Key application method and device and related product

Through node interaction in the blockchain network, cross-institutional access to trusted computing resources is achieved, the security risks existing in the centralized control panel are solved and the security of trusted computing is improved.

CN119995840APending Publication Date: 2025-05-13TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311514907.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the prior art, centralized control panels have the risk of centralized misconduct in trusted computing scenarios, which affects the security of trusted computing, and the trusted execution environment of different institutions cannot be directly accessed.

Method used

Through the interaction between the first node and the second node in the blockchain network, the first console can represent the second console to call the first trusted computing resource of the first institution to apply for the encryption key, realizing the second institution's access requirements for the first trusted computing resource of the first institution through the second institution.

Benefits of technology

It avoids the risk of centralized evil, improves the security of trusted computing, and realizes the need to access trusted computing resources across institutions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995840A_ABST
    Figure CN119995840A_ABST
Patent Text Reader

Abstract

The invention discloses a key application method, a key application device and a related product, which can be applied to various scenes such as cloud technology, artificial intelligence, intelligent traffic, auxiliary driving and the like. The method comprises the following steps: receiving an encryption key application message sent by a second control console; sending an encryption key application message to a first control console; sending an encryption key application message to a first control console; and synchronizing the encryption key to the second node, so that the second control table downloads the encryption key through the second node. Visibly, interaction between the first control console and the second control console can be realized through the block chain network, so that the first control console can act as the second control console to call the first trusted computing resource application encryption key of the first mechanism, and the access demand of the second mechanism to the first trusted computing resource of the first mechanism is realized. Thus, through decentralization of the block chain network, the risk of centralization can be avoided, and the security of trusted computing is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of blockchain technology, and in particular to a key application method, device and related products. Background Art

[0002] Trusted computing is a technical means to ensure the integrity of server systems and applications and to ensure that they run in the desired trusted state. In a trusted computing scenario, encryption keys are used to encrypt data involved in trusted computing tasks, and decryption keys only exist in the trusted execution environment that performs trusted computing tasks. The trusted execution environment will issue encryption keys to trusted computing participating organizations that participate in trusted computing tasks. Currently, different organizations have their own independent trusted execution environments, and one organization cannot access the trusted computing resources in the trusted execution environment of another organization.

[0003] In the related art, multiple institutions, each with trusted computing resources, use a centralized control console. The first institution can initiate a member invitation to the second institution through the centralized control console. If the members of the second institution agree, the second institution can apply for encryption keys from the trusted computing resources of the first institution through the centralized control console. However, the centralized control console is connected to the trusted computing resources of each institution, so it can reach the trusted computing resources of each institution, which is prone to the risk of centralized malicious behavior, affecting the security of trusted computing. Summary of the invention

[0004] The embodiments of the present application provide a key application method, device and related products, the purpose of which is to support cross-institutional access to trusted computing resources while ensuring the security of trusted computing.

[0005] In a first aspect, the present application provides a key application method, which is applied to a first node in a blockchain network, wherein the first node is communicatively connected to a first control station, which is communicatively connected to a first trusted computing resource of a first institution, and the blockchain network further includes a second node, wherein the second node is communicatively connected to a second control station, and the second control station is communicatively connected to a second trusted computing resource of a second institution, including:

[0006] receiving an encryption key application message sent by the second control station; the encryption key application message is generated by the second control station, and the encryption key application message is synchronized to the first node through the second node;

[0007] Sending the encryption key application message to the first control station, so that the first control station responds to the encryption key application message and calls the first trusted computing resource to apply for the encryption key;

[0008] Receiving the encryption key sent by the first control station;

[0009] The encryption key is synchronized to the second node, so that the second control station downloads the encryption key through the second node.

[0010] A second aspect of the present application provides a key application device, which is applied to a first node in a blockchain network, wherein the first node is communicatively connected to a first control station, which is communicatively connected to a first trusted computing resource of a first institution, and the blockchain network further includes a second node, wherein the second node is communicatively connected to a second control station, and the second control station is communicatively connected to a second trusted computing resource of a second institution, including:

[0011] A message receiving module, used to receive an encryption key application message sent by the second control station; the encryption key application message is generated by the second control station, and the encryption key application message is synchronized to the first node through the second node;

[0012] a message sending module, configured to send the encryption key application message to the first control station, so that the first control station responds to the encryption key application message and calls the first trusted computing resource to apply for the encryption key;

[0013] A key receiving module, used for receiving the encryption key sent by the first control station;

[0014] A key synchronization module is used to synchronize the encryption key to the second node so that the second control console downloads the encryption key through the second node.

[0015] A third aspect of the present application provides a computer device, the device comprising a processor and a memory:

[0016] The memory is used to store a computer program and transmit the computer program to the processor;

[0017] The processor is used to execute the steps of the key application method as described in the first aspect according to the computer program.

[0018] A fourth aspect of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium is used to store a computer program, and the computer program is used to execute the steps of the key application method described in the first aspect above.

[0019] In a fifth aspect, the present application provides a computer program product or a computer program, the computer program product or the computer program includes a computer instruction, the computer instruction is stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the steps of the key application method described in the first aspect above.

[0020] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:

[0021] In the technical solution of the present application, the blockchain network includes a first node and a second node, the first node is connected to the first control station in communication, the first control station is connected to the first trusted computing resource of the first organization, the second node is connected to the second control station in communication, and the second control station is connected to the second trusted computing resource of the second organization. After the second control station generates an encryption key application message, it will send it to the second node, and the second node will synchronize the encryption key application message to the first node, and the first node will receive the encryption key application message sent by the second control station; the second node will send the encryption key application message to the first control station, and the first control station will respond to the encryption key application message and can call the first trusted computing resource to apply for the encryption key; then, the first control station will send the encryption key obtained by the application to the first node; then the first node can synchronize the encryption key to the second node, so that the second control station can download the encryption key through the second node.

[0022] Each institution has an independent control station, the first institution has a first control station, and the second institution has a second control station. The interaction between the first and second nodes of the blockchain network can be realized. In this application, through the interaction between the first node and the second node of the blockchain network, the first control station can act on behalf of the second control station to call the first trusted computing resource of the first institution to apply for an encryption key, so that the second institution can encrypt the data based on the encryption key obtained in the application and provide it to the first trusted computing resource, thereby realizing the second institution's cross-institutional access to the first trusted computing resource of the first institution. In this way, through the decentralization of the blockchain network, the risk of centralized evil can be avoided, and the security of trusted computing can be improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 A schematic diagram of a key application method in a related technology provided in an embodiment of the present application;

[0024] Figure 2a A scenario architecture diagram of a key application method provided in an embodiment of the present application;

[0025] Figure 2bA schematic diagram of the structure of a distributed system provided in an embodiment of the present application;

[0026] Figure 2c A schematic diagram of the structure of a block provided in an embodiment of the present application;

[0027] Figure 3 A schematic diagram of a trusted computing provided in an embodiment of the present application;

[0028] Figure 4 A flowchart of a key application method provided in an embodiment of the present application;

[0029] Figure 5 A schematic diagram of a scenario of a key application method provided in an embodiment of the present application;

[0030] Figure 6a A signaling interaction diagram of an alliance member invitation process provided in an embodiment of the present application;

