the resource transfer value is 5 and the current digital resource is 10, then the business transaction is executed in the core account layer. That is, the digital resource to be transferred in the current data resource is processed to obtain an updated digital resource, such as (10-5) in the example.

[0119] Furthermore, the business server associates and stores the first-moment data, updated digital resources, and transaction data carrying data signatures in the core account database. To achieve the beneficial effects of this application, three fields are added to the design of the core account database: transaction authorization start time (i.e., the second moment), transaction authorization end time (i.e., the latest moment in the transaction verification time range), and data signature. Please refer to Table 1 for details. Table 1 is a schematic table of key fields included in an optimized core account database provided by an embodiment of this application. See Table 1 for details:

[0120] Table 1

[0121]

[0122]

[0123] In this embodiment of the application, the transaction types listed in Table 1 include, but are not limited to, deductions and transfers; the transaction amount refers to the resource transfer value in the business transaction; the account balance refers to the updated digital resources; the transaction posting time refers to the first moment; the transaction authorization start time refers to the second moment; and the transaction authorization end time refers to the sum of the second moment and the authorization duration, i.e., the latest moment within the verification transaction time range. It is understood that the newly added data signature field is unique to prevent duplicate data signatures in the core account database.

[0124] This application does not describe the process of the verification device verifying the legality of transaction data in this embodiment; please refer to the following text. Figure 7 The description in the corresponding embodiments.

[0125] This technical solution uses cryptographic methods to push the authorization behavior of business objects down to the core account layer. Fund deductions (i.e., digital resource transfers) at the core account layer only recognize the authorization of the business object and do not require trust in the transaction instructions issued by the business organization (i.e., the business server). Furthermore, the core account layer cannot forge digital resource transfer transaction records without the authorization of the business object, thus circumventing the vulnerabilities of the organization's internal system and preventing financial losses to business accounts due to malicious acts by criminals. In terms of post-transaction auditing, each digital resource transfer transaction of the business account has a corresponding data signature of the business object's authorization in the core account database, shortening the evidence-gathering process and thus improving audit efficiency and credibility.

[0126] In this embodiment, the business server sends transaction data initiated by the business account to the core account layer at a first moment. The transaction data includes the business transaction and the corresponding verification transaction time range, and carries a data signature. In the core account layer, the business server can verify the data signature to obtain a verification result. If the verification result is successful, the business transaction is validated for legality based on the first moment and the verification transaction time range, yielding a verification result. Further, if the verification result indicates that the business transaction is legal, the business server associates and stores the transaction data with the data signature at the first moment in the core account database corresponding to the core account layer. Both the data signature and the transaction data stored in the core account database are sent to the verification device. The verification device verifies the legality of the transaction data based on the data signature. As can be seen, the business server directly sends the transaction data with the data signature to the core account layer, and the core account layer verifies the legality of the business transaction through the data signature and the verification transaction time range. Therefore, in scenarios without business account authorization, the core account layer will not recognize the business transaction and will not execute it, thus improving the security of the business account. In addition, by using data signatures, verification devices can verify the legality of transaction data, thus improving the efficiency and accuracy of transaction data verification.

[0127] Please see Figure 5 , Figure 5 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 2 This method can be implemented by a business server (e.g., the one mentioned above). Figure 1 The business server 100 shown can execute the commands, or the business terminal (e.g., the one described above) can execute them. Figure 1 The terminal device 101a shown can be used to execute the test, or it can be used by a verification device (such as the one described above). Figure 1 The verification device 102a) shown can be executed, but it can also be executed interactively by at least two of the following entities: the business server, the terminal device, and the verification device. No limitation is made here. For ease of understanding, this embodiment of the application illustrates the method as being executed interactively by the business server and the terminal device. Figure 5 As shown, the data processing method may include at least the following steps S201-S206.

[0128] Step S201: At a third moment earlier than the first moment, obtain the certificate application request initiated by the business terminal; the certificate application request includes the business account and the business public key of the business account; the business public key is generated by the business terminal when applying for the business account.

[0129] Specifically, in this embodiment, when the application client installed on the business terminal (i.e., the terminal device) applies for a business account, it will simultaneously generate a pair of asymmetric keys, which include a business private key and a business public key. This embodiment does not limit the cryptographic algorithm of the asymmetric key, and any cryptographic algorithm that can generate public and private key pairs can be used.

[0130] Furthermore, the business terminal (i.e., the terminal device) generates a certificate application request including the business account and the business public key. Before generating the business transaction, the certificate application request is sent to the business server. It can be understood that the business server receives the certificate application request at the third moment earlier than at the first moment.

[0131] Step S202: Based on the certificate application request, generate a business certificate for the business account and return the business certificate to the business terminal; the business certificate is used to indicate to the business terminal that the business account application was successful.

[0132] Specifically, the business server verifies the certificate application request. If the certificate application request is verified as a valid request, a business certificate is generated for the business account, which indicates that the business terminal has successfully applied for the business account. If the certificate application request is verified as an invalid request, the business server refuses to generate a business certificate for the business account, and thus refuses to create the business account for the business object. In other words, the business account of the business terminal is an invalid business account.

[0133] As can be seen from the above, the public-private key pair generated by the application client is a necessary condition for opening a business account in this application, and the business public key must be stored at the core account layer of the business information system, that is, stored in the core account database.

[0134] This application embodiment uses a business server to issue a business certificate to a terminal device as an example. In actual applications, the terminal device can also send a certificate application request to a credible certificate authority. It is understood that the process by which the certificate authority issues a business certificate to the terminal device based on the certificate application request is the same as the process described above, so it will not be described in detail here.

[0135] Step S203: Store the business public key and business account association in the core account database.

[0136] For details, please refer to the steps above. Figure 6 , Figure 6 This is an interactive illustration of a data processing method provided in an embodiment of this application. Figure 1 .like Figure 6 As shown, the data processing method may include at least the following steps A-F.

[0137] Step A: When applying for a business account, the terminal device simultaneously generates an asymmetric key pair, and the business private key is secretly held.

[0138] Step B: The terminal device generates a certificate application request that includes the business public key.

[0139] Step C: The terminal device sends a certificate application request to the business server.

[0140] Step D: The business server issues a business certificate to the business account based on the certificate application request.

