Authorization method and device based on block chain, computer and readable storage medium

By implementing centralized management of child blockchain addresses by parent blockchain addresses in the blockchain network, the problem of users needing to frequently switch private keys and addresses is solved, reducing resource waste and optimizing the operation experience.

CN120034343APending Publication Date: 2025-05-23TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202311585477.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-23
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the blockchain network, users need to frequently switch different private keys and addresses to operate data and assets of different accounts, resulting in complex asset transaction operations and waste of resources.

Method used

Through blockchain address collection, the parent blockchain address can directly manage the child blockchain address. In the later stage, only the private key of the parent blockchain address is maintained to operate the child blockchain address. Specific methods include obtaining the parent blockchain address and its child address, private key signature and permission management data on the chain processing.

Benefits of technology

The centralized management of multiple sub-blockchain addresses by the parent blockchain address is realized, reducing resource waste and optimizing the operation experience. Even if the private key of the sub-blockchain address is lost, it can be managed through the parent blockchain address.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034343A_ABST
    Figure CN120034343A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an authorization method and device based on a block chain, a computer and a readable storage medium, and relates to a data transmission technology in the field of artificial intelligence, the method can be applied to the field of maps, and the method comprises the following steps: obtaining a first parent block chain address and M first sub-block chain addresses corresponding to the first parent block chain address; obtaining first operation permissions corresponding to the M first sub-block chain addresses, and authorizing the M first operation permissions to the first parent block chain address; signing a first operation authority corresponding to the first sub-block chain address by adopting a sub-address private key of the first sub-block chain address to obtain M authority authorization signatures, and generating first authority management data according to the first operation authority and the authority authorization signatures corresponding to the M first sub-block chain addresses and the first parent block chain address, and performing uplink processing on the first authority management data. By adopting the method and the device, the transaction operation is optimized, and the resource waste is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a blockchain-based authorization method, device, computer, and readable storage medium. Background Art

[0002] When users store or trade data through the blockchain network, the security of the data is guaranteed by the openness and immutability of the blockchain network. With the development of the blockchain network, as more and more data exists on the blockchain network, users want to ensure the security of the data while also wanting to protect the privacy of some data. Therefore, data authority management has become an important part of the blockchain network.

[0003] Users need to switch between different private keys and addresses of the resource client in order to have the authority to operate the data and assets in different accounts separately, but this complicates asset trading operations and causes waste of resources. Summary of the invention

[0004] The embodiments of the present application provide a blockchain-based authorization method, device, computer and readable storage medium. Through blockchain address aggregation, child blockchain addresses can be directly managed through parent blockchain addresses. In the later stage, only the private key of the parent blockchain address needs to be maintained to operate the child blockchain address.

[0005] On the one hand, an embodiment of the present application provides an authorization method based on blockchain, the method comprising:

[0006] Get the first parent blockchain address and the M first child blockchain addresses corresponding to the first parent blockchain address; M is a positive integer;

[0007] Obtain the first operation permissions corresponding to the M first child blockchain addresses respectively, and authorize the M first operation permissions to the first parent blockchain address;

[0008] The sub-address private key of each first sub-blockchain address is used to sign the first operation permission corresponding to the first sub-blockchain address, and the permission authorization signatures corresponding to the M first operation permissions are obtained. The first permission management data is generated according to the first operation permissions and the permission authorization signatures corresponding to the M first sub-blockchain addresses, and the first parent blockchain address, and the first permission management data is processed on the chain.

[0009] On the one hand, an embodiment of the present application provides an authorization device based on blockchain, the device comprising:

[0010] A data acquisition module, used to acquire the first parent blockchain address and M first child blockchain addresses corresponding to the first parent blockchain address; M is a positive integer;

[0011] An authorization module, used to obtain the first operation permissions corresponding to the M first child blockchain addresses respectively, and authorize the M first operation permissions to the first parent blockchain address;

[0012] The on-chain processing module is used to use the sub-address private key of each first sub-blockchain address to sign the first operation permission corresponding to the first sub-blockchain address, obtain the permission authorization signatures corresponding to the M first operation permissions, generate the first permission management data according to the first operation permissions and permission authorization signatures corresponding to the M first sub-blockchain addresses, and the first parent blockchain address, and perform on-chain processing on the first permission management data.

[0013] The data acquisition module includes:

[0014] A hash processing unit, used to obtain M first sub-blockchain addresses, and perform hash processing on the M first sub-blockchain addresses respectively to obtain address hashes corresponding to the M first sub-blockchain addresses respectively;

[0015] The parent address generation unit is used to combine the M address hashes to obtain a combined private key, generate a public key for the combined private key, obtain a combined public key corresponding to the combined private key, and generate a first parent blockchain address based on the combined public key.

[0016] The data acquisition module includes:

[0017] A hash processing unit, used to obtain the first parent blockchain address, determine the first parent blockchain address as a root seed, and perform hash processing on the root seed to obtain a seed hash value;

[0018] A private key generation unit, used to obtain a master private key and a master chain code from a seed hash value, generate M index numbers, generate M random data according to the master chain code, and derive M sub-private keys based on the master private key, the M index numbers and the M random data;

[0019] The sub-address determination unit is used to generate public keys for the M sub-private keys, obtain sub-public keys corresponding to the M sub-private keys, and determine M first sub-blockchain addresses based on the M sub-public keys.

[0020] Among them, it also includes:

[0021] A first encryption module is used to obtain transaction data, generate a symmetric key for the transaction data, encrypt the transaction data using the symmetric key to obtain first encrypted data, and upload the first encrypted data to the blockchain;

[0022] An information acquisition module, used to acquire a decryption method and data authorization information for the first encrypted data;

[0023] An authority verification module, configured to, when receiving an access request from a target blockchain address to the first encrypted data, perform authority verification on the target blockchain address based on the data authorization information;

[0024] A second encryption module is used to encrypt the decryption method and the symmetric key using the first public key of the target blockchain address to obtain second encrypted data if the target blockchain address authority verification is passed;

[0025] The data sending module sends the second encrypted data to the target blockchain address, so that the target blockchain address decrypts the second encrypted data through the first private key to obtain a decryption method and a symmetric key, and uses the decryption method and the symmetric key to decrypt the first encrypted data to obtain transaction data; the first private key is the private key of the target blockchain address.

[0026] Among them, the permission verification module includes:

[0027] A first verification unit, configured to determine that the target blockchain address is authenticated if the data authorization information includes the target blockchain address;

[0028] The second verification unit is used to search for the second permission management data corresponding to the target blockchain address if the target blockchain address is not included in the data authorization information; if the second permission management data is found and the second sub-blockchain address of the target blockchain address exists in the second permission management data, detect the second sub-blockchain address based on the second permission management data; if the second permission management data includes the second sub-blockchain address, determine that the target blockchain address permission verification is passed.

[0029] Among them, it also includes:

[0030] A permission splitting module is used to obtain the second operation permission of the first parent blockchain address, split the second operation permission to obtain sub-operation permissions, and authorize the sub-operation permissions to M first child blockchain addresses;

[0031] The permission distribution module is used to use the parent address private key of the first parent blockchain address to sign the sub-operation permissions corresponding to the M first child blockchain addresses, generate permission distribution signatures, generate permission distribution data according to the sub-operation permissions and permission distribution signatures corresponding to the M first child blockchain addresses, and upload the permission distribution data to the chain.

[0032] Among them, it also includes:

[0033] The first acquisition module is used to obtain the sub-operation permission corresponding to the i-th first child blockchain address when receiving the transfer operation of the digital asset corresponding to the first parent blockchain address; the sub-operation permission corresponding to the i-th first child blockchain address includes the operation type, operation period and operation data volume; i is a positive integer less than or equal to M;

[0034] The second acquisition module is used to obtain the amount of transferred asset data of the i-th first sub-blockchain address within the operation cycle and the amount of data to be transferred requested by the transfer operation if the operation type is an asset transfer operation type;

[0035] The asset transfer module is used to obtain the assets to be transferred corresponding to the amount of data to be transferred from the digital assets of the first parent blockchain address if the sum of the amount of transferred asset data and the amount of asset data to be transferred is less than or equal to the amount of operation data, and transfer the assets to be transferred to the target address; the target address refers to the destination requested by the transfer operation of the i-th first child blockchain address.