[0031] Figure 6b A signaling interaction diagram of a key application process provided in an embodiment of the present application;

[0032] Figure 6c A signaling interaction diagram of a member information update process provided in an embodiment of the present application;

[0033] Figure 7 A schematic diagram of the structure of a key application device provided in an embodiment of the present application;

[0034] Figure 8 A schematic diagram of the structure of the server in the embodiment of the present application;

[0035] Fig. 9 A schematic diagram of the structure of a terminal device in an embodiment of the present application. DETAILED DESCRIPTION

[0036] Currently, a centralized control console is usually used to unify the communication with the trusted computing resources of multiple institutions. Through this centralized control console, cross-institutional access to computing resources can be achieved. For example, see Figure 1 , which is a schematic diagram of a key application method in a related technology provided by an embodiment of the present application. Figure 1As shown. The centralized control console is connected to the trusted computing resources of organization A and the trusted computing resources of organization B respectively, and the centralized control console also includes a database. Members of organization A include Alice, and members of organization B include Bob. Assuming that the trusted computing tasks performed by the trusted computing resources of organization A need to use the data provided by Bob, then Bob needs to apply for the encryption key issued by the trusted execution environment where the trusted computing resources of organization A are located. Specifically, Alice of organization A has created a computing alliance, then Alice can send an alliance invitation request to the centralized control console to request Bob to join the computing alliance, and the centralized control console will store the alliance invitation request in the database; Bob can read the alliance invitation request in the database through the centralized control console. If bob agrees to join, bob can apply for the encryption key from the trusted computing resources of organization A through the centralized control console; after the application is successful, the centralized platform can store the encryption key in the database; bob can read the encryption key in the database through the centralized control console to encrypt the data using the encryption key and provide the encrypted data to the trusted computing resources of organization A.

[0037] However, the centralized control console can communicate with the trusted computing resources of various institutions, indicating that it can reach the trusted computing resources of various institutions, which is prone to the risk of centralized malicious behavior and affects the security of trusted computing.

[0038] In view of the above problems, a key application method, device and related products are provided in the present application, the purpose of which is to support cross-institutional access to trusted computing resources while ensuring the security of trusted computing. The key application method is applied to a first node in a blockchain network, the first node is connected to a first control station in communication, the first control station is connected to a first trusted computing resource of the first institution in communication, the blockchain network also includes a second node, the second node is connected to a second control station in communication, the second control station is connected to a second trusted computing resource of the second institution in communication, in the technical solution provided in the present application, an encryption key application message sent by the second control station is received; the encryption key application message is generated by the second control station, and the encryption key application message is synchronized to the first node through the second node. Send an encryption key application message to the first control station so that the first control station responds to the encryption key application message and calls the first trusted computing resource to apply for an encryption key. Receive the encryption key sent by the first control station; the encryption key is sent by the first control station to the first node. Synchronize the encryption key to the second node so that the second control station downloads the encryption key through the second node.

[0039] Thus, in this application, through the interaction between the first node and the second node of the blockchain network, the first control station can act on behalf of the second control station to call the first trusted computing resource of the first institution to apply for an encryption key, so that the second institution can encrypt the data based on the encryption key obtained and provide it to the first trusted computing resource, thereby realizing the second institution's cross-institutional access to the first trusted computing resource of the first institution. Through the decentralization of the blockchain network, the risk of centralized evil can be avoided, and the security of trusted computing can be improved.

[0040] The execution subject of the key application method provided in the embodiment of the present application can be a terminal device on which the first node is deployed. As an example, the terminal device can specifically include but is not limited to mobile phones, desktop computers, tablet computers, laptops, PDAs, intelligent voice interaction devices, smart home appliances, vehicle terminals, aircraft, etc. The embodiments of the present invention can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, smart transportation, assisted driving, etc. The execution subject of the key application method provided in the embodiment of the present application can also be a server on which the first node is deployed. As an example, the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. In addition, the server can also be a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and basic cloud computing services such as big data and artificial intelligence platforms.

[0041] See also Figure 2a , which is a scenario architecture diagram of a key application method provided by an embodiment of the present application, in which a computer device 100 is included, and the computer device 100 can be a terminal device or a server in the above-mentioned various forms. The computer device 100 deploys a first node of the blockchain network, the first node is communicatively connected to the first control station, the first control station is communicatively connected to the first trusted computing resource of the first institution, and the blockchain network also includes a second node, the second node is communicatively connected to the second control station, and the second control station is communicatively connected to the second trusted computing resource of the second institution.

[0042] It should be noted that the second node can be deployed on the computer device 100 or on other computer devices. The first control console and the first computing resource of the first organization can be deployed on the same computer device or on different computer devices, which is not limited in this application. The second organization is similar and will not be described in detail here.

[0043] The following describes the key application method provided in this application by taking the deployment of the second node on other computer devices as an example.

[0044] The computer device 100 receives the encryption key application message sent by the second control station; the encryption key application message is generated by the second control station, and the encryption key application message is synchronized to the computer device 100 through the second node. The computer device 100 then sends the encryption key application message to the first control station, so that the first control station responds to the encryption key application message and calls the first trusted computing resource to apply for the encryption key. Then, the computer device 100 receives the encryption key sent by the first control station; finally, the computer device 100 synchronizes the encryption key to the second node, so that the second control station downloads the encryption key through the second node.

[0045] It can be seen that in this application, through the decentralization of the blockchain network, through the first node and the second node of the blockchain network, the first control station can proxy the second control station to call the first trusted computing resource of the first institution to apply for an encryption key, so that the second institution can encrypt the data based on the encryption key obtained and provide it to the first trusted computing resource, thereby realizing the second institution's cross-institutional access to the first trusted computing resource of the first institution. It can avoid the risk of centralized evil and improve the security of trusted computing.

[0046] The key application method involved in the embodiment of the present application can be applied to a distributed system formed by connecting a client and multiple nodes in a blockchain network (any form of computing device in the access network, such as a server and a user terminal) through network communication.

[0047] Take the distributed system as the blockchain system as an example, see Figure 2b , Figure 2b 2 is a schematic diagram of a distributed system provided by an embodiment of the present invention. The distributed system 200 is formed by multiple nodes 300 (any form of computing devices in the access network, such as servers and user terminals) and clients 400, and a point-to-point network is formed between the nodes 300. In a distributed system, any machine such as a server or a terminal can join and become a node, and the node includes a hardware layer, an intermediate layer, an operating system layer, and an application layer.

[0048] See also Figure 2b The functions of each node in the blockchain system shown include:

[0049] 1) Routing: a basic function of a node, used to support communication between nodes.

[0050] In addition to the routing function, the node can also have the following functions:

[0051] 2) Applications, which are deployed in the blockchain to implement specific businesses according to actual business needs, record data related to the implementation of functions to form record data, carry digital signatures in the record data to indicate the source of the task data, and send the record data to other nodes in the blockchain system for other nodes to add the record data to the temporary block when they successfully verify the source and integrity of the record data.

