Resource processing method and device based on block chain, equipment and medium
Patent Information
- Application Number
- CN202311666068.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-05
- Publication Date
- 2025-06-06
Smart Images

Figure CN120106844A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to blockchain and smart contract technology, and in particular to a blockchain-based resource processing method, device, equipment and medium. Background Art
[0002] Blockchain technology is a distributed ledger technology in the field of information technology. It is generally composed of consensus, transaction blocks and state data storage, cryptographic identity security and other contents. Since the ledger is distributed and the blocks are consensus-based, it has the characteristics of being tamper-proof, traceable, and jointly maintained. Smart contract is an automatically executed contract based on blockchain technology. It is a computer protocol designed to disseminate, verify or execute contracts in an information-based manner. Smart contracts allow trusted transactions without a third party, and these transactions are monitorable and irreversible. In the resource processing scenario, traditional technologies usually directly send resource transfer requests carrying virtual resources to smart contracts. When receiving resource transfer requests, smart contracts execute smart contracts to transfer resources.
[0003] However, traditional resource processing methods can easily lead to repeated execution of smart contracts during the resource processing process, resulting in malicious repeated transfer of resources, and the security of resource transfer is low. Summary of the invention
[0004] Based on this, it is necessary to provide a blockchain-based resource processing method, device, equipment and medium that can improve the security of resource transfer in response to the above technical problems.
[0005] In a first aspect, the present application provides a resource processing method based on blockchain, which is applied to a node of a blockchain network, wherein a smart contract is provided in the node, and the method comprises:
[0006] Receive resource transfer request from client;
[0007] Obtain at least one virtual resource indicated by the resource transfer request, and obtain a first message authentication code indicated by the resource transfer request; the first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key;
[0008] Querying a message authentication code consistent with the first message authentication code from an authentication code repository, the authentication code repository being used to store a message authentication code that first appears in a received historical resource transfer request;
[0009] When a message authentication code consistent with the first message authentication code is not found, executing the smart contract to transfer resources based on the at least one virtual resource and obtaining a resource transfer result;
[0010] The resource transfer result is stored in the blockchain network, and the first message authentication code is stored in the authentication code repository.
[0011] In a second aspect, the present application provides a resource processing device based on blockchain, which is applied to a node of a blockchain network, wherein a smart contract is provided in the node, and the device comprises:
[0012] A receiving module, used for receiving a resource transfer request from a client;
[0013] An acquisition module, used to acquire at least one virtual resource indicated by the resource transfer request, and acquire a first message authentication code indicated by the resource transfer request; the first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key;
[0014] A query module, configured to query a message authentication code consistent with the first message authentication code from an authentication code repository, wherein the authentication code repository is configured to store a message authentication code that first appears in a received historical resource transfer request;
[0015] A transfer module, configured to execute the smart contract when a message authentication code consistent with the first message authentication code is not found, so as to transfer resources based on the at least one virtual resource and obtain a resource transfer result;
[0016] A storage module is used to store the resource transfer result in the blockchain network and store the first message authentication code in the authentication code repository.
[0017] In one embodiment, the apparatus further comprises:
[0018] An authentication module is used to generate a second message authentication code according to the authentication code generation strategy, based on the encryption key, and at least one virtual resource indicated by the received resource transfer request; when the first message authentication code is consistent with the second message authentication code, notify the query module to execute the step of querying the authentication code repository for a message authentication code that is consistent with the first message authentication code.
[0019] In one embodiment, the authentication module is also used to fuse the encryption key and a preset constant to obtain a fusion result; perform hash processing on at least one virtual resource indicated by the received resource transfer request through a hash function indicated by the authentication code generation strategy to obtain a first hash result; and generate a second message authentication code based on the fusion result and the first hash result.
[0020] In one embodiment, the preset constants include a first preset constant and a second preset constant, the fusion result includes a first fusion result and a second fusion result, the first fusion result is obtained by fusing the encryption key and the first preset constant, and the second fusion result is obtained by fusing the encryption key and the second preset constant; the authentication module is also used to fuse the first fusion result and the first hash result to obtain a third fusion result; hash the third fusion result through the hash function to obtain a second hash result; fuse the second fusion result and the second hash result to obtain a fourth fusion result; hash the fourth fusion result through the hash function to obtain a second message authentication code.
[0021] In one embodiment, the authentication module is also used to adjust the key length of the encryption key to obtain an adjusted encryption key when the key length of the encryption key is inconsistent with the block length of the hash function; the key length of the adjusted encryption key is consistent with the block length of the hash function; and the adjusted encryption key is merged with a preset constant to obtain a fusion result.
[0022] In one embodiment, the authentication module is also used to, when the key length of the encryption key is greater than the block length of the hash function, use the encryption key as the object of the first round of hash processing, use the first round as the current round, hash the object through the hash function, and obtain the hash value of the current round; use the next round as the current round, use the hash value as the object of the current round of hash processing, return to the step of hashing the object through the hash function to obtain the hash value of the current round, and iterate until the length of the obtained hash value is consistent with the block length, and stop, and determine the adjusted encryption key based on the hash value obtained from the last round of hash processing.
[0023] In one embodiment, the authentication module is also used to create a byte array with a length consistent with the block length when the key length of the encryption key is less than the block length of the hash function; fill the encryption key into the byte array; determine the unfilled byte position in the byte array, and fill the preset bytes at the determined byte position to obtain the adjusted encryption key.
[0024] In one embodiment, any message authentication code stored in the authentication code repository includes at least one character, and the characters in any message authentication code are taken from a preset character set. The acquisition module is also used to obtain the authentication code binary data indicated by the resource transfer request; encode the authentication code binary data to obtain a first message authentication code, and the first message authentication code includes at least one character, and the characters in the first message authentication code are taken from the preset character set.
[0025] In one embodiment, the acquisition module is also used to group the binary bits contained in the authentication code binary data to obtain multiple binary bit combinations, each of which contains multiple binary bits; for each of the binary bit combinations, determine the character index corresponding to the targeted binary bit combination according to the multiple binary bits contained in the targeted binary bit combination; obtain a coding comparison table, which records the mapping relationship between the character index and the characters in the preset character set; according to the character indexes corresponding to the multiple binary bit combinations, determine the characters corresponding to the multiple binary bit combinations from the coding comparison table; splice the characters corresponding to the multiple binary bit combinations to obtain a first message authentication code, and the data length of the first message authentication code is less than the data length of the authentication code binary data.
[0026] In one embodiment, the acquisition module is also used to determine the number of binary bits contained in the authentication code binary data; when the number is not an integer multiple of a preset number, the authentication code binary data is padded to obtain padded binary data, and the number of binary bits contained in the padded binary data is an integer multiple of the preset number; the padded binary data is grouped to obtain multiple binary bit combinations.
[0027] In one embodiment, the character index is data expressed in decimal, and the acquisition module is further used to convert multiple binary bits contained in the targeted binary bit combination into data expressed in decimal for each of the targeted binary bit combinations, so as to obtain the character index corresponding to the targeted binary bit combination.
[0028] In one embodiment, the transfer module is further used to stop executing the smart contract and generate prompt information for indicating that the resource transfer request is a duplicate request when a message authentication code consistent with the first message authentication code is queried.
[0029] In a third aspect, the present application provides a computer device including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the steps in the method embodiments of the present application are implemented.
[0030] In a fourth aspect, the present application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in the method embodiments of the present application.
[0031] In a fifth aspect, the present application provides a computer program product, including a computer program, which implements the steps in the method embodiments of the present application when the computer program is executed by a processor.