[0036] On the one hand, an embodiment of the present application provides a computer device, including a processor, a memory, and an input and output interface;

[0037] The processor is connected to the memory and the input / output interface respectively, wherein the input / output interface is used to receive and output data, the memory is used to store a computer program, and the processor is used to call the computer program so that a computer device including the processor executes the method in one aspect of an embodiment of the present application.

[0038] On the one hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program, and the computer program is suitable for being loaded and executed by a processor so that a computer device having the processor executes the method in one aspect of the embodiment of the present application.

[0039] In one aspect, an embodiment of the present application provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the method provided in various optional ways in one aspect of the embodiment of the present application. In other words, when the computer instruction is executed by the processor, the method provided in various optional ways in one aspect of the embodiment of the present application is implemented.

[0040] The implementation of the embodiments of the present application will have the following beneficial effects: by maintaining the parent and child blockchain addresses, the operation permissions of the child blockchain addresses are aggregated to the parent blockchain address, and the parent blockchain address can centrally manage multiple child blockchain addresses. Even if the private key of the child blockchain address is lost, the parent blockchain address can be logged in through the private key of the parent blockchain address to manage the child blockchain address. In the later stage, only the private key of the parent blockchain address needs to be maintained, which reduces resource waste and optimizes the operation experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0042] Figure 1 This is a network interaction architecture diagram of a blockchain-based authorization method provided in an embodiment of the present application;

[0043] Figure 2 This is a schematic diagram of a scenario of a blockchain-based authorization method provided in an embodiment of the present application;

[0044] Figure 3 This is a flowchart of a blockchain-based authorization method provided in an embodiment of the present application. Figure 1 ;

[0045] Figure 4 This is a flowchart of a blockchain-based authorization method provided in an embodiment of the present application. Figure 2 ;

[0046] Figure 5 This is a flowchart of a blockchain-based authorization method provided in an embodiment of the present application. Figure 3 ;

[0047] Figure 6 It is a schematic diagram of a device provided in an embodiment of the present application;

[0048] Figure 7 It is a structural diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0049] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0050] Among them, if it is necessary to collect object (such as object, etc.) data in this application, a prompt interface or pop-up window will be displayed before and during the collection. The prompt interface or pop-up window is used to prompt the object that certain data is currently being collected. Only after the object issues a confirmation operation on the prompt interface or pop-up window, the relevant steps of data acquisition will be started, otherwise it will end. Moreover, the acquired object data will be used in reasonable and legal scenarios or purposes. Optionally, in some scenarios where the object data needs to be used but the object authorization is not obtained, you can also request authorization from the object, and use the object data when the authorization is passed.

[0051] Blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm. Blockchain is essentially a decentralized database, a string of data blocks generated by cryptographic methods. Each data block contains a batch of network transaction information, which is used to verify the validity of its information (anti-counterfeiting) and generate the next block. Blockchain can include the underlying blockchain platform, platform product service layer, and application service layer. Blockchain technology is a distributed infrastructure and computing method that uses block chain data structures to verify and store data, uses distributed node consensus algorithms to generate and update data, uses cryptography to ensure the security of data transmission and access, and uses smart contracts composed of automated script codes to program and operate data.

[0052] For ease of understanding, the following will explain blockchain and its related concepts:

[0053] 1. Blockchain: In a narrow sense, blockchain is a chain data structure with blocks as the basic unit. Digital summaries are used in blocks to verify previously acquired transactions, which is suitable for the needs of tamper-proof and scalability in distributed accounting scenarios. In a broad sense, blockchain also refers to the distributed accounting technology implemented by the blockchain structure, including distributed consensus, privacy and security protection, peer-to-peer communication technology, network protocols, smart contracts, etc.

[0054] The goal of blockchain is to realize a distributed data record book, which only allows additions but not deletions. The basic structure of the underlying ledger is a linear linked list. The linked list is composed of "blocks" connected in series, and the hash value of the previous block is recorded in the subsequent block. Whether each block (and the transactions in the block) is legal can be quickly verified by calculating the hash value. If a node in the network proposes to add a new block, it must reach a consensus on the block through the consensus mechanism.

[0055] 2. Block: It is a data packet that carries transaction data on the blockchain network. It is a data structure marked with a timestamp and the hash value corresponding to the previous block. The block is verified and confirmed by the consensus mechanism of the network. The block includes a block header and a block body. The block header can record the meta information of the current block, including the current version number, the hash value corresponding to the previous block, the timestamp, the random number, the hash value of the Merkle Root, and other data. The block body can record the detailed data generated within a period of time, including all transaction records or other information generated during the block creation process that have been verified by the current block, which can be understood as a form of account book. In addition, the detailed data of the block body can include the unique Merkle Root generated through the hash process of the Merkle Tree and recorded in the block header.

[0056] The predecessor block, also known as the parent block, is sorted in time by recording the hash value corresponding to the block and the hash value corresponding to the parent block in the block header.

[0057] 3. Hash value: Also known as information characteristic value or characteristic value, the hash value is generated by converting input data of any length into a password and performing a fixed output through a hash algorithm. The original input data cannot be retrieved by decrypting the hash value. It is a one-way encryption function. In the blockchain, each block (except the initial block) contains the hash value of the previous block. The hash value is the potential core foundation and the most important aspect of blockchain technology. It retains the authenticity of the recorded and viewed data, as well as the integrity of the blockchain as a whole.

[0058] 4. Smart Contract: The concept of smart contract has three elements: commitment, agreement, and digital form. Therefore, it can expand the application scope of blockchain to all aspects of financial industry transactions, payments, settlements, and clearing. Smart contract means that when a pre-programmed condition is triggered, the corresponding contract terms are immediately executed. Its working principle is similar to the if-then statement of a computer program.

[0059] 5. Digital Signature: (also known as public key digital signature) is a digital string that can only be generated by the sender of the information and cannot be forged by others. This digital string is also an effective proof of the authenticity of the information sent by the sender. It is a method for identifying digital information similar to an ordinary physical signature written on paper, but it is implemented using technology in the field of public key encryption. A set of digital signatures usually defines two complementary operations, one for signing and the other for verification. Digital signature is the application of asymmetric key encryption technology and digital summary technology.

[0060] 6. Artificial Intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science that attempts to understand the essence of intelligence and produce a new intelligent machine that can respond in a similar way to human intelligence. Artificial intelligence is to study the design principles and implementation methods of various intelligent machines so that the machines have the functions of perception, reasoning and decision-making. For example, in this application, artificial intelligence technology can be used to realize the automatic detection of the relevant information of the first operation authority.

[0061] Artificial intelligence technology is a comprehensive discipline that covers a wide range of fields, including both hardware-level and software-level technologies. Basic artificial intelligence technologies generally include sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, pre-trained model technology, operation / interaction systems, mechatronics and other technologies. Among them, the pre-trained model is also called a large model or a basic model. After fine-tuning, it can be widely used in downstream tasks in various major directions of artificial intelligence. Artificial intelligence software technology mainly includes computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0062] The underlying blockchain platform can include object management, basic services, smart contracts, and operational detection processing modules. Among them, the object management module is responsible for the identity information management of all blockchain participants, including maintaining public and private key generation (account management), key management, and the maintenance of the correspondence between the user's real identity and the blockchain address (authority management), etc., and, under authorization, supervises and audits the transactions of certain real identities and provides risk control rule configuration (risk control audit); the basic service module is deployed on all blockchain node devices to verify the validity of business requests, and records valid requests to storage after consensus is reached. For a new business request, the basic service first performs interface adaptation analysis and authentication processing (interface adaptation), and then encrypts the business information through the consensus algorithm (consensus management). The smart contract module is responsible for the registration and issuance of contracts, as well as contract triggering and contract execution. Developers can define the contract logic in a programming language and publish it to the blockchain (contract registration). According to the logic of the contract terms, the key or other events are called to trigger the execution and complete the contract logic. It also provides the function of contract upgrade and cancellation. The operation detection module is mainly responsible for the deployment, configuration modification, contract setting, cloud adaptation and real-time status visualization output of the product during the product release process, such as alarm, network status detection, node equipment health status detection, etc.