[0052] For example, the services implemented by the application include:

[0053] 2.1) Wallet, used to provide the function of conducting electronic currency transactions, including initiating transactions (i.e., sending the transaction record of the current transaction to other nodes in the blockchain system. After successful verification by other nodes, as a response to acknowledge the validity of the transaction, the transaction record data is stored in the temporary block of the blockchain; of course, the wallet also supports querying the remaining electronic currency in the electronic currency address;

[0054] 2.2) Shared ledger, used to provide functions such as storage, query and modification of account data, and send the record data of the operation on the account data to other nodes in the blockchain system. After other nodes verify the validity, as a response to acknowledge the validity of the account data, the record data will be stored in a temporary block, and a confirmation can also be sent to the node that initiated the operation.

[0055] 2.3) Smart contracts are computerized protocols that can execute the terms of a contract. They are implemented by deploying code on a shared ledger that is executed when certain conditions are met. The code is used to complete automated transactions based on actual business needs, such as querying the logistics status of the goods purchased by the buyer and transferring the buyer's electronic currency to the merchant's address after the buyer signs for the goods. Of course, smart contracts are not limited to executing contracts for transactions, but can also execute contracts for processing received information.

[0056] 3) Blockchain, including a series of blocks that are connected to each other in the order of their generation. Once a new block is added to the blockchain, it will not be removed. The block records the record data submitted by the nodes in the blockchain system.

[0057] See also Figure 2c, which is a schematic diagram of the structure of a block provided by an embodiment of the present invention. Each block (BlockStructure) includes the hash value of the transaction record stored in this block (the hash value of this block) and the hash value of the previous block. Each block is connected by the hash value to form a blockchain. In addition, the block can also include information such as the timestamp when the block was generated. Blockchain is essentially a decentralized database, a string of data blocks generated by cryptographic methods. Each data block contains relevant information for verifying the validity of its information (anti-counterfeiting) and generating the next block.

[0058] For ease of understanding, first combine Figure 3 , introduce trusted computing, Figure 3 A schematic diagram of a trusted computing provided in an embodiment of the present application. Trusted computing includes data providers, computing model providers, computing task creators, and computing result users. The data provider provides a data source for the trusted computing task. It will not disclose plaintext data, but only provide the trusted computing task with ciphertext data encrypted with an encryption key, that is, it will encrypt private plaintext data to obtain public ciphertext data. Figure 3 As shown, it includes data provider A and data provider B. The encryption key is issued to the data provider by the trusted execution environment that executes the trusted computing task. For example, the trusted computing resources deployed by the trusted execution environment have a key management service, which can generate a key pair, issue the encryption key to the data provider, and store the decryption key in the trusted execution environment, so that the encrypted ciphertext data can be decrypted and used when the trusted execution environment executes the trusted computing task. The model provider provides the trusted computing task with a computing model applied when executing the trusted computing task. The computing task creator can create a trusted computing task. The data provider and the computing model provider will approve the trusted computing task. For example, the data provider will approve whether the trusted computing task can use the data provided by it, and the computing model provider will approve whether the trusted computing task can use the computing model provided by it. Among them, the encryption key is the encryption public key, and the decryption key is the decryption private key.

[0059] If the approval of the trusted computing task is passed, the trusted computing task will be sent to the trusted execution environment for execution. In the trusted execution environment, the ciphertext data provided by the data provider will be pulled and decrypted, and then the calculation result will be calculated by combining it with the calculation model provided by the pulled calculation model provider. The calculation result is then encrypted with another encryption key and sent to the calculation result user, who stores the encrypted calculation result in the database. The calculation result user can use the locally stored decryption key corresponding to another encryption key to decrypt the calculation result, and store the decrypted calculation result as a private calculation result in the local database.

[0060] In addition, it may also include a computing alliance creator, which is used to create a computing alliance and invite data providers, computing model providers, computing task creators, computing result users, etc. to join the computing alliance.

[0061] Next, the key application method provided by the embodiment of the present application is specifically introduced with the computer device that deploys the first node in the blockchain network as the execution subject. The first node is communicatively connected to the first control station, the first control station is communicatively connected to the first trusted computing resource of the first institution, and the blockchain network also includes a second node, the second node is communicatively connected to the second control station, and the second control station is communicatively connected to the second trusted computing resource of the second institution.

[0062] See also Figure 4 , which is a flow chart of a key application method provided in an embodiment of the present application. In this method, the following steps are included:

[0063] S401: Receive an encryption key application message sent by a second control station.

[0064] In an embodiment of the present application, the encryption key application message is generated by the second control station. The encryption key application message is a message generated when the target member of the second organization, as a data provider, wants to provide data to the first trusted computing resource of the first organization and needs to apply for an encryption key from the first trusted computing resource. As an example, the encryption key can be an encryption public key used to encrypt data in an asymmetric key.

[0065] After the second control station generates the encryption key application message, it sends it to the second node that is communicatively connected to the second control station. The second node then synchronizes the encryption key application message to the first node based on the sharing function of the blockchain network, so that the first node receives the encryption key application message sent by the second control station.

[0066] S402: Send an encryption key application message to the first control station.

[0067] The first node sends the received encryption key application message to the first control center, and the first control center responds to the encryption key application message and calls the first trusted computing resource to apply for the encryption key.

[0068] As an example, if the first control console and the first trusted computing resource are deployed on different computer devices respectively, then after receiving the encryption key application message, the first control console can forward it to the computer device where the first trusted computing resource is deployed, so that it can respond to the encryption key application message and apply for an encryption key that can encrypt data for the target member of the second organization.

[0069] As an example, the first trusted computing resource may include a key management service, which can be used to manage the key of the first trusted computing resource, issue encryption keys to data providers of the first computing resource, and manage decryption keys corresponding to the encryption keys. When the data provider provides data encrypted based on the encryption key, the key management service can use the decryption key stored therein to decrypt the encrypted data so that the data can be used when executing the corresponding trusted computing task in the trusted execution environment where the first trusted computing resource is located. After receiving the encryption key application message, the above-mentioned first control console can respond to the encryption key application message and forward it to the first trusted computing resource to call the key management service of the first trusted computing resource to apply for an encryption key for the target member of the second organization.

[0070] In a possible implementation of the present application, the blockchain network includes an encryption key application contract event, and the triggering condition of the encryption key application contract event is that the blockchain network receives an encryption key application message, and the first control station subscribes to the encryption key application contract event. Then S402 can be specifically: when it is detected that there is an encryption key application message in the blockchain network, it indicates that the triggering condition of the encryption key application contract event is met, then the first node can send the encryption key application message to the first control station that subscribes to the encryption key application contract event.

[0071] As an example, a smart contract is deployed in the blockchain network, which includes multiple interfaces. The interfaces define the triggering conditions of contract events. When it is detected that the blockchain network has received an encryption key application message (that is, when the triggering conditions are met), the interface executes to trigger the encryption key application contract event, so that the first node sends the encryption key application message to the first control console that subscribes to the encryption key application contract event.

[0072] It should be noted that the blockchain network can also send the encryption key application message to other control stations that subscribe to the encryption key application contract event, but only the first control station has the authority to process it, and other control stations do not have the authority to process it, so other control stations can ignore the encryption key application message. Exemplarily, the chain identity issued by the blockchain network to each control station can be used to verify whether each control station has the authority to process the message. The specific issuance method and specific application method of the chain identity can refer to the introduction of the following embodiment.