[0141] Step E: Associate the business server with the business account and business public key.

[0142] Step F: The business server returns the business certificate to the terminal device.

[0143] In this case, the execution order of step F can be before the execution order of step E, or after the execution order of step E, or the execution order of step F can be synchronized with the execution order of step E.

[0144] In step S204, at the first moment, the transaction data initiated by the business account is sent to the core account layer; the transaction data includes the business transaction and the corresponding verification transaction time range, and the transaction data carries a data signature.

[0145] Step S205: In the core account layer, the data signature is verified to obtain the verification result. If the verification result is successful, the legality of the business transaction is verified based on the first moment and the time range of the verification transaction to obtain the verification result.

[0146] Step S206: If the verification result indicates that the business transaction is legitimate, the transaction data with the data signature carried at the first moment is associated and stored in the core account database corresponding to the core account layer; the data signature and transaction data stored in the core account database are both sent to the verification device; the verification device is used to verify the legitimacy of the transaction data based on the data signature.

[0147] Specifically, the key point of this step lies in the core account database, where each transaction data has a data signature authorized by the business object. The business private key corresponding to this data signature is secretly held by the business object, making it impossible to forge the data signature even within the business system. Furthermore, the transaction data in this embodiment includes a verification transaction time range for validating the legality of the transaction data, preventing business transaction changes from occurring within an unexpected timeframe for the business object, thus enhancing the security of the business account.

[0148] For the specific implementation process of steps S204-S206, please refer to the above text. Figure 2 Steps S101-S103 in the corresponding embodiments will not be described in detail here.

[0149] In this embodiment, the business server sends transaction data initiated by the business account to the core account layer at a first moment. The transaction data includes the business transaction and the corresponding verification transaction time range, and carries a data signature. In the core account layer, the business server can verify the data signature to obtain a verification result. If the verification result is successful, the business transaction is validated for legality based on the first moment and the verification transaction time range, yielding a verification result. Further, if the verification result indicates that the business transaction is legal, the business server associates and stores the transaction data with the data signature at the first moment in the core account database corresponding to the core account layer. Both the data signature and the transaction data stored in the core account database are sent to the verification device. The verification device verifies the legality of the transaction data based on the data signature. As can be seen, the business server directly sends the transaction data with the data signature to the core account layer, and the core account layer verifies the legality of the business transaction through the data signature and the verification transaction time range. Therefore, in scenarios without business account authorization, the core account layer will not recognize the business transaction and will not execute it, thus improving the security of the business account. In addition, by using data signatures, verification devices can verify the legality of transaction data, thus improving the efficiency and accuracy of transaction data verification.

[0150] Further, please see Figure 7 , Figure 7 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 3 This data processing method can be performed by a business server (e.g., the one mentioned above). Figure 1 The business server 100 shown can execute the service, or it can be executed by a terminal device (i.e., a business terminal, such as the one described above). Figure 1 The terminal device 101a shown can be used to execute the test, or it can be used by a verification device (such as the one described above). Figure 1 The verification device 102a) shown can be executed, but it can also be executed interactively by at least two of the following entities: the business server, the terminal device, and the verification device. No limitation is made here. For ease of understanding, this embodiment uses the method executed by the verification device as an example for illustration. Figure 7 As shown, the data processing method may include at least the following steps S301-S304.

[0151] Step S301: Obtain a transaction verification request for the business account, and generate a transaction acquisition request for the business account based on the transaction verification request.

[0152] Specifically, this application does not limit the device that initiates the transaction verification request. It can be initiated by a business terminal that is bound to a business account. For example, when a business object has doubts about a certain business transaction, it can send a transaction verification request for the business account to the verification device through the business terminal. Alternatively, the verification object can initiate the transaction verification request. For example, when the verification object periodically queries the business data stored in the core account database of the business server, it can generate a transaction verification request for the business account through the verification device.

[0153] Furthermore, the verification device generates a transaction acquisition request for the business account based on the transaction verification request.

[0154] Step S302: Send a transaction retrieval request to the business server so that the business server can retrieve the data to be verified of the business account from the core account database corresponding to the core account layer according to the transaction retrieval request; the data to be verified includes transaction data initiated by the business account; the transaction data includes the business transaction and the verification transaction time range corresponding to the business transaction; the verification transaction time range is used to instruct the business server to verify the legality of the business transaction.

[0155] Specifically, this application does not limit the number of data to be verified; there can be one or more, which can be determined according to the actual application scenario. For example, using a business account as the dimension, the business server can determine all transaction data stored in the core account database associated with the business account as the data to be verified. As another example, using the transaction posting time (i.e., the first moment) as the dimension, the business server can determine the transaction data in the core account database at the first moment as the data to be verified.

[0156] Step S303: Obtain the data to be verified returned by the business server. If the data to be verified does not include the data signature of the transaction data, then the transaction data is determined to be illegal transaction data.

[0157] Specifically, during post-audit, the verification device only needs to check the transaction data in the core account database to determine the legality of the transfer of digital resources from the business account. If the transaction record for the transfer of digital resources does not have a data signature authorized by the business object or the data signature verification fails, the verification device can determine that the transaction is an unauthorized transaction by the business object.

[0158] Step S304: If the data to be verified includes the data signature of the transaction data, then verify the legality of the transaction data based on the data signature.

[0159] Specifically, the process involves retrieving the first business public key and the second business public key from the data to be verified. The second business public key is either the business public key provided by the business terminal bound to the business account, or a business public key obtained from the blockchain that is bound to the business account. The first and second business public keys are compared to obtain a comparison result. If the comparison result indicates that the first and second business public keys are different, the transaction data is determined to be illegal. If the comparison result indicates that the first and second business public keys are the same, the transaction signature is verified based on the first business public key to obtain a verification result. If the verification result is a verification failure, the transaction data is determined to be illegal. If the verification result is a verification success, the transaction data is determined to be legitimate.

[0160] It is understandable that the first business public key is equivalent to the above. Figure 2 The business public key in the corresponding embodiment is the business public key associated with the business account and stored in the core account database. Therefore, the verification device regards the first business public key as a public key to be verified. The second business public key can be provided by the business device (i.e., the terminal device) bound to the business account, or it can be obtained from the blockchain network when the terminal device stores the valid business public key generated when applying for the business account in the blockchain network.