[0032] The above-mentioned resource processing method, device, equipment and medium based on blockchain, by receiving a resource transfer request from a client, obtains at least one virtual resource indicated by the resource transfer request, and obtains the first message authentication code indicated by the resource transfer request, the first message authentication code is generated according to the preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key. Query the message authentication code consistent with the first message authentication code from the authentication code repository, the authentication code repository is used to store the message authentication code that first appears in the received historical resource transfer request. When the message authentication code consistent with the first message authentication code is not queried, the smart contract is executed to transfer resources based on at least one virtual resource to obtain the resource transfer result. The resource transfer result is stored in the blockchain network, and the first message authentication code is stored in the authentication code repository. Compared with the traditional resource processing method, the present application generates a message authentication code corresponding to the virtual resource based on the encryption key and the virtual resource to be submitted to the blockchain network. An authentication code repository is maintained through the message authentication code that first appears in the historical resource transfer request of the node, and the maintained authentication code repository is used to determine whether each resource transfer request received is a repeated request. Only when the resource transfer request is the first request, the smart contract is executed to transfer resources based on virtual resources, avoiding the repeated execution of smart contracts in the resource processing process, thereby avoiding malicious repeated transfer of resources and improving the security of resource transfer. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 This is an application environment diagram of a resource processing method based on blockchain in one embodiment;
[0034] Figure 2 It is a flowchart of a resource processing method based on blockchain in one embodiment;
[0035] Figure 3 A schematic diagram of the interaction between a client and a blockchain network in one embodiment;
[0036] Figure 4 A schematic diagram of comparison between physical resources and virtual resources in one embodiment;
[0037] Figure 5 A schematic diagram of deployment of a smart contract in a node in one embodiment;
[0038] Figure 6 A schematic diagram of the principle of block storage in a blockchain network in one embodiment;
[0039] Figure 7 A schematic diagram of the principle of repeated request generation in one embodiment;
[0040] Figure 8A schematic diagram of a usage entry of a virtual resource in one embodiment;
[0041] Fig. 9 is a schematic diagram of virtual resources in one embodiment;
[0042] Fig.10 A schematic diagram of a scenario in which virtual resource transfer is achieved through touch in one embodiment;
[0043] Fig.11 It is a flowchart of a resource processing method based on blockchain in another embodiment;
[0044] Fig.12 is a structural block diagram of a resource processing device based on blockchain in one embodiment;
[0045] Fig.13 is a structural block diagram of a resource processing device based on blockchain in another embodiment;
[0046] Fig.14 is an internal structure diagram of a computer device in one embodiment;
[0047] Fig.15 FIG. 4 is a diagram showing the internal structure of a computer device in another embodiment. DETAILED DESCRIPTION
[0048] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0049] The resource processing method based on blockchain provided in this application can be applied to Figure 1In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can be set up separately and can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other servers. Among them, the terminal 102 can be, but is not limited to, various desktop computers, laptops, smart phones, tablet computers, vehicle-mounted terminals, intelligent voice interaction devices, aircraft, smart home appliances and portable wearable devices. Smart home appliances can be smart speakers, smart TVs and smart air conditioners. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, cloud security, host security and other network security services, CDN, and basic cloud computing services such as big data and artificial intelligence platforms. The terminal 102 and the server 104 can be directly or indirectly connected by wired or wireless communication, and this application is not limited here.
[0050] It can be understood that the node can be a server 104, and the client can be set in the terminal 102. Specifically, the server 104 can receive a resource transfer request from the client in the terminal 102; obtain at least one virtual resource indicated by the resource transfer request, and obtain the first message authentication code indicated by the resource transfer request; the first message authentication code is generated by the client in the terminal 102 according to the preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key. The server 104 can query the message authentication code consistent with the first message authentication code from the authentication code repository, and the authentication code repository is used to store the message authentication code that appears for the first time in the received historical resource transfer request. When the message authentication code consistent with the first message authentication code is not queried, the server 104 can execute the smart contract to perform resource transfer based on at least one virtual resource and obtain the resource transfer result. The server 104 can store the resource transfer result to the blockchain network and store the first message authentication code to the authentication code repository.
[0051] In one embodiment, Figure 2 As shown, a resource processing method based on blockchain is provided, which is applied to nodes of a blockchain network, and a smart contract is set in the node. It can be understood that the node can be a computer device, and the computer device can be a terminal or a server. The method can be executed by the terminal or the server alone, or it can be implemented through the interaction between the terminal and the server. This embodiment is described by taking the method applied to the node of the blockchain network as an example, and includes the following steps:
[0052] Step 202: Receive a resource transfer request from a client.
[0053] The resource transfer request is a computer instruction requesting the transfer of virtual resources.
[0054] Specifically, the client may generate a resource transfer request in response to the resource transfer operation, and send the resource transfer request to a node of the blockchain network. The node of the blockchain network may receive the resource transfer request sent by the client.
[0055] In one embodiment, Figure 3 As shown, the blockchain network includes node 1, node 2, node 3, ..., node n, where n is an integer. Node 1, node 2, node 3, ..., node n are all provided with smart contracts. For example, the resource processing method based on blockchain in this application can be applied to node 1 in the blockchain network. It can be understood that node 1 of the blockchain network can receive the resource transfer request sent by the client and perform subsequent resource processing.
[0056] Step 204, obtain at least one virtual resource indicated by the resource transfer request, and obtain a first message authentication code indicated by the resource transfer request; the first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key.
[0057] Among them, the virtual resource is a virtual resource, different virtual resources have different resource identifiers, and the resource identifier is used to uniquely identify the virtual resource.
[0058] Specifically, after receiving a resource transfer request sent by a client, a node of the blockchain network can determine at least one virtual resource indicated by the resource transfer request and determine a first message authentication code indicated by the resource transfer request.
[0059] In one embodiment, the client generates a first message authentication code according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key. The resource transfer request carries at least one virtual resource and the generated first message authentication code. After receiving the resource transfer request sent by the client, the node of the blockchain network can directly obtain at least one virtual resource carried by the resource transfer request and the first message authentication code carried by the resource transfer request.
[0060] To facilitate further understanding of the virtual resources in this application and to better distinguish between traditional physical resources and the virtual resources in this application, the following description is given. Figure 4As shown, the resource issuing agency can issue physical resources and virtual resources. For physical resources, if the user has a lot of physical resources but does not use them often, the user can go to the resource issuing agency to open a resource account and store the physical resources in the resource issuing agency. When the user needs to use them, go to the resource issuing agency to take out the physical resources. Alternatively, the user can also bind the resource account opened by the resource issuing agency with the payment application. When the resource needs to be paid, the payment application can be used to scan the code to deduct the physical resources to be paid from the resource account. For virtual resources, after the resource issuing agency issues them, they can be directly bound to the user's payment application. When the resource needs to be paid, the payment application can be used to scan the code to deduct the virtual resources to be paid.
[0061] Step 206: query an authentication code repository for a message authentication code that is consistent with the first message authentication code. The authentication code repository is used to store the message authentication code that appears for the first time in the received historical resource transfer request.
[0062] The historical resource transfer request is a resource transfer request received by a node of the blockchain network before receiving a resource transfer request indicating a first message authentication code. It can be understood that the authentication code repository is used to store the message authentication code indicated by each historical resource transfer request and that appears for the first time.
[0063] Specifically, the authentication code repository stores the message authentication codes indicated by each historical resource transfer request and appearing for the first time. After obtaining the first message authentication code indicated by the current resource transfer request, the node of the blockchain network can query the authentication code repository for a message authentication code that is consistent with the first message authentication code. It can be understood that the query result may include a message authentication code that is not consistent with the first message authentication code queried from the authentication code repository, and a message authentication code that is consistent with the first message authentication code queried from the authentication code repository.
[0064] Step 208: When a message authentication code consistent with the first message authentication code is not found, the smart contract is executed to transfer resources based on at least one virtual resource to obtain a resource transfer result.
