Block chain data processing method and device, equipment and storage medium
Through a two-layer blockchain network, the main blockchain is used to perform asset transactions and the sub-blockchain to store historical log data, which solves the problem of low security of digital assets in the existing technology, realizes traceability and restriction of abnormal signature devices, and improves the security of digital assets.
Patent Information
- Application Number
- CN202311546705.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-17
- Publication Date
- 2025-05-20
AI Technical Summary
In the prior art, institutional-level digital asset management solutions are implemented through secure multi-party computing. However, due to the inability to trace the signature source, the existence of malicious parties has led to the low security of digital assets.
A two-layer blockchain network is adopted, the main blockchain network is used to perform asset transactions, and the sub-blockchain network is used to store historical log data of the signature collaboration device. When an abnormal signature occurs in asset transactions, the target signature collaboration device for the abnormal signature is determined through the historical log data of the sub-blockchain network.
It has achieved the security improvement of institutional digital assets, and can trace abnormal signatures based on historical log data, restricting their participation in signatures, thereby improving the security of digital assets.
Smart Images

Figure CN120020845A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of blockchain technology, etc., and in particular to a blockchain data processing method, apparatus, device and storage medium. Background Art
[0002] Institutional-level digital asset management solutions usually adopt the Secure Multi-Party Computation (MPC) method. The Secure Multi-Party Computation method means that multiple participating parties use their respective private key shards to sign asset transactions to obtain partial signatures, and asset transactions are executed based on the partial signatures of the participating parties. In the Secure Multi-Party Computation method, since it is impossible to trace which participating party's signature is based on the partial signature, if a certain participating party maliciously participates in the signature, the security of the institutional digital assets will be relatively low. Summary of the Invention
[0003] Embodiments of the present application provide a blockchain data processing method, apparatus, device and storage medium, which can improve the security of institutional digital assets.
[0004] On the one hand, an embodiment of the present application provides a blockchain data processing method, including:
[0005] Obtain transaction attribute information of an executed asset transaction from a blockchain in a blockchain network; the above transaction attribute information is recorded on the above blockchain when node devices in the above blockchain network verify that N asset transaction signatures all pass the verification based on a public key corresponding to the asset transaction, N is a positive integer greater than or equal to K, K is the restricted signature number of the institution corresponding to the asset transaction, the above N asset transaction signatures are obtained by signature collaboration devices in a signature collaboration device cluster of the above institution using their corresponding private key shards to sign the above asset transaction, and the number of devices in the above signature collaboration device cluster is greater than or equal to N;
[0006] Perform abnormal signature detection on the above asset transaction according to the above transaction attribute information to obtain a detection result;
[0007] When the above detection result indicates that there is an abnormal signature in the above asset transaction, obtain historical log data of signature collaboration devices in the above signature collaboration device cluster from a sub-blockchain in a sub-blockchain network;
[0008] Determine a target signature collaboration device that performs an abnormal signature on the above asset transaction from the above signature collaboration device cluster according to the above historical log data.
[0009] On the one hand, an embodiment of the present application provides a blockchain data processing apparatus, including:
[0010] A first acquisition module, configured to acquire transaction attribute information of an executed asset transaction from a blockchain in a blockchain network; the above-mentioned transaction attribute information is recorded on the above-mentioned blockchain when node devices in the above-mentioned blockchain network verify that N asset transaction signatures are all verified through based on a public key corresponding to the asset transaction, where N is a positive integer greater than or equal to K, and K is the restricted signature number of the institution corresponding to the above-mentioned asset transaction. The above-mentioned N asset transaction signatures are obtained by signature collaboration devices in a signature collaboration device cluster of the above-mentioned institution using their corresponding private key shards to sign the above-mentioned asset transaction, and the number of devices in the above-mentioned signature collaboration device cluster is greater than or equal to N;
[0011] A detection module, configured to perform abnormal signature detection on the above-mentioned asset transaction according to the above-mentioned transaction attribute information to obtain a detection result;
[0012] A second acquisition module, configured to, when the above-mentioned detection result indicates that the above-mentioned asset transaction has an abnormal signature, acquire historical log data of signature collaboration devices in the above-mentioned signature collaboration device cluster from a sub-blockchain in a sub-blockchain network;
[0013] A determination module, configured to determine a target signature collaboration device that performs an abnormal signature on the above-mentioned asset transaction from the above-mentioned signature collaboration device cluster according to the above-mentioned historical log data.
[0014] Optionally, the determination module includes an acquisition unit, an interception unit, and a determination unit;
[0015] The acquisition unit is configured to acquire the execution time of the above-mentioned asset transaction from the above-mentioned blockchain;
[0016] The interception unit is configured to intercept, according to the above-mentioned execution time, a historical log data segment of signature collaboration devices in the above-mentioned signature collaboration device cluster within a first historical time period from the above-mentioned historical log data; the above-mentioned first historical time period includes the above-mentioned execution time and the time before the above-mentioned execution time;
[0017] The determination unit is configured to determine a target signature collaboration device that performs an abnormal signature on the above-mentioned asset transaction from the above-mentioned signature collaboration device cluster according to the above-mentioned historical log data segment.
[0018] Optionally, the determination unit determines a target signature collaboration device that performs an abnormal signature on the above-mentioned asset transaction from the above-mentioned signature collaboration device cluster according to the above-mentioned historical log data segment, including:
[0019] Filtering signature collaboration devices that perform signature operations within the above-mentioned first historical time period from the above-mentioned signature collaboration device cluster according to the above-mentioned historical log data segment;
[0020] Determine the execution time of the signature operation performed by the signature collaboration device obtained by screening according to the above historical log data segment;
[0021] Based on the execution time of the above asset transaction and the execution times respectively corresponding to the signature collaboration devices obtained by the above screening, among the signature collaboration devices obtained by the above screening, the target signature collaboration device for performing an abnormal signature on the above asset transaction.
[0022] Optionally, the determining unit determines, based on the execution time of the above asset transaction and the execution times respectively corresponding to the signature collaboration devices obtained by the above screening, among the signature collaboration devices obtained by the above screening, the target signature collaboration device for performing an abnormal signature on the above asset transaction, including:
[0023] Obtain the time intervals between the execution time of the above asset transaction and the execution times respectively corresponding to the signature collaboration devices obtained by the above screening;
[0024] Among the signature collaboration devices obtained by the above screening, determine the candidate signature collaboration devices corresponding to the above time intervals that are less than the time interval threshold;
[0025] Determine the above candidate signature collaboration devices as the target signature collaboration devices for performing an abnormal signature on the above asset transaction.
[0026] The detection module includes a first query unit, a second query unit, and a detection unit;
[0027] The first query unit is used to query, according to the above transaction attribute information, the number of times the above asset transaction has been executed on the above blockchain within a second historical time period;
[0028] The second query unit is used to query, from the above sub-blockchain, the limited execution times of the asset transactions of the above institution within a unit time period; the unit time period is the same as the time period corresponding to the above second historical time period;
[0029] The detection unit is used to perform abnormal signature detection on the above asset transaction according to the number of times the above asset transaction has been executed within the second historical time period and the limited execution times, and obtain a detection result.
[0030] Optionally, the above asset transaction is to log in to the asset client of the above institution, and the above transaction attribute information includes the login information of the login person;
[0031] The above detection unit performs abnormal signature detection on the above asset transaction according to the number of times the above asset transaction has been executed within the second historical time period and the limited execution times, and obtains a detection result, including:
[0032] When the number of times the above asset transaction is executed within the second historical time period is less than the above limit execution times, obtain the login information of the above institution from the above sub-blockchain;
[0033] Determine the similarity between the login information of the above institution and the login information of the above login person;
[0034] When the above similarity is less than the similarity threshold, determine that the above asset transaction has an abnormal signature, and generate a detection result indicating that the above asset transaction has an abnormal signature.
[0035] Optionally, the above asset transaction is to transfer digital assets from the account address of the above institution, and the above transaction attribute information includes the object attribute information of the transferor and the asset quantity corresponding to the digital assets transferred by the above transferor;
[0036] The above detection unit performs abnormal signature detection on the above asset transaction according to the number of times the above asset transaction is executed within the second historical time period and the limit execution times, and obtains a detection result, including:
[0037] When the number of times the above asset transaction is executed within the second historical time period is less than the above limit execution times, query the position level of the above transferor in the above institution from the above sub-blockchain according to the object attribute information of the above transferor;
[0038] Determine the restricted asset quantity transferred by the above transferor each time according to the above position level;
[0039] When the asset quantity corresponding to the digital assets transferred by the above transferor is greater than the above restricted asset quantity, determine that the above asset transaction has an abnormal signature, and generate a detection result indicating that the above asset transaction has an abnormal signature.
[0040] Optionally, the device further includes an update module and a selection module;
[0041] The determination module is further configured to determine the impact degree of the abnormal signature of the asset transaction on the above institution according to the above transaction attribute information;
[0042] The update module is configured to update the credit degree of the signature collaboration devices in the above signature collaboration device cluster according to the above impact degree, and obtain the updated credit degree of the signature collaboration devices in the above signature collaboration device cluster;
[0043] The selection module is configured to select the signature collaboration devices participating in the next signature from the above signature collaboration device cluster according to the above updated credit degree.
[0044] Optionally, the updating module updates the credit of the signature collaboration devices in the signature collaboration device cluster according to the above influence degree, and obtains the updated credit of the signature collaboration devices in the signature collaboration device cluster, including:
[0045] Determine candidate signature collaboration devices selected to participate in signature when signing the above asset transaction according to the credit of the signature collaboration devices in the above signature collaboration device cluster; the above candidate signature collaboration devices include the above target signature collaboration device;
[0046] According to the above influence degree, reduce the credit of the above target signature collaboration device to obtain the updated credit of the above target signature collaboration device;
[0047] According to the above influence degree, increase the credit of the remaining signature collaboration devices to obtain the updated credit of the remaining signature collaboration devices; the remaining signature collaboration devices are devices other than the above target signature collaboration device in the above candidate signature collaboration devices.
[0048] Optionally, the device may further include a removal module and a sending module;
[0049] The removal module is used to remove the above target signature collaboration device from the above signature collaboration device cluster when the updated credit of the above target signature collaboration device is less than the credit threshold;
[0050] The updating module is further used to count the number of devices in the above signature collaboration device cluster, and update the limit signature number of the above institution according to the above number of devices to obtain the updated limit signature number;
[0051] The sending module is used to send the above number of devices and the above updated limit signature number to the signature collaboration devices in the above signature collaboration device cluster; the signature collaboration devices in the above signature collaboration device cluster are used to delete their corresponding private key shards and generate updated private key shards according to the above number of devices and the above updated limit signature number.
[0052] Optionally, the first acquisition module acquires the transaction attribute information of the executed asset transaction from the blockchain in the blockchain network, including:
[0053] Receive an audit request for the asset transaction of the above institution; the above audit request carries the institution attribute information of the above institution;
[0054] According to the institution attribute information carried in the above audit request, acquire the transaction attribute information of the executed asset transaction belonging to the above institution from the blockchain in the above blockchain network.
[0055] One aspect of the embodiments of the present application provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.
[0056] One aspect of the embodiments of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are implemented.
[0057] One aspect of the embodiments of the present application provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the above method are implemented.