[0161] Please refer to the above process as well. Figure 8 , Figure 8 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 4 .like Figure 8 As shown, the data processing method includes the following steps.

[0162] Step S31: Obtain the data to be verified for the business account from the business server; the data to be verified includes transaction data.

[0163] Step S32: Does the transaction data have a data signature? The verification device checks whether the transaction data has a data signature. If the transaction data carries a data signature, proceed to step S33; if the transaction data does not carry a data signature, the verification device proceeds to step S38.

[0164] Step S33: Obtain the first business public key of the business account from the data to be verified.

[0165] Step S34: Obtain the second business public key of the business account.

[0166] Step S35: Are the first service public key and the second service public key the same? The verification device checks whether the first service public key and the second service public key are the same. If they are the same, proceed to step S36. If the first service public key and the second service public key are different, the verification device proceeds to step S38.

[0167] Step S36: Is the data signature verified? The verification device verifies the data signature and obtains the verification result. If the verification result is successful, proceed to step S37; if the verification result is unsuccessful, proceed to step S38.

[0168] Step S37: Determine that the transaction data is legitimate.

[0169] Step S38: Determine that the transaction data is illegal transaction data.

[0170] To enhance the security of business accounts and digital resources within business information systems, this application proposes a zero-trust-based business account design method. This method optimizes traditional business account design in three aspects: account application, transaction recording, and post-event auditing. It combines the authorization for transferring digital resources from business accounts to business objects using cryptographic methods, thereby mitigating the potential for unauthorized transfer of digital resources from business accounts within the business organization. Furthermore, through data signatures, verification devices can verify the legality of transaction data, thus improving the efficiency and accuracy of transaction data verification.

[0171] Further, please see Figure 9 , Figure 9 This is a flowchart illustrating a data processing method provided in an embodiment of this application. Figure 5 This method can be implemented by a business server (e.g., the one mentioned above). Figure 1 The business server 100 shown can execute the commands, or the business terminal (e.g., the one described above) can execute them. Figure 1 The terminal device 101a shown can be used to execute the test, or it can be used by a verification device (such as the one described above). Figure 1 The verification device 102a) shown can be executed, but it can also be executed interactively by at least two of the following entities: the business server, the terminal device, and the verification device. No limitation is made here. For ease of understanding, this embodiment of the application uses the execution of the method by the terminal device as an example for illustration. Figure 9 As shown, the data processing method may include at least the following steps S401-S403.

[0172] Step S401: Respond to the completion operation for the business transaction in the business account and determine the verification transaction time range used to verify the legality of the business transaction.

[0173] Specifically, the earliest moment is determined as the second moment of the response to the completion of the business transaction; the transaction verification time threshold is obtained, and the earliest moment and the transaction verification time threshold are summed to obtain the latest moment; a transaction verification time range including the earliest moment and the latest moment is generated.

[0174] The transaction verification time threshold can be adjusted according to the needs of the actual application scenario. Figure 3 The transaction time threshold is verified using a 2-minute example.

[0175] Step S402: Generate a data signature for the transaction data; the transaction data includes the business transaction and the time range for verifying the transaction.

[0176] Specifically, when applying for a business account, a business private key and a business public key are generated; a certificate application request including the business account and the business public key is generated and sent to the business server so that the business server can generate a business certificate for the business account according to the certificate application request; the business certificate returned by the business server is obtained; the business certificate is used to indicate that the business terminal has successfully applied for a business account.

[0177] Specifically, the process involves generating transaction data that includes business transactions and verifies the transaction time range; obtaining the business private key; and using the business private key to sign the transaction data to obtain the data signature of the transaction data.

[0178] Please see again. Figure 3 Terminal device 101a generates transaction data 30b, which includes the business transaction (including the business account and the digital resources to be transferred) and the time range for verifying the transaction. Terminal device 101a obtains the privately stored business key 30c and uses the private key 30c to sign the transaction data 30b, obtaining the data signature 30d of the transaction data 30b.

[0179] The key point of this step is that the asymmetric public-private key pair generated by the application client is a necessary condition for opening an account, and the application client's business public key must be pushed down to the core account layer of the business information system.

[0180] Step S403: Transaction data carrying a data signature is sent to the business server via the business account, so that the business server sends the transaction data carrying the data signature to the core account layer at the first moment. The core account layer is used to verify the data signature and obtain a verification result. The verification result includes a successful verification result. The verification result is used to instruct the core account layer to perform legality verification on the business transaction based on the first moment and the verification transaction time range, and obtain a verification result. The verification result includes a legal verification result. The legal verification result is used to instruct the core account layer to associate and store the transaction data carrying the data signature at the first moment in the core account database. The data signature and transaction data stored in the core account database are both sent to the verification device. The verification device is used to verify the legality of the transaction data based on the data signature.

[0181] Specifically, the key point of this step lies in the core account database, where each transaction has a data signature authorized by the business object. Because the business private key is secretly held by the business object, this data signature cannot be forged within the business information system. Furthermore, this application adds an authorization time range for transaction verification to the data-signed transaction data, preventing transaction changes to the business account from occurring within an unexpected timeframe, thus enhancing the security of transaction data and business accounts.

[0182] Please refer to the above process as well. Figure 10 , Figure 10 This is an interactive illustration of a data processing method provided in an embodiment of this application. Figure 2 .like Figure 10 As shown, the data processing method includes the following steps.

[0183] Step S41: The terminal device responds to the completion operation of the business transaction, and determines the time range for verifying the transaction and the value of the resources to be transferred.

[0184] Step S42: The terminal device signs the transaction data using the business private key to obtain a data signature.

[0185] Step S43: The terminal device sends transaction data carrying a data signature to the business server.

[0186] Step S44: At the first instant, the business server synchronously sends the transaction data carrying the data signature to the core account layer. At the first instant, the business server receives the transaction data carrying the data signature sent by the terminal device and then synchronizes it to the core account layer.

[0187] Step S45: The business server verifies the data signature and obtains the verification result. If the verification result is a failure, the business server executes step S46; if the verification result is a success, the business server executes step S47.

[0188] Step S46: The business server determines that the transaction data is illegal transaction data.

[0189] Step S47: The business server identifies the relationship between the first moment and the transaction verification time range. If the first moment is within the transaction verification time range, the business server executes step S48; if the first moment is later than the latest moment of the transaction verification time range, the business server executes step S46.