[0065] Among them, Figure 5 As shown, smart contracts are set in the nodes of the blockchain network. It can be understood that smart contracts are automatically executed computer protocols based on blockchain technology.
[0066] Specifically, when a message authentication code consistent with the first message authentication code is not queried from the authentication code repository, the node of the blockchain network can execute the smart contract to transfer resources based on at least one virtual resource and obtain a resource transfer result. It can be understood that the node of the blockchain network can use at least one virtual resource as an input of the smart contract so that the node of the blockchain network can transfer resources based on at least one virtual resource and output a resource transfer result.
[0067] Step 210: store the resource transfer result in the blockchain network, and store the first message authentication code in the authentication code storage library.
[0068] Specifically, after obtaining the resource transfer result, the node of the blockchain network may store the resource transfer result in the blockchain network. Also, when a message authentication code consistent with the first message authentication code is not queried from the authentication code repository, it means that the first message authentication code indicated by the resource transfer request is the first time it appears, and the node of the blockchain network has not received the first message authentication code before, then the node of the blockchain network may store the first message authentication code that appears for the first time in the authentication code repository.
[0069] In one embodiment, Figure 6 As shown, it is a schematic diagram of the block structure provided by this embodiment, and each block includes the data stored in this block, that is, the resource transfer result, the hash value of the resource transfer result stored in this block, that is, the hash of this block, and the hash value of the previous block, that is, the hash of the previous block. For example, for block 2, block 2 includes the data stored in this block, that is, the resource transfer result, the hash value of the resource transfer result stored in this block, that is, the hash value of block 2, and the hash value of the previous block, that is, the hash value of block 1. For block 3, block 3 includes the data stored in this block, that is, the resource transfer result, the hash value of the resource transfer result stored in this block, that is, the hash value of block 3, and the hash value of the previous block, that is, the hash value of block 2. It can be understood that each block is connected by a hash value to form a blockchain network. In addition, the block can also include information such as the timestamp when the block is generated.
[0070] In the above-mentioned resource processing method based on blockchain, by receiving a resource transfer request from a client, at least one virtual resource indicated by the resource transfer request is obtained, and the first message authentication code indicated by the resource transfer request is obtained. The first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key. A message authentication code consistent with the first message authentication code is queried from an authentication code repository, and the authentication code repository is used to store the message authentication code that first appears in the received historical resource transfer request. When a message authentication code consistent with the first message authentication code is not queried, the smart contract is executed to perform resource transfer based on at least one virtual resource to obtain a resource transfer result. The resource transfer result is stored in the blockchain network, and the first message authentication code is stored in the authentication code repository. Compared with the traditional resource processing method, the present application generates a message authentication code corresponding to the virtual resource based on the encryption key and the virtual resource to be submitted to the blockchain network. An authentication code repository is maintained through the message authentication code that first appears in the historical resource transfer request of the node, and the maintained authentication code repository is used to determine whether each resource transfer request received is a repeated request. Only when the resource transfer request is the first request, the smart contract is executed to transfer resources based on virtual resources, avoiding the repeated execution of smart contracts in the resource processing process, thereby avoiding malicious repeated transfer of resources and improving the security of resource transfer.
[0071] It is understandable that Figure 7 As shown, in the traditional resource processing method, during the resource processing process, the data sent by the client to the node of the blockchain network is at risk of being intercepted by an attacker. When the attacker sends a resource transfer request to the node of the blockchain network based on the intercepted data, it will cause the smart contract to be repeatedly executed, resulting in malicious repeated transfer of resources, and the security of resource transfer is low. In this application, a message authentication code corresponding to the virtual resource is generated based on the encryption key and the virtual resource to be submitted to the blockchain network. By judging whether the message authentication code is sent repeatedly, it is judged whether each resource transfer request received is a repeated request. Only when the resource transfer request is the first request, the smart contract is executed, avoiding the repeated execution of the smart contract during the resource processing process, thereby avoiding malicious repeated transfer of resources and improving the security of resource transfer.
[0072] In one embodiment, the method also includes: generating a second message authentication code according to an authentication code generation strategy, based on an encryption key, and at least one virtual resource indicated by a received resource transfer request; when the first message authentication code is consistent with the second message authentication code, executing the step of querying a message authentication code consistent with the first message authentication code from an authentication code repository.
[0073] It can be understood that the second message authentication code is generated according to the authentication code generation strategy used when generating the first message authentication code, based on the encryption key used when generating the first message authentication code, and at least one virtual resource indicated by the received resource transfer request.
[0074] Specifically, the nodes of the blockchain network may generate a second message authentication code according to the authentication code generation strategy used when generating the first message authentication code, according to the encryption key used when generating the first message authentication code, and at least one virtual resource indicated by the received resource transfer request. The nodes of the blockchain network may compare the first message authentication code with the second message authentication code. When the first message authentication code is consistent with the second message authentication code, the nodes of the blockchain network may query the message authentication code consistent with the first message authentication code from the authentication code repository. When a message authentication code consistent with the first message authentication code is not found, the nodes of the blockchain network may execute a smart contract to perform resource transfer based on at least one virtual resource to obtain a resource transfer result. Furthermore, the nodes of the blockchain network may store the resource transfer result to the blockchain network and store the first message authentication code to the authentication code repository.
[0075] In one embodiment, the node of the blockchain network can perform hash processing on at least one virtual resource indicated by the received resource transfer request through the hash function indicated by the authentication code generation policy to obtain a hash result. It can be understood that the node of the blockchain network can use the at least one virtual resource indicated by the received resource transfer request as the input of the hash function indicated by the authentication code generation policy, so as to perform hash processing on at least one virtual resource indicated by the received resource transfer request through the hash function indicated by the authentication code generation policy, and output the hash result. Furthermore, the node of the blockchain network can directly generate a second message authentication code based on the encryption key and the obtained hash result.
[0076] In the above embodiment, the second message authentication code is generated according to the authentication code generation strategy used when generating the first message authentication code, the encryption key used when generating the first message authentication code, and at least one virtual resource indicated by the received resource transfer request. When the first message authentication code is consistent with the second message authentication code, it means that the virtual resources sent by the client to the node of the blockchain network have not been tampered with. When it is determined that the virtual resources have not been tampered with, it is determined whether the resource transfer request is a repeated request. When it is determined that the resource transfer request is not a repeated request, the resource transfer is performed. In this way, the repeated execution of the smart contract in the resource processing process can be avoided, the malicious repeated transfer of resources can be prevented, and the security of resource transfer can be improved. At the same time, it also prevents the virtual resources from being maliciously tampered with during the transmission from the client to the blockchain network, further improving the security of resource transfer.
[0077] In one embodiment, when a message authentication code consistent with the first message authentication code is not found, a smart contract is executed to transfer resources based on at least one virtual resource to obtain a resource transfer result, including: when a message authentication code consistent with the first message authentication code is not found, a second message authentication code is generated according to an authentication code generation strategy, an encryption key, and at least one virtual resource indicated by the received resource transfer request. When the first message authentication code is consistent with the second message authentication code, a smart contract is executed to transfer resources based on at least one virtual resource to obtain a resource transfer result.
[0078] Specifically, a node of a blockchain network may receive a resource transfer request from a client, obtain at least one virtual resource indicated by the resource transfer request, and obtain a first message authentication code indicated by the resource transfer request, wherein the first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key. The node of the blockchain network may query a message authentication code consistent with the first message authentication code from an authentication code repository, and the authentication code repository is used to store the message authentication code that first appears in the received historical resource transfer request. When a message authentication code consistent with the first message authentication code is not queried, the node of the blockchain network may generate a second message authentication code according to the authentication code generation strategy, based on the encryption key, and at least one virtual resource indicated by the received resource transfer request. When the first message authentication code is consistent with the second message authentication code, the node of the blockchain network may execute a smart contract to perform resource transfer based on at least one virtual resource, obtain a resource transfer result, store the resource transfer result in the blockchain network, and store the first message authentication code in the authentication code repository.