[0058] The present application provides a two-layer blockchain network. One layer of the blockchain network is used to execute asset transactions, and the second layer of the blockchain network (i.e., the sub-blockchain network) is used to store the historical log data of signature collaboration devices. When an abnormal signature occurs in a certain asset transaction in the first layer of the blockchain network, the historical log data in the second layer of the blockchain network can be used to determine which signature collaboration devices perform abnormal signatures on the asset transaction, that is, it is possible to trace which participating parties perform abnormal signatures on the asset transaction based on the historical log data. Furthermore, the signature collaboration devices with abnormal signatures can be restricted from participating in signatures, improving the security of digital assets. At the same time, by storing the historical log data on the second layer of the blockchain network, the data processing pressure on the first layer of the blockchain network will not be increased, and the problem that the signature participating parties cannot be traced in the secure multi-party calculation method can be solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0060] Figure 1 It is a schematic diagram of a blockchain data processing system provided by the present application;
[0061] Figure 2 It is a schematic diagram of the interaction scenario between devices in a blockchain data processing system provided by the present application;
[0062] Figure 3 It is a schematic diagram of the interaction scenario between devices in a blockchain data processing system provided by the present application;
[0063] Figure 4 It is a schematic flowchart of a blockchain data processing method provided by the present application;
[0064] Figure 5 It is a schematic flowchart of a blockchain data processing method provided by this application;
[0065] Figure 6 It is a schematic diagram of a scenario for detecting abnormal signatures in asset transactions provided by this application;
[0066] Figure 7 It is a schematic diagram of a scenario for detecting abnormal signatures in asset transactions provided by this application;
[0067] Figure 8 It is a schematic structural diagram of a blockchain data processing device provided by an embodiment of this application;
[0068] Figure 9 It is a schematic structural diagram of a computer device provided by an embodiment of this application. Detailed implementation manners
[0069] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the protection scope of this application.
[0070] First, introduce the blockchain data processing system to which this solution is applied. Please refer to Figure 1 , Figure 1 It is a schematic structural diagram of a blockchain data processing system provided by an embodiment of this application. The blockchain data processing system may include a blockchain network, a sub-blockchain network, a signature collaboration device cluster, and one or more terminals.
[0071] Among them, the blockchain network is an end-to-end decentralized network jointly composed of multiple node devices (which can also be called blockchain nodes). The number of node devices in the blockchain network can be deployed according to actual needs, and this application does not limit the number of node devices; for example Figure 1 in this, it is described by taking the blockchain network including 4 node devices as an example. The 4 node devices are node device 101, node device 102, node device 103, and node device 104 respectively.
[0072] It can be understood that the functions involved in each node device in the blockchain network include:
[0073] 1) Routing, which is a basic function of the node device and is used to support communication between node devices.
[0074] For example, as Figure 1As shown, data or blocks can be transmitted between node devices through a network connection. The network connection between the above node devices can perform data transmission based on node identifiers. Each node device has a corresponding node identifier, and each of the above node devices can store the node identifiers of other node devices that are connected to itself, so as to broadcast the acquired data or generated blocks to other node devices according to the node identifiers of other node devices in the future. For example, node device 101 can maintain a list of node identifiers, and this list of node identifiers stores the node names and node identifiers of other node devices, as shown in Table 1:
[0075] Table 1
[0076] Node Name Node Identifier Node Device 101 117.xxx.xxx.174 Node Device 102 117.xxx.xxx.145 Node Device 103 117.xxx.xxx.183 Node Device 104 117.xxx.xxx.125 … …
[0077] Among them, the node identifier can be the Internet Protocol (IP) address for network interconnection and any other information that can be used to identify node devices in the blockchain network. Table 1 only takes the IP address as an example for illustration.
[0078] Suppose the node identifier of node device 101 is 117.xxx.xxx.174. Then node device 101 can send a data synchronization request to node device 102 through 117.xxx.xxx.174, and node device 102 can know that this data synchronization request is sent by node device 101 through the node identifier 117.xxx.xxx.174; similarly, node device 102 can send transaction data A to node device 101 through the node identifier 117.xxx.xxx.145, and node device 101 can know that this transaction data A is sent by node device 102 through the node identifier 117.xxx.xxx.145. The data transmission between other node devices is also like this, so it will not be elaborated one by one.
[0079] 2) An application, which is used to be deployed in the blockchain, implements specific services according to actual business requirements, records the data related to the implemented functions to form record data, carries a digital signature in the record data to indicate the source of the task data, and sends the record data to other node devices in the blockchain network. When other node devices verify the source and integrity of the record data successfully, they add the record data to the temporary block.
[0080] For example, the services implemented by the application include:
[0081] 2.1) Resource management service. The node device may include a resource client, which can be used to implement the resource management service function and establish a communication connection with the decentralized application client based on this resource management service function. The resource client is a tool responsible for managing and storing users' digital resources. For example, digital resources can be transferred to other accounts based on the resource client, or digital resources transferred from other accounts can be received based on the resource client. The resource client can be a hardware device or a software program.
[0082] It can be understood that with the wide deployment of various decentralized applications on the blockchain and the increase in users' activities on the blockchain, when ordinary users use decentralized applications, they can use the blockchain key management tool for login. The address in the blockchain key management tool corresponds to a user on the blockchain. The decentralized application can obtain the user address from the key management tool through some interfaces. In order to solve the problem that the Dapp background cannot trust the user address used when the decentralized application logs in.
[0083] 2.2) Shared ledger, which is used to provide functions such as storage, query, and modification of account data (i.e., transaction data). The recorded data of the operations on the account data is sent to other nodes in the blockchain network. After other nodes verify its validity, as a response to acknowledging the validity of the account data, the recorded data is stored in a temporary block, and a confirmation can also be sent to the node device that initiated the operation.
[0084] For example, each node device can receive the data to be recorded during normal operation and maintain the shared ledger (i.e., the blockchain) based on the received data to be recorded. To ensure information intercommunication within the shared ledger network, there can be a network connection between each node device in the shared ledger network, and data can be transmitted between node devices through the above network connection. For example, when any node device in the shared ledger network receives the data to be recorded, other node devices in the shared ledger network will verify the data to be recorded according to the consensus algorithm. After successful verification (i.e., after reaching a consensus), the data to be recorded is stored as data in the shared ledger, so that the data stored on all node devices in the shared ledger network is consistent.
[0085] 2.3) Smart contract, a computerized protocol that can execute the terms of a certain contract. It is implemented through code deployed on the shared ledger and used to execute when certain conditions are met. According to actual business requirements, the code is used to complete automated transactions. For example, query the logistics status of the goods purchased by the buyer and transfer the buyer's digital resources to the merchant's address after the buyer signs for the goods. Of course, smart contracts are not limited to executing contracts for transactions, but can also execute contracts for processing received information.
[0086] Among them, the node device in the blockchain network of the present application can be the backend service device of the blockchain application, which can be used to verify the signature of the asset transaction. When the asset transaction is verified, the asset transaction is executed and stored on the blockchain.
[0087] Among them, the asset transaction can refer to transferring digital assets from an institution and logging in to the asset client of the institution. The asset client can refer to the client used to manage the digital assets of the institution. The digital assets can refer to digital collections, game themes, game coins, digital copyrights, game props, etc.
[0088] Among them, the sub-blockchain network is an end-to-end decentralized network jointly composed of multiple sub-node devices (which can also be called blockchain nodes). The number of sub-node devices in the sub-blockchain network can be deployed according to actual needs, and the present application does not limit the number of sub-node devices; for Figure 1 example, it is described by taking that the sub-blockchain network includes 4 sub-node devices as an example. The 4 sub-node devices are respectively node device 111, node device 112, node device 113, and node device 114. A sub-blockchain is stored in each sub-node device in the sub-blockchain network, and the sub-blockchain is used to store the historical log data of the signature collaboration device.
[0089] Among them, the signature collaboration device cluster includes multiple signature collaboration devices. Each signature collaboration device stores one or more private key shards of an institution. The private key shard is used to sign the asset transaction to obtain the asset transaction signature when the signature collaboration device determines that the asset transaction is legal, and send the asset transaction signature to the node device in the blockchain network. The present application does not limit the number of signature collaboration devices; for Figure 1 example, it is described by taking that there are 4 signature collaboration devices as an example. The 4 signature collaboration devices are respectively signature collaboration device 121, signature collaboration device 122, signature collaboration device 123, and signature collaboration device 124.
[0090] In the present application, an institution includes multiple private key shards, and the multiple private key shards correspond to the public key of the institution, that is, the multiple private key shards form a complete private key of the institution, that is, the private key shards corresponding to the private key of the institution are dispersed in multiple signature collaboration devices. The private key shard can be determined based on the number of devices in the signature collaboration device cluster and the limit signature number. The limit signature number can be used to indicate that when at least the limit signature number of signature collaboration devices in the signature collaboration device cluster complete the signature of the asset transaction, the node device in the blockchain network executes the asset transaction.
[0091] Among them, the terminal can refer to the device used to audit the asset transaction in the blockchain network. The number of terminal devices can be deployed according to actual needs, and the present application does not limit the number of terminals; forFigure 1 Taking 1 terminal as an example for illustration, i.e., terminal 131. Auditing may refer to detecting whether there is an abnormal signature in an asset transaction. When there is an abnormal signature in the asset transaction, according to the historical log data on the sub-blockchain, the signature cooperation device that executes the abnormal signature is determined from the signature cooperation device cluster.
[0092] Among them, the node device in the blockchain network, the sub-node device in the sub-blockchain network, and the signature cooperation device in the signature cooperation device cluster may refer to a terminal or a server. The server may be an independent physical server, or a server cluster or distributed system composed of at least two physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery network (CDN), and big data and artificial intelligence platforms.
[0093] Currently, since the private key shards of an institution are scattered in multiple signature cooperation devices, when the signature cooperation device in the signature cooperation device cluster signs an asset transaction based on its corresponding private key shard, if there is an abnormal signature in the asset transaction, it is impossible to trace which signature cooperation devices signed the asset transaction based on the asset transaction signature, increasing the probability of illegal users doing evil and resulting in relatively low security of the institution's digital assets.
[0094] Based on this, the present application provides a two-layer blockchain network as shown in Figure 1 One layer of the blockchain network is used to execute asset transactions, and the second layer of the blockchain network (i.e., the sub-blockchain network) is used to store the historical log data of the signature cooperation devices. When there is an abnormal signature in a certain asset transaction in the first layer of the blockchain network, the historical log data in the second layer of the blockchain network can be used to determine which signature cooperation devices perform abnormal signatures on the asset transaction, that is, it is possible to trace which participating parties perform abnormal signatures on the asset transaction based on the historical log data. Furthermore, the signature cooperation devices with abnormal signatures can be restricted from participating in signatures, improving the security of digital assets. At the same time, by storing the historical log data on the second layer of the blockchain network, the data processing pressure on the first layer of the blockchain network is not increased, and the problem that the signature participants cannot be traced in the secure multi-party computing method can be solved.