[0190] Step S48: The business server determines that the transaction data is legitimate.

[0191] Step S49: The business server executes business transactions, associates and stores transaction data, first-time data, and updates digital resources.

[0192] As described above, the business server directly sends transaction data carrying a data signature to the core account layer. At the core account layer, the legality of the business transaction is verified through the data signature and the transaction time range. Therefore, in scenarios without business account authorization, the core account layer will not recognize the business transaction and will not execute it, thus improving the security of the business account. Furthermore, through data signature, the verification device can verify the legality of the transaction data, thereby improving the efficiency and accuracy of transaction data verification.

[0193] Further, please see Figure 11 , Figure 11 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 1 The aforementioned data processing device 1 can be a computer program (including program code) running on a computer device, for example, the data processing device 1 is an application software; specifically, the data processing device 1 can run on a business server and can be used to execute the corresponding steps in the methods provided in the embodiments of this application. Figure 11 As shown, the data processing device 1 may include: a data sending module 11, a transaction verification module 12, and a first storage module 13.

[0194] The data sending module 11 is used to send transaction data initiated by the business account to the core account layer at the first moment; the transaction data includes the business transaction and the corresponding verification transaction time range, and the transaction data carries a data signature;

[0195] The transaction verification module 12 is used to verify the data signature in the core account layer and obtain the verification result. If the verification result is a successful verification result, the legality of the business transaction is verified according to the first moment and the time range of the verification transaction, and the verification result is obtained.

[0196] The first storage module 13 is used to associate and store the transaction data carrying the data signature in the core account database corresponding to the core account layer if the verification result indicates that the business transaction is legitimate. The data signature and transaction data stored in the core account database are both sent to the verification device. The verification device is used to verify the legitimacy of the transaction data based on the data signature.

[0197] The specific functional implementations of the data sending module 11, the transaction verification module 12, and the first storage module 13 can be found in the above description. Figure 2 Steps S101-S103 in the corresponding embodiment will not be described again here.

[0198] Please see again Figure 11The transaction verification module 12 may include: a relationship identification unit 121, a first determination unit 122, and a second determination unit 123.

[0199] The relationship identification unit 121 is used to identify the relationship between the first moment and the transaction verification time range; the earliest moment of the transaction verification time range is equal to the second moment when the business terminal bound to the business account responds to the completion operation for the business transaction; the latest moment of the transaction verification time range is later than the second moment.

[0200] The first determining unit 122 is used to determine the verification result as the verification result for the legality verification of the business transaction if the relationship between the first moment and the verification transaction time range is that the first moment is within the verification transaction time range; the verification result is used to indicate that the business transaction is legal.

[0201] The second determining unit 123 is used to determine the invalid verification result as the verification result for the legality verification of the business transaction if the relationship between the first moment and the time range of the verification transaction is that the first moment is later than the latest moment; the invalid verification result is used to indicate that the business transaction is not legal.

[0202] The specific functional implementation of the relationship identification unit 121, the first determination unit 122, and the second determination unit 123 can be found in the above description. Figure 2 Step S102 in the corresponding embodiment will not be described again here.

[0203] Please see again Figure 11 The first storage module 13 may include: a first acquisition unit 131, a second acquisition unit 132, and a data storage unit 133.

[0204] The first acquisition unit 131 is used to acquire the current digital resources of the business account in the core account database corresponding to the core account layer.

[0205] The second acquisition unit 132 is used to acquire the resource transfer value in the business transaction. If the current digital resource contains the digital resource to be transferred corresponding to the resource transfer value, the digital resource to be transferred in the current digital resource is processed by resource transfer, and the current digital resource after resource transfer is determined as the updated digital resource.

[0206] Data storage unit 133 is used to associate and store first-time, updated digital resources and transaction data carrying data signatures into the core account database.

[0207] The specific functional implementation methods of the first acquisition unit 131, the second acquisition unit 132, and the data storage unit 133 can be found in the above description. Figure 2 Step S103 in the corresponding embodiment will not be described again here.

[0208] Please see again Figure 11 The transaction verification module 12 may include: a third acquisition unit 124, a summary generation unit 125, a third determination unit 126, and a fourth determination unit 127.

[0209] The third acquisition unit 124 is used to obtain the business public key of the business account from the core account database, and to perform signature verification processing on the data signature using the business public key to obtain the first digital digest.

[0210] The summary generation unit 125 is used to generate a second digital summary of the transaction data, compare the first digital summary with the second digital summary, and obtain a comparison result.

[0211] The third determining unit 126 is used to determine the signature success result as the signature verification result if the comparison result indicates that the first digital digest and the second digital digest are the same; the signature success result is also used to indicate that the data signature is obtained by a business terminal bound to a business account, which signs the transaction data using the business private key of the business account.

[0212] The fourth determining unit 127 is used to determine the signature failure result as the signature verification result if the comparison result indicates that the first digital digest is different from the second digital digest.

[0213] The specific functional implementation of the third acquisition unit 124, the summary generation unit 125, the third determination unit 126, and the fourth determination unit 127 can be found in the above description. Figure 2 Step S102 in the corresponding embodiment will not be described again here.

[0214] Please see again Figure 11 The data processing device 1 may further include: a request acquisition module 14, a certificate generation module 15, and a second storage module 16.

[0215] The request acquisition module 14 is used to acquire a certificate application request initiated by the business terminal at a third time earlier than the first time. The certificate application request includes the business account and the business public key of the business account. The business public key is generated by the business terminal when applying for the business account.

[0216] The certificate generation module 15 is used to generate a business certificate for a business account based on a certificate application request and return the business certificate to the business terminal; the business certificate is used to indicate to the business terminal that the business account application was successful.

[0217] The second storage module 16 is used to associate and store the business public key and business account in the core account database.

[0218] The specific functional implementation of the request acquisition module 14, the certificate generation module 15, and the second storage module 16 can be found in the above description. Figure 5 Steps S201-S203 in the corresponding embodiment will not be described again here.