[0063] The platform product service layer provides the basic capabilities and implementation framework of typical applications. Developers can superimpose business features based on these basic capabilities to complete the blockchain implementation of business logic. The application service layer provides application services based on blockchain solutions for business participants to use.

[0064] In the examples of this application, see Figure 1 , Figure 1 This is a network interaction architecture diagram of a blockchain-based authorization method provided by an embodiment of the present application. The embodiment of the present application can be implemented by a computer device, which includes but is not limited to a terminal device or a server. In other words, the computer device can be a server or a terminal device, or a system composed of a server and a terminal device. The blockchain network 101 shown in the network architecture diagram can include but is not limited to a blockchain network corresponding to a consortium chain. The blockchain network 101 can include multiple blockchain nodes, such as Figure 1The blockchain nodes 101a, 101b, and 101c shown in the figure can exchange data with each other. Each blockchain node can receive data sent from the outside world when performing normal work, and perform block chain processing based on the received data, and can also send data to the outside world. In order to ensure data intercommunication between each blockchain node, there can be a data connection between each blockchain node, for example, there is a data connection between blockchain node 101a and blockchain node 101b, there is a data connection between blockchain node 101a and blockchain node 101c, and there is a data connection between blockchain node 101b and blockchain node 101c. When any blockchain node in the blockchain network receives input information, other blockchain nodes in the blockchain network obtain the input information according to the consensus algorithm, and store the input information as data in the shared data, so that the data stored on all blockchain nodes in the blockchain network are consistent. Among them, each blockchain node can have one or more blockchain addresses. Optionally, the multiple blockchain addresses may include multiple sub-blockchain addresses (such as sub-blockchain address 1021, sub-blockchain address 1022 and sub-blockchain address 1023, etc.), and a parent blockchain address 103, wherein a user can access or manage each sub-blockchain address through the parent blockchain address 103.

[0065] It should be understood that, taking blockchain node 101b as an example, when there are multiple child blockchain addresses (child blockchain address 1021, child blockchain address 1022, and child blockchain address 1023, etc.), each child blockchain address can be processed to finally obtain a parent blockchain address 103. Alternatively, a parent blockchain address can be generated, and the parent blockchain address can be used as a seed to generate one or more child blockchain addresses, such as generating a parent blockchain address 103, and using the parent blockchain address 103 as a seed to generate child blockchain addresses 1021, child blockchain address 1022, and child blockchain address 1023, etc. After obtaining the parent and child blockchain addresses, the operation permissions of all corresponding child blockchain addresses can be obtained, and the child address private key of each child blockchain address can be used to sign the operation permissions corresponding to the child blockchain address and generate permission management data for chain processing, so that the parent blockchain address can collect the operation permissions of all corresponding child blockchain addresses, so that all operations on the child blockchain addresses can be implemented by the parent blockchain address. For example, when the child blockchain address 1021 is subsequently operated through the parent blockchain address 103, the operation permissions of the child blockchain addresses (child blockchain address 1021, child blockchain address 1022 and child blockchain address 1023, etc.) corresponding to the parent blockchain address 103 can be directly detected based on the parent-child relationship of the blockchain address, as well as the authorization status of the child blockchain address 1021 (query the permission management data in the blockchain). If there is a child blockchain address 1021 with operation permissions, and the permissions of the child blockchain address 1021 are aggregated to the parent blockchain address 103, it can be determined that the parent blockchain address 103 has the operation permission and responds to the operation.

[0066] Through the above process, the parent-child relationship between the parent blockchain address and the child blockchain address is maintained, and the operation permissions of the child blockchain address are aggregated to the parent blockchain address, realizing the centralized management of multiple child blockchain addresses by the parent blockchain address. In the later stage, it is only necessary to maintain the private key of the parent blockchain address to manage the child blockchain address and operate on the child blockchain address, which reduces resource waste and optimizes the operation experience.

[0067] For details, see Figure 2 , Figure 2 This is a scenario diagram of a blockchain-based authorization method provided in an embodiment of the present application.

[0068] like Figure 2As shown, the transfer of 10 digital assets (such as ERC20 digital assets, etc.) in the first child blockchain 2022 through the first parent blockchain 203 is taken as an example. Among them, ERC stands for Ethereum Request for Comment, which is a set of business resource issuance protocols based on blockchain networks, defining some technical standards and interfaces. ERC20 digital resources can be digital resources created by trusted proxy contracts and have more functions and application scenarios.

[0069] In an embodiment of the present application, by obtaining the first operation permission 1, the first operation permission 2, and the first operation permission 3 corresponding to the first child blockchain address 2021, the first child blockchain address 2022, and the first child blockchain address 2023 respectively, the above-mentioned first operation permission 1, the first operation permission 2, and the first operation permission 3 are authorized to the first parent blockchain address 203; the sub-address private key of the first child blockchain address is used to sign the first operation permission corresponding to the first child blockchain address, and the permission authorization signatures corresponding to the first operation permissions are obtained, that is, the first operation permission 1 is signed by the sub-address private key 1 to obtain permission authorization signature 1, the first operation permission 2 is signed by the sub-address private key 2 to obtain permission authorization signature 2, and the first operation permission 3 is signed by the sub-address private key 3 to obtain permission authorization signature 3; based on the first operation permission 1, the first operation permission 2, the first operation permission 3 and the permission authorization signature 1, the permission authorization signature 2, the permission authorization signature 3 and the first parent blockchain address, the first permission management data is generated, the first permission management data is processed on the chain, stored in the blockchain node 201b, and broadcast to the blockchain network based on the consensus mechanism. Through the above process, all operations on the first child blockchain address 2021, the first child blockchain address 2022, and the first child blockchain address 2023 can be implemented by the first parent blockchain 203. Later, when the 10 ERC20 digital assets in the first child blockchain address 2022 are transferred through the first parent blockchain address 203, the operation authority of the first child blockchain address 2022 corresponding to the first parent blockchain address 203 can be directly detected based on the first authority management data in the blockchain node 201b, and it can be determined that the operation authority is authorized to the first parent blockchain address 203, then it can be determined that the first parent blockchain address has the authority to transfer the digital assets in the first child blockchain address 2022, and the 10 ERC20 digital assets in the first child blockchain address 2022 can be transferred to the blockchain node 303.

[0070] Since the operation permissions of the first child blockchain address 2021, the first child blockchain address 2022, and the first child blockchain address 2023 are authorized to the first parent blockchain address 203, centralized management of multiple first child blockchain addresses (first child blockchain address 2021, first child blockchain address 2022, and first child blockchain address 2023) by the first parent blockchain address 203 is achieved. Even if the private key of the first child blockchain address 2023 is lost, the assets in the first child blockchain address 2023 can be operated by logging in to the first parent blockchain address through the private key of the first parent blockchain address 203, thereby realizing the transfer of 10 ERC20 digital assets in the first child blockchain address 2023, thereby optimizing the operation experience.

[0071] For further information, see Figure 3 , Figure 3 This is a flowchart of a blockchain-based authorization method provided in an embodiment of the present application. Figure 1 .like Figure 3 As shown, in Figure 3 In the described method embodiment, the first blockchain node may be used as the execution subject for description. The first blockchain node may be any blockchain node in the blockchain network. Specifically, the process includes the following steps:

[0072] Step S103, obtain the first parent blockchain address and M first child blockchain addresses corresponding to the first parent blockchain address; M is a positive integer.