[0095] In specific implementation, Figure 1 The blockchain data processing system in the middle can be used to implement Figure 2 The execution process of asset transaction B in, and is used to implement Figure 3 The auditing process of asset transaction B in. The node device 20a in Figure 2 may refer to Figure 1Any node device in the blockchain network Figure 2 The signature cooperation devices 21a, 22a, and 23a in Figure 1 belong to the signature cooperation device cluster in. This signature cooperation device cluster belongs to institution A. The signature cooperation device 21a includes a private key shard 21b, the signature cooperation device 22a includes a private key shard 22b, and the signature cooperation device 23a respectively includes a private key shard 23b. The private key shards 21b, 22b, and 23b can form the complete private key of institution A. The limited signature quantity of institution A is 2, that is, the node device 20a will execute the asset transaction B only when at least 2 signature cooperation devices among the 3 signature cooperation devices send the asset transaction signatures
[0096] As Figure 2 shown, the node device 20a in the blockchain network can receive the asset transaction B regarding institution A and send the asset transaction B to all signature cooperation devices in the signature cooperation device cluster of institution A. After receiving the asset transaction B, the signature cooperation devices in the signature cooperation device cluster can perform a legality verification on the asset transaction B to obtain a verification result. If the verification result indicates that the asset transaction B is legal, the corresponding private key shard is used to sign the asset transaction B to obtain the asset transaction B signature; if the verification result indicates that the asset transaction B is illegal, the signature of the asset transaction B is refused, that is, the asset transaction B is intercepted. As Figure 2 shown, after the signature cooperation device 21a receives the asset transaction B, it can perform a legality verification on the asset transaction B to obtain a verification result 1. If the verification result 1 indicates that the asset transaction B is legal, the private key shard 21b in the signature cooperation device 21a is used to sign the asset transaction B to obtain the asset transaction signature 21c
[0097] Similarly, after the signature cooperation device 22a receives the asset transaction B, it can perform a legality verification on the asset transaction B to obtain a verification result 2. If the verification result 2 indicates that the asset transaction B is legal, the private key shard 22b in the signature cooperation device 22a is used to sign the asset transaction B to obtain the asset transaction signature 22c. After the signature cooperation device 23a receives the asset transaction B, it can perform a legality verification on the asset transaction B to obtain a verification result 3. If the verification result 3 indicates that the asset transaction B is illegal, the signature of the asset transaction B using the private key shard 23b is refused, that is, the asset transaction B is intercepted
[0098] It should be noted that when asset transaction B meets at least one of the following conditions, it is determined that asset transaction B is legal: (1) Verify that the sender of the asset transaction is an authorized object of institution A, and the authorized object refers to a user who has the operation authority for the asset transactions of institution A; (2) The number of executions of asset transactions within a predetermined time period is less than the restricted execution number; (3) The quantity of assets corresponding to the digital assets of this asset transaction is less than the restricted asset quantity for a single transaction.
[0099] As Figure 2 shown, the signature cooperation device 21a can send the asset transaction signature 21c to the node device 20a, and the signature cooperation device 22a can send the asset transaction signature 22c to the node device 20a; since the number of asset transaction signatures received by the node device 20a is 2, that is, the number of asset transaction signatures received by the node device 20a is equal to the restricted signature number, therefore, the node device 20a can execute asset transaction B and store asset transaction B on the blockchain. Specifically, the node device 20a can perform a merging process on the asset transaction signature 21c and the asset transaction signature 22a to obtain the complete transaction signature of institution A. Here, the merging process can refer to processes such as summation processing, product processing, subtraction processing, etc. Decrypt the complete asset transaction signature using the public key of institution A to obtain the first hash value, and perform a hash operation on the asset transaction to obtain the second hash value; when the first hash value is different from the second hash value, it indicates that asset transaction B has been tampered with during transmission, or there is a signature of a device other than the signature cooperation device in the asset transaction signature, and the node device 20a can suspend the execution of asset transaction B and refuse to store asset transaction B on the blockchain. When the first hash value and the second hash value are the same, it indicates that no information loss, tampering, or other abnormal situations have occurred during the transmission of asset transaction B, and the node device 20a can execute asset transaction B and store asset transaction B on the blockchain, that is, store the transaction attribute information of asset transaction B on the blockchain.
[0100] In practice, it is found that there are abnormal signatures of asset transactions by signature cooperation devices in the signature cooperation device cluster. The abnormal signatures include at least one of the following three situations: (1) The asset transaction is legal, and the signature cooperation device does not sign the asset transaction; (2) The signature cooperation device does not perform a legality verification on the asset transaction and directly signs the asset transaction; (3) Signing an illegal asset transaction will result in relatively low security of the institution's digital assets. Based on this, this application can audit asset transactions to improve the security of the institution's digital assets. The audit process of digital assets is as Figure 3 shown.
[0101] Figure 3 The signature cooperation device 30a in Figure 2The signature collaboration device 21a in Figure 3 The signature collaboration device 31a in Figure 2 can refer to the signature collaboration device 22a in Figure 3 The signature collaboration device 32a in Figure 2 can refer to the signature collaboration device 23a in Figure 3 The child node device 33a in Figure 1 can refer to any node device in the sub-blockchain network in Figure 3 The 34a in Figure 2 can be the node device 20a in Figure 1 The terminal 35a can refer to any terminal in the terminals in
[0102] As Figure 3 shown, the signature collaboration device 30a, the signature collaboration device 31a, and the signature collaboration device 32a can periodically send their respective historical log data to the child node device 33a, or, after the signature collaboration device 30a, the signature collaboration device 31a, and the signature collaboration device 32a perform signature operations on any asset transaction, send their respective historical log data to the child node device 33a. The historical log data received by the child node device 33a is stored on the sub-blockchain. The historical log data can refer to the newly added log data in each signature collaboration device. The historical log data can refer to the newly added log data after the first historical time. The second historical time is the time of the last (most recent) synchronization of the historical log data to the child node device 33a.
[0103] The terminal 35a can periodically obtain the transaction attribute information of the newly added asset transactions on the blockchain in the node device 34a. The newly added asset transactions can refer to the un-audited asset transactions on the blockchain. The newly added asset transactions can refer to the asset transactions stored on the blockchain after the second historical time. The second historical time can refer to the time of the most recent reading of the attribute information of the asset transactions from the blockchain. Taking the newly added asset transaction including asset transaction C as an example for illustration, this asset transaction C belongs to institution A. The terminal 35a can perform abnormal signature detection on the asset transaction C according to the transaction attribute information to obtain a detection result; when the detection result indicates that the asset transaction C is abnormal, read the historical log data corresponding to the signature collaboration device 30a, the signature collaboration device 31a, and the signature collaboration device 32a respectively from the sub-blockchain in the sub-blockchain network. The historical log data read by the terminal 35a can refer to the newly added log data on the sub-blockchain. For example, this historical log data can refer to the log data written to the blockchain after the third historical time. The third historical time can refer to the time of the most recent reading of the historical log data from the sub-blockchain.
[0104] After the terminal 35a obtains the historical log data of each signature collaboration device, it can determine a target signature collaboration device that abnormally signs the asset transaction C from the signature collaboration device 30a, the signature collaboration device 31a, and the signature collaboration device 32a according to the historical log data of each signature collaboration device. Further, the terminal 35a can restrict the target signature collaboration device from participating in signing the asset transaction, improving the security of the digital assets of the institution.
[0105] Further, please refer to Figure 4 which is a schematic flowchart of a blockchain data processing method provided by an embodiment of the present application. As Figure 4 shown, this method can be performed by Figure 1 the auditing device in, and the auditing device can include at least one of a terminal and a server. In the present application, the auditing device can be collectively referred to as a computer device.
[0106] Among them, this method can include the following steps:
[0107] S101. Obtain the transaction attribute information of the executed asset transaction from the blockchain in the blockchain network; the above transaction attribute information is recorded on the above blockchain when the node devices in the above blockchain network verify that N asset transaction signatures are all verified through based on the public key corresponding to the asset transaction. N is a positive integer greater than or equal to K, and K is the restricted signature number of the institution corresponding to the above asset transaction. The above N asset transaction signatures are obtained by the signature collaboration devices in the signature collaboration device cluster of the above institution using their corresponding private key shards to sign the above asset transaction. The number of devices in the above signature collaboration device cluster is greater than or equal to N.
[0108] In the present application, the computer device can periodically obtain the transaction attribute information of the executed asset transaction from the blockchain in the blockchain network, or after the computer device receives an audit request for the asset transaction on the blockchain, it obtains the transaction attribute information of the executed asset transaction from the blockchain. The asset transaction can refer to the newly written asset transaction on the blockchain after the last time the asset transaction is read from the blockchain.
[0109] It should be noted that an asset transaction can refer to transferring digital assets from the account address of an institution. In this case, the transaction attribute information includes one or more of the asset quantity corresponding to the digital assets to be transferred, the object attribute information of the recipient of the digital assets, the object attribute information of the transferor, etc. The object attribute information of the transferor includes the name, account, etc. of the transferor, and the object attribute information of the recipient includes the account address, name, account, etc. of the recipient. An asset transaction can also refer to transferring digital assets to the account address of an institution. In this case, the transaction attribute information includes one or more of the asset quantity corresponding to the digital assets to be transferred, the object attribute information of the recipient of the digital assets, the object attribute information of the transferor, etc. An asset transaction can also refer to logging in to the asset client of an institution. The asset client can be a client used to manage the digital assets of the institution. In this case, the transaction attribute information can include the login information of the login user, and the login information can include the login account, nickname, and login key. The login key can refer to a password, fingerprint information, face recognition information, etc.
[0110] It should be noted that the asset transaction can refer to the node device in the blockchain network storing the asset transaction on the blockchain when the number of received asset transaction signatures is greater than or equal to the limit signature number and the verification of N asset transaction signatures passes. The limit signature number can be determined by at least one of the total asset quantity of the digital assets of the institution and the number of devices in the collaborative signature device cluster. There is a positive correlation between the limit signature number and the total asset quantity and the number of devices. For example, the larger the total asset quantity, the larger the limit signature number; the smaller the total asset quantity, the smaller the limit signature number.
[0111] It should be noted that the signature collaborative devices in the signature collaborative device cluster can belong to users in different positions in the institution, which is conducive to improving the signature security of asset transactions. The verification of all N asset transaction signatures passing (verification passing) can include: the node device performing a merging process on the N asset transaction signatures to obtain the complete signature of the asset transaction. The merging process can include addition, subtraction, multiplication, etc. Decrypting the complete signature using the public key of the institution to obtain the first hash value, performing a hash operation on the asset transaction to obtain the second hash value, and when the first hash value is the same as the second hash value, it is determined that all N asset transaction signatures are verified to pass.
[0112] S102. Perform abnormal signature detection on the above asset transaction according to the above transaction attribute information to obtain a detection result.
[0113] In this application, the computer device can perform anomaly signature detection on the asset transaction according to the transaction attribute information, and obtain a detection result, which can be used to indicate that there is an anomaly signature in the asset transaction, or to indicate that there is no anomaly signature in the asset transaction. The anomaly signature includes at least one of the following three situations: (1) The asset transaction is legal, and the signature cooperation device does not sign the asset transaction; (2) The signature cooperation device does not perform legality verification on the asset transaction and directly signs the asset transaction; (3) Sign the asset transaction that is not legal.
[0114] In one embodiment, when a single computer device performs anomaly signature detection on an asset transaction, the computer device can perform anomaly signature detection on the asset transaction according to the transaction attribute information, obtain a first detection result, and determine the first detection result as the detection result regarding the asset transaction.
[0115] In one embodiment, the computer device can belong to any audit device in the audit network. The audit network can refer to a network used to perform anomaly signature detection on asset transactions on the blockchain. The audit network is a decentralized network, and the audit network can include multiple audit devices. The computer device can perform anomaly signature detection on the asset transaction according to the transaction attribute information, obtain a first detection result, which is used to indicate that there is an anomaly signature in the asset transaction, or to indicate that there is no anomaly signature in the asset transaction. Other devices in the audit network can perform anomaly signature detection on the asset transaction according to the transaction data information, obtain a second detection result, and receive the second detection result sent by other devices. Other devices can refer to other audit devices in the audit network except the computer device. The computer device can count the number of devices that detect an anomaly signature in the asset transaction in the audit network, denoted as the number of anomaly devices, and the total number of devices in the audit network according to the first detection result and the second detection result. According to the number of anomaly devices and the total number of devices, obtain the detection result regarding the asset transaction. By verifying the anomaly signature detection of the asset transaction through multiple devices, the problem that a single device is maliciously attacked or the detection result is inaccurate due to detection errors of a single device can be avoided, and the detection accuracy can be improved.