[0219] In this embodiment, the business server sends transaction data initiated by the business account to the core account layer at a first moment. The transaction data includes the business transaction and the corresponding verification transaction time range, and carries a data signature. In the core account layer, the business server can verify the data signature to obtain a verification result. If the verification result is successful, the business transaction is validated for legality based on the first moment and the verification transaction time range, yielding a verification result. Further, if the verification result indicates that the business transaction is legal, the business server associates and stores the transaction data with the data signature at the first moment in the core account database corresponding to the core account layer. Both the data signature and the transaction data stored in the core account database are sent to the verification device. The verification device verifies the legality of the transaction data based on the data signature. As can be seen, the business server directly sends the transaction data with the data signature to the core account layer, and the core account layer verifies the legality of the business transaction through the data signature and the verification transaction time range. Therefore, in scenarios without business account authorization, the core account layer will not recognize the business transaction and will not execute it, thus improving the security of the business account. In addition, by using data signatures, verification devices can verify the legality of transaction data, thus improving the efficiency and accuracy of transaction data verification.

[0220] Further, please see Figure 12 , Figure 12 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 2 The aforementioned data processing device 2 can be a computer program (including program code) running on a computer device, for example, the data processing device 2 is an application software; specifically, the data processing device 2 can run on a verification device and can be used to execute the corresponding steps in the methods provided in the embodiments of this application. Figure 12 As shown, the data processing device 2 may include: a request generation module 21, a request sending module 22, a data determination module 23, and a data verification module 24.

[0221] The request generation module 21 is used to obtain the transaction verification request for the business account and generate the transaction acquisition request for the business account based on the transaction verification request.

[0222] The request sending module 22 is used to send a transaction acquisition request to the business server, so that the business server can obtain the data to be verified of the business account from the core account database corresponding to the core account layer according to the transaction acquisition request; the data to be verified includes transaction data initiated by the business account; the transaction data includes the business transaction and the verification transaction time range corresponding to the business transaction; the verification transaction time range is used to instruct the business server to verify the legality of the business transaction;

[0223] The data determination module 23 is used to obtain the data to be verified returned by the business server. If the data to be verified does not include the data signature of the transaction data, the transaction data is determined to be illegal transaction data.

[0224] The data verification module 24 is used to verify the legality of the transaction data based on the data signature if the data to be verified includes the data signature of the transaction data.

[0225] The specific functional implementation methods of the request generation module 21, request sending module 22, data determination module 23, and data verification module 24 can be found in the above description. Figure 7 Steps S301-S304 in the corresponding embodiment will not be described again here.

[0226] Please see again Figure 12 The data verification module 24 may include: a public key acquisition unit 241, a public key comparison unit 242, a first determination unit 243, a signature verification unit 244, a second determination unit 245, and a third determination unit 246.

[0227] The public key acquisition unit 241 is used to obtain the first business public key of the business account from the data to be verified, and to obtain the second business public key; the second business public key refers to the business public key provided by the business terminal bound to the business account, or the business public key obtained from the blockchain that is bound to the business account.

[0228] The public key comparison unit 242 is used to compare the first business public key with the second business public key to obtain the comparison result;

[0229] The first determining unit 243 is used to determine that the transaction data is illegal transaction data if the comparison result indicates that the first business public key is different from the second business public key;

[0230] The signature verification unit 244 is used to perform signature verification processing on the transaction signature based on the first business public key if the comparison result indicates that the first business public key is the same as the second business public key, and obtain the signature verification result.

[0231] The second determining unit 245 is used to determine that the transaction data is illegal transaction data if the signature verification result is a signature verification failure result;

[0232] The third determining unit 246 is used to determine that the transaction data is legitimate if the verification result is a successful verification result.

[0233] The specific functional implementation methods of the public key acquisition unit 241, public key comparison unit 242, first determination unit 243, signature verification unit 244, second determination unit 245, and third determination unit 246 can be found above. Figure 7 Step S304 in the corresponding embodiment will not be described again here.

[0234] In this embodiment, the business server sends transaction data initiated by the business account to the core account layer at a first moment. The transaction data includes the business transaction and the corresponding verification transaction time range, and carries a data signature. In the core account layer, the business server can verify the data signature to obtain a verification result. If the verification result is successful, the business transaction is validated for legality based on the first moment and the verification transaction time range, yielding a verification result. Further, if the verification result indicates that the business transaction is legal, the business server associates and stores the transaction data with the data signature at the first moment in the core account database corresponding to the core account layer. Both the data signature and the transaction data stored in the core account database are sent to the verification device. The verification device verifies the legality of the transaction data based on the data signature. As can be seen, the business server directly sends the transaction data with the data signature to the core account layer, and the core account layer verifies the legality of the business transaction through the data signature and the verification transaction time range. Therefore, in scenarios without business account authorization, the core account layer will not recognize the business transaction and will not execute it, thus improving the security of the business account. In addition, by using data signatures, verification devices can verify the legality of transaction data, thus improving the efficiency and accuracy of transaction data verification.

[0235] Further, please see Figure 13 , Figure 13 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 3 The aforementioned data processing device 3 can be a computer program (including program code) running on a computer device; for example, the data processing device 3 is an application software. Specifically, the data processing device 3 can run on a business terminal and can be used to execute the corresponding steps in the methods provided in the embodiments of this application. Figure 13 As shown, the data processing device 3 may include: a time determination module 31, a first generation module 32, and a first transmission module 33.

[0236] The time determination module 31 is used to respond to the completion operation of the business transaction in the business account and determine the time range of the verification transaction used to verify the legality of the business transaction.

[0237] The first generation module 32 is used to generate a data signature for the transaction data; the transaction data includes business transactions and the time range for verifying the transactions.

[0238] The first sending module 33 is used to send transaction data carrying a data signature to the business server through the business account, so that the business server sends the transaction data carrying the data signature to the core account layer at the first moment. The core account layer is used to verify the data signature and obtain the verification result. The verification result includes a successful verification result. The verification result is used to instruct the core account layer to perform legality verification on the business transaction according to the first moment and the verification transaction time range, and obtain a verification result. The verification result includes a legal verification result. The legal verification result is used to instruct the core account layer to associate and store the transaction data carrying the data signature at the first moment in the core account database. The data signature and transaction data stored in the core account database are both sent to the verification device. The verification device is used to verify the legality of the transaction data according to the data signature.

[0239] The specific functional implementation of the time determination module 31, the first generation module 32, and the first sending module 33 can be found in the above description. Figure 9 Steps S401-S403 in the corresponding embodiment will not be described again here.