[0073] In an embodiment of the present application, the first blockchain node can obtain the first parent blockchain address and the M first child blockchain addresses corresponding to the first parent blockchain address in the following two ways:

[0074] One is to obtain M first child blockchain addresses, hash the M first child blockchain addresses respectively, and obtain the address hashes corresponding to the M first child blockchain addresses respectively; combine the M address hashes to obtain a combined private key, generate a public key for the combined private key, obtain a combined public key corresponding to the combined private key, and generate the first parent blockchain address based on the combined public key. Among them, in order to ensure the security of the combined private key, the hash algorithm used to hash the M first child blockchain addresses is confidential, that is, only the first blockchain node knows the hash algorithm, and other blockchain nodes cannot obtain the hash algorithm. Therefore, the M first child blockchain addresses can also be hashed to obtain the address hashes corresponding to the M first child blockchain addresses respectively; combine the M address hashes to obtain a hash public key, generate a private key for the hash public key, obtain a hash private key, and determine the first parent blockchain address based on the hash public key.

[0075] The second is to obtain the first parent blockchain address, and the specific process of the M first child blockchain addresses corresponding to the first parent blockchain address can also be: obtain the first parent blockchain address, determine the first parent blockchain address as the root seed, hash the root seed, and obtain the seed hash value; obtain the master private key and the master chain code from the seed hash value, generate M index numbers, generate M random data according to the master chain code, and derive M child private keys based on the master private key, based on the M index numbers and the M random data, that is, one index number and one random data, derive one child private key; generate public keys for the M child private keys to obtain the child public keys corresponding to the M child private keys, and determine M first child blockchain addresses based on the M child public keys, that is, one child public key corresponds to one first child blockchain address.

[0076] Step S102: Obtain the first operation permissions corresponding to the M first child blockchain addresses respectively, and authorize the M first operation permissions to the first parent blockchain address.

[0077] In the embodiment of the present application, the first blockchain node detects M first child blockchain addresses, obtains the first operation permissions corresponding to the M first child blockchain addresses, responds to the authorization click operation, associates the first operation permission with the first parent blockchain address, and realizes the authorization of the M first operation permissions to the first parent blockchain address. For example, the first blockchain node displays M first child blockchain addresses and the first parent blockchain address in response to the address viewing operation; it can respond to the authorization operation for the M first child blockchain addresses and the first parent blockchain address, and authorize the first operation permissions corresponding to the M first child blockchain addresses to the first parent blockchain address. Optionally, it can also respond to the selection authorization operation for P first child blockchain addresses among the M first child blockchain addresses, and authorize the first operation permissions corresponding to the P first child blockchain addresses to the first parent blockchain address, where P is a positive integer less than or equal to M. That is, the operation permissions of all first child blockchain addresses under the first parent blockchain address can be authorized to the first parent blockchain address, and the operation permissions of some first child blockchain addresses under the first parent blockchain address can also be authorized to the first parent blockchain address. The following takes the authorization of M first child blockchain addresses as an example for description.

[0078] Step S103: Use the sub-address private key of each first sub-blockchain address to sign the first operation permission corresponding to the first sub-blockchain address, obtain the permission authorization signatures corresponding to the M first operation permissions, generate the first permission management data according to the first operation permissions and permission authorization signatures corresponding to the M first sub-blockchain addresses, and the first parent blockchain address, and perform on-chain processing on the first permission management data.

[0079] In an embodiment of the present application, the parent-child relationship and the authorization relationship between the first parent-child blockchain addresses need to be authorized by signature and stored on the blockchain. Specifically, the first blockchain node calculates the first operation permission corresponding to each first child blockchain address through a hash function to obtain a hash summary, that is, to obtain the hash summary corresponding to the M first child blockchain addresses, and use the sub-address private key of each first child blockchain to sign the corresponding hash summary to generate a digital signature, to obtain the permission authorization signatures corresponding to the M first operation permissions, and to package the first operation permissions and permission authorization signatures corresponding to the M first child blockchain addresses, and the first parent blockchain address to generate the first permission management data, and to process the first permission management data on the chain. If there are P first child blockchain addresses as mentioned above, the first permission management data includes the first parent blockchain address, the first operation permissions and permission authorization signatures corresponding to the P first child blockchain addresses.

[0080] Among them, hash function calculation refers to a one-way operation that maps an input value to a message digest of a fixed length through a hash function. The hash function can map an input value of any length to an output of a fixed length, for example, it can be MD5 (Message Digest Algorithm 5), SHA-256 (Secure Hash Algorithm 256, 256-bit hash algorithm), etc.

[0081] The first authority management data may be as shown in Table 1:

[0082] Table 1

[0083]

[0084] It is understandable that in a blockchain, before a block is put on the chain, the block must be agreed upon by the consensus nodes in the blockchain network, and the block can only be added to the blockchain after the consensus is passed. It is understandable that when blockchain is used in some scenarios of commercial organizations, not all participating nodes in the blockchain (i.e., blockchain nodes in the above blockchain network) have sufficient resources and necessity to become consensus nodes of the blockchain. For example, in Figure 1 In the blockchain network shown, blockchain nodes 101a, 101b, and 101c can be used as consensus nodes in the blockchain network. Consensus nodes in the blockchain network participate in consensus, that is, consensus on blocks (including a batch of transactions), that is, voting on blocks; while non-consensus nodes do not participate in consensus, but will help spread block and voting messages, as well as synchronize status with each other.

[0085] See also Figure 4 , Figure 4This is a flowchart of a blockchain-based authorization method provided in an embodiment of the present application. Figure 2 The blockchain-based authorization method can be executed by a blockchain node, which can be Figure 1 Any blockchain node shown, for example, can be blockchain node 101b. The following will be described by taking the execution of the authorization method by a blockchain node as an example. The following will be described by taking the execution of the authorization method by a resource client as an example. Among them, the blockchain-based authorization method can at least include the following steps S201-S204:

[0086] Step S201, obtain transaction data, generate a symmetric key for the transaction data, use the symmetric key to encrypt the transaction data, obtain first encrypted data, and process the first encrypted data on the chain; obtain a decryption method and data authorization information for the first encrypted data.

[0087] In the embodiment of the present application, the first blockchain node obtains the specific information to be disclosed as transaction data, generates a random number by using a random number generator, or generates a symmetric key for the transaction data by using a password, wherein the password is a password that the user can remember. In order to ensure that the key generated by the password will not be cracked, a random number needs to be added to the password, and the password after adding the random number is hashed. The result of the calculation is used as the symmetric key, and the transaction data is encrypted using the symmetric key to obtain the first encrypted data; wherein, the encryption method uses a symmetric encryption algorithm, and the symmetric encryption algorithm mainly has two forms: block encryption and sequence encryption. Block encryption will first divide the plaintext data into several fixed-length data blocks as the basic encryption unit, and then encrypt these data blocks in turn. Sequence encryption only encrypts one byte or character at a time, and the key used will also change continuously. Common symmetric encryption algorithms include DES (Data Encryption Standard), 3DES (Triple Data Encryption Algorithm), AES (Advanced Encryption Standard), and IDEA (International Data Encryption Algorithm). The following takes the AES (Advanced Encryption Standard) algorithm as an example to illustrate the symmetric encryption process. The first blockchain node splits the plaintext of the transaction data into multiple plaintext blocks (such as plaintext block 0, plaintext block 1, plaintext block 2, plaintext block 3, etc.). The length of the plaintext block can be 128 bits, 192 bits or 256 bits, which is determined by the length of the symmetric key. The above plaintext blocks are encrypted based on the symmetric key through the AES encryptor to obtain ciphertext blocks (such as ciphertext block 0, ciphertext block 1, ciphertext block 2, ciphertext block 3, etc.), and all ciphertext blocks are combined and arranged to obtain the first encrypted data.