[0116] For example, if the ratio between the number of abnormal devices and the total number of devices is greater than the ratio threshold, it is determined that the asset transaction has an abnormal signature, and a detection result indicating that the asset transaction has an abnormal signature is generated. If the ratio between the number of abnormal devices and the total number of devices is less than or equal to the ratio threshold, it is determined that the asset transaction does not have an abnormal signature, and a detection result indicating that the asset transaction does not have an abnormal signature is generated. The ratio threshold can be determined based on the total number of the institution's digital assets, or the ratio threshold can be determined according to the asset type of the institution's digital assets. The asset type is used to reflect the security requirements of the digital assets. For example, the higher the security requirements, the larger the ratio threshold; the lower the security requirements, the smaller the ratio threshold.
[0117] S103. When the above detection result indicates that the above asset transaction has an abnormal signature, obtain the historical log data of the signature collaboration devices in the above signature collaboration device cluster from the sub-blockchain of the sub-blockchain network.
[0118] In this application, when the detection result indicates that the asset transaction stores an abnormal signature, the computer device can obtain the historical log data corresponding to each signature collaboration device in the signature collaboration device cluster from the sub-blockchain of the sub-blockchain network. The historical log data of each signature collaboration device is stored on the sub-blockchain, which will not increase the storage pressure of the node devices in the blockchain network. At the same time, it can also prevent the historical log data from being tampered with, improving the accuracy and security of the historical log data.
[0119] It should be noted that the historical log data is the running log of the signature collaboration devices in the signature collaboration device cluster, which reflects the operations performed by the signature collaboration devices in the signature collaboration device cluster and the time of performing the operations, etc. The operations performed can include at least one of a signature operation and a non-signature operation. The non-signature operation can be operations such as updating the private key shard and updating the restricted signature quantity.
[0120] S104. According to the historical log data, determine the target signature collaboration device that performs an abnormal signature on the above asset transaction from the signature collaboration device cluster.
[0121] In this application, the computer device can determine the signature collaboration device that performs an abnormal signature on the asset transaction from the signature collaboration device cluster according to the historical log data corresponding to each signature collaboration device, and use the signature collaboration device that performs an abnormal signature on the asset transaction as the target signature collaboration device.
[0122] This application provides a two - layer blockchain network. One layer of the blockchain network is used to execute asset transactions, and the second - layer blockchain network (i.e., the sub - blockchain network) is used to store the historical log data of signature - collaborating devices. When an abnormal signature occurs in a certain asset transaction in the first - layer blockchain network, the historical log data in the second - layer blockchain network can be used to determine which signature - collaborating devices perform abnormal signatures on the asset transaction, that is, it is possible to trace which participating parties perform abnormal signatures on the asset transaction based on the historical log data. Furthermore, the signature - collaborating devices with abnormal signatures can be restricted from participating in signatures, improving the security of digital assets. At the same time, by storing the historical log data on the second - layer blockchain network, it will not increase the data - processing pressure on the first - layer blockchain network, and the problem that the signature - participating parties cannot be traced in the secure multi - party calculation method can be solved.
[0123] Further, please refer to Figure 5 which is a schematic flowchart of a blockchain data - processing method provided by an embodiment of this application. As Figure 5 shown, this method can be performed by Figure 1 the auditing device in, and the auditing device can include at least one of a terminal and a server. In this application, the auditing device can be collectively referred to as a computer device.
[0124] Among them, this method can include the following steps:
[0125] S201. Obtain the transaction attribute information of the executed asset transaction from the blockchain in the blockchain network; the above - mentioned asset transaction is recorded on the above - mentioned blockchain when the node devices in the above - mentioned blockchain network verify that N asset - transaction signatures are all verified through based on the public key corresponding to the asset transaction. N is a positive integer greater than or equal to K, and K is the restricted signature number of the institution corresponding to the asset transaction. The above - mentioned N asset - transaction signatures are obtained by the signature - collaborating devices in the signature - collaborating device cluster of the above - mentioned institution using their corresponding private - key shards to sign the above - mentioned asset transaction, and the number of devices in the above - mentioned signature - collaborating device cluster is greater than or equal to N.
[0126] In one embodiment, the computer device can receive an audit request for the asset transaction of the above - mentioned institution; the above - mentioned audit request carries the institution - attribute information of the above - mentioned institution; according to the institution - attribute information carried in the above - mentioned audit request, obtain the transaction attribute information of the executed asset transaction belonging to the above - mentioned institution from the blockchain in the blockchain network.
[0127] Specifically, the computer device can receive an audit request for the asset transactions of an institution. The audit request carries the institutional attribute information of the institution, and the institutional attribute information includes the name, code, etc. of the institution. The audit request is used to indicate the detection of abnormal signatures for the asset transactions of the institution. Then, the computer device can obtain the transaction attribute information of the executed asset transactions belonging to the institution from the blockchain in the blockchain network according to the institutional attribute information carried by the audit request.
[0128] It should be noted that the asset transactions here can refer to the asset transactions newly added on the blockchain after the last detection. For example, the computer device can obtain the blocks on the blockchain scanned in the last detection, and according to the block identifier of the blocks scanned in the last detection, obtain the newly added blocks on the blockchain, scan the newly added blocks, and obtain the transaction attribute information of the executed asset transactions of the institution. If the maximum block height of the blocks scanned in the last detection is 20 and the maximum block height of the current blocks on the blockchain is 50, the computer device can scan the blocks on the blockchain with block heights from 21 to 50 according to the institutional attribute information to obtain the transaction attribute information of the executed asset transactions of the institution, without scanning all the blocks on the blockchain, thus improving the efficiency of obtaining the transaction attribute information of the asset transactions.
[0129] S202. Perform abnormal signature detection on the above asset transactions according to the above transaction attribute information to obtain a detection result.
[0130] In one embodiment, the above performing abnormal signature detection on the above asset transactions according to the above transaction attribute information to obtain a detection result includes: querying the number of times the above asset transactions are executed in the second historical period from the above blockchain; querying the limited execution times of the asset transactions of the above institution per unit time from the above sub-blockchain; the duration of the above unit time is the same as the duration corresponding to the above second historical period. Perform abnormal signature detection on the above asset transactions according to the number of times the above asset transactions are executed in the second historical period and the limited execution times to obtain a detection result.
[0131] Optionally, when the asset transaction is to transfer digital assets from the account address of the institution, the computer device can query the number of times of transferring digital assets from the account address of the institution on the blockchain of the blockchain network within the second historical time period according to the transaction attribute information, and determine the number of times of transferring digital assets as the number of times the asset transaction is executed within the second historical time period. From the sub-blockchain, query the maximum number of times of transferring digital assets allowed to be transferred from the account address of the institution within the unit time, and determine the maximum number of times as the restricted execution number of the asset transfer within the current time. Then, perform abnormal signature detection on the asset transaction according to the number of times the asset transaction is executed within the second historical time period and the restricted execution number to obtain a detection result. For example, if the number of times the asset transaction is executed within the second historical time period is greater than the restricted execution number, it indicates that there are illegal users frequently transferring digital assets from the account address of the institution, and the asset transaction is not intercepted by the signature cooperation devices in the signature cooperation device cluster, it is determined that the asset transaction has an abnormal signature, and a detection result indicating that the asset transaction has an abnormal signature is generated. If the number of times the asset transaction is executed within the second historical time period is less than the restricted execution number, the computer device can perform abnormal signature detection on the asset transaction in combination with other parameters to obtain a detection result. By performing abnormal signature detection on the asset transaction, it is beneficial to identify the abnormal behavior of illegal users frequently transferring digital assets from the account address of the institution, and is beneficial to improving the security of the digital assets of the institution.
[0132] Optionally, such as Figure 6As shown, when the asset transaction is to transfer digital assets from the account address of the institution, the computer device can, according to the transaction attribute information, query from the blockchain of the blockchain network the number of times digital assets are transferred from the account address of the institution within the second historical time period, and determine the number of times digital assets are transferred as the number of times the asset transaction is executed within the second historical time period. From the sub-blockchain, query the maximum number of transfers allowed to transfer digital assets from the account address of the institution within a unit time period, and determine this maximum number of transfers as the restricted execution number of the asset transfer within the current time period. Then, perform abnormal signature detection on the asset transaction according to the number of times the asset transaction is executed within the second historical time period and the restricted execution number to obtain a detection result. For example, if the number of times the asset transaction is executed within the second historical time period is greater than the restricted execution number, it indicates that there are illegal users frequently transferring digital assets to the account address of the institution, and the asset transaction is not intercepted by the signature cooperation devices in the signature cooperation device cluster. It is determined that the asset transaction has an abnormal signature, and a detection result indicating that the asset transaction has an abnormal signature is generated. If the number of times the asset transaction is executed within the second historical time period is less than the restricted execution number, the computer device can perform abnormal signature detection on the asset transaction in combination with other parameters to obtain a detection result. By performing abnormal signature detection on the asset transaction, it is beneficial to identify the abnormal behavior of illegal users frequently transferring digital assets to the account address of the institution, and is beneficial to improving the security of the institution's digital assets.
[0133] Optionally, such as Figure 7As shown, when the asset transaction is to log in to the asset client of the institution, the computer device can query the number of times of logging in to the asset client of the institution on the blockchain according to the asset transaction attribute information, and determine the number of times of logging in to the asset client of the institution in the second historical period as the number of times the asset transaction is executed in the second historical period. From the sub-blockchain, query the maximum number of logins allowed to the asset client of the institution within the unit time period, and determine this maximum number of logins as the restricted execution times of the asset transfer during the night time. Then, perform abnormal signature detection on the asset transaction according to the number of times the asset transaction is executed in the second historical period and the restricted execution times, and obtain the detection result. For example, if the number of times the asset transaction is executed in the second historical period is greater than the restricted execution times, it indicates that there are illegal users frequently logging in to the asset client of the institution, and the asset transaction is not intercepted by the signature cooperation devices in the signature cooperation device cluster. It is determined that the asset transaction has an abnormal signature, and a detection result indicating that the asset transaction has an abnormal signature is generated. If the number of times the asset transaction is executed in the second historical period is less than the restricted execution times, the computer device can perform abnormal signature detection on the asset transaction in combination with other parameters to obtain the detection result. By performing abnormal signature detection on the asset transaction, it is beneficial to identify illegal users frequently logging in to the asset client of the institution and improve the security of the digital assets of the institution.
[0134] It should be noted that the second historical period can include the execution time of the asset transaction and a period of time before the execution time. For example, if the execution time is 12:00:00, the second historical period can refer to 12:00:00~12:10:00. The unit time period can refer to one hour, two hours, 20 minutes, etc. The unit time period is the same as the duration corresponding to the second historical period. For example, if the second historical period is 12:00:00~12:10:00, the unit time period is 10 minutes.
[0135] In one embodiment, the above asset transaction is to log in to the asset client of the above institution, and the above transaction attribute information includes the login information of the login user; performing abnormal signature detection on the above asset transaction according to the number of times the above asset transaction is executed in the second historical period and the restricted execution times to obtain the detection result includes: when the number of times the above asset transaction is executed in the second historical period is less than the restricted execution times, obtaining the login information of the above institution from the above sub-blockchain; determining the similarity between the login information of the above institution and the login information of the above login user. When the similarity is less than the similarity threshold, it is determined that the above asset transaction has an abnormal signature, and a detection result indicating that the above asset transaction has an abnormal signature is generated.