[0073] In this way, a smart contract is deployed in the blockchain network in advance, and its interface is used to execute the contract event that triggers the encryption key application, so that the blockchain network can automatically send the encryption key application message to the control console that has subscribed to the contract event without human intervention, which can improve the data interaction efficiency and speed of the blockchain network and reduce supervision costs.

[0074] S403: Receive the encryption key sent by the first control station.

[0075] After the first control console calls the first trusted computing resource to apply for the encryption key, the first control console sends the encryption key to the first node.

[0076] It is understandable that if the target members of the second organization want to provide data to the first trusted computing resource of the first organization as a data provider, the target members of the second structure must first join the computing alliance of the first organization to participate in the trusted computing tasks performed in the trusted execution environment where the first trusted computing resource is deployed.

[0077] Therefore, in a possible implementation manner of the present application, before S401, the key application method may further include the following steps:

[0078] A1: Receive the alliance member invitation message sent by the first control console.

[0079] After an object with alliance member invitation authority in the first institution triggers an alliance member invitation operation, the first control console may generate an alliance member invitation message in response to the alliance member invitation operation, for inviting a target member of the second institution to join the computing alliance of the first institution.

[0080] In the embodiment of the present application, the object refers to a member of the first organization, and the alliance member invitation permission refers to the permission to invite members of other organizations to join the computing alliance of the first organization. For example, the object with the alliance member invitation permission may be a member of the computing alliance that created the first organization.

[0081] A2: Synchronize the alliance member invitation message to the second node.

[0082] Based on the sharing function of the blockchain network, the first node synchronizes the alliance member invitation message to the second node, and the second node then sends the alliance member invitation message to the second control console.

[0083] In this way, before the target member of the second organization applies for an encryption key from the first trusted computing resource, the object in the first organization with the authority to invite alliance members first sends an invitation to the target member to join the computing alliance of the first organization, so that the target member has the authority to provide data to the first trusted computing resource, and further enables the second control console to apply for an encryption key from the first trusted computing resource.

[0084] As an example, the blockchain network includes an alliance member invitation contract event, and the second control station subscribes to it. The triggering condition of the alliance member invitation contract event is that the blockchain network receives an alliance member invitation message. Then, when it is detected that the blockchain network has an alliance member invitation message, the alliance member invitation contract event is triggered, and the second node can send an alliance member invitation message to the second control station that has subscribed to the alliance member invitation contract event.

[0085] It is understandable that there may be a situation where the target member of the second organization already belongs to the computing alliance of the first organization. In this case, the first control console does not need to send an invitation to the target member of the second organization. The second control console can directly generate an encryption key application message to apply for an encryption key from the first trusted computing resource.

[0086] Therefore, in a possible implementation of the present application, the blockchain network stores the member information of the computing alliance of the first institution. Before A1, the key application method may further include the following steps:

[0087] B1: If, in response to the member information confirmation request sent by the first control center, it is confirmed that the member information of the computing alliance of the first institution includes the target member, a first confirmation result is sent to the first control center.

[0088] In response to the alliance member invitation operation, the first control console may generate a member information confirmation request and send it to the first node before generating the alliance member invitation message, so that the first node can confirm whether the member information of the computing alliance of the first institution includes the target member. The member information confirmation request is used to confirm whether the member information of the computing alliance of the first institution includes the target member.

[0089] If the first node confirms that the member information of the computing alliance of the first organization includes the target member, the first node can send a first confirmation result to the first control center, that is, send a result that the target member is already a member of the computing alliance of the first organization. Then the first control center can stop generating the alliance member invitation message.

[0090] Accordingly, A1 may specifically include:

[0091] B2: If, in response to the member information confirmation request sent by the first control center, it is confirmed that the member information of the computing alliance of the first institution does not include the target member, a second confirmation result is sent to the first control center.

[0092] If the first node confirms that the member information of the computing alliance of the first organization does not include the target member, the first node can send a second confirmation result to the first control center, that is, a result that the target member is not a member of the computing alliance of the first organization. The first control center can generate an alliance member invitation message to send to the first node.

[0093] B3: Receive the alliance member invitation message sent by the first control console.

[0094] In this way, after receiving the first confirmation result, it is possible to avoid repeatedly generating and sending alliance member invitation messages, thereby avoiding wasting resources.

[0095] In a possible implementation manner of the present application, the key application method may further include the following steps:

[0096] C1: Receive the alliance member invitation processing result sent by the second control console.

[0097] After the first node receives the alliance member invitation message sent by the first control console, it will synchronize it to the second node, and the second node will then send the alliance member invitation message to the second control console, so that the second control console will present it to the target members of the second organization in response to the alliance member invitation message.

[0098] The second control console can generate an alliance member invitation processing result based on the target member's operation on the alliance member invitation message, and the second control console then sends it to the second node, and the second node synchronizes the alliance member invitation processing result to the first node.

[0099] In an embodiment of the present application, the target member's operation on the alliance member invitation message can be an approval operation or a rejection operation. For example, the second control console can display the alliance member invitation interface to the target member, which may include the text "The object with alliance member invitation authority in the first organization invites you to join the computing alliance of the first organization", and may also include an "Agree" control or a "Reject" control. The user can operate to trigger the "Agree" control or the "Reject" control, so that the second control console generates an alliance member invitation processing result indicating approval to join or refusal to join.

[0100] C2: Send the alliance member invitation processing result to the first control console.

[0101] The first node sends the alliance member invitation processing result sent by the second control station to the first control station.

[0102] C3: If the result of the alliance member invitation processing is approval, in response to the operation of the first control console to add the target member to the computing alliance of the first institution, the member information of the computing alliance of the first institution stored in the blockchain network is updated to obtain the updated member information.

[0103] If the result of the alliance member invitation processing is agreement to join the trusted computing of the first institution, the first control console can add the target member to the computing alliance of the first institution, and the first node can update the member information of the computing alliance of the first institution stored in the blockchain network to obtain the updated member information.

[0104] As an example, the blockchain network includes an invitation processing result contract event, and the first control station subscribes to it. The triggering condition of the invitation processing result contract event is that the blockchain network receives the alliance member invitation processing result. Then, when it is detected that the blockchain network has an alliance member invitation processing result, the invitation processing result contract event is triggered, and the first node can send the alliance member invitation processing result to the first control station that subscribes to the invitation processing result contract event.

[0105] In this way, the member information of the computing alliance of the first institution stored in the blockchain network is updated in a timely manner, ensuring the accuracy of the information stored in the blockchain network and facilitating the control console connected to the node communication of the blockchain network to query at any time.

[0106] It is understandable that other institutions may have a need to understand the member information of the computing alliance of the first institution. When it is updated, other institutions need to understand the updated member information in a timely manner.

[0107] Therefore, in a possible implementation of the present application, the blockchain network may further include a third node, the third node is communicatively connected to a third control console, and the third control console is communicatively connected to a third trusted computing resource of a third institution. The key application method may further include: synchronizing the updated member information to the third node, so that the third node sends the updated member information to the third control console.

[0108] As an example, the blockchain network includes a member information update contract event, and the third control station subscribes to it. The triggering condition of the member information update contract event is that the blockchain network updates the member information. Then, when it is detected that the blockchain network updates the member information, the member information update contract event is triggered, and the third node can send the updated member information to the third control station that subscribes to the member information update contract event.