[0088] Among them, since the public key and private key of the symmetric key are the same, after one data authorization, the authorized node can obtain the symmetric key. If the symmetric key is continued to be used for data encryption processing, the previously authorized node can directly decrypt and obtain the encrypted data. Therefore, after obtaining the transaction data, the first blockchain node can generate a symmetric key for the transaction data. In other words, for each transaction data that needs to be encrypted and uploaded to the chain, a separate symmetric key is used. For example, the transaction data can be hashed to obtain the transaction hash of the transaction data, and the transaction hash can be converted into a key random number, and the key random number can be used to generate a symmetric key; or, the symmetric key can be directly randomly generated. This improves the security of the data.

[0089] Furthermore, after obtaining the first encrypted data, the first encrypted data needs to be processed on the chain through three stages: pre-chain processing stage, on-chain processing stage and smart contract processing stage; obtain the decryption method corresponding to the algorithm used to encrypt the first encrypted data, and the list of objects authorized for disclosure, and determine the list of objects as data authorization information.

[0090] Among them, the first encrypted data needs to be processed and signed in the pre-chain processing stage. These processes can be done through corresponding tools, such as serialization tools and various elliptic curve signature tools; the on-chain processing stage is divided into two parts: transaction broadcast and block consensus. The blockchain node receives the signed first encrypted data and broadcasts the received signed first encrypted data to other nodes for block consensus to keep the blockchain nodes consistent; after the on-chain processing is completed, the signed first encrypted data has been recorded on the blockchain. For pure evidence storage business, writing the signed first encrypted data into the block has completed the business processing. It is only necessary to record the transaction hash of the evidence storage business and query it through the transaction hash when retrieving it. However, most business scenarios require certain logical processing, so they also need to be processed through smart contracts. Smart contract processing includes contract logic processing and modifying the state Merkle tree and other processes.

[0091] Step S202: When a request for access to the first encrypted data from the target blockchain address is received, authority verification is performed on the target blockchain address based on the data authorization information.

[0092] In the embodiment of the present application, when the first blockchain node receives a request from the target blockchain address to access the first encrypted data, it is necessary to query the data authorization information obtained in step S201, and compare whether there is content in the data authorization information that can prove that the target blockchain can access the first encrypted data. If so, it is confirmed that the target blockchain address has been verified, and step S203 is executed. The target blockchain address can be verified through the following two processes. One is that if the data authorization information includes the target blockchain address, it is determined that the target blockchain address has been verified; the other is that if the data authorization information does not include the target blockchain address, the second permission management data corresponding to the target blockchain address is searched. If the second permission management data is found, and the second sub-blockchain address of the target blockchain address exists in the second permission management data, the second sub-blockchain address is detected based on the second permission management data. If the second permission management data includes the second sub-blockchain address, it is determined that the target blockchain address has been verified, and step S203 is executed. If the target blockchain address is not included in the data authorization information, and the second permission management data does not include any second sub-blockchain address under the target blockchain address, or the target blockchain address is not included in the data authorization information, and the target blockchain address does not have a sub-blockchain address in the second permission management data corresponding to it (i.e., the target blockchain address), it is determined that the permission verification of the target blockchain address has failed, and a data acquisition failure message can be fed back to the target blockchain address.

[0093] Step S203: If the authority verification of the target blockchain address is passed, the first public key of the target blockchain address is used to encrypt the decryption method and the symmetric key to obtain the second encrypted data.

[0094] In an embodiment of the present application, after the first blockchain node determines that the target blockchain address has passed the authority verification, it obtains the first public key of the target blockchain address, and uses an asymmetric encryption algorithm to encrypt the symmetric key and decryption method obtained in step S201 and step S202 based on the first public key to obtain the second encrypted data. Among them, the asymmetric encryption algorithm is different from the symmetric encryption algorithm. In the symmetric encryption algorithm, the encryption and decryption processes use the same key. The encryption and decryption processes of the asymmetric encryption algorithm use a pair of different keys (public key and private key). At this time, the first public key of the target blockchain address is used to encrypt the symmetric key and decryption method, and the first private key of the target blockchain address is required to decrypt. For the public key, it can be disclosed to others in a non-confidential manner, while the private key is kept confidential by the decryption party and is not disclosed to the public. Since the asymmetric encryption method allows the communicating parties to establish secure communication without exchanging keys in advance, it is widely used in identity authentication, digital signatures, and other information exchange fields.

[0095] Step S204, sending the second encrypted data to the target blockchain address, so that the target blockchain address decrypts the second encrypted data through the first private key, obtains a decryption method and a symmetric key, and uses the decryption method and the symmetric key to decrypt the first encrypted data to obtain transaction data; the first private key is the private key of the target blockchain address.

[0096] In an embodiment of the present application, after the first blockchain node sends the above-mentioned second encrypted data to the target blockchain address, the target blockchain address can use the private key of the target blockchain address, that is, the first private key, to decrypt the second encrypted data, and obtain a decryption method and a symmetric key that can decrypt the first encrypted data. Based on the decryption method and the symmetric key, the first encrypted data on the blockchain is decrypted to obtain the transaction data requested to be viewed by the target blockchain address.

[0097] Among them, if the data transaction party uses a hash function to generate a data summary for the transaction data, and then uses a private key to encrypt the data summary to generate a data signature, and attaches the data signature to the transaction data for encryption and chain processing, then the target blockchain address needs to undergo a signature verification process, that is, after decrypting the first encrypted data to obtain the specific content, it is necessary to use the public key of the data transaction party to decrypt the digital signature therein to obtain a data summary, and then compare the transaction data content with the result obtained by using a hash function and the above data summary. If the two are consistent, it can be determined that the transaction data has not been tampered with.

[0098] Through the above process, the transaction data uploaded to the chain by the data transaction party is publicly visible. As long as the blockchain node is in the specified blockchain address whitelist (data authorization information), it can use its own public key to encrypt the decryption method and symmetric key to obtain the corresponding encrypted data, and decrypt the encrypted data based on its own private key to obtain the decryption method and symmetric key, and then decrypt based on the decryption method and symmetric key to obtain and view the above transaction data, without the need to use the public key of the authorized object of the transaction data to encrypt the transaction data and upload it to the chain, which increases the diversity of data authorization methods and makes data authorization disclosure operations more flexible.

[0099] See also Figure 5 , Figure 5 This is a flowchart of a blockchain-based authorization method provided in an embodiment of the present application. Figure 3 The blockchain-based authorization method can be executed by a blockchain node, which can be Figure 1Any blockchain node shown, for example, can be blockchain node 101b. The following will be described by taking the execution of the authorization method by a blockchain node as an example. The following will be described by taking the execution of the authorization method by a resource client as an example. Among them, the blockchain-based authorization method can at least include the following steps S301-S305:

[0100] Step S301: obtain the second operation permission of the first parent blockchain address, split the second operation permission to obtain sub-operation permissions, and authorize the sub-operation permissions to M first child blockchain addresses.