[0136] Specifically, when the number of times the asset transaction is executed within the second historical time period is less than the above-mentioned restricted execution times, the computer device can obtain the login information of the institution from the sub-blockchain. The login information of the institution may refer to the login information of a user with the permission to log in to the asset client of the institution. The login information may include the login account, name, password, login key, etc. The computer device can use a similarity algorithm to calculate the similarity between the login information of the above-mentioned institution and the login information of the above-mentioned login person. The similarity algorithm may include a cosine similarity algorithm, a Manhattan distance algorithm, a Pearson similarity algorithm, etc. When the similarity is less than the similarity threshold, it indicates that an illegal user has logged in to the asset client of the institution and this illegal login has not been intercepted by the signature cooperation devices in the signature cooperation device cluster. Therefore, it is determined that the above-mentioned asset transaction has an abnormal signature, and a detection result indicating that the above-mentioned asset transaction has an abnormal signature is generated. Detecting the abnormal signature of the asset transaction through the login information of the login person is beneficial to identifying that an illegal user has logged in to the asset client of the institution and improving the security of the digital assets of the institution.
[0137] In one embodiment, the above-mentioned asset transaction is to transfer digital assets from the account address of the above-mentioned institution. The above-mentioned transaction attribute information includes the object attribute information of the transferor and the asset quantity corresponding to the digital assets transferred by the above-mentioned transferor. The above-mentioned detecting the abnormal signature of the above-mentioned asset transaction according to the number of times the above-mentioned asset transaction is executed within the second historical time period and the restricted execution times to obtain a detection result includes: when the number of times the above-mentioned asset transaction is executed within the second historical time period is less than the above-mentioned restricted execution times, query the position level of the above-mentioned transferor in the above-mentioned institution from the above-mentioned sub-blockchain according to the object attribute information of the above-mentioned transferor. According to the above-mentioned position level, determine the restricted asset quantity transferred by the above-mentioned transferor each time; when the asset quantity corresponding to the digital assets transferred by the above-mentioned transferor is greater than the above-mentioned restricted asset quantity, determine that the above-mentioned asset transaction has an abnormal signature, and generate a detection result indicating that the above-mentioned asset transaction has an abnormal signature.
[0138] Specifically, when the number of times the above-mentioned asset transaction is executed within the second historical time period is less than the above-mentioned restricted execution times, the computer device can query the position level of the above-mentioned transferor in the above-mentioned institution from the above-mentioned sub-blockchain according to the object attribute information of the above-mentioned transferor. According to the above-mentioned position level, determine the maximum asset quantity transferred by the above-mentioned transferor each time, and determine this maximum asset quantity as the restricted asset quantity transferred each time; when the asset quantity corresponding to the digital assets transferred by the above-mentioned transferor is greater than the above-mentioned restricted asset quantity, it indicates that there is an act of a user illegally embezzling the digital assets of the institution and this asset transaction has not been intercepted by the signature cooperation devices in the signature cooperation device cluster. Therefore, the computer device can determine that the above-mentioned asset transaction has an abnormal signature and generate a detection result indicating that the above-mentioned asset transaction has an abnormal signature.
[0139] It should be noted that when multiple auditing devices in the auditing network jointly perform anomaly signature detection on asset transactions based on transaction attribute information, the implementation method for performing anomaly signature detection on the above asset transactions based on the above transaction attribute information to obtain a detection result can be replaced with performing anomaly signature detection on the above asset transactions based on the above transaction attribute information to obtain a first detection result. The implementation process of other devices in the auditing network performing anomaly signature detection on asset transactions based on transaction attribute information to obtain a second detection result can refer to the implementation process of the above computer device performing anomaly signature detection on asset transactions based on transaction attribute information to obtain a first detection result, and the repeated parts will not be elaborated.
[0140] S203. When the above detection result indicates that there is an anomaly signature in the above asset transaction, obtain the historical log data of the signature cooperation devices in the above signature cooperation device cluster from the sub-blockchain of the sub-blockchain network.
[0141] S204. Obtain the execution time of the above asset transaction from the above blockchain.
[0142] S205. Intercept the historical log data segment of the signature cooperation devices in the above signature cooperation device cluster within the first historical time period according to the above execution time; the above first historical time period includes the above execution time and the time before the above execution time.
[0143] S206. Determine the target signature cooperation device that performs anomaly signature on the above asset transaction from the above signature cooperation device cluster according to the above historical log data segment.
[0144] In steps S204 - S206, since the execution time of the signature operation on the asset transaction by the signature collaboration devices in the signature collaboration device cluster is before the execution time of the asset transaction, the computer device can obtain the time when the asset transaction is uploaded to the blockchain and use this upload time as the execution time of the asset transaction. Then, based on this execution time, it can intercept the historical log data segment of the signature collaboration devices in the signature collaboration device cluster within the first historical time period. This first historical time period includes the execution time and the time before the execution time. For example, if the execution time is 12:00:00, the first historical time period can be 12:00:00 - 12:10:00. That is, this first historical time period includes the time when the signature collaboration devices perform the signature operation on the asset transaction, which means the historical log data segment includes the log data corresponding to the execution time when the asset transaction is signed by the signature collaboration devices. The computer device can determine the target signature collaboration device that performs an abnormal signature on the asset transaction from the signature collaboration device cluster based on this historical log data segment. Through the historical log data, it is possible to trace back to the signature collaboration device that performs an abnormal signature on the asset transaction, which is beneficial to improving the security of the institution's digital assets.
[0145] In one embodiment, the method of determining the target signature collaboration device that performs an abnormal signature on the asset transaction from the signature collaboration device cluster based on the above historical log data segment includes: The computer device can screen the signature collaboration devices that perform the signature operation within the first historical time period from the signature collaboration device cluster according to the above historical log data segment; determine the execution time of the signature operation of the screened signature collaboration devices according to the above historical log data segment. Based on the above generation time and the execution times corresponding to the screened signature collaboration devices respectively, determine the target signature collaboration device that performs an abnormal signature on the asset transaction from the screened signature collaboration devices.
[0146] Specifically, when the signature collaboration device does not perform a signature operation within the first historical time period, it indicates that the signature collaboration device has intercepted an illegal asset transaction, or the signature collaboration device has not been selected to participate in the signature; therefore, the computer device can, based on this historical log data segment, screen out the signature collaboration devices that perform signature operations within the first historical time period from the signature collaboration device cluster, that is, filter out the signature collaboration devices that do not perform signature operations within the first historical time period from the previous collaboration device cluster. Further, based on the above historical log data segment, determine the execution time of the signature operation performed by the screened signature collaboration devices, and based on the generation time of the asset transaction and the respective execution times corresponding to the above-screened signature collaboration devices, determine the target signature collaboration device that performs an abnormal signature on the above asset transaction from the above-screened signature collaboration devices. By analyzing the historical log data segment, it is beneficial to accurately determine the signature collaboration device that performs an abnormal signature and improve the security of the institution's digital assets.
[0147] In one embodiment, the target signature collaboration device that performs an abnormal signature on the above asset transaction from the above-screened signature collaboration devices based on the execution time of the above asset transaction and the respective execution times corresponding to the above-screened signature collaboration devices includes: obtaining the time intervals between the execution time of the asset transaction and the respective execution times corresponding to the above-screened signature collaboration devices; determining, from the above-screened signature collaboration devices, the candidate signature collaboration devices corresponding to which the above time intervals are less than the time interval threshold. Determine the above candidate signature collaboration devices as the target signature collaboration devices that perform an abnormal signature on the above asset transaction.
[0148] Specifically, usually the time interval between the execution time of the signature operation performed by the signature collaboration device on the asset transaction and the execution time of the asset transaction is relatively short. Therefore, the computer device can perform a subtraction operation on the execution time of the asset transaction and the respective execution times corresponding to the above-screened signature collaboration devices to obtain the time intervals between the execution time of the asset transaction and the respective execution times corresponding to the above-screened signature collaboration devices. Then, the computer device can determine, from the above-screened signature collaboration devices, the candidate signature collaboration devices corresponding to which the above time intervals are less than the time interval threshold, and can determine the above candidate signature collaboration devices as the target signature collaboration devices that perform an abnormal signature on the above asset transaction. By using the execution time of the asset transaction and the execution time of the signature operation performed by the signature collaboration device to determine the signature collaboration device that performs an abnormal signature, it is beneficial to accurately determine the signature collaboration device that performs an abnormal signature and improve the security of the institution's digital assets.
[0149] In one embodiment, the computer device may determine the impact degree brought by the abnormal signature of the asset transaction to the above-mentioned institution according to the above-mentioned transaction attribute information; according to the above-mentioned impact degree, update the credit degrees of the signature cooperation devices in the above-mentioned signature cooperation device cluster to obtain the updated credit degrees of the signature cooperation devices in the above-mentioned signature cooperation device cluster. According to the above-mentioned updated credit degrees, select the signature cooperation devices participating in the next signature from the above-mentioned signature cooperation device cluster.
[0150] Specifically, when the asset transaction is to transfer digital assets from the account address of the institution, the computer device may determine the impact degree brought by the abnormal signature of the asset transaction to the institution according to at least one of the asset quantity and asset type corresponding to the transferred digital assets in the transaction attribute information. The impact degree reflects the asset loss of the institution's digital assets caused by the abnormal signature of the asset transaction. For example, there is a positive correlation between the asset quantity and the impact degree. The larger the asset quantity, the higher the impact degree; the smaller the asset quantity, the lower the impact degree. The computer device may update the credit degrees of the signature cooperation devices in the above-mentioned signature cooperation device cluster according to the above-mentioned impact degree to obtain the updated credit degrees of the signature cooperation devices in the above-mentioned signature cooperation device cluster. According to the above-mentioned updated credit degrees, select the signature cooperation devices participating in the next signature from the above-mentioned signature cooperation device cluster. For example, the signature cooperation devices with updated credit degrees greater than a certain credit degree in the signature cooperation device cluster may be used as the signature cooperation devices participating in the next signature.
[0151] It should be noted that the signature cooperation devices selected to participate in the next signature may participate in signing the new asset transaction when receiving the new asset transaction next time. Specifically, when the signature cooperation devices participating in the next signature verify that the new asset transaction is legal, they sign the new asset transaction to obtain the new asset transaction signature; when the signature cooperation devices participating in the next signature verify that the new asset transaction is illegal, they refuse to sign the new asset transaction.
[0152] In one embodiment, the above-mentioned step of updating the credit degrees of the signature cooperation devices in the above-mentioned signature cooperation device cluster according to the above-mentioned impact degree to obtain the updated credit degrees of the signature cooperation devices in the above-mentioned signature cooperation device cluster includes: the computer device may determine the candidate signature cooperation devices selected to participate in the signature when signing the above-mentioned asset transaction according to the credit degrees of the signature cooperation devices in the above-mentioned signature cooperation device cluster; the above-mentioned candidate signature cooperation devices include the above-mentioned target signature cooperation device; according to the above-mentioned impact degree, reduce the credit degree of the above-mentioned target signature cooperation device to obtain the updated credit degree of the above-mentioned target signature cooperation device. According to the above-mentioned impact degree, increase the credit degrees of the remaining signature cooperation devices to obtain the updated credit degrees of the above-mentioned remaining signature cooperation devices; the above-mentioned remaining signature cooperation devices are the devices other than the above-mentioned target signature cooperation device among the above-mentioned candidate signature cooperation devices.