[0240] Please see again Figure 13 The time determination module 31 may include: a first determination unit 311, a first acquisition unit 312, and a first generation unit 313.

[0241] The first determining unit 311 is used to determine the second moment of the response to the completion operation of the business transaction as the earliest moment;

[0242] The first acquisition unit 312 is used to acquire the verification transaction time threshold, and to sum the earliest time and the verification transaction time threshold to obtain the latest time.

[0243] The first generation unit 313 is used to generate a verification transaction time range that includes the earliest and latest times.

[0244] The specific functional implementation of the first determining unit 311, the first acquiring unit 312, and the first generating unit 313 can be found in the above description. Figure 9 Step S401 in the corresponding embodiment will not be described again here.

[0245] Please see again Figure 13The data processing device 3 may further include: a second generation module 34, a second sending module 35, and a certificate acquisition module 36.

[0246] The second generation module 34 is used to generate a business private key and a business public key when applying for a business account.

[0247] The second sending module 35 is used to generate a certificate application request including a business account and a business public key, and send the certificate application request to the business server so that the business server can generate a business certificate for the business account according to the certificate application request;

[0248] Certificate acquisition module 36 is used to obtain the business certificate returned by the business server; the business certificate is used to indicate that the business terminal has successfully applied for a business account.

[0249] The first generation module 32 may include a second generation unit 321 and a second acquisition unit 322.

[0250] The second generation unit 321 is used to generate transaction data including business transactions and the time range for verifying transactions;

[0251] The second acquisition unit 322 is used to acquire the business private key, and to perform signature processing on the transaction data using the business private key to obtain the data signature of the transaction data.

[0252] The specific functional implementation of the second generation module 34, the second sending module 35, the certificate acquisition module 36, the second generation unit 321, and the second acquisition unit 322 can be found above. Figure 9 Step S402 in the corresponding embodiment will not be described again here.

[0253] In this embodiment, the business server sends transaction data initiated by the business account to the core account layer at a first moment. The transaction data includes the business transaction and the corresponding verification transaction time range, and carries a data signature. In the core account layer, the business server can verify the data signature to obtain a verification result. If the verification result is successful, the business transaction is validated for legality based on the first moment and the verification transaction time range, yielding a verification result. Further, if the verification result indicates that the business transaction is legal, the business server associates and stores the transaction data with the data signature at the first moment in the core account database corresponding to the core account layer. Both the data signature and the transaction data stored in the core account database are sent to the verification device. The verification device verifies the legality of the transaction data based on the data signature. As can be seen, the business server directly sends the transaction data with the data signature to the core account layer, and the core account layer verifies the legality of the business transaction through the data signature and the verification transaction time range. Therefore, in scenarios without business account authorization, the core account layer will not recognize the business transaction and will not execute it, thus improving the security of the business account. In addition, by using data signatures, verification devices can verify the legality of transaction data, thus improving the efficiency and accuracy of transaction data verification.

[0254] Further, please see Figure 14 , Figure 14 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 14 As shown, the computer device 1000 may include: at least one processor 1001, such as a CPU, at least one network interface 1004, a user interface 1003, a memory 1005, and at least one communication bus 1002. The communication bus 1002 is used to implement communication between these components. In some embodiments, the user interface 1003 may include a display screen and a keyboard, and the network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be high-speed RAM or non-volatile memory, such as at least one disk drive. Optionally, the memory 1005 may also be at least one storage device located remotely from the aforementioned processor 1001. Figure 14 As shown, the memory 1005, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a device control application program.

[0255] exist Figure 14In the computer device 1000 shown, the network interface 1004 provides network communication functionality; the user interface 1003 is mainly used to provide an input interface for the user; and the processor 1001 can be used to call the device control application program stored in the memory 1005 to achieve:

[0256] In the first instant, the transaction data initiated by the business account is sent to the core account layer; the transaction data includes the business transaction and the corresponding verification transaction time range, and the transaction data carries a data signature;

[0257] In the core account layer, the data signature is verified to obtain the verification result. If the verification result is successful, the legality of the business transaction is verified based on the first moment and the time range of the verification transaction to obtain the verification result.

[0258] If the verification result indicates that the business transaction is legitimate, the transaction data along with the data signature will be stored in the core account database corresponding to the core account layer. The data signature and transaction data stored in the core account database are both sent to the verification device. The verification device is used to verify the legitimacy of the transaction data based on the data signature.

[0259] Alternatively, processor 1001 can be used to call the device control application stored in memory 1005 to achieve:

[0260] Obtain the transaction verification request for the business account, and generate a transaction acquisition request for the business account based on the transaction verification request;

[0261] A transaction retrieval request is sent to the business server, which then retrieves the business account's data to be verified from the core account database corresponding to the core account layer. The data to be verified includes transaction data initiated by the business account. The transaction data includes the business transaction and the corresponding verification transaction time range. The verification transaction time range is used to instruct the business server to verify the legality of the business transaction.

[0262] Obtain the data to be verified returned by the business server. If the data to be verified does not include the data signature of the transaction data, then the transaction data is determined to be illegal transaction data.

[0263] If the data to be verified includes the data signature of the transaction data, then the legality of the transaction data is verified based on the data signature.

[0264] Alternatively, processor 1001 can be used to call the device control application stored in memory 1005 to achieve:

[0265] In the business account, respond to the completion operation for the business transaction and determine the time range for verifying the legality of the business transaction;

[0266] Generate data signatures for transaction data; transaction data includes business transactions and the time range for verifying transactions.

[0267] The business account sends transaction data carrying a data signature to the business server, enabling the business server to immediately send the transaction data carrying the data signature to the core account layer. The core account layer verifies the data signature and obtains a verification result, including a successful verification result. The verification result instructs the core account layer to verify the legality of the business transaction based on the immediate time and the transaction verification time range, obtaining a verification result, including a valid verification result. The valid verification result instructs the core account layer to associate and store the transaction data carrying the data signature in the core account database. Both the data signature and the transaction data stored in the core account database are sent to the verification device. The verification device verifies the legality of the transaction data based on the data signature.