[0101] In the embodiment of the present application, it is necessary to query all operation permissions of the first parent blockchain address, obtain the second operation permission, split the second operation permission, and obtain sub-operation permissions, such as N sub-operation permissions, where N is a positive integer. The first blockchain node associates the sub-operation permission with the M first sub-blockchain addresses, and grants sub-operation permissions to the M first sub-blockchain addresses, where the sub-operation permission can be one or more of the business operation permissions such as asset transfer, asset freezing and asset statistics, that is, the sub-operation permission obtained by splitting the second operation permission can be distributed to the M first sub-blockchain addresses, where one first sub-blockchain address can obtain one or more sub-operation permissions, and different first sub-blockchain addresses may have the same sub-operation permission, or may not have the same sub-operation permission. There may also be a situation where some first sub-blockchain addresses do not obtain sub-operation permissions, which is not limited here. For example, the second operation permission is divided into sub-operation permission 1, sub-operation permission 2, and sub-operation permission 3. There are two first sub-blockchain addresses (first sub-blockchain address 1 and first sub-blockchain address 2). After the sub-operation permission is granted to the first sub-blockchain address, the sub-operation permission of the first sub-blockchain address can be: the first sub-blockchain address 1 has sub-operation permission 1 and sub-operation permission 2, and the first sub-blockchain address 2 has sub-operation permission 2 and sub-operation permission 3; the sub-operation permission of the first sub-blockchain address can also be: the first sub-blockchain address 1 has sub-operation permission 1, sub-operation permission 2, and sub-operation permission 3, and the first sub-blockchain address 2 has sub-operation permission 2, etc. The other sub-operation permission granting situations are not specifically exemplified here. If the sub-operation permission 1 is the asset transfer permission, the first parent blockchain address grants the sub-operation permission 1 to the jth first child blockchain address, and the jth first child blockchain address can operate the digital assets in the first parent blockchain address to transfer to any account; if the sub-operation permission 1 is asset transfer and the sub-operation permission 2 is asset freezing, the first parent blockchain address grants the sub-operation permission 1 and the sub-operation permission 2 to the kth first child blockchain address, and the kth first child blockchain address can operate the digital assets in the first parent blockchain address to transfer to any account, and can also freeze the digital assets in the first parent blockchain address. j is a positive integer less than or equal to M, and k is a positive integer less than or equal to M.

[0102] Step S302: Use the parent address private key of the first parent blockchain address to sign the sub-operation permissions corresponding to the M first child blockchain addresses, generate a permission distribution signature, generate permission distribution data according to the sub-operation permissions and permission distribution signatures corresponding to the M first child blockchain addresses, and upload the permission distribution data to the chain.

[0103] In the embodiment of the present application, after the first parent blockchain address authorizes the sub-operation authority to the M first child blockchain addresses, the authorization relationship is only recognized by the resource client, and the authorization relationship is not recognized by the other blockchain nodes. The sub-operation authority corresponding to the M first child blockchain addresses is hashed to obtain the authorization information summary, and the authorization information summary is signed with the parent address private key of the first parent blockchain address to obtain the authority distribution signature. According to the sub-operation authority and authority distribution signature corresponding to the M first child blockchain addresses, authority distribution data is generated, and the authority distribution data is processed on the chain. The on-chain processing step can refer to the specific process in step S201.

[0104] Step S303: When the i-th first child blockchain address is received and the digital asset transfer operation corresponding to the first parent blockchain address is performed, the sub-operation permission corresponding to the i-th first child blockchain address is obtained; the sub-operation permission corresponding to the i-th first child blockchain address includes the operation type, operation period and operation data volume; i is a positive integer less than or equal to M.

[0105] In the embodiment of the present application, when the i-th first child blockchain address is received, for the transfer operation of the digital asset corresponding to the first parent blockchain address, the permission distribution signature in the above-mentioned permission distribution data can be decrypted using the parent address public key of the first parent blockchain address to obtain the permission distribution summary, and then the sub-operation permissions corresponding to the M first child blockchain addresses are verified based on the permission distribution summary to determine the sub-operation permission corresponding to the i-th first child blockchain address. Optionally, the sub-operation permission corresponding to the i-th first child blockchain address may include but is not limited to the operation type, operation cycle, and operation data volume.

[0106] Among them, the sub-operation permissions can be shown in Table 2:

[0107] Table 2

[0108] Sub-operation permissions Operation Type Operation cycle (days) Operation data volume Sub-operation permission 1 Asset transfer 100 1000 Sub-operation permission 2 Asset Freeze 90 6000 … … … … Sub-operation permission n Asset Statistics 30 9000

[0109] Step S304: If the operation type is an asset transfer operation type, the amount of asset data transferred within the operation cycle of the i-th first sub-blockchain address and the amount of data to be transferred requested by the transfer operation are obtained.

[0110] In the embodiment of the present application, the sub-operation authority includes the operation type, the operation cycle and the operation data volume. If the operation type is an asset transfer operation type, the amount of asset data transferred within the operation cycle of the i-th first child blockchain address and the amount of data to be transferred requested by the transfer operation are obtained. The amount of data transferred and the amount of data to be transferred are used to determine whether the i-th first child blockchain address can successfully transfer the digital assets in the first parent blockchain address; the amount of data to be transferred is the number of digital assets that need to be transferred when the i-th first child blockchain address performs a transfer operation on the digital assets corresponding to the first parent blockchain address. The operation cycle is the time limit for the first parent blockchain address to authorize the i-th first child blockchain address to operate the digital assets in the first parent blockchain address based on the sub-operation authority, that is, the i-th first child blockchain address can control the digital assets in the first parent blockchain address within the operation cycle, but cannot control them outside the operation cycle.

[0111] Step S305: If the sum of the amount of transferred asset data and the amount of to-be-transferred asset data is less than or equal to the amount of operation data, the to-be-transferred asset corresponding to the amount of to-be-transferred data is obtained from the digital assets of the first parent blockchain address, and the to-be-transferred asset is transferred to the target address; the target address refers to the destination requested by the transfer operation of the i-th first child blockchain address.

[0112] In an embodiment of the present application, if the sum of the amount of transferred asset data and the amount of to-be-transferred asset data is less than or equal to the amount of operation data, it can be determined that the i-th first child blockchain address can successfully initiate an operation to transfer the digital assets in the first parent blockchain address, obtain the to-be-transferred assets corresponding to the amount of to-be-transferred data from the digital assets of the first parent blockchain address, and send the to-be-transferred assets to the target address, which refers to the destination requested by the transfer operation of the i-th first child blockchain address. The amount of operation data is the number of operable digital assets authorized by the first parent blockchain address to the i-th first child blockchain address; the target address can be the remaining first child blockchain addresses corresponding to the first parent blockchain address, or it can be any blockchain address that is not related to the first parent blockchain. For example, the first parent blockchain address can be located at Figure 1 The blockchain node 101b shown has a target address located at Figure 1 In the blockchain node 101c shown.

[0113] For example, when the amount of transferred asset data is 800 and the amount of operation data is 1000, if the amount of asset data to be transferred is 500, the i-th first child blockchain address cannot transfer the digital assets corresponding to the amount of asset data to be transferred of 500. If the amount of asset data to be transferred is 100, then an operation can be initiated to obtain the asset to be transferred corresponding to the amount of data to be transferred of 100 from the digital assets of the first parent blockchain address, and transfer the asset to be transferred to the target address, and successfully transfer the asset to be transferred to the target address.

[0114] For further information, see Figure 6 , Figure 6 Schematic diagram of a device provided in an embodiment of the present application. The device may be a computer program (including program code, etc.) running in a computer device, for example, the device may be an application software; the device may be used to execute the corresponding steps in the method provided in an embodiment of the present application. Figure 6 As shown, the device 600 can be used to implement Figure 3 , Figure 4 , Figure 5 The method in the corresponding embodiment, specifically, the device may include: a data acquisition module 11, an authorization module 12, an on-chain processing module 13, a first encryption module 14, an information acquisition module 15, an authority verification module 16, a second encryption module 17, a data sending module 18, an authority splitting module 19, an authority distribution module 20, a first acquisition module 21, a second acquisition module 22 and an asset transfer module 23.

[0115] The data acquisition module 11 is used to obtain the first parent blockchain address and M first child blockchain addresses corresponding to the first parent blockchain address; M is a positive integer.

[0116] The data acquisition module 11 includes:

[0117] The hash processing unit 111 is used to obtain M first sub-blockchain addresses, and perform hash processing on the M first sub-blockchain addresses respectively to obtain address hashes corresponding to the M first sub-blockchain addresses respectively.