[0109] In this way, when the member information of the computing alliance of the first institution is updated, the third control console can receive the updated member information in time, which can meet the need of the third institution to understand the member information of the computing alliance of the first institution in real time.

[0110] S404: Synchronize the encryption key to the second node.

[0111] The first node synchronizes the encryption key sent by the first control console to the second node. When the target member of the second organization needs to provide data for the first trusted computing resource, the second control console can download the encryption key through the second node. The second control console encrypts the data provided by the target member based on the encryption key, and sends the encrypted data to the first trusted computing resource through the blockchain network and the first control console, participating in the trusted computing task performed by the computing alliance of the first organization.

[0112] As an example, the blockchain network includes a key application success contract event, and the second control station subscribes to it. The triggering condition of the key application success contract event is that the blockchain network receives the encryption key. Then, when it is detected that the blockchain network has an encryption key, the key application success contract event is triggered, and the second node can send a message of successful encryption key application to the second control station that has subscribed to the key application success contract event.

[0113] It is understandable that in order to improve the security of the information exchanged in the blockchain network, before each node in the blockchain network realizes data interaction, the blockchain network needs to issue a chain identity to the control console that communicates with each node, so that the blockchain network can authenticate the identity of each control console that sends data based on the chain identity.

[0114] In a possible implementation of the present application, the encryption key application message sent by the second control station to the second node may be a signed encryption key application message. The second control station may apply for a chain identity from the blockchain network. After the blockchain issues a chain identity to the second control station, the second control station may sign the encryption key application message based on the chain identity, so that the blockchain network can verify the identity information of the second control station based on the signed encryption key application message.

[0115] As an example, the chain identity may include a signature private key, a signature public key, a Transport Layer Security (TLS) private key, a TLS public key, and a Certificate Authority (CA) certificate. The second control station may store the signature private key and the TLS private key in a local database. The second control station may sign the encryption key application message based on the signature private key. When the encryption key application message needs to be sent, it may be signed based on the TLS private key so that when the second node receives the signed encryption key application message, it may verify the signed encryption key application message based on the TLS public key and the signature public key to determine that it is the encryption key application message sent by the second control station. The CA certificate may also be verified to determine the identity information of the second control station.

[0116] In this way, a chain identity is issued to the control center that communicates with each node. When the node receives the data sent by the control center, it can authenticate the data to improve the security of the information exchanged in the blockchain network.

[0117] See also Figure 5 ,Should Figure 5 A scenario diagram of a key application method provided for an embodiment of the present application. In this scenario, the blockchain network includes a first node, a second node, a third node, and a fourth node. The first node is connected to the first control station in communication, the second node is connected to the second control station in communication, the third node is connected to the third control station in communication, the fourth node is connected to the fourth control station in communication, the first control station is connected to the first trusted computing resource of the first institution in communication, the second control station is connected to the second trusted computing resource of the second institution in communication, the third control station is connected to the third trusted computing resource of the third institution in communication, and the fourth control station is connected to the fourth trusted computing resource of the fourth institution in communication. The first control station, the second control station, the third control station, and the fourth control station have databases respectively. The founding member of the computing alliance of the first institution is Alice, and Alice wants to invite Bob of the second institution to join the computing alliance. Exemplarily, the first control station can issue a trusted computing task to the first trusted computing resource of the first institution so that the trusted computing task is executed in the trusted execution environment where the first trusted computing resource is deployed.

[0118] like Figure 5 As shown, the second control station can apply for an encryption key from the key management service of the first trusted computing resource through the first node and the second node of the blockchain network and the first control station. The key management service of the first trusted computing resource can send the encryption key to the second control station through the first control station, the first node and the second node of the blockchain network.

[0119] Specifically, the first control station can generate an alliance member invitation message based on Alice's alliance member invitation request for Bob, and submit it to the blockchain network to trigger the alliance member invitation contract event. The blockchain sends the alliance member invitation message to the control station that subscribes to the alliance member invitation contract event, but only the second control station has the authority to process it. The second control station notifies Bob to process the alliance member invitation message. If Bob agrees to the invitation, the blockchain network will issue a chain identity to the second control station. The second control station then generates an encryption key application message and signs it with the chain identity. The second control station sends the encryption key application message to the first control station through the blockchain network, and the first control station forwards it to the key management service of the first trusted computing resource to apply for the encryption key. After the application is successful, the first control station sends the encryption key to the blockchain network, so that when Bob provides data to the first trusted computing resource, the second control station can download the encryption key through the blockchain network and encrypt the data provided by Bob. The second control station then provides the encrypted data to the first trusted computing resource through the blockchain network.

[0120] In addition, the second control station will send the alliance member invitation processing result to the blockchain network, triggering the invitation processing result contract event. The blockchain network sends the alliance member invitation processing result to the control station that subscribes to the invitation processing result contract event, but only the first control station has the authority to process the alliance member invitation processing result. If the alliance member invitation processing result is agreed, Alice will add Bob to the computing alliance of the first organization. The first control station will send the joining information to the blockchain network, triggering the alliance member update contract event. The blockchain network sends the updated member information to each control station that subscribes to the alliance member update contract event, so that each can save it to the local database for easy query at any time.

[0121] For ease of understanding, let's combine Figure 6a-6c The key application method provided in this application is introduced in detail. It can be mainly divided into the invitation initiation stage, the chain identity application stage, the encryption public key application stage and the member information update stage. The blockchain network deploys a smart contract, and multiple interfaces in the smart contract are used to execute and trigger the alliance member invitation contract event, the encryption key application contract event, the key application success contract event and the member information update contract event. The second control console subscribes to the alliance member invitation contract event and the key application success contract event, the first control console subscribes to the encryption key application contract event, and the first control console and the second control console both subscribe to the member information update contract event.

[0122] First, see Figure 6a , which is a signaling interaction diagram of an alliance member invitation process provided by an embodiment of the present application, combined with Figure 6a, the invitation initiation phase is introduced, which includes the following steps:

[0123] S601: In response to an alliance member invitation operation triggered by a founding member of a computing alliance of a first institution, a first control console performs identity authentication on the member initiating the alliance member invitation operation.

[0124] The first control station verifies whether the member who initiated the alliance member invitation operation has the alliance member invitation authority. In the embodiment of the present application, the alliance member invitation operation is initiated by a founding member of the computing alliance of the first institution, who has the alliance member invitation authority.

[0125] S602: The first control station determines whether the target member has been invited.

[0126] As an example, the first control console may check in the local database whether there is an alliance member invitation message for inviting the target member of the second organization to join the computing alliance of the first organization. This application does not limit this.

[0127] S603: If the first control station determines that an invitation has been sent to the target member, it may send a member information confirmation request to the first node.

[0128] The member information confirmation request is used to confirm whether the member information of the computing alliance of the first institution includes the target member.

[0129] S604: The first node responds to the member information confirmation request sent by the first control center, confirms whether the member information of the computing alliance of the first institution stored in the blockchain network includes the target member, and sends the member information confirmation result to the first control center.

[0130] S605: If the member information confirmation result is that the member information of the computing alliance of the first organization does not include the target member, the first control console may generate an alliance member invitation message.