[0268] It should be understood that the computer device 1000 described in the embodiments of this application can perform the data verification methods or apparatus described in the preceding embodiments, and will not be repeated here. In addition, the beneficial effects of using the same method will not be repeated here either.

[0269] This application also provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the data verification methods or apparatus described in the preceding embodiments, which will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.

[0270] The aforementioned computer-readable storage medium can be the data verification device provided in any of the foregoing embodiments or the internal storage unit of the aforementioned computer device, such as the hard disk or memory of the computer device. The computer-readable storage medium can also be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device. Furthermore, the computer-readable storage medium can include both internal storage units and external storage devices of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.

[0271] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium and executes the computer program, enabling the computer device to perform the data verification methods or apparatus described in the preceding embodiments, which will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.

[0272] The terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other step units inherent to these processes, methods, apparatuses, products, or devices.

[0273] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0274] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.

Claims

1. A data processing method, characterized in that, The method is executed by the business server and includes: At the third moment, a certificate application request initiated by the business terminal is obtained; the certificate application request includes a business account and the business public key of the business account; the business public key is generated by the business terminal when applying for the business account; Based on the certificate application request, a business certificate is generated for the business account, and the business certificate is returned to the business terminal; the business certificate is used to indicate to the business terminal that the application for the business account has been successful. The business public key and the business account are associated and stored in the core account database corresponding to the core account layer; At a time later than the third time, transaction data initiated by the business account is acquired and synchronously sent to the core account layer; the transaction data includes the business transaction and the corresponding verification transaction time range, and the transaction data carries a data signature; In the core account layer, the business public key associated with the business account is obtained from the core account database. The data signature is verified using the business public key to obtain a verification result. If the verification result is a successful verification result, the legality of the business transaction is verified based on the first moment and the verification transaction time range to obtain a verification result. If the verification result indicates that the business transaction is legitimate, then the transaction data carrying the data signature at the first moment and the transaction data at the first moment are associated and stored in the core account database corresponding to the core account layer; the data signature and the transaction data stored in the core account database are both sent to the verification device; the verification device is used to verify the legitimacy of the transaction data based on the data signature.

2. The method according to claim 1, characterized in that, The step of verifying the legality of the business transaction based on the first time point and the verification transaction time range, and obtaining the verification result, includes: Identify the relationship between the first moment and the verification transaction time range; the earliest moment of the verification transaction time range is equal to the second moment when the business terminal bound to the business account responds to the completion operation for the business transaction; the latest moment of the verification transaction time range is later than the second moment; If the relationship between the first moment and the verification transaction time range is that the first moment falls within the verification transaction time range, then the verification result is determined as the verification result for the legality verification of the business transaction; the verification result is used to indicate that the business transaction is legal. If the relationship between the first moment and the time range of the verified transaction is that the first moment is later than the latest moment, then the invalid verification result is determined as the verification result for the legality verification of the business transaction; the invalid verification result is used to indicate that the business transaction is not legal.

3. The method according to claim 1, characterized in that, The step of associating and storing the transaction data carrying the data signature at the first moment with the core account database corresponding to the core account layer includes: In the core account database corresponding to the core account layer, obtain the current digital resources of the business account; Obtain the resource transfer value in the business transaction; if the current digital resource contains the digital resource to be transferred corresponding to the resource transfer value, then perform resource transfer processing on the digital resource to be transferred in the current digital resource, and determine the current digital resource after resource transfer processing as the updated digital resource. The first moment, the updated digital resource, and the transaction data carrying the data signature are associated and stored in the core account database.

4. The method according to claim 1, characterized in that, The step of verifying the data signature using the business public key to obtain the verification result includes: The data signature is verified using the business public key to obtain a first digital digest. A second digital digest of the transaction data is generated, and the first digital digest and the second digital digest are compared to obtain a comparison result. If the comparison result indicates that the first digital digest is the same as the second digital digest, then the signature verification success result is determined as the signature verification result; the signature verification success result is also used to indicate that the data signature is obtained by a business terminal bound to the business account, which signs the transaction data using the business private key of the business account; If the comparison result indicates that the first digital digest is different from the second digital digest, then the signature verification failure result is determined as the signature verification result.

5. A data processing method, characterized in that, The method is performed by a verification device and includes: Obtain a transaction verification request for a business account, and generate a transaction acquisition request for the business account based on the transaction verification request; The transaction acquisition request is sent to the business server, so that the business server can obtain the data to be verified of the business account from the core account database corresponding to the core account layer according to the transaction acquisition request; the data to be verified includes transaction data initiated by the business account; the transaction data includes business transactions and the verification transaction time range corresponding to the business transactions; the verification transaction time range is used to instruct the business server to perform legality verification on the business transactions; Obtain the data to be verified returned by the business server. If the data to be verified does not include the data signature of the transaction data, then the transaction data is determined to be illegal transaction data. If the data to be verified includes the data signature of the transaction data, then the legality of the transaction data is verified based on the data signature. The core account database stores a first business public key and the business account in association. The first business public key stored in the core account database is included in the certificate application request sent by the business terminal at a third time. The first business public key is generated by the business terminal when applying for the business account. The certificate application request is used by the business server to generate a business certificate for the business account. The business certificate is used to indicate that the business terminal has successfully applied for the business account.

6. The method according to claim 5, characterized in that, The step of verifying the legality of the transaction data based on the data signature includes: Obtain the first business public key of the business account from the data to be verified, and obtain the second business public key; the second business public key refers to the business public key provided by the business terminal bound to the business account, or the business public key obtained from the blockchain that is bound to the business account; The first business public key is compared with the second business public key to obtain the comparison result; If the comparison result indicates that the first business public key is different from the second business public key, then the transaction data is determined to be illegal transaction data; If the comparison result indicates that the first business public key is the same as the second business public key, then the data signature is verified based on the first business public key to obtain the verification result. If the verification result is a verification failure, then the transaction data is determined to be illegal transaction data; If the verification result is successful, then the transaction data is determined to be legitimate transaction data.