[0118] The parent address generation unit 112 is used to combine the M address hashes to obtain a combined private key, generate a public key for the combined private key, obtain a combined public key corresponding to the combined private key, and generate a first parent blockchain address based on the combined public key.

[0119] The data acquisition module 11 includes:

[0120] A hash processing unit 113 is used to obtain the first parent blockchain address, determine the first parent blockchain address as a root seed, and perform hash processing on the root seed to obtain a seed hash value;

[0121] The private key generation unit 114 is used to obtain a master private key and a master chain code from the seed hash value, generate M index numbers, generate M random data according to the master chain code, and derive M sub-private keys based on the master private key, the M index numbers and the M random data;

[0122] The sub-address determining unit 115 is used to generate public keys for the M sub-private keys, obtain sub-public keys corresponding to the M sub-private keys, and determine M first sub-blockchain addresses based on the M sub-public keys.

[0123] The authorization module 12 is used to obtain the first operation permissions corresponding to the M first child blockchain addresses respectively, and authorize the M first operation permissions to the first parent blockchain address.

[0124] The on-chain processing module 13 is used to use the sub-address private key of each first sub-blockchain address to sign the first operation permission corresponding to the first sub-blockchain address, obtain the permission authorization signatures corresponding to the M first operation permissions, generate the first permission management data according to the first operation permissions and permission authorization signatures corresponding to the M first sub-blockchain addresses, and the first parent blockchain address, and perform on-chain processing on the first permission management data.

[0125] The first encryption module 14 is used to obtain transaction data, generate a symmetric key for the transaction data, encrypt the transaction data using the symmetric key to obtain first encrypted data, and upload the first encrypted data to the chain.

[0126] The information acquisition module 15 is used to obtain a decryption method and data authorization information for the first encrypted data.

[0127] The specific functions of the first encryption module 14 and the information acquisition module 15 can be found in the above Figure 4 The specific description of step S201 of the corresponding embodiment is not repeated here.

[0128] The authority verification module 16 is used to verify the authority of the target blockchain address based on the data authorization information when receiving an access request from the target blockchain address to the first encrypted data.

[0129] The authority verification module 16 includes:

[0130] The first verification unit 161 is used to determine whether the target blockchain address is authenticated if the data authorization information includes the target blockchain address.

[0131] The second verification unit 162 is used to search for the second permission management data corresponding to the target blockchain address if the target blockchain address is not included in the data authorization information; if the second permission management data is found and the second sub-blockchain address of the target blockchain address exists in the second permission management data, detect the second sub-blockchain address based on the second permission management data; if the second permission management data includes the second sub-blockchain address, determine that the target blockchain address permission verification is passed.

[0132] The second encryption module 17 is used to encrypt the decryption method and the symmetric key using the first public key of the target blockchain address to obtain the second encrypted data if the target blockchain address authority verification is passed.

[0133] The data sending module 18 sends the second encrypted data to the target blockchain address, so that the target blockchain address decrypts the second encrypted data through the first private key, obtains the decryption method and the symmetric key, and uses the decryption method and the symmetric key to decrypt the first encrypted data to obtain the transaction data; the first private key is the private key of the target blockchain address. The specific functions of the data sending module 18 can be found in the above Figure 4 The specific description of step S204 of the corresponding embodiment is not repeated here.

[0134] The authority splitting module 19 is used to obtain the second operation authority of the first parent blockchain address, split the second operation authority to obtain sub-operation authority, and authorize the sub-operation authority to M first child blockchain addresses. The specific functions of the authority splitting module 19 can be found in the above Figure 5 The specific description of step S301 of the corresponding embodiment is not repeated here.

[0135] The permission distribution module 20 is used to use the parent address private key of the first parent blockchain address to sign the sub-operation permissions corresponding to the M first child blockchain addresses, generate a permission distribution signature, generate permission distribution data according to the sub-operation permissions and permission distribution signatures corresponding to the M first child blockchain addresses, and perform chain processing on the permission distribution data.

[0136] The first acquisition module 21 is used to obtain the sub-operation permission corresponding to the i-th first child blockchain address when receiving the i-th first child blockchain address for the transfer operation of the digital asset corresponding to the first parent blockchain address; the sub-operation permission corresponding to the i-th first child blockchain address includes the operation type, operation period and operation data amount; i is a positive integer less than or equal to M.

[0137] The second acquisition module 22 is used to obtain the amount of transferred asset data of the i-th first sub-blockchain address within the operation cycle and the amount of data to be transferred requested by the transfer operation if the operation type is an asset transfer operation type.

[0138] The asset transfer module 23 is used to obtain the to-be-transferred assets corresponding to the to-be-transferred data volume from the digital assets of the first parent blockchain address if the sum of the transferred asset data volume and the to-be-transferred asset data volume is less than or equal to the operation data volume, and transfer the to-be-transferred assets to the target address; the target address refers to the destination requested by the transfer operation of the i-th first child blockchain address. The specific functions of the asset transfer module 23 can be found in the above Figure 5 The specific description of step S305 of the corresponding embodiment is not repeated here.

[0139] See also Figure 7 , Figure 7 Schematic diagram of the structure of a computer device provided in an embodiment of the present application. Figure 7 As shown, the computer device in the embodiment of the present application may include: one or more processors 701, a network interface 704 and a memory 705. In addition, the above-mentioned computer device 700 may also include: a user interface 703, and at least one communication bus 702. Among them, the communication bus 702 is used to realize the connection and communication between these components. Among them, the user interface 703 may include a display screen (Display), a keyboard (Keyboard), and the optional user interface 703 may also include a standard wired interface and a wireless interface. The network interface 704 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 705 may be a high-speed RAM memory, or it may be a non-volatile memory (non-volatile memory), such as at least one disk storage. The memory 705 may optionally also be at least one storage device located away from the aforementioned processor 701. As Figure 7 As shown, the memory 705 as a computer-readable storage medium may include an operating system, a network communication module, a user interface module, and a device control application. Figure 7 In the computer device 700 shown, the network interface 704 can provide a network communication element; the user interface 703 is mainly used to provide an input interface for the user; and the processor 701 can be used to call the device control application stored in the memory 705.

[0140] The embodiment of the present application provides a computer device, including: a processor, an input / output interface, and a memory, wherein the processor obtains a computer program in the memory and executes the computer program. Figure 3 , Figure 4 and Figure 5The steps of the method shown in are operated to achieve: obtaining the first parent blockchain address and the M first child blockchain addresses corresponding to the first parent blockchain address; M is a positive integer; obtaining the first operation permissions corresponding to the M first child blockchain addresses, and authorizing the M first operation permissions to the first parent blockchain address; using the sub-address private key of each first child blockchain address, signing the first operation permission corresponding to the first child blockchain address, obtaining the permission authorization signatures corresponding to the M first operation permissions, generating the first permission management data according to the first operation permissions and permission authorization signatures corresponding to the M first child blockchain addresses, and the first parent blockchain address, and processing the first permission management data on the chain. Subsequently, based on the maintenance of the parent-child relationship of the blockchain address, it is possible to realize the collection of authorized assets, the public visibility of authorization, and the authorization of applications such as family cards.

[0141] The present application also provides a computer-readable storage medium storing a computer program suitable for being loaded and executed by the processor. Figure 3 , Figure 4 and Figure 5 For details on the methods provided in each step, please refer to the Figure 3 , Figure 4 and Figure 5 The implementation methods provided in each step are not repeated here. In addition, the description of the beneficial effects of adopting the same method is not repeated. For technical details not disclosed in the computer-readable storage medium embodiment involved in this application, please refer to the description of the method embodiment of this application. As an example, the computer program can be deployed to execute on one computer device, or on multiple computer devices located in one place, or on multiple computer devices distributed in multiple locations and interconnected by a communication network.