[0131] S606: The first control station sends the alliance member invitation message to the first node.

[0132] S607: The first node synchronizes the alliance member invitation message to the second node.

[0133] S608: When an alliance member invitation message is detected in the blockchain network, an alliance member invitation contract event is triggered.

[0134] S609: The second node sends an alliance member invitation message to the second control console that subscribes to the alliance member invitation contract event.

[0135] S610: The second control console stores the alliance member invitation message in a local database.

[0136] S611: The second control console notifies the target member of the second organization to process the alliance member invitation message.

[0137] S612: In response to the target member's operation on the alliance member invitation message, the second control console generates an alliance member invitation processing result.

[0138] S613: If the alliance member invitation processing result is rejection, the second control station can send the alliance member invitation processing result to the first control station via the second node and the first node of the blockchain network, and the first control station will then send the alliance member invitation processing result to the founding member of the computing alliance of the first organization.

[0139] Next, see Figure 6b , which is a signaling interaction diagram of a key application process provided by an embodiment of the present application. Figure 6b , introduces the chain identity application stage and the encryption public key application stage, including the following steps:

[0140] S614: If the alliance member invitation processing result is approval, the second control console generates a chain identity request message.

[0141] The chain identity request message is used by the second control console to apply for its own chain identity from the blockchain network.

[0142] S615: The second control console sends the chain identity request message to the blockchain network.

[0143] S616: The blockchain network responds to the chain identity request message and issues a chain identity to the second control console.

[0144] S617: The second control station encrypts the private key in the chain identity and stores it in the local database.

[0145] S618: The second control console generates an encryption key application message and signs it based on the private key in the chain identity.

[0146] S619: The second control station sends the signed encryption key application message to the second node.

[0147] S620: If the second node successfully verifies the signature of the encryption key application message based on the public key in the chain identity of the second control station, the signed encryption key application message is synchronized to the first node.

[0148] S621: When an encryption key application message is detected in the blockchain network, an encryption key application contract event is triggered.

[0149] S622: The first node sends an encryption key application message to the first control station that subscribes to the encryption key application contract event. In response to the encryption key application message, the first control station calls the first trusted computing resource to apply for the encryption key.

[0150] S623: The first trusted computing resource sends the encryption key to the first node via the first control console.

[0151] S624: The first node synchronizes the encryption key to the second node.

[0152] S625: When it is detected that there is an encryption key in the blockchain network, a key application success contract event is triggered.

[0153] S626: The second node sends key application success information to the target member via the second control console.

[0154] Next, see Figure 6c , which is a signaling interaction diagram of a member information update process provided by an embodiment of the present application. Figure 6c , the member information updating stage is introduced. After step S612, the member information updating stage includes the following steps:

[0155] S627: The second control console sends the alliance member invitation processing result to the second node.

[0156] S628: The second node synchronizes the alliance member invitation processing result to the first node.

[0157] S629: When it is detected that there is an alliance member invitation processing result in the blockchain network, the invitation processing result contract event is triggered.

[0158] S630: The first node sends the alliance member invitation processing result to the first control station that has subscribed to the invitation processing result contract event.

[0159] S631: If the alliance member invitation processing result is approval, the first control console adds the target member to the computing alliance of the first institution.

[0160] S632: In response to the first control console's operation of adding a target member, the first node determines whether the creating member of the computing alliance of the first institution has the alliance member invitation authority.

[0161] S633: If it is determined that it has the authority to invite alliance members, the member information of the computing alliance of the first institution stored in the blockchain network is updated.

[0162] S634: When it is detected that there is updated member information in the blockchain network, a member information update contract event is triggered.

[0163] S635: The first node sends the updated member information to the first control station that has subscribed to the member information update contract event.

[0164] S636: The first control station stores the updated member information in the local database of the first control station.

[0165] S637: The second node sends the updated member information to the second control console that has subscribed to the member information update contract event.

[0166] S638: The second control station stores the updated member information in the local database of the second control station.

[0167] It should be noted that the present application does not limit the execution order of S635 and S637. They can be executed simultaneously, and the updated member information can be sent to multiple control consoles that have subscribed to the member information update contract event at the same time, or they can be executed sequentially.

[0168] In this way, information interaction between multiple control consoles can be achieved based on the blockchain network, ensuring the security of information, enabling cross-institutional access to computing resources, and ensuring the security of trusted computing.

[0169] Based on the key application method provided in the above embodiment, the present application also provides a key application device. The key application device provided in the embodiment of the present application is specifically introduced below.

[0170] See also Figure 7 , which is a schematic diagram of the structure of a key application device provided in an embodiment of the present application. It is applied to a first node in a blockchain network, the first node is connected to a first control station in communication, the first control station is connected to a first trusted computing resource of a first institution in communication, the blockchain network also includes a second node, the second node is connected to a second control station in communication, the second control station is connected to a second trusted computing resource of a second institution in communication, such as Figure 7 As shown, the key application device 700 may specifically include:

[0171] The message receiving module 710 is used to receive the encryption key application message sent by the second control station; the encryption key application message is generated by the second control station, and the encryption key application message is synchronized to the first node through the second node;

[0172] The message sending module 720 is used to send an encryption key application message to the first control station, so that the first control station responds to the encryption key application message and calls the first trusted computing resource to apply for the encryption key;

[0173] The key receiving module 730 is used to receive the encryption key sent by the first control station;

[0174] The key synchronization module 740 is used to synchronize the encryption key to the second node so that the second control console downloads the encryption key through the second node.

[0175] As an implementation mode, the blockchain network includes an encryption key application contract event. The triggering condition of the encryption key application contract event is that the blockchain network receives an encryption key application message, and the first control station subscribes to the encryption key application contract event. The message sending module 720 can be specifically used for:

[0176] When an encryption key application message is detected in the blockchain network, an encryption key application message that triggers the encryption key application contract event is sent to the first control station that subscribes to the encryption key application contract event.

[0177] As an implementation manner, the key application device 700 may further include:

[0178] An invitation message receiving module, used to receive an alliance member invitation message sent by the first control station; the alliance member invitation message is generated by the first control station in response to an alliance member invitation operation triggered by an object with alliance member invitation authority in the first institution; the alliance member invitation operation is used to invite a target member of the second institution to join the computing alliance of the first institution;

[0179] The invitation message synchronization module is used to synchronize the alliance member invitation message to the second node, so that the second node sends the alliance member invitation message to the second control console.

[0180] As an implementation mode, the blockchain network stores the member information of the computing alliance of the first institution, and the key application device 700 may further include:

[0181] A confirmation result sending module is used to send a first confirmation result to the first control center if it is confirmed in response to the member information confirmation request sent by the first control center that the member information of the computing alliance of the first organization includes the target member, so that the first control center stops generating the alliance member invitation message; the member information confirmation request is used to confirm whether the member information of the computing alliance of the first organization includes the target member;

[0182] Accordingly, the invitation message receiving module may specifically include:

[0183] a confirmation result sending unit, configured to send a second confirmation result to the first control center, if it is confirmed in response to the member information confirmation request sent by the first control center that the member information of the computing alliance of the first institution does not include the target member, so that the first control center generates an alliance member invitation message;

[0184] The invitation message receiving unit is used to receive the alliance member invitation message sent by the first control console.