[0153] Specifically, the computer device may determine, according to the credit of the signature collaboration devices in the signature collaboration device cluster, the signature collaboration devices selected to participate in the signature when signing the asset transaction, as candidate signature collaboration devices; the candidate signature collaboration devices include the target signature collaboration device. Then, according to the influence degree, the credit of the target signature collaboration device may be reduced to obtain the updated credit of the target signature collaboration device. According to the influence degree, the credit of the remaining signature collaboration devices may be increased to obtain the updated credit of the remaining signature collaboration devices; the remaining signature collaboration devices are the devices other than the target signature collaboration device among the candidate signature collaboration devices. That is, the credit of the signature collaboration devices other than the candidate signature collaboration devices in the signature collaboration device cluster remains unchanged. By updating the credit of the signature collaboration devices based on the influence degree, it is beneficial to select the signature collaboration devices participating in the signature based on the credit, improve the signature accuracy of the asset transaction, avoid illegal users from doing evil, and improve the security of the institution's digital assets.
[0154] In one embodiment, when the updated credit of the target signature collaboration device is less than the credit threshold, the computer device may remove the target signature collaboration device from the signature collaboration device cluster; count the number of devices in the signature collaboration device cluster, and update the limit signature number of the institution according to the number of devices to obtain the updated limit signature number. Send the number of devices and the updated limit signature number to the signature collaboration devices in the signature collaboration device cluster; the signature collaboration devices in the signature collaboration device cluster are used to delete their corresponding private key shards and generate updated private key shards according to the number of devices and the updated limit signature number.
[0155] Specifically, when the updated credit of the target signature collaboration device is less than the credit threshold, the computer device may remove the target signature collaboration device from the signature collaboration device cluster, enabling the target signature collaboration device to have the qualification to participate in the signature, avoiding the target signature collaboration device from performing abnormal signatures again, and improving the signature accuracy and security of the digital assets. Then, the computer device may count the number of devices in the signature collaboration device cluster, and update the limit signature number of the institution according to the number of devices to obtain the updated limit signature number. Send the number of devices and the updated limit signature number to the signature collaboration devices in the signature collaboration device cluster; the signature collaboration devices in the signature collaboration device cluster may run the MPC protocol according to the number of devices and the updated limit signature number to obtain their corresponding updated private key shards and delete their corresponding original private key shards, which is beneficial to improving the signature accuracy of the asset transaction and the security of the institution's digital assets.
[0156] In one embodiment, the computer device may verify the legality of the asset transaction according to the transaction attribute information to obtain a verification result. If the verification result indicates that the asset transaction is legal, the computer device may count the number of asset transaction signatures received by the statistical node device. When the number of received asset transaction signatures is less than the device quantity threshold, it is determined that there is an abnormal signature in the asset transaction, and a detection result for indicating the existence of an abnormal signature in the asset transaction is generated. The device quantity threshold is greater than the restricted signature quantity and less than or equal to the total number of devices in the signature cooperation device cluster. The computer device may obtain the historical log data of each signature cooperation device from the sub-blockchain, and determine the signature cooperation devices that have not signed the asset transaction according to the historical log data, indicating that the signature devices that have not signed the asset transaction maliciously refrain from signing the legal asset transaction, thus realizing malicious interception of the legal asset transaction. Therefore, the computer device may use the signature cooperation devices in the signature cooperation device cluster that have not signed the asset transaction as the target signature cooperation devices for abnormally signing the asset transaction, which is beneficial to ensuring the normal execution of the asset transaction of the institution and improving the security of the digital assets of the institution.
[0157] It should be noted that the device quantity threshold may be determined according to the total number of devices in the signature cooperation device cluster, or the device quantity threshold may be determined according to the number of signature cooperation devices selected to participate in the signature in the current round of signature cooperation device cluster, or the device quantity threshold may be determined according to the total asset quantity, asset type, etc. of the institution.
[0158] This application provides a two-layer blockchain network. One layer of the blockchain network is used to execute asset transactions, and the second layer of the blockchain network (i.e., the sub-blockchain network) is used to store the historical log data of the signature cooperation devices. When an abnormal signature appears in a certain asset transaction in the first layer of the blockchain network, the historical log data in the second layer of the blockchain network can be used to determine which signature cooperation devices abnormally sign the asset transaction, that is, it is possible to trace which participating parties abnormally sign the asset transaction based on the historical log data. Furthermore, the signature cooperation devices with abnormal signatures can be restricted from participating in the signature, improving the security of digital assets. At the same time, by storing the historical log data on the second layer of the blockchain network, the data processing pressure on the first layer of the blockchain network will not be increased, and the problem that the signature participating parties cannot be traced in the secure multi-party calculation method can be solved.
[0159] Please refer to Figure 8 , which is a schematic structural diagram of a blockchain data processing device provided by an embodiment of this application. The above blockchain-based data processing device may be a computer program (including program code) running in a network device. For example, the blockchain-based data processing device is an application software; this device may be used to execute the corresponding steps in the method provided by the embodiment of this application. As Figure 8As shown in the figure, the blockchain data processing device may include:
[0160] A first acquisition module 811, configured to acquire transaction attribute information of an executed asset transaction from a blockchain in a blockchain network; the above-mentioned transaction attribute information is recorded on the above-mentioned blockchain when the node devices in the above-mentioned blockchain network verify that N asset transaction signatures are all verified through based on the public key corresponding to the asset transaction, N is a positive integer greater than or equal to K, K is the restricted signature quantity of the institution corresponding to the above-mentioned asset transaction, the above-mentioned N asset transaction signatures are obtained by signature cooperation devices in the signature cooperation device cluster of the above-mentioned institution using their corresponding private key shards to sign the above-mentioned asset transaction, and the number of devices in the above-mentioned signature cooperation device cluster is greater than or equal to N;
[0161] A detection module 812, configured to perform abnormal signature detection on the above-mentioned asset transaction according to the above-mentioned transaction attribute information to obtain a detection result;
[0162] A second acquisition module 813, configured to, when the above-mentioned detection result indicates that there is an abnormal signature in the above-mentioned asset transaction, acquire historical log data of signature cooperation devices in the above-mentioned signature cooperation device cluster from a sub-blockchain in a sub-blockchain network;
[0163] A determination module 814, configured to determine a target signature cooperation device that performs an abnormal signature on the above-mentioned asset transaction from the above-mentioned signature cooperation device cluster according to the above-mentioned historical log data.
[0164] Optionally, the determination module 814 includes an acquisition unit 81a, an interception unit 82a, and a determination unit 83a;
[0165] The acquisition unit 81a is configured to acquire the execution time of the above-mentioned asset transaction from the above-mentioned blockchain;
[0166] The interception unit 82a is configured to intercept a historical log data segment of signature cooperation devices in the above-mentioned signature cooperation device cluster within a first historical time period according to the above-mentioned execution time from the above-mentioned historical log data; the above-mentioned first historical time period includes the above-mentioned execution time and the time before the above-mentioned execution time;
[0167] The determination unit 83a is configured to determine a target signature cooperation device that performs an abnormal signature on the above-mentioned asset transaction from the above-mentioned signature cooperation device cluster according to the above-mentioned historical log data segment.
[0168] Optionally, the determination unit 83a determines a target signature cooperation device that performs an abnormal signature on the above-mentioned asset transaction from the above-mentioned signature cooperation device cluster according to the above-mentioned historical log data segment, including:
[0169] Screen the signature collaboration devices that perform signature operations within the first historical time period from the above-mentioned signature collaboration device cluster according to the above historical log data segment;
[0170] Determine the execution time of the signature operation performed by the screened signature collaboration devices according to the above historical log data segment;
[0171] According to the execution time of the above asset transaction and the execution times corresponding to the above screened signature collaboration devices respectively, determine the target signature collaboration devices that perform abnormal signatures on the above asset transaction from the above screened signature collaboration devices.
[0172] Optionally, the determining unit 83a determines the target signature collaboration devices that perform abnormal signatures on the above asset transaction from the above screened signature collaboration devices according to the execution time of the above asset transaction and the execution times corresponding to the above screened signature collaboration devices respectively, including:
[0173] Obtain the time intervals between the execution time of the above asset transaction and the execution times corresponding to the above screened signature collaboration devices respectively;
[0174] From the above screened signature collaboration devices, determine the candidate signature collaboration devices corresponding to the above time intervals that are less than the time interval threshold;
[0175] Determine the above candidate signature collaboration devices as the target signature collaboration devices that perform abnormal signatures on the above asset transaction.
[0176] The detection module 812 includes a first query unit 84a, a second query unit 85a, and a detection unit 86a;
[0177] The first query unit 84a is used to query the number of times the above asset transaction is executed within the second historical time period from the above blockchain according to the above transaction attribute information;
[0178] The second query unit 85a is used to query the limited execution times of the asset transactions of the above institution within the unit time length from the above sub-blockchain; the unit time length is the same as the time length corresponding to the above second historical time period;
[0179] The detection unit 86a is used to perform abnormal signature detection on the above asset transaction according to the number of times the above asset transaction is executed within the second historical time period and the limited execution times, and obtain a detection result.
[0180] Optionally, the above asset transaction is to log in to the asset client of the above institution, and the above transaction attribute information includes the login information of the login person;
[0181] The above detection unit 86a performs abnormal signature detection on the above asset transaction according to the number of times the above asset transaction is executed within the second historical time period and the restricted execution times, and obtains a detection result, including:
[0182] When the number of times the above asset transaction is executed within the second historical time period is less than the restricted execution times, obtain the login information of the above institution from the above sub-blockchain;
[0183] Determine the similarity between the login information of the above institution and the login information of the above login person;
[0184] When the above similarity is less than the similarity threshold, determine that the above asset transaction has an abnormal signature, and generate a detection result indicating that the above asset transaction has an abnormal signature.
[0185] Optionally, the above asset transaction is to transfer digital assets from the account address of the above institution, and the above transaction attribute information includes the object attribute information of the transferor and the asset quantity corresponding to the digital assets transferred by the above transferor;
[0186] The above detection unit 86a performs abnormal signature detection on the above asset transaction according to the number of times the above asset transaction is executed within the second historical time period and the restricted execution times, and obtains a detection result, including:
[0187] When the number of times the above asset transaction is executed within the second historical time period is less than the restricted execution times, query the position level of the above transferor in the above institution from the above sub-blockchain according to the object attribute information of the above transferor;
[0188] Determine the restricted asset quantity transferred by the above transferor each time according to the above position level;
[0189] When the asset quantity corresponding to the digital assets transferred by the above transferor is greater than the above restricted asset quantity, determine that the above asset transaction has an abnormal signature, and generate a detection result indicating that the above asset transaction has an abnormal signature.
[0190] Optionally, the device further includes an update module 815 and a selection module 816;
[0191] The determination module 814 is further configured to determine the impact degree of the abnormal signature of the asset transaction on the above institution according to the above transaction attribute information;
[0192] The update module 815 is configured to update the credit degree of the signature cooperation devices in the above signature cooperation device cluster according to the above impact degree, and obtain the updated credit degree of the signature cooperation devices in the above signature cooperation device cluster;
[0193] A selection module 816, configured to select, according to the updated credit degrees described above, signature collaboration devices from the signature collaboration device cluster described above to participate in the next signature.
[0194] Optionally, the update module 815 updates the credit degrees of the signature collaboration devices in the signature collaboration device cluster according to the influence degree described above to obtain the updated credit degrees of the signature collaboration devices in the signature collaboration device cluster, including:
[0195] Determine candidate signature collaboration devices selected to participate in the signature when signing the asset transaction according to the credit degrees of the signature collaboration devices in the signature collaboration device cluster described above; the candidate signature collaboration devices include the target signature collaboration device described above;
[0196] Reduce the credit degree of the target signature collaboration device according to the influence degree described above to obtain the updated credit degree of the target signature collaboration device;
[0197] Increase the credit degrees of the remaining signature collaboration devices according to the influence degree described above to obtain the updated credit degrees of the remaining signature collaboration devices; the remaining signature collaboration devices are the devices other than the target signature collaboration device among the candidate signature collaboration devices.