[0142] The computer-readable storage medium may be the device provided in any of the aforementioned embodiments or the internal storage unit of the computer device, such as the hard disk or memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a smart memory card (smart media card, SMC), a secure digital (secure digital, SD) card, a flash card (flash card), etc. equipped on the computer device. Further, the computer-readable storage medium may also include both the internal storage unit of the computer device and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium may also be used to temporarily store data that has been output or is to be output.

[0143] The present application also provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device performs the above Figure 3 , Figure 4 and Figure 5 The methods provided in various optional ways.

[0144] The terms "first", "second", etc. in the description, claims, and drawings of the embodiments of the present application are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, device, product, or equipment that includes a series of steps or units is not limited to the listed steps or modules, but optionally includes steps or modules that are not listed, or optionally includes other step units inherent to these processes, methods, devices, products, or equipment.

[0145] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in this description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0146] The method and related apparatus provided by the embodiment of the present application are described with reference to the method flow chart and / or structural diagram provided by the embodiment of the present application. Specifically, each process and / or box in the method flow chart and / or structural diagram, as well as the combination of the processes and / or boxes in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable device to generate a machine, so that the instructions executed by the processor of the computer or other programmable device generate instructions for implementing the process in the process. Figure 1 A process or multiple processes and / or structures Figure 1 These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable device to work in a specific way, so that the instructions stored in the computer-readable memory produce a product including an instruction device, which implements the functions specified in the process. Figure 1A process or multiple processes and / or structures Figure 1 These computer program instructions can also be loaded onto a computer or other programmable device so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide the functions for implementing the process. Figure 1 A flow or multiple flows and / or structures illustrate the steps of the functions specified in one block or multiple blocks.

[0147] The steps in the method of the embodiment of the present application can be adjusted in order, combined and deleted according to actual needs.

[0148] The modules in the device of the embodiment of the present application can be merged, divided and deleted according to actual needs.

[0149] The above disclosure is only the preferred embodiment of the present application, which certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.

Claims

1. A blockchain-based authorization method, It is characterized in that The method comprises: Obtain the first parent blockchain address and the M first child blockchain addresses corresponding to the first parent blockchain address; M is a positive integer; Obtain the first operation permissions respectively corresponding to the M first child blockchain addresses, and authorize the M first operation permissions to the first parent blockchain address; The sub-address private key of each first child blockchain address is used to sign the first operation permission corresponding to the first child blockchain address, and the permission authorization signatures corresponding to the M first operation permissions are obtained. According to the first operation permissions and permission authorization signatures corresponding to the M first child blockchain addresses, and the first parent blockchain address, first permission management data is generated, and the first permission management data is processed on the chain.

2. The method according to claim 1, It is characterized in that The obtaining of the first parent blockchain address and the M first child blockchain addresses corresponding to the first parent blockchain address includes: Obtain M first sub-blockchain addresses, and perform hash processing on the M first sub-blockchain addresses respectively to obtain address hashes corresponding to the M first sub-blockchain addresses respectively; The M address hashes are combined to obtain a combined private key, a public key is generated from the combined private key to obtain a combined public key corresponding to the combined private key, and a first parent blockchain address is generated based on the combined public key.

3. The method according to claim 1, It is characterized in that The obtaining of the first parent blockchain address and the M first child blockchain addresses corresponding to the first parent blockchain address includes: Obtaining a first parent blockchain address, determining the first parent blockchain address as a root seed, and performing a hashing process on the root seed to obtain a seed hash value; Obtain a master private key and a master chain code from the seed hash value, generate M index numbers, generate M random data according to the master chain code, and derive M sub-private keys based on the master private key, the M index numbers and the M random data; Generate public keys for the M sub-private keys to obtain sub-public keys corresponding to the M sub-private keys respectively, and determine M first sub-blockchain addresses based on the M sub-public keys.

4. The method according to claim 1, It is characterized in that The method further comprises: Acquire transaction data, generate a symmetric key for the transaction data, encrypt the transaction data using the symmetric key to obtain first encrypted data, and upload the first encrypted data to a blockchain; Obtaining a decryption method and data authorization information for the first encrypted data; When receiving a request from a target blockchain address to access the first encrypted data, performing authority verification on the target blockchain address based on the data authorization information; If the target blockchain address authority verification is passed, the first public key of the target blockchain address is used to encrypt the decryption method and the symmetric key to obtain second encrypted data; The second encrypted data is sent to the target blockchain address, so that the target blockchain address decrypts the second encrypted data through the first private key to obtain the decryption method and the symmetric key, and the first encrypted data is decrypted using the decryption method and the symmetric key to obtain the transaction data; the first private key is the private key of the target blockchain address.

5. The method according to claim 4, It is characterized in that The performing authority verification on the target blockchain address based on the data authorization information includes: If the data authorization information includes the target blockchain address, determining that the authority verification of the target blockchain address is passed; If the target blockchain address is not included in the data authorization information, the second permission management data corresponding to the target blockchain address is searched; if the second permission management data is found and the second sub-blockchain address of the target blockchain address exists in the second permission management data, the second sub-blockchain address is detected based on the second permission management data; if the second permission management data includes the second sub-blockchain address, it is determined that the target blockchain address permission verification has passed.

6. The method according to claim 1, It is characterized in that The method further comprises: Obtain a second operation permission of the first parent blockchain address, split the second operation permission to obtain sub-operation permissions, and authorize the sub-operation permissions to the M first child blockchain addresses; The parent address private key of the first parent blockchain address is used to sign the sub-operation permissions corresponding to the M first child blockchain addresses respectively, to generate a permission distribution signature, and according to the sub-operation permissions corresponding to the M first child blockchain addresses and the permission distribution signature, permission distribution data is generated, and the permission distribution data is processed on the chain.

7. The method according to claim 6, It is characterized in that The method further comprises: When receiving the i-th first child blockchain address, for the transfer operation of the digital asset corresponding to the first parent blockchain address, obtain the sub-operation permission corresponding to the i-th first child blockchain address; the sub-operation permission corresponding to the i-th first child blockchain address includes the operation type, operation period and operation data volume; i is a positive integer less than or equal to M; If the operation type is an asset transfer operation type, then the amount of asset data transferred of the i-th first sub-blockchain address within the operation cycle and the amount of data to be transferred requested by the transfer operation are obtained; If the sum of the amount of transferred asset data and the amount of to-be-transferred asset data is less than or equal to the amount of operation data, the to-be-transferred asset corresponding to the amount of to-be-transferred data is obtained from the digital assets of the first parent blockchain address, and the to-be-transferred asset is transferred to the target address; the target address refers to the destination requested by the transfer operation of the i-th first child blockchain address.

8. A blockchain-based authorization device, It is characterized in that The device comprises: A data acquisition module, used to acquire a first parent blockchain address and M first child blockchain addresses corresponding to the first parent blockchain address; M is a positive integer; An authorization module, used to obtain the first operation permissions respectively corresponding to the M first child blockchain addresses, and authorize the M first operation permissions to the first parent blockchain address; The on-chain processing module is used to use the sub-address private key of each first sub-blockchain address to sign the first operation permission corresponding to the first sub-blockchain address, obtain the permission authorization signatures corresponding to the M first operation permissions, generate first permission management data according to the first operation permissions and permission authorization signatures corresponding to the M first sub-blockchain addresses, and the first parent blockchain address, and perform on-chain processing on the first permission management data.

9. A computer device, It is characterized in that Includes processor, memory, input and output interfaces; The processor is connected to the memory and the input / output interface respectively, wherein the input / output interface is used to receive and output data, the memory is used to store a computer program, and the processor is used to call the computer program so that the computer device executes the method described in any one of claims 1-7.

10. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores a computer program, and the computer program is suitable for being loaded and executed by a processor, so that a computer device having the processor executes the method according to any one of claims 1 to 7.

11. A computer program product, It is characterized in that The computer program product comprises a computer program, which is stored in a computer-readable storage medium and is suitable for being read and executed by a processor, so that a computer device having the processor executes the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Data integrity verification method and system applied to intelligent platform

    CN120614201A