[0079] In this embodiment, when a message authentication code consistent with the first message authentication code is not found, a second message authentication code is generated according to the authentication code generation strategy used when generating the first message authentication code, the encryption key used when generating the first message authentication code, and at least one virtual resource indicated by the received resource transfer request. When the first message authentication code is consistent with the second message authentication code, the smart contract is executed again to transfer resources based on at least one virtual resource to obtain a resource transfer result. In this way, the repeated execution of smart contracts in the resource processing process can be avoided, malicious repeated transfer of resources can be prevented, and the security of resource transfer can be improved. At the same time, the virtual resources can be prevented from being maliciously tampered with during transmission from the client to the blockchain network, further improving the security of resource transfer.
[0080] In one embodiment, a second message authentication code is generated according to an authentication code generation strategy, based on an encryption key, and at least one virtual resource indicated by a received resource transfer request, including: fusing the encryption key and a preset constant to obtain a fusion result; performing hash processing on at least one virtual resource indicated by the received resource transfer request through a hash function indicated by the authentication code generation strategy to obtain a first hash result; and generating a second message authentication code based on the fusion result and the first hash result.
[0081] The first hash result is a hash result obtained by hashing at least one virtual resource indicated by the received resource transfer request through a hash function indicated by the authentication code generation policy.
[0082] Specifically, the nodes of the blockchain network may fuse the encryption key and the preset constant to obtain a fusion result, and perform hash processing on at least one virtual resource indicated by the received resource transfer request through the hash function indicated by the authentication code generation strategy to obtain a first hash result. It can be understood that the nodes of the blockchain network may use at least one virtual resource indicated by the received resource transfer request as the input of the hash function indicated by the authentication code generation strategy, and perform hash processing on at least one virtual resource indicated by the received resource transfer request through the hash function indicated by the authentication code generation strategy to obtain a first hash result. Furthermore, the nodes of the blockchain network may generate a second message authentication code based on the fusion result and the first hash result.
[0083] In one embodiment, the node of the blockchain network may fuse the obtained fusion result with the first hash result to obtain a second message authentication code.
[0084] In one embodiment, when the key length of the encryption key is consistent with the block length of the hash function, the nodes of the blockchain network can directly merge the encryption key and the preset constant to obtain a fusion result.
[0085] In the above embodiment, the fusion result is obtained by fusing the encryption key and the preset constant. The at least one virtual resource indicated by the received resource transfer request is hashed by the hash function indicated by the authentication code generation strategy to obtain a first hash result. Then, based on the fusion result and the first hash result, a second message authentication code is generated. It can be understood that the first message authentication code is also generated according to the same authentication code generation strategy as that for generating the second message authentication code. Therefore, this embodiment improves the stability of the generated first message authentication code and the second message authentication code, thereby further improving the security of resource transfer.
[0086] In one embodiment, the preset constants include a first preset constant and a second preset constant, and the fusion result includes a first fusion result and a second fusion result, the first fusion result is obtained by fusing the encryption key and the first preset constant, and the second fusion result is obtained by fusing the encryption key and the second preset constant; according to the fusion result and the first hash result, a second message authentication code is generated, including: fusing the first fusion result and the first hash result to obtain a third fusion result; hashing the third fusion result through a hash function to obtain a second hash result; fusing the second fusion result and the second hash result to obtain a fourth fusion result; hashing the fourth fusion result through a hash function to obtain a second message authentication code.
[0087] The third fusion result is a fusion result obtained by fusion of the first fusion result and the first hash result. The second hash result is a hash result obtained by hashing the third fusion result using a hash function indicated by the authentication code generation strategy. The fourth fusion result is a fusion result obtained by fusion of the second fusion result and the second hash result.
[0088] Specifically, the node of the blockchain network may fuse the encryption key and the first preset constant to obtain a first fusion result, and fuse the encryption key and the second preset constant to obtain a second fusion result. Furthermore, the node of the blockchain network may fuse the first fusion result and the first hash result to obtain a third fusion result, and hash the third fusion result through a hash function to obtain a second hash result. It is understood that the node of the blockchain network may use the third fusion result as the input of the hash function to hash the third fusion result through the hash function to obtain a second hash result. The node of the blockchain network may fuse the second fusion result and the second hash result to output a fourth fusion result, and hash the fourth fusion result through the hash function to obtain a second message authentication code. It is understood that the node of the blockchain network may use the fourth fusion result as the input of the hash function to hash the fourth fusion result through the hash function to output a second message authentication code.
[0089] In the above embodiment, a first fusion result is obtained by fusing an encryption key and a first preset constant. A second fusion result is obtained by fusing an encryption key and a second preset constant. The first fusion result and the first hash result are fused to obtain a third fusion result. The third fusion result is hashed by a hash function to obtain a second hash result. The second fusion result and the second hash result are fused to obtain a fourth fusion result. Furthermore, the fourth fusion result is hashed by a hash function to obtain a second message authentication code. It can be understood that the first message authentication code is also generated according to the same authentication code generation strategy as that for generating the second message authentication code. Therefore, this embodiment further improves the stability of the generated first message authentication code and the second message authentication code, thereby further improving the security of resource transfer.
[0090] In one embodiment, an encryption key and a preset constant are fused to obtain a fusion result, including: when the key length of the encryption key is inconsistent with the block length of the hash function, the key length of the encryption key is adjusted to obtain an adjusted encryption key; the key length of the adjusted encryption key is consistent with the block length of the hash function; the adjusted encryption key and the preset constant are fused to obtain a fusion result.
[0091] Specifically, the nodes of the blockchain network may compare the key length of the encryption key with the block length of the hash function. When the key length of the encryption key is inconsistent with the block length of the hash function, the nodes of the blockchain network may adjust the key length of the encryption key to obtain an adjusted encryption key. The key length of the adjusted encryption key is consistent with the block length of the hash function. Furthermore, the nodes of the blockchain network may fuse the adjusted encryption key with a preset constant to obtain a fusion result.
[0092] It is understood that the key length of the encryption key is inconsistent with the block length of the hash function, which may specifically include the key length of the encryption key being greater than the block length of the hash function, and the key length of the encryption key being greater than or less than the block length of the hash function. It is understood that when the key length of the encryption key is greater than or less than the block length of the hash function, the nodes of the blockchain network may adjust the key length of the encryption key to obtain the adjusted encryption key.
[0093] In the above embodiment, when the key length of the encryption key is inconsistent with the block length of the hash function, the adjusted encryption key is obtained by adjusting the key length of the encryption key, wherein the key length of the adjusted encryption key is consistent with the block length of the hash function. Furthermore, by fusing the adjusted encryption key and the preset constant, a fusion result is obtained, thereby improving the accuracy of the fusion result. It can be understood that the first message authentication code is also generated according to the same authentication code generation strategy as that for generating the second message authentication code. Therefore, this embodiment further improves the stability of the generated first message authentication code and the second message authentication code, thereby further improving the security of resource transfer.
[0094] In one embodiment, when the key length of the encryption key is inconsistent with the block length of the hash function, the key length of the encryption key is adjusted to obtain the adjusted encryption key, including: when the key length of the encryption key is greater than the block length of the hash function, the encryption key is used as the object of the first round of hash processing, the first round is used as the current round, the object is hashed through the hash function to obtain the hash value of the current round; the next round is used as the current round, the hash value is used as the object of the current round of hash processing, the step of returning to the hash function to hash the object to obtain the hash value of the current round is iteratively executed until the length of the obtained hash value is consistent with the block length, and the adjusted encryption key is determined based on the hash value obtained from the last round of hash processing.