[0198] Optionally, the apparatus may further include a removal module 817 and a sending module 818;
[0199] The removal module 817 is configured to remove the target signature collaboration device from the signature collaboration device cluster when the updated credit degree of the target signature collaboration device is less than the credit degree threshold;
[0200] The update module 815 is further configured to count the number of devices in the signature collaboration device cluster and update the limit signature number of the institution according to the number of devices to obtain the updated limit signature number;
[0201] The sending module 818 is configured to send the number of devices and the updated limit signature number to the signature collaboration devices in the signature collaboration device cluster; the signature collaboration devices in the signature collaboration device cluster are configured to delete their corresponding private key shards and generate updated private key shards according to the number of devices and the updated limit signature number.
[0202] Optionally, the first acquisition module 811 acquires the transaction attribute information of the executed asset transaction from the blockchain in the blockchain network, including:
[0203] Receive an audit request for the asset transaction of the institution; the audit request carries the institution attribute information of the institution;
[0204] Obtain the transaction attribute information of the executed asset transactions belonging to the above institution from the blockchain in the above blockchain network according to the institution attribute information carried in the above audit request.
[0205] In this application, a two-layer blockchain network is provided. One layer of the blockchain network is used to execute asset transactions, and the second layer of the blockchain network (i.e., the sub-blockchain network) is used to store the historical log data of signature collaboration devices. When an abnormal signature occurs in a certain asset transaction in the first layer of the blockchain network, the historical log data in the second layer of the blockchain network can be used to determine which signature collaboration devices perform abnormal signatures on the asset transaction, that is, it is possible to trace which participating parties perform abnormal signatures on the asset transaction based on the historical log data. Furthermore, the signature collaboration devices with abnormal signatures can be restricted from participating in signatures, improving the security of digital assets. At the same time, by storing the historical log data on the second layer of the blockchain network, the data processing pressure on the first layer of the blockchain network will not be increased, and the problem that the signature participants cannot be traced in the secure multi-party computing method can be solved.
[0206] Please refer to Figure 9 , which is a schematic structural diagram of a computer device provided by an embodiment of this application. As Figure 9 shown, the above computer device 1000 may refer to a terminal or a server, including: a processor 1001, a network interface 1004, and a memory 1005. In addition, the above computer device 1000 may further include: a user interface 1003 and at least one communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. Among them, in some embodiments, the user interface 1003 may include a display screen (DiSPlay) and a keyboard (Keyboard). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory or a non-volatile memory (non-volatile MeMory), such as at least one disk memory. Optionally, the memory 1005 may further be at least one storage device far from the aforementioned processor 1001. As Figure 9 shown, the memory 1005, as a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a computer program.
[0207] In Figure 9 the computer device 1000 shown, the network interface 1004 can provide network communication functions; while the user interface 1003 is mainly used to provide an input interface; and the processor 1001 can be used to call the computer program stored in the memory 1005 to execute:
[0208] Obtain the transaction attribute information of the executed asset transaction from the blockchain in the blockchain network; the above transaction attribute information is recorded on the above blockchain when the node devices in the above blockchain network verify that N asset transaction signatures are all verified through based on the public key corresponding to the asset transaction, where N is a positive integer greater than or equal to K, and K is the limit signature quantity of the institution corresponding to the above asset transaction. The above N asset transaction signatures are obtained by the signature collaboration devices in the signature collaboration device cluster of the above institution using their corresponding private key shards to sign the above asset transaction, and the number of devices in the above signature collaboration device cluster is greater than or equal to N;
[0209] Perform abnormal signature detection on the above asset transaction according to the above transaction attribute information to obtain a detection result;
[0210] When the above detection result indicates that there is an abnormal signature in the above asset transaction, obtain the historical log data of the signature collaboration devices in the above signature collaboration device cluster from the sub-blockchain in the sub-blockchain network;
[0211] Determine the target signature collaboration device that performs abnormal signature on the above asset transaction from the above signature collaboration device cluster according to the above historical log data.
[0212] Optionally, the processor 1001 calls the computer program stored in the memory 1005 to execute determining the target signature collaboration device that performs abnormal signature on the above asset transaction from the above signature collaboration device cluster according to the above historical log data, including:
[0213] Obtain the execution time of the above asset transaction from the above blockchain;
[0214] Intercept the historical log data segment of the signature collaboration devices in the above signature collaboration device cluster within the first historical time period according to the above execution time from the above historical log data; the above first historical time period includes the above execution time and the time before the above execution time;
[0215] Determine the target signature collaboration device that performs abnormal signature on the above asset transaction from the above signature collaboration device cluster according to the above historical log data segment.
[0216] Optionally, the processor 1001 calls the computer program stored in the memory 1005 to execute determining the target signature collaboration device that performs abnormal signature on the above asset transaction from the above signature collaboration device cluster according to the above historical log data segment, including:
[0217] Screen the signature collaboration devices that perform signature operations within the above first historical time period from the above signature collaboration device cluster according to the above historical log data segment;
[0218] Determine the execution time of the signature operation performed by the signature collaboration device obtained by screening according to the above historical log data segment;
[0219] According to the execution time of the above asset transaction and the execution time corresponding to each of the above signature collaboration devices obtained by screening, determine the target signature collaboration device that performs an abnormal signature on the above asset transaction from the above signature collaboration devices obtained by screening.
[0220] Optionally, the processor 1001 calls the computer program stored in the memory 1005 to execute the target signature collaboration device that performs an abnormal signature on the above asset transaction from the above signature collaboration devices obtained by screening according to the execution time of the above asset transaction and the execution time corresponding to each of the above signature collaboration devices obtained by screening, including:
[0221] Obtain the time interval between the execution time of the above asset transaction and the execution time corresponding to each of the above signature collaboration devices obtained by screening;
[0222] From the above signature collaboration devices obtained by screening, determine the candidate signature collaboration devices corresponding to the above time intervals that are less than the time interval threshold;
[0223] Determine the above candidate signature collaboration devices as the target signature collaboration devices that perform an abnormal signature on the above asset transaction.
[0224] Optionally, the processor 1001 calls the computer program stored in the memory 1005 to execute the abnormal signature detection on the above asset transaction according to the above transaction attribute information to obtain a detection result, including:
[0225] According to the above transaction attribute information, query the number of times the above asset transaction has been executed on the above blockchain within the second historical time period;
[0226] Query the limited execution times of the asset transactions of the above institution within the unit time from the above sub-blockchain; the unit time is the same as the time length corresponding to the above second historical time period;
[0227] Perform abnormal signature detection on the above asset transaction according to the number of times the above asset transaction has been executed within the second historical time period and the limited execution times to obtain a detection result.
[0228] Optionally, the above asset transaction is to log in to the asset client of the above institution, and the above transaction attribute information includes the login information of the login person;
[0229] Optionally, the processor 1001 calls the computer program stored in the memory 1005 to execute the abnormal signature detection on the above asset transaction according to the number of times the above asset transaction has been executed within the second historical time period and the limited execution times to obtain a detection result, including:
[0230] When the number of times the above asset transaction is executed within the second historical time period is less than the above limit execution times, obtain the login information of the above institution from the above sub-blockchain;
[0231] Determine the similarity between the login information of the above institution and the login information of the above login person;
[0232] When the above similarity is less than the similarity threshold, determine that the above asset transaction has an abnormal signature, and generate a detection result indicating that the above asset transaction has an abnormal signature.
[0233] Optionally, the above asset transaction is to transfer digital assets from the account address of the above institution, and the above transaction attribute information includes the object attribute information of the transferor and the asset quantity corresponding to the digital assets transferred by the above transferor;
[0234] Optionally, the processor 1001 calls the computer program stored in the memory 1005 to perform abnormal signature detection on the above asset transaction according to the number of times the above asset transaction is executed within the second historical time period and the limit execution times, and obtain a detection result, including:
[0235] When the number of times the above asset transaction is executed within the second historical time period is less than the above limit execution times, query the position level of the above transferor in the above institution from the above sub-blockchain according to the object attribute information of the above transferor;
[0236] Determine the restricted asset quantity transferred by the above transferor each time according to the above position level;
[0237] When the asset quantity corresponding to the digital assets transferred by the above transferor is greater than the above restricted asset quantity, determine that the above asset transaction has an abnormal signature, and generate a detection result indicating that the above asset transaction has an abnormal signature.
[0238] Optionally, the processor 1001 can call the computer program stored in the memory 1005 to execute:
[0239] Determine the influence degree brought by the abnormal signature of the asset transaction to the above institution according to the above transaction attribute information;
[0240] Update the credit of the signature collaboration devices in the above signature collaboration device cluster according to the above influence degree to obtain the updated credit of the signature collaboration devices in the above signature collaboration device cluster;
[0241] Select the signature collaboration devices participating in the next signature from the above signature collaboration device cluster according to the above updated credit.
[0242] Optionally, the processor 1001 invokes a computer program stored in the memory 1005 to execute updating the credit of the signature collaboration devices in the signature collaboration device cluster according to the above influence degree, and obtaining the updated credit of the signature collaboration devices in the signature collaboration device cluster, including:
[0243] Determine candidate signature collaboration devices selected to participate in signing when signing the above asset transaction according to the credit of the signature collaboration devices in the above signature collaboration device cluster; the above candidate signature collaboration devices include the above target signature collaboration device;
[0244] Reduce the credit of the above target signature collaboration device according to the above influence degree to obtain the updated credit of the above target signature collaboration device;
[0245] Increase the credit of the remaining signature collaboration devices according to the above influence degree to obtain the updated credit of the remaining signature collaboration devices; the above remaining signature collaboration devices are the devices other than the above target signature collaboration device among the above candidate signature collaboration devices.
[0246] Optionally, the processor 1001 may invoke a computer program stored in the memory 1005 to execute:
[0247] When the updated credit of the above target signature collaboration device is less than the credit threshold, remove the above target signature collaboration device from the above signature collaboration device cluster;
[0248] Count the number of devices in the above signature collaboration device cluster, and update the limit signature number of the above institution according to the above number of devices to obtain the updated limit signature number;
[0249] Send the above number of devices and the above updated limit signature number to the signature collaboration devices in the above signature collaboration device cluster; the signature collaboration devices in the above signature collaboration device cluster are used to delete their corresponding private key shards and generate updated private key shards according to the above number of devices and the above updated limit signature number.
[0250] Optionally, the processor 1001 invokes a computer program stored in the memory 1005 to execute obtaining transaction attribute information of an executed asset transaction from a blockchain in a blockchain network, including:
[0251] Receive an audit request for an asset transaction of the above institution; the above audit request carries the institution attribute information of the above institution;
[0252] According to the institution attribute information carried in the above audit request, obtain transaction attribute information of executed asset transactions belonging to the above institution from the blockchain in the above blockchain network.
[0253] This application provides a two-layer blockchain network. One layer of the blockchain network is used to execute asset transactions, and the second layer of the blockchain network (i.e., the sub-blockchain network) is used to store the historical log data of signature collaboration devices. When an abnormal signature occurs in a certain asset transaction in the first layer of the blockchain network, the historical log data in the second layer of the blockchain network can be used to determine which signature collaboration devices perform abnormal signatures on the asset transaction, that is, it is possible to trace which participating parties perform abnormal signatures on the asset transaction based on the historical log data. Furthermore, the signature collaboration devices with abnormal signatures can be restricted from participating in signatures, improving the security of digital assets. At the same time, by storing the historical log data on the second layer of the blockchain network, the data processing pressure on the first layer of the blockchain network will not be increased, and the problem that the signature participants cannot be traced in the secure multi-party computing method can be solved.