[0185] As an implementation manner, the key application device 700 may further include:

[0186] A processing result receiving module, used to receive the alliance member invitation processing result sent by the second control station; the alliance member invitation processing result is generated by the second control station based on the target member's operation on the alliance member invitation message, and the alliance member invitation processing result is synchronized to the first node through the second node;

[0187] A processing result sending module, used for sending the alliance member invitation processing result to the first control console;

[0188] The member information updating module is used to update the member information of the computing alliance of the first institution stored in the blockchain network in response to the operation of the first control console to add the target member to the computing alliance of the first institution if the result of the alliance member invitation processing is approval, and obtain the updated member information.

[0189] As an implementation mode, the blockchain network further includes a third node, the third node is communicatively connected to a third control station, the third control station is communicatively connected to a third trusted computing resource of a third institution, and the key application device 700 may further include:

[0190] The member information synchronization module is used to synchronize the updated member information to the third node, so that the third node sends the updated member information to the third control console.

[0191] As an implementation method, the above-mentioned encryption key application message is a signed encryption key application message; the signed encryption key application message is obtained by the second control station signing the encryption key application message based on the corresponding chain identity; the chain identity is obtained by the second control station applying to the blockchain network.

[0192] An embodiment of the present application provides a computer device, which may be a server. Figure 8: is a schematic diagram of a server structure provided in an embodiment of the present application. The server 900 may have relatively large differences due to different configurations or performances, and may include one or more central processing units (CPU) 922 (for example, one or more processors) and memory 932, and one or more storage media 930 (for example, one or more mass storage devices) storing application programs 942 or data 944. Among them, the memory 932 and the storage medium 930 can be short-term storage or permanent storage. The program stored in the storage medium 930 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the server. Furthermore, the central processing unit 922 can be configured to communicate with the storage medium 930 to execute a series of instruction operations in the storage medium 930 on the server 900.

[0193] The server 900 may also include one or more power supplies 926, one or more wired or wireless network interfaces 950, one or more input and output interfaces 958, and / or one or more operating systems 941, such as Windows Server 2000. TM , Mac OS X TM , Unix TM ,Linux TM , FreeBSD TM etc.

[0194] The CPU 922 is used to execute the following steps:

[0195] receiving an encryption key application message sent by the second control station; the encryption key application message is generated by the second control station, and the encryption key application message is synchronized to the first node through the second node;

[0196] Sending the encryption key application message to the first control station, so that the first control station responds to the encryption key application message and calls the first trusted computing resource to apply for the encryption key;

[0197] Receiving the encryption key sent by the first control station;

[0198] The encryption key is synchronized to the second node, so that the second control station downloads the encryption key through the second node.

[0199] The present application embodiment also provides another computer device, which may be a terminal device. Fig. 9For the sake of convenience, only the parts related to the embodiments of the present application are shown. For specific technical details not disclosed, please refer to the method part of the embodiments of the present application. Take the terminal device as a mobile phone as an example:

[0200] Fig. 9 The block diagram shows a partial structure of a mobile phone provided in an embodiment of the present application. Fig. 9 The mobile phone includes: a radio frequency (RF) circuit 1010, a memory 1020, an input unit 1030, a display unit 1040, a sensor 1050, an audio circuit 1060, a wireless fidelity (WiFi) module 1070, a processor 1080, and a power supply 1090. Those skilled in the art can understand that Fig. 9 The mobile phone structure shown in the figure does not constitute a limitation on the mobile phone, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0201] Combine the following Fig. 9 A detailed introduction to the various components of the mobile phone:

[0202] The RF circuit 1010 can be used for receiving and sending signals during information transmission or communication. In particular, after receiving the downlink information of the base station, it is sent to the processor 1080 for processing; in addition, the uplink data is sent to the base station. Generally, the RF circuit 1010 includes but is not limited to an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier (full name: LowNoiseAmplifier, English abbreviation: LNA), a duplexer, etc. In addition, the RF circuit 1010 can also communicate with the network and other devices through wireless communication. The above-mentioned wireless communications may use any communication standard or protocol, including but not limited to Global System of Mobile communications (Global System of Mobile communication, English abbreviation: GSM), General Packet Radio Service (General Packet Radio Service, GPRS), Code Division Multiple Access (Code Division Multiple Access, English abbreviation: CDMA), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (Long Term Evolution, English abbreviation: LTE), e-mail, Short Messaging Service (SMS), etc.

[0203] The memory 1020 can be used to store software programs and modules. The processor 1080 executes various functional applications and data processing of the mobile phone by running the software programs and modules stored in the memory 1020. The memory 1020 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory 1020 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0204] The input unit 1030 can be used to receive input digital or character information, and to generate key signal input related to the user settings and function control of the mobile phone. Specifically, the input unit 1030 may include a touch panel 1031 and other input devices 1032. The touch panel 1031, also known as a touch screen, can collect the user's touch operation on or near it (such as the user's operation on the touch panel 1031 or near the touch panel 1031 using any suitable object or accessory such as a finger, stylus, etc.), and drive the corresponding connection device according to a pre-set program. Optionally, the touch panel 1031 may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch orientation, detects the signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into contact coordinates, and then sends it to the processor 1080, and can receive and execute commands sent by the processor 1080. In addition, the touch panel 1031 can be implemented in various types such as resistive, capacitive, infrared, and surface acoustic waves. In addition to the touch panel 1031, the input unit 1030 may also include other input devices 1032. Specifically, the other input devices 1032 may include but are not limited to one or more of a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, a joystick, etc.

[0205] The display unit 1040 can be used to display information input by the user or information provided to the user and various menus of the mobile phone. The display unit 1040 may include a display panel 1041. Optionally, the display panel 1041 may be configured in the form of a liquid crystal display (full name in English: Liquid Crystal Display, English abbreviation: LCD), an organic light-emitting diode (full name in English: Organic Light-Emitting Diode, English abbreviation: OLED), etc. Further, the touch panel 1031 may cover the display panel 1041. When the touch panel 1031 detects a touch operation on or near it, it is transmitted to the processor 1080 to determine the type of touch event. Subsequently, the processor 1080 provides a corresponding visual output on the display panel 1041 according to the type of touch event. Although in Fig. 9 In the embodiment, the touch panel 1031 and the display panel 1041 are used as two independent components to realize the input and output functions of the mobile phone, but in some embodiments, the touch panel 1031 and the display panel 1041 can be integrated to realize the input and output functions of the mobile phone.

[0206] The mobile phone may also include at least one sensor 1050, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor may adjust the brightness of the display panel 1041 according to the brightness of the ambient light, and the proximity sensor may turn off the display panel 1041 and / or the backlight when the mobile phone is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that identify the posture of the mobile phone (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that can be configured in the mobile phone, such as gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., they will not be repeated here.

[0207] The audio circuit 1060, the speaker 1061, and the microphone 1062 can provide an audio interface between the user and the mobile phone. The audio circuit 1060 can transmit the received audio data to the speaker 1061 after converting the received audio data into an electrical signal, which is converted into a sound signal for output; on the other hand, the microphone 1062 converts the collected sound signal into an electrical signal, which is received by the audio circuit 1060 and converted into audio data, and then the audio data is output to the processor 1080 for processing, and then sent to another mobile phone through the RF circuit 1010, or the audio data is output to the memory 1020 for further processing.