[0095] Specifically, when the key length of the encryption key is greater than the block length of the hash function, the nodes of the blockchain network can use the encryption key as the object of the first round of hash processing, and use the first round as the current round to hash the object through the hash function to obtain the hash value of the current round. The nodes of the blockchain network can use the next round as the current round, use the hash value as the object of the current round of hash processing, return to the step of hashing the object through the hash function to obtain the hash value of the current round, and iteratively execute until the length of the obtained hash value is consistent with the block length, and stop, and determine the adjusted encryption key based on the hash value obtained in the last round of hash processing. It can be understood that in each round of hash processing, the nodes of the blockchain network can use the hashed object as the input of the hash function to hash the object through the hash function to obtain the hash value of the current round.
[0096] In one embodiment, the nodes of the blockchain network can directly use the hash value obtained from the last round of hash processing as the adjusted encryption key.
[0097] In the above embodiment, when the key length of the encryption key is greater than the block length of the hash function, the encryption key is used as the object of the first round of hash processing, the first round is used as the current round, the object is hashed through the hash function to obtain the hash value of the current round, the next round is used as the current round, the hash value is used as the object of the current round of hash processing, and the step of returning to the hash function to hash the object to obtain the hash value of the current round is iteratively executed until the length of the obtained hash value is consistent with the block length, and the adjusted encryption key is determined based on the hash value obtained by the last round of hash processing. Then, the adjusted encryption key and the preset constant are subsequently merged to obtain the fusion result, thereby improving the accuracy of the fusion result. It can be understood that the first message authentication code is also generated according to the same authentication code generation strategy as the second message authentication code. Therefore, this embodiment further improves the stability of the generated first message authentication code and the second message authentication code, thereby further improving the security of resource transfer.
[0098] In one embodiment, when the key length of the encryption key is inconsistent with the block length of the hash function, the key length of the encryption key is adjusted to obtain the adjusted encryption key, including: when the key length of the encryption key is less than the block length of the hash function, a byte array whose length is consistent with the block length is created; the encryption key is filled into the byte array; in the byte array, the unfilled byte position is determined, and the preset bytes are filled at the determined byte position to obtain the adjusted encryption key.
[0099] Specifically, when the key length of the encryption key is less than the block length of the hash function, the node of the blockchain network can create a byte array with a length consistent with the block length of the hash function, and fill the encryption key into the byte array. Furthermore, the node of the blockchain network can determine the unfilled byte position in the byte array, and fill the preset byte at the determined byte position to obtain the adjusted encryption key. It can be understood that the node of the blockchain network can use the content filled in the byte array as the adjusted encryption key.
[0100] In the above embodiment, when the key length of the encryption key is less than the block length of the hash function, the encryption key is filled into the byte array by creating a byte array with a length consistent with the block length. In the byte array, the unfilled byte position is determined, and the preset bytes are filled at the determined byte position to obtain the adjusted encryption key. Furthermore, the adjusted encryption key and the preset constant are subsequently fused to obtain a fusion result, thereby improving the accuracy of the fusion result. It can be understood that the first message authentication code is also generated according to the same authentication code generation strategy as that for generating the second message authentication code. Therefore, this embodiment further improves the stability of the generated first message authentication code and the second message authentication code, thereby further improving the security of resource transfer.
[0101] In one embodiment, any message authentication code stored in the authentication code repository includes at least one character, and the characters in any message authentication code are taken from a preset character set. Obtaining a first message authentication code indicated by a resource transfer request includes: obtaining authentication code binary data indicated by the resource transfer request; encoding the authentication code binary data to obtain a first message authentication code, and the first message authentication code includes at least one character, and the characters in the first message authentication code are taken from a preset character set.
[0102] The authentication code binary data is a message authentication code represented by a plurality of binary bits. It can be understood that the first message authentication code is a message authentication code represented by at least one character taken from a preset character set. It can be understood that the first message authentication code is a message authentication code obtained by encoding the authentication code binary data.
[0103] Specifically, the client generates authentication code binary data according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key, and sends the authentication code binary data to a node of the blockchain network. The node of the blockchain network can receive the authentication code binary data sent by the client, and encode the authentication code binary data to obtain a first message authentication code composed of at least one character taken from a preset character set.
[0104] In one embodiment, the preset character set may include at least one character selected from uppercase letters AZ, lowercase letters az, or numbers 0-9.
[0105] In the above embodiment, the authentication code binary data indicated by the resource transfer request is obtained, and the authentication code binary data is encoded to obtain the first message authentication code, wherein the first message authentication code includes at least one character, and the characters in the first message authentication code are taken from a preset character set. In this way, by encoding the authentication code binary data into the first message authentication code composed of characters, when the first message authentication code is subsequently stored in the authentication code repository, the readability of the authentication code repository can be improved, thereby facilitating the maintenance of the authentication code repository.
[0106] In one embodiment, encoding the authentication code binary data to obtain a first message authentication code includes: grouping the binary bits contained in the authentication code binary data to obtain multiple binary bit combinations, each binary bit combination containing multiple binary bits; for each binary bit combination, determining the character index corresponding to the binary bit combination according to the multiple binary bits contained in the binary bit combination; obtaining a coding comparison table, the coding comparison table recording the mapping relationship between the character index and the characters in a preset character set; determining the characters corresponding to the multiple binary bit combinations from the coding comparison table according to the character indexes corresponding to the multiple binary bit combinations; and concatenating the characters corresponding to the multiple binary bit combinations to obtain the first message authentication code, wherein the data length of the first message authentication code is less than the data length of the authentication code binary data.
[0107] The character index is the index information used to find the corresponding character in the preset character set in the encoding comparison table.
[0108] Specifically, the nodes of the blockchain network can group the binary bits contained in the authentication code binary data to obtain multiple binary bit combinations, wherein each binary bit combination contains multiple binary bits. For each binary bit combination, the nodes of the blockchain network can determine the character index corresponding to the binary bit combination according to the multiple binary bits contained in the binary bit combination. The nodes of the blockchain network can obtain a coding comparison table, wherein the coding comparison table records the mapping relationship between the character index and the characters in the preset character set. The nodes of the blockchain network can determine the characters that have a mapping relationship with each of the multiple binary bit combinations from the coding comparison table based on the character indexes corresponding to the multiple binary bit combinations and the mapping relationship between the character indexes recorded in the coding comparison table and the characters in the preset character set. Furthermore, the nodes of the blockchain network can splice the characters corresponding to each of the multiple binary bit combinations determined from the coding comparison table, and use the spliced result as the first message authentication code. Among them, the data length of the first message authentication code is less than the data length of the authentication code binary data, that is, the number of characters contained in the first message authentication code is less than the number of binary bits contained in the authentication code binary data.
[0109] In one embodiment, the nodes of the blockchain network can determine the number of binary bits contained in the authentication code binary data, and determine whether the number of binary bits contained in the authentication code binary data is an integer multiple of a preset number. When the number of binary bits contained in the authentication code binary data is an integer multiple of a preset number, the nodes of the blockchain network can directly group the binary data to obtain multiple binary bit combinations. Among them, the number of binary bits contained in each binary bit combination is an integer multiple of the preset number.
[0110] In one embodiment, the character index is data represented by hexadecimal. For each binary bit combination, multiple binary bits contained in the binary bit combination are converted into data represented by hexadecimal to obtain the character index corresponding to the binary bit combination.