[0254] It should be noted that in the embodiments of this application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as processing circuits or memories), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the functions of the module or unit.
[0255] In addition, it should be pointed out here that: The embodiments of this application also provide a computer-readable storage medium, and the computer-readable storage medium stores the computer program executed by the aforementioned blockchain data processing device, and the aforementioned computer program includes program instructions. When the aforementioned processor executes the aforementioned program instructions, it can execute the description of the aforementioned blockchain data processing method in the corresponding previous embodiments. Therefore, it will not be elaborated here. In addition, the description of the beneficial effects of using the same method will not be elaborated either. For the technical details not disclosed in the embodiments of the computer-readable storage medium involved in this application, please refer to the description of the method embodiments of this application.
[0256] As an example, the aforementioned program instructions can be deployed to be executed on a computer device, or be deployed to be executed on at least two computer devices at one location. Or, they can be executed on at least two computer devices distributed at least two locations and interconnected through a communication network. The at least two computer devices distributed at least two locations and interconnected through a communication network can form a blockchain network.
[0257] The above computer-readable storage medium may be the blockchain data processing device provided in any of the foregoing embodiments or the middle storage unit of the above computer device, such as the hard disk or the middle memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc., equipped on the computer device. Further, the computer-readable storage medium may also include both the middle storage unit and the external storage device of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium may also be used to temporarily store the data that has been output or is to be output.
[0258] The terms "first", "second", etc. in the description, claims, and drawings of the embodiments of the present application are used to distinguish the content in different media, rather than to describe a specific order. In addition, the term "comprising" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product, or equipment that includes a series of steps or units is not limited to the listed steps or modules, but may optionally further include steps or modules that are not listed, or may optionally further include other step units inherent to these processes, methods, devices, products, or equipment.
[0259] When collecting and processing relevant data in this application book (such as the initial behavior characteristics corresponding to the user's interaction behavior, and the user's object characteristics, etc.) during the actual application, it should strictly comply with the requirements of relevant laws and regulations, obtain the informed consent or separate consent of the personal information subject, and within the scope authorized by laws and regulations and the personal information subject, carry out subsequent data use and processing behaviors.
[0260] The embodiments of the present application also provide a computer program product, including a computer program. When the above computer program is executed by a processor, it implements the descriptions of the above blockchain data processing method and decoding method in the corresponding foregoing embodiments. Therefore, details will not be repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated either. For the technical details not disclosed in the embodiments of the computer program product involved in the present application, please refer to the description of the method embodiments of the present application.
[0261] Those of ordinary skill in the art will appreciate that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described in terms of function in the above description. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0262] The methods and related devices provided by the embodiments of this application are described with reference to the method flowcharts and / or structural schematic diagrams provided by the embodiments of this application. Specifically, each process and / or block of the method flowchart and / or structural schematic diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable network-connected devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable network-connected devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or structural schematic Figure 1 one block or multiple blocks. These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable network-connected device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one process or multiple processes and / or structural schematic Figure 1 one block or multiple blocks. These computer program instructions can also be loaded onto a computer or other programmable network-connected device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or structural schematic one block or multiple blocks.
[0263] The foregoing disclosure is only for the preferred embodiments of this application, and of course, it cannot be used to limit the scope of the rights of this application. Therefore, equivalent changes made in accordance with the claims of this application still fall within the scope covered by this application.
Claims
1. A blockchain data processing method, characterized in that: include: Obtaining transaction attribute information of executed asset transactions from a blockchain in a blockchain network; the transaction attribute information is recorded on the blockchain when N asset transaction signatures are verified by a node device in the blockchain network based on a public key corresponding to the asset transaction, where N is a positive integer greater than or equal to K, K is the number of restricted signatures of the institution corresponding to the asset transaction, and the N asset transaction signatures are obtained by signing the asset transaction by a signature collaboration device in a signature collaboration device cluster of the institution using its corresponding private key shard, and the number of devices in the signature collaboration device cluster is greater than or equal to N; Perform abnormal signature detection on the asset transaction according to the transaction attribute information to obtain a detection result; When the detection result indicates that there is an abnormal signature in the asset transaction, obtaining historical log data of the signature cooperation device in the signature cooperation device cluster from the sub-blockchain of the sub-blockchain network; According to the historical log data, a target signature cooperation device that performs abnormal signing on the asset transaction is determined from the signature cooperation device cluster.
2. The method according to claim 1, characterized in that: The step of determining, according to the historical log data, a target signature cooperation device that performs abnormal signature on the asset transaction from the signature cooperation device cluster includes: Obtaining the execution time of the asset transaction from the blockchain; According to the execution time, extracting from the historical log data a historical log data segment of the signature cooperation device in the signature cooperation device cluster within a first historical time period; the first historical time period includes the execution time and the time before the execution time; According to the historical log data fragment, a target signature cooperation device that performs abnormal signing on the asset transaction is determined from the signature cooperation device cluster.
3. The method according to claim 2, characterized in that The step of determining, according to the historical log data fragment, a target signature cooperation device that performs abnormal signature on the asset transaction from the signature cooperation device cluster includes: According to the historical log data fragment, screening signature cooperation devices that perform signature operations within the first historical time period from the signature cooperation device cluster; Determining, based on the historical log data fragments, the execution time of the signature operation performed by the screened signature cooperation device; According to the execution time of the asset transaction and the execution times corresponding to the screened signature cooperation devices, a target signature cooperation device that performs abnormal signing on the asset transaction is selected from the screened signature cooperation devices.
4. The method according to claim 3, characterized in that The target signature cooperation device for abnormally signing the asset transaction from the signature cooperation devices obtained by screening according to the execution time of the asset transaction and the execution time corresponding to the selected signature cooperation devices respectively includes: Obtaining the time interval between the execution time of the asset transaction and the execution time corresponding to each of the screened signature cooperation devices; Determine, from the signature cooperation devices obtained by the screening, a signature cooperation device to be selected whose corresponding time interval is less than a time interval threshold; The candidate signature cooperation device is determined as the target signature cooperation device for performing abnormal signature on the asset transaction.
5. The method according to claim 1, characterized in that The performing abnormal signature detection on the asset transaction according to the transaction attribute information to obtain a detection result includes: According to the transaction attribute information, querying the number of times the asset transaction was executed in a second historical time period from the blockchain; Querying the sub-blockchain for the number of execution limits on the asset transactions of the institution within a unit time period; the unit time period is the same as the time period corresponding to the second historical time period; According to the number of times the asset transaction is executed in the second historical time period and the limited number of executions, abnormal signature detection is performed on the asset transaction to obtain a detection result.
6. The method according to claim 5, characterized in that The asset transaction is logged into the asset client of the institution, and the transaction attribute information includes the login information of the logon person; The abnormal signature detection is performed on the asset transaction according to the number of times the asset transaction is executed in the second historical time period and the limited number of executions to obtain the detection result, including: When the number of times the asset transaction is executed in the second historical time period is less than the limit execution number, obtaining the login information of the institution from the sub-blockchain; Determining a similarity between the login information of the organization and the login information of the registrant; When the similarity is less than a similarity threshold, it is determined that an abnormal signature exists in the asset transaction, and a detection result indicating that an abnormal signature exists in the asset transaction is generated.
7. The method according to claim 5, characterized in that The asset transaction is to transfer digital assets from the account address of the institution, and the transaction attribute information includes the object attribute information of the transferor and the asset quantity corresponding to the digital assets transferred by the transferor; The abnormal signature detection is performed on the asset transaction according to the number of times the asset transaction is executed in the second historical time period and the limited number of executions to obtain the detection result, including: When the number of times the asset transaction is executed in the second historical time period is less than the limit execution number, querying the position level of the transferor in the institution from the sub-blockchain according to the object attribute information of the transferor; Determine the limit on the amount of assets that the transferor can transfer out at one time according to the job level; When the asset quantity corresponding to the digital assets transferred by the transferor is greater than the restricted asset quantity, it is determined that an abnormal signature exists in the asset transaction, and a detection result indicating that an abnormal signature exists in the asset transaction is generated.
8. The method according to claim 1, characterized in that The method further comprises: Determining the impact of the abnormal signature of the asset transaction on the institution based on the transaction attribute information; According to the influence, updating the credit of the signature cooperation device in the signature cooperation device cluster, and obtaining the updated credit of the signature cooperation device in the signature cooperation device cluster; According to the updated credit, a signature cooperation device participating in the next signing is selected from the signature cooperation device cluster.
9. The method according to claim 8, characterized in that The updating of the credibility of the signature cooperation device in the signature cooperation device cluster according to the influence to obtain the updated credibility of the signature cooperation device in the signature cooperation device cluster includes: Determine, according to the credit of the signature cooperation device in the signature cooperation device cluster, a candidate signature cooperation device selected to participate in signing when signing the asset transaction; the candidate signature cooperation device includes the target signature cooperation device; According to the influence, the credibility of the target signature cooperation device is reduced to obtain an updated credibility of the target signature cooperation device; According to the influence, the credit of the remaining signature cooperation devices is increased to obtain the updated credit of the remaining signature cooperation devices; the remaining signature cooperation devices are the devices among the candidate signature cooperation devices except the target signature cooperation device.
10. The method according to claim 8, characterized in that The method further comprises: When the updated credit of the target signature cooperation device is less than the credit threshold, removing the target signature cooperation device from the signature cooperation device cluster; Counting the number of devices in the signature cooperation device cluster, and updating the restricted signature number of the organization according to the number of devices to obtain an updated restricted signature number; The number of devices and the number of update restriction signatures are sent to the signature collaboration device in the signature collaboration device cluster; the signature collaboration device in the signature collaboration device cluster is used to delete its corresponding private key shard, and generate an updated private key shard based on the number of devices and the number of update restriction signatures.
11. The method according to claim 1, characterized in that: The obtaining of transaction attribute information of executed asset transactions from the blockchain in the blockchain network includes: receiving an audit request for asset transactions of the institution; the audit request carries the institution attribute information of the institution; According to the institution attribute information carried in the audit request, the transaction attribute information of the executed asset transactions belonging to the institution is obtained from the blockchain in the blockchain network.
12. A blockchain data processing device, characterized in that: include: A first acquisition module is used to obtain transaction attribute information of executed asset transactions from a blockchain in a blockchain network; the transaction attribute information is recorded on the blockchain when N asset transaction signatures are verified by a node device in the blockchain network based on a public key corresponding to the asset transaction, where N is a positive integer greater than or equal to K, K is the number of restricted signatures of the institution corresponding to the asset transaction, and the N asset transaction signatures are obtained by signing the asset transaction by a signature collaboration device in a signature collaboration device cluster of the institution using its corresponding private key shard, and the number of devices in the signature collaboration device cluster is greater than or equal to N; A detection module, used to perform abnormal signature detection on the asset transaction according to the transaction attribute information to obtain a detection result; A second acquisition module is used to acquire historical log data of the signature collaboration device in the signature collaboration device cluster from the sub-blockchain of the sub-blockchain network when the detection result indicates that there is an abnormal signature in the asset transaction; A determination module is used to determine, based on the historical log data, a target signature cooperation device that performs abnormal signing on the asset transaction from the signature cooperation device cluster.
13. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 11 are implemented.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.
15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.