[0208] WiFi is a short-range wireless transmission technology. The mobile phone can help users send and receive emails, browse web pages and access streaming media through the WiFi module 1070. It provides users with wireless broadband Internet access. Fig. 9 A WiFi module 1070 is shown, but it is understandable that it is not an essential component of the mobile phone and can be omitted as needed without changing the essence of the invention.

[0209] The processor 1080 is the control center of the mobile phone. It uses various interfaces and lines to connect various parts of the entire mobile phone. By running or executing software programs and / or modules stored in the memory 1020, and calling data stored in the memory 1020, it executes various functions of the mobile phone and processes data, thereby collecting overall data and information of the mobile phone. Optionally, the processor 1080 may include one or more processing units; preferably, the processor 1080 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface, and application programs, and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 1080.

[0210] The mobile phone also includes a power supply 1090 (such as a battery) for supplying power to various components. Preferably, the power supply can be logically connected to the processor 1080 through a power management system, so that the power management system can manage functions such as charging, discharging, and power consumption.

[0211] Although not shown, the mobile phone may also include a camera, a Bluetooth module, etc., which will not be described in detail here.

[0212] In the embodiment of the present application, the processor 1080 included in the mobile phone also has the following functions:

[0213] receiving an encryption key application message sent by the second control station; the encryption key application message is generated by the second control station, and the encryption key application message is synchronized to the first node through the second node;

[0214] Sending the encryption key application message to the first control station, so that the first control station responds to the encryption key application message and calls the first trusted computing resource to apply for the encryption key;

[0215] Receiving the encryption key sent by the first control station;

[0216] The encryption key is synchronized to the second node, so that the second control station downloads the encryption key through the second node.

[0217] An embodiment of the present application further provides a computer-readable storage medium for storing a computer program. When the computer program is executed on a computer device, the computer device executes any one of the implementation methods of a key application method described in the aforementioned embodiments.

[0218] The embodiment of the present application also provides a computer program product including a computer program, which, when executed on a computer device, enables the computer device to execute any one of the implementations of a key application method described in the aforementioned embodiments.

[0219] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems and devices described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0220] In the several embodiments provided in the present application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are only schematic. For example, the division of the system is only a logical function division. There may be other division methods in actual implementation, such as multiple systems can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0221] The systems described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0222] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0223] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (full name in English: Read-Only Memory, English abbreviation: ROM), random access memory (full name in English: Random Access Memory, English abbreviation: RAM), disk or optical disk and other media that can store computer programs.

[0224] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A key application method, characterized in that: Applied to a first node in a blockchain network, the first node is communicatively connected to a first control station, the first control station is communicatively connected to a first trusted computing resource of a first institution, the blockchain network further includes a second node, the second node is communicatively connected to a second control station, the second control station is communicatively connected to a second trusted computing resource of a second institution, the method includes: receiving an encryption key application message sent by the second control station; the encryption key application message is generated by the second control station, and the encryption key application message is synchronized to the first node through the second node; Sending the encryption key application message to the first control station, so that the first control station responds to the encryption key application message and calls the first trusted computing resource to apply for the encryption key; Receiving the encryption key sent by the first control station; The encryption key is synchronized to the second node, so that the second control station downloads the encryption key through the second node.

2. The method according to claim 1, characterized in that The blockchain network includes an encryption key application contract event, the triggering condition of the encryption key application contract event is that the blockchain network receives the encryption key application message, the first control station subscribes to the encryption key application contract event, and the sending of the encryption key application message to the first control station includes: When it is detected that the encryption key application message exists in the blockchain network, the encryption key application message that triggers the encryption key application contract event is sent to the first control station that subscribes to the encryption key application contract event.

3. The method according to claim 1, characterized in that Before receiving the encryption key application message sent by the second control station, the method further includes: receiving an alliance member invitation message sent by the first control station; the alliance member invitation message is generated by the first control station in response to an alliance member invitation operation triggered by an object in the first institution having alliance member invitation authority; the alliance member invitation operation is used to invite a target member of the second institution to join the computing alliance of the first institution; The alliance member invitation message is synchronized to the second node, so that the second node sends the alliance member invitation message to the second control station.

4. The method according to claim 3, characterized in that The blockchain network stores member information of the computing alliance of the first organization. Before receiving the alliance member invitation message sent by the first control console, the method further includes: If, in response to the member information confirmation request sent by the first control center, it is confirmed that the member information of the computing alliance of the first institution includes the target member, a first confirmation result is sent to the first control center so that the first control center stops generating the alliance member invitation message; the member information confirmation request is used to confirm whether the member information of the computing alliance of the first institution includes the target member; The receiving the alliance member invitation message sent by the first control station includes: If, in response to the member information confirmation request sent by the first control station, it is confirmed that the member information of the computing alliance of the first institution does not include the target member, a second confirmation result is sent to the first control station so that the first control station generates the alliance member invitation message; Receive the alliance member invitation message sent by the first control station.

5. The method according to claim 3 or 4, characterized in that: The method further comprises: receiving an alliance member invitation processing result sent by the second control station; the alliance member invitation processing result is generated by the second control station based on the target member's operation on the alliance member invitation message, and the alliance member invitation processing result is synchronized to the first node through the second node; Sending the alliance member invitation processing result to the first control station; If the alliance member invitation processing result is approval, in response to the operation of the first control console to add the target member to the computing alliance of the first institution, the member information of the computing alliance of the first institution stored in the blockchain network is updated to obtain the updated member information.

6. The method according to claim 5, characterized in that The blockchain network further includes a third node, the third node is communicatively connected to a third control station, the third control station is communicatively connected to a third trusted computing resource of a third institution, and the method further includes: The updated member information is synchronized to the third node, so that the third node sends the updated member information to the third control station.

7. The method according to any one of claims 1 to 4 and 6, characterized in that: The encryption key application message is a signed encryption key application message; the signed encryption key application message is obtained by the second control station signing the encryption key application message based on the corresponding chain identity; the chain identity is obtained by the second control station applying to the blockchain network.

8. A key application device, characterized in that: A first node in a blockchain network, the first node is communicatively connected to a first control station, the first control station is communicatively connected to a first trusted computing resource of a first institution, the blockchain network further includes a second node, the second node is communicatively connected to a second control station, the second control station is communicatively connected to a second trusted computing resource of a second institution, the device includes: A message receiving module, used to receive an encryption key application message sent by the second control station; the encryption key application message is generated by the second control station, and the encryption key application message is synchronized to the first node through the second node; a message sending module, configured to send the encryption key application message to the first control station, so that the first control station responds to the encryption key application message and calls the first trusted computing resource to apply for the encryption key; A key receiving module, used for receiving the encryption key sent by the first control station; A key synchronization module is used to synchronize the encryption key to the second node so that the second control console downloads the encryption key through the second node.

9. A computer device, characterized in that: The computer device comprises a processor and a memory: The memory is used to store a computer program and transmit the computer program to the processor; The processor is used to execute the key application method according to any one of claims 1 to 7 according to the computer program.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store a computer program, and the computer program is used to execute the key application method according to any one of claims 1 to 7.