[0111] In the above embodiment, by grouping the binary bits contained in the authentication code binary data, a plurality of binary bit combinations are obtained, each of which contains a plurality of binary bits. For each binary bit combination, the character index corresponding to the binary bit combination is determined according to the plurality of binary bits contained in the binary bit combination. A coding comparison table is obtained, in which a mapping relationship between a character index and a character in a preset character set is recorded. According to the character indexes corresponding to the plurality of binary bit combinations, the characters corresponding to the plurality of binary bit combinations are determined from the coding comparison table. The characters corresponding to the plurality of binary bit combinations are concatenated to obtain a first message authentication code, wherein the data length of the first message authentication code is less than the data length of the authentication code binary data. Furthermore, when a message authentication code consistent with the first message authentication code is subsequently queried from the authentication code repository, the query efficiency of the message authentication code can be improved, thereby improving the resource transfer efficiency.
[0112] In one embodiment, each binary bit contained in the authentication code binary data is grouped to obtain multiple binary bit combinations, including: determining the number of binary bits contained in the authentication code binary data; when the number is not an integer multiple of a preset number, padding the authentication code binary data to obtain padded binary data, the number of binary bits contained in the padded binary data is an integer multiple of the preset number; grouping the padded binary data to obtain multiple binary bit combinations.
[0113] Specifically, the nodes of the blockchain network can determine the number of binary bits contained in the authentication code binary data, and determine whether the number of binary bits contained in the authentication code binary data is an integer multiple of a preset number. When the number of binary bits contained in the authentication code binary data is not an integer multiple of a preset number, the nodes of the blockchain network can pad the authentication code binary data according to the preset number to obtain the padded binary data. The number of binary bits contained in the padded binary data is an integer multiple of the preset number. Furthermore, the nodes of the blockchain network can group the padded binary data to obtain multiple binary bit combinations. The number of binary bits contained in each bit combination is an integer multiple of the preset number.
[0114] In the above embodiment, by determining the number of binary bits contained in the authentication code binary data. When the number is not an integer multiple of the preset number, the authentication code binary data is padded to obtain the padded binary data, wherein the number of binary bits contained in the padded binary data is an integer multiple of the preset number. Furthermore, the padded binary data is grouped to obtain multiple binary bit combinations, which can improve the accuracy of subsequent encoding. Furthermore, when a message authentication code that is consistent with the first message authentication code is subsequently queried from the authentication code repository, the query efficiency of the message authentication code can be improved, thereby improving the efficiency of resource transfer.
[0115] In one embodiment, the character index is data represented by decimal system, and for each binary bit combination, the character index corresponding to the binary bit combination is determined based on multiple binary bits contained in the binary bit combination, including: for each binary bit combination, the multiple binary bits contained in the binary bit combination are converted into data represented by decimal system to obtain the character index corresponding to the binary bit combination.
[0116] Specifically, for each binary bit combination, the node of the blockchain network can convert multiple binary bits contained in the targeted binary bit combination into data represented by decimal system, and use the converted decimal data as the character index corresponding to the targeted binary bit combination.
[0117] In the above embodiment, for each binary bit combination, by converting multiple binary bits contained in the binary bit combination into data represented by decimal, the character index corresponding to the binary bit combination is obtained, which can improve the efficiency of obtaining the character index, further improve the query efficiency of the message authentication code, and thus further improve the resource transfer efficiency.
[0118] In one embodiment, the method further includes: when a message authentication code consistent with the first message authentication code is queried, stopping the execution of the smart contract and generating a prompt message for indicating that the resource transfer request is a duplicate request.
[0119] Specifically, when a message authentication code consistent with the first message authentication code is queried from the authentication code repository, the node of the blockchain network can stop executing the smart contract, that is, not execute the smart contract set in the node, and generate a prompt message for characterizing that the resource transfer request is a duplicate request.
[0120] In the above embodiment, when a message authentication code consistent with the first message authentication code is queried, indicating that the resource transfer request is a repeated request, the execution of the smart contract is stopped, and a prompt message is generated to indicate that the resource transfer request is a repeated request, thereby avoiding repeated execution of the smart contract during the resource processing process, thereby avoiding malicious repeated transfer of resources and improving the security of resource transfer.
[0121] In one embodiment, the resource processing method based on blockchain of the present application is applied to the virtual resource payment scenario. Figure 8 As shown, the client of the present application can be installed on the user's payment terminal, and the payment terminal can display the resource management page, that is, the "My" page, through the client. The resource management page can display the virtual resource viewing entrance, that is, the "Virtual Resources" displayed in the "My" page. The client can respond to the trigger operation for the "Virtual Resources" and enter the "Virtual Resource Package" page, such as Fig. 9 As shown in FIG. 1 , the “Virtual Resource Package” page may display virtual resources 901. The virtual resources 901 may include detailed virtual resource information such as the resource issuing authority, resource quantity, and resource identifier. The client may respond to the trigger operation of the “touch” control and transfer the virtual resources 901 through touch. Fig.10 As shown, 1001 is a payment terminal in a virtual resource payment scenario, and 1002 is a payment terminal in a virtual resource payment scenario. The payment terminal 1001 and the payment terminal 1002 can realize the transfer of virtual resources 901 by touching each other.
[0122] like Fig.11 As shown, in one embodiment, a resource processing method based on blockchain is provided, and the method is applied to a node of a blockchain network, and a smart contract is set in the node. It can be understood that the node can be a computer device, and the computer device can be a terminal or a server. The method can be executed by the terminal or the server alone, or it can be implemented through the interaction between the terminal and the server. This embodiment is described by taking the method applied to the node of the blockchain network as an example, and the method specifically includes the following steps:
[0123] Step 1102, receiving a resource transfer request from a client, obtaining at least one virtual resource indicated by the resource transfer request, and obtaining authentication code binary data indicated by the resource transfer request.
[0124] Step 1104, determining the number of binary bits contained in the authentication code binary data; when the number is not an integer multiple of a preset number, padding the authentication code binary data to obtain the padded binary data.
[0125] The number of binary bits included in the binary data after the padding is an integer multiple of the preset number.
[0126] Step 1106, grouping the binary data after the padding to obtain a plurality of binary bit combinations, each of which contains a plurality of binary bits.
[0127] Step 1108: for each binary bit combination, convert the multiple binary bits contained in the binary bit combination into data represented by decimal system, and obtain the character index corresponding to the binary bit combination.
[0128] Step 1110, obtaining a coding comparison table, which records a mapping relationship between a character index and a character in a preset character set.
[0129] Step 1112, according to the character indexes corresponding to the multiple binary bit combinations, respectively, determining the characters corresponding to the multiple binary bit combinations from the encoding comparison table.
[0130] Step 1114, concatenate the characters corresponding to the multiple binary bit combinations to obtain a first message authentication code.
[0131] Among them, the first message authentication code includes at least one character, and the characters in the first message authentication code are taken from a preset character set; the first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key; the data length of the first message authentication code is less than the data length of the authentication code binary data.
[0132] Step 1116, when the key length of the encryption key is greater than the block length of the hash function, the encryption key is used as the object of the first round of hash processing, and the first round is used as the current round. The object is hashed through the hash function to obtain the hash value of the current round.
[0133] Step 1118, taking the next round as the current round, and the hash value as the object of this round of hash processing, returning to the step of hashing the object through the hash function, and obtaining the hash value of this round is iteratively executed until the length of the obtained hash value is consistent with the block length, and determining the adjusted encryption key based on the hash value obtained in the last round of hash processing.
[0134] Step 1120: When the key length of the encryption key is less than the block length of the hash function, a byte array having a length consistent with the block length is created.
[0135] Step 1122, fill the encryption key into the byte array, determine the unfilled byte position in the byte array, and fill the preset bytes at the determined byte position to obtain the adjusted encryption key.
[0136] The key length of the adjusted encryption key is consistent with the block length of the hash function.
[0137] Step 1124, merge the adjusted encryption key and the preset constant to obtain a fusion result.