7. A data processing method, characterized in that, The method is executed by the business terminal and includes: When applying for a business account, a business public key is generated; A certificate application request including the business account and the business public key is generated, and the certificate application request is sent to the business server so that the business server generates a business certificate for the business account according to the certificate application request; the business server is used to associate and store the business public key and the business account in the core account database corresponding to the core account layer; Obtain the business certificate returned by the business server; the business certificate is used to indicate that the business terminal has successfully applied for the business account; The business account responds to the completion operation for the business transaction and determines the verification transaction time range for verifying the legality of the business transaction; Generate a data signature for the transaction data; the transaction data includes the business transaction and the time range for verifying the transaction. The transaction data carrying the data signature is sent to the business server through the business account, so that the business server sends the transaction data carrying the data signature to the core account layer at the first moment. The core account layer is used to obtain the business public key associated with the business account from the core account database, and to perform signature verification processing on the data signature using the business public key to obtain a signature verification result. The signature verification result includes a signature success result. The signature verification result is used to instruct the core account layer to perform legality verification on the business transaction according to the first moment and the verification transaction time range to obtain a verification result. The verification result includes a verification legality result. The verification legality result is used to instruct the core account layer to associate and store the transaction data carrying the data signature at the first moment in the core account database. The data signature and the transaction data stored in the core account database are both used to send to the verification device. The verification device is used to verify the legality of the transaction data based on the data signature.

8. The method according to claim 7, characterized in that, The determination of the verification transaction time range used to verify the legality of the business transaction includes: The earliest moment is determined as the second moment when the response to the completion operation of the business transaction is performed; Obtain the transaction verification time threshold, and sum the earliest time and the transaction verification time threshold to obtain the latest time; Generate a verification transaction time range that includes the earliest time and the latest time.

9. The method according to claim 7, characterized in that, The data signature for generating transaction data includes: Generate transaction data including the business transaction and the time range of the verification transaction; Obtain the business private key, and use the business private key to sign the transaction data to obtain the data signature of the transaction data.

10. A data processing apparatus, characterized in that, The device operates on a business server and includes: The request acquisition module is used to acquire a certificate application request initiated by a business terminal at a third time. The certificate application request includes a business account and the business public key of the business account. The business public key is generated by the business terminal when applying for the business account. The certificate generation module is used to generate a business certificate for the business account according to the certificate application request, and return the business certificate to the business terminal; the business certificate is used to indicate to the business terminal that the application for the business account has been successful. The second storage module is used to associate and store the business public key and the business account in the core account database corresponding to the core account layer. The data sending module is used to acquire transaction data initiated by the business account at a first moment later than the third moment, and synchronously send the transaction data to the core account layer; the transaction data includes the business transaction and the verification transaction time range corresponding to the business transaction, and the transaction data carries a data signature; The transaction verification module is used to retrieve the business public key associated with the business account from the core account database in the core account layer, perform signature verification on the data signature using the business public key, and obtain a signature verification result. If the signature verification result is a successful signature verification result, the legality of the business transaction is verified according to the first time and the verification transaction time range, and a verification result is obtained. The first storage module is configured to, if the verification result indicates that the business transaction is legitimate, associate and store the transaction data carrying the data signature at the first moment in the core account database corresponding to the core account layer; the data signature and the transaction data stored in the core account database are both sent to the verification device; the verification device is configured to verify the legitimacy of the transaction data based on the data signature.

11. A data processing apparatus, characterized in that, The device operates on the verification equipment and includes: The request generation module is used to obtain transaction verification requests for business accounts and generate transaction acquisition requests for business accounts based on the transaction verification requests. A request sending module is used to send the transaction acquisition request to the business server, so that the business server can obtain the data to be verified of the business account from the core account database corresponding to the core account layer according to the transaction acquisition request; the data to be verified includes transaction data initiated by the business account; the transaction data includes the business transaction and the verification transaction time range corresponding to the business transaction; the verification transaction time range is used to instruct the business server to perform legality verification on the business transaction; The data determination module is used to obtain the data to be verified returned by the business server. If the data to be verified does not include the data signature of the transaction data, then the transaction data is determined to be illegal transaction data. A data verification module is used to verify the legality of the transaction data based on the data signature if the data to be verified includes the data signature of the transaction data. The core account database stores a first business public key and the business account in association. The first business public key stored in the core account database is included in the certificate application request sent by the business terminal at a third time. The first business public key is generated by the business terminal when applying for the business account. The certificate application request is used by the business server to generate a business certificate for the business account. The business certificate is used to indicate that the business terminal has successfully applied for the business account.

12. A data processing apparatus, characterized in that, The device operates on a service terminal and includes: The second generation module is used to generate a business public key when applying for a business account; The second sending module is used to generate a certificate application request including the business account and the business public key, and send the certificate application request to the business server, so that the business server generates a business certificate for the business account according to the certificate application request; the business server is used to associate and store the business public key and the business account in the core account database corresponding to the core account layer; The certificate acquisition module is used to acquire the business certificate returned by the business server; the business certificate is used to indicate that the business terminal has successfully applied for the business account; The time determination module is used to respond to the completion operation of the business transaction in the business account and determine the verification transaction time range for verifying the legality of the business transaction; The first generation module is used to generate a data signature for transaction data; the transaction data includes the business transaction and the verification transaction time range. A first sending module is used to send the transaction data carrying the data signature to the business server through the business account, so that the business server sends the transaction data carrying the data signature to the core account layer at a first moment. The core account layer is used to obtain the business public key associated with the business account from the core account database, and to perform signature verification processing on the data signature using the business public key to obtain a signature verification result. The signature verification result includes a signature success result. The signature verification result is used to instruct the core account layer to perform legality verification on the business transaction according to the first moment and the verification transaction time range to obtain a verification result. The verification result includes a verification legality result. The verification legality result is used to instruct the core account layer to associate and store the transaction data carrying the data signature at the first moment in the core account database. The data signature and the transaction data stored in the core account database are both used to send to a verification device. The verification device is used to verify the legality of the transaction data based on the data signature.

13. A computer device, characterized in that, include: Processor, memory, and network interface; The processor is connected to the memory and the network interface, wherein the network interface is used to provide data communication functions, the memory is used to store computer programs, and the processor is used to invoke the computer programs to cause the computer device to perform the method according to any one of claims 1 to 9.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded and executed by a processor to cause a computer device having the processor to perform the method of any one of claims 1-9.

15. A computer program product, characterized in that, The computer program product includes a computer program stored in a computer-readable storage medium, the computer program being adapted to be read and executed by a processor to cause a computer device having the processor to perform the method of any one of claims 1-9.