[0138] Step 1126: Perform hash processing on at least one virtual resource indicated by the received resource transfer request using a hash function indicated by the authentication code generation policy to obtain a first hash result.
[0139] Step 1128, generating a second message authentication code according to the fusion result and the first hash result.
[0140] Step 1130: When the first message authentication code is consistent with the second message authentication code, query the authentication code repository for a message authentication code that is consistent with the first message authentication code.
[0141] The authentication code repository is used to store the message authentication code that appears for the first time in the received historical resource transfer request.
[0142] Step 1132, when a message authentication code consistent with the first message authentication code is not found, the smart contract is executed to transfer resources based on at least one virtual resource to obtain a resource transfer result.
[0143] Step 1134, storing the resource transfer result in the blockchain network, and storing the first message authentication code in the authentication code storage library.
[0144] Step 1136: When a message authentication code consistent with the first message authentication code is found, the execution of the smart contract is stopped, and a prompt message is generated to indicate that the resource transfer request is a duplicate request.
[0145] The present application also provides an application scenario, which applies the above-mentioned resource processing method based on blockchain. Specifically, the resource processing method based on blockchain can be applied to the scenario of resource transfer during shopping. When a customer goes to a store to shop and checks out at the cashier, the payment terminal used by the customer to check out is installed with a client. It can be understood that the node in this application can be the cashier's cashier device. Specifically, when checking out, the payment terminal can send a resource transfer request to the cashier device through the client, and the cashier device can receive the resource transfer request of the client, obtain at least one virtual resource indicated by the resource transfer request, and obtain the authentication code binary data indicated by the resource transfer request. Determine the number of binary bits contained in the authentication code binary data; when the number is not an integer multiple of the preset number, the authentication code binary data is padded to obtain the padded binary data. Among them, the number of binary bits contained in the padded binary data is an integer multiple of the preset number. Group the padded binary data to obtain multiple binary bit combinations, each of which contains multiple binary bits. For each binary bit combination, convert the multiple binary bits contained in the binary bit combination into data represented by decimal, and obtain the character index corresponding to the binary bit combination. Obtain a coding comparison table, which records the mapping relationship between the character index and the character in the preset character set. According to the character indexes corresponding to the multiple binary bit combinations, the characters corresponding to the multiple binary bit combinations are determined from the coding comparison table. The characters corresponding to the multiple binary bit combinations are concatenated to obtain a first message authentication code. Among them, the first message authentication code includes at least one character, and the characters in the first message authentication code are taken from the preset character set; the first message authentication code is generated according to the preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key; the data length of the first message authentication code is less than the data length of the authentication code binary data.
[0146] When the key length of the encryption key is greater than the block length of the hash function, the cash register device can use the encryption key as the object of the first round of hash processing, use the first round as the current round, and use the hash function to hash the object to obtain the hash value of the current round. Use the next round as the current round, use the hash value as the object of the current round of hash processing, return to the step of using the hash function to hash the object to obtain the hash value of the current round, and iterate until the length of the obtained hash value is consistent with the block length, and determine the adjusted encryption key based on the hash value obtained in the last round of hash processing. When the key length of the encryption key is less than the block length of the hash function, create a byte array with a length consistent with the block length. Fill the encryption key into the byte array, determine the unfilled byte position in the byte array, and fill the preset byte at the determined byte position to obtain the adjusted encryption key. The key length of the adjusted encryption key is consistent with the block length of the hash function. The adjusted encryption key and the preset constant are merged to obtain a fusion result. Use the hash function indicated by the authentication code generation policy to hash at least one virtual resource indicated by the received resource transfer request to obtain a first hash result. A second message authentication code is generated according to the fusion result and the first hash result. When the first message authentication code is consistent with the second message authentication code, a query is performed from the authentication code repository for a message authentication code consistent with the first message authentication code. The authentication code repository is used to store the message authentication code that first appears in the received historical resource transfer request.
[0147] When a message authentication code consistent with the first message authentication code is not found, the cash register device can execute the smart contract to transfer resources based on at least one virtual resource to obtain a resource transfer result. The resource transfer result is stored in the blockchain network, and the first message authentication code is stored in the authentication code repository. When a message authentication code consistent with the first message authentication code is found, the execution of the smart contract is stopped, and a prompt message is generated to indicate that the resource transfer request is a duplicate request.
[0148] It can be understood that the present application generates a message authentication code corresponding to a virtual resource based on an encryption key and a virtual resource to be submitted to the blockchain network. An authentication code repository is maintained through the message authentication code that first appears in the historical resource transfer request of the cash register device, and the maintained authentication code repository is used to determine whether each received resource transfer request is a repeated request. Only when the resource transfer request is the first request, the cash register device executes the smart contract to transfer resources based on the virtual resource, avoiding repeated execution of the smart contract during the resource transfer process, thereby avoiding repeated payment of resources during shopping and improving the security of resource transfer.
[0149] The present application also provides an application scenario, which applies the above-mentioned resource processing method based on blockchain. Specifically, the resource processing method based on blockchain can be applied to the scenario of resource transfer between two familiar users. It can be understood that the virtual resource in the present application can be money, Xiaohong and Xiaoming are familiar with each other, Xiaohong borrows money from Xiaoming, and the node in the present application can be the payment terminal held by Xiaohong, and the payment terminal held by Xiaoming is installed with a client. Specifically, when Xiaoming lends money to Xiaohong, the payment terminal held by Xiaoming can send a resource transfer request to the payment terminal held by Xiaohong through the client, and the payment terminal can receive the resource transfer request of the client, obtain at least one virtual resource indicated by the resource transfer request, and obtain the first message authentication code indicated by the resource transfer request. The first message authentication code is generated according to the preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key. The message authentication code consistent with the first message authentication code is queried from the authentication code repository, and the authentication code repository is used to store the message authentication code that appears for the first time in the received historical resource transfer request. When a message authentication code consistent with the first message authentication code is not found, the smart contract is executed to transfer resources based on at least one virtual resource to obtain a resource transfer result. The resource transfer result is stored in the blockchain network, and the first message authentication code is stored in the authentication code repository.
[0150] It can be understood that the present application generates a message authentication code corresponding to the virtual resource based on the encryption key and the virtual resource to be submitted to the blockchain network. Through the message authentication code that first appears in the historical resource transfer request of the payment terminal, an authentication code repository is maintained, and the maintained authentication code repository is used to determine whether each received resource transfer request is a repeated request. Only when the resource transfer request is the first request, the smart contract is executed to transfer resources based on virtual resources, thereby avoiding repeated execution of smart contracts during resource processing, thereby avoiding malicious repeated transfer of resources and improving the security of resource transfer.
[0151] It should be understood that, although each step in the flow chart of the above-mentioned embodiments is shown in order, these steps are not necessarily performed in order. Unless there is a clear explanation in this article, the execution of these steps does not have strict order restrictions, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the above-mentioned embodiments may include a plurality of sub-steps or a plurality of stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these sub-steps or stages is not necessarily performed in order, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.
[0152] In one embodiment, Fig.12As shown, a resource processing device 1200 based on blockchain is provided, which is applied to a node of a blockchain network, and a smart contract is set in the node. The device specifically includes:
[0153] The receiving module 1202 is used to receive a resource transfer request from a client;
[0154] The acquisition module 1204 is used to acquire at least one virtual resource indicated by the resource transfer request, and acquire a first message authentication code indicated by the resource transfer request; the first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key;
[0155] A query module 1206, configured to query a message authentication code that is consistent with the first message authentication code from an authentication code repository, the authentication code repository being configured to store the message authentication code that first appears in a received historical resource transfer request;
[0156] The transfer module 1208 is configured to execute the smart contract to transfer resources based on at least one virtual resource and obtain a resource transfer result when a message authentication code consistent with the first message authentication code is not found;
[0157] The storage module 1210 is used to store the resource transfer result in the blockchain network and store the first message authentication code in the authentication code storage library.
[0158] In one embodiment, Fig.13 As shown, the device also includes:
[0159] The authentication module 1212 is used to generate a second message authentication code according to the authentication code generation strategy, based on the encryption key, and at least one virtual resource indicated by the received resource transfer request; when the first message authentication code is consistent with the second message authentication code, the query module 1206 is notified to execute the step of querying the message authentication code consistent with the first message authentication code from the authentication code repository.
[0160] In one embodiment, the authentication module 1212 is also used to fuse the encryption key and the preset constant to obtain a fusion result; generate a hash function indicated by the authentication code strategy, hash at least one virtual resource indicated by the received resource transfer request, and obtain a first hash result; generate a second message authentication code based on the fusion result and the first hash result.
[0161] In one embodiment, the preset constants include a first preset constant and a second preset constant, and the fusion result includes a first fusion result and a second fusion result, the first fusion result is obtained by fusing the encryption key and the first preset constant, and the second fusion result is obtained by fusing the encryption key and the second preset constant; the authentication module 1212 is also used to fuse the first fusion result and the first hash result to obtain a third fusion result; hash the third fusion result through a hash function to obtain a second hash result; fuse the second fusion result and the second hash result to obtain a fourth fusion result; hash the fourth fusion result through a hash function to obtain a second message authentication code.
[0162] In one embodiment, the authentication module 1212 is also used to adjust the key length of the encryption key to obtain an adjusted encryption key when the key length of the encryption key is inconsistent with the block length of the hash function; the key length of the adjusted encryption key is consistent with the block length of the hash function; and the adjusted encryption key is merged with a preset constant to obtain a fusion result.
[0163] In one embodiment, the authentication module 1212 is also used to, when the key length of the encryption key is greater than the block length of the hash function, use the encryption key as the object of the first round of hash processing, use the first round as the current round, hash the object through the hash function, and obtain the hash value of the current round; use the next round as the current round, use the hash value as the object of the current round of hash processing, return to the step of hashing the object through the hash function, and iteratively execute the steps of obtaining the hash value of the current round until the length of the obtained hash value is consistent with the block length, and determine the adjusted encryption key based on the hash value obtained from the last round of hash processing.
[0164] In one embodiment, the authentication module 1212 is also used to create a byte array with a length consistent with the block length when the key length of the encryption key is less than the block length of the hash function; fill the encryption key into the byte array; determine the unfilled byte position in the byte array, and fill the preset bytes at the determined byte position to obtain the adjusted encryption key.
[0165] In one embodiment, any message authentication code stored in the authentication code repository includes at least one character, and the characters in any message authentication code are taken from a preset character set. The acquisition module 1204 is also used to obtain the authentication code binary data indicated by the resource transfer request; encode the authentication code binary data to obtain a first message authentication code, and the first message authentication code includes at least one character, and the characters in the first message authentication code are taken from a preset character set.
[0166] In one embodiment, the acquisition module 1204 is also used to group the binary bits contained in the authentication code binary data to obtain multiple binary bit combinations, each binary bit combination containing multiple binary bits; for each binary bit combination, determine the character index corresponding to the binary bit combination according to the multiple binary bits contained in the binary bit combination; obtain a coding comparison table, which records the mapping relationship between the character index and the characters in the preset character set; according to the character indexes corresponding to the multiple binary bit combinations, respectively, determine the characters corresponding to the multiple binary bit combinations from the coding comparison table; splice the characters corresponding to the multiple binary bit combinations to obtain a first message authentication code, and the data length of the first message authentication code is less than the data length of the authentication code binary data.
[0167] In one embodiment, the acquisition module 1204 is also used to determine the number of binary bits contained in the authentication code binary data; when the number is not an integer multiple of a preset number, the authentication code binary data is padded to obtain the padded binary data, and the number of binary bits contained in the padded binary data is an integer multiple of the preset number; the padded binary data is grouped to obtain multiple binary bit combinations.
[0168] In one embodiment, the character index is data represented by decimal system, and the acquisition module 1204 is further used to convert multiple binary bits contained in the targeted binary bit combination into data represented by decimal system for each binary bit combination, so as to obtain the character index corresponding to the targeted binary bit combination.
[0169] In one embodiment, the transfer module 1208 is further used to stop executing the smart contract when a message authentication code consistent with the first message authentication code is queried, and generate a prompt message for indicating that the resource transfer request is a duplicate request.
[0170] The above-mentioned resource processing device based on blockchain, by receiving a resource transfer request from a client, obtains at least one virtual resource indicated by the resource transfer request, and obtains the first message authentication code indicated by the resource transfer request, the first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key. Query the message authentication code consistent with the first message authentication code from the authentication code repository, the authentication code repository is used to store the message authentication code that first appears in the received historical resource transfer request. When the message authentication code consistent with the first message authentication code is not queried, the smart contract is executed to transfer resources based on at least one virtual resource to obtain the resource transfer result. The resource transfer result is stored in the blockchain network, and the first message authentication code is stored in the authentication code repository. Compared with the traditional resource processing method, the present application generates a message authentication code corresponding to the virtual resource based on the encryption key and the virtual resource to be submitted to the blockchain network. An authentication code repository is maintained through the message authentication code that first appears in the historical resource transfer request of the node, and the maintained authentication code repository is used to determine whether each resource transfer request received is a repeated request. Only when the resource transfer request is the first request, the smart contract is executed to transfer resources based on virtual resources, avoiding the repeated execution of smart contracts in the resource processing process, thereby avoiding malicious repeated transfer of resources and improving the security of resource transfer.
[0171] Each module in the above-mentioned blockchain-based resource processing device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0172] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Fig.14As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a resource processing method based on blockchain is implemented.
[0173] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Fig.15 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless method can be implemented through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a resource processing method based on blockchain is implemented. The display unit of the computer device is used to form a visually visible image, and can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covered on the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse, etc.
[0174] Those skilled in the art will understand that Fig.14 and Fig.15The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0175] In one embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above method embodiments when executing the computer program.
[0176] In one embodiment, a computer-readable storage medium is provided, storing a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0177] In one embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0178] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.
[0179] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), tape, floppy disk, flash memory or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0180] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0181] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the attached claims.
Claims
1. A resource processing method based on blockchain, It is characterized in that A node applied to a blockchain network, wherein a smart contract is provided in the node, and the method comprises: Receive resource transfer request from client; Obtain at least one virtual resource indicated by the resource transfer request, and obtain a first message authentication code indicated by the resource transfer request; the first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key; Querying a message authentication code consistent with the first message authentication code from an authentication code repository, the authentication code repository being used to store a message authentication code that first appears in a received historical resource transfer request; When a message authentication code consistent with the first message authentication code is not found, executing the smart contract to transfer resources based on the at least one virtual resource and obtaining a resource transfer result; The resource transfer result is stored in the blockchain network, and the first message authentication code is stored in the authentication code repository.
2. The method according to claim 1, It is characterized in that The method further comprises: Generate a second message authentication code according to the authentication code generation strategy, the encryption key, and at least one virtual resource indicated by the received resource transfer request; When the first message authentication code is consistent with the second message authentication code, the step of querying the authentication code repository for a message authentication code consistent with the first message authentication code is performed.
3. The method according to claim 2, It is characterized in that The step of generating a second message authentication code according to the authentication code generation strategy, the encryption key, and at least one virtual resource indicated by the received resource transfer request comprises: Merging the encryption key and the preset constant to obtain a fusion result; Performing hash processing on at least one virtual resource indicated by the received resource transfer request through a hash function indicated by the authentication code generation policy to obtain a first hash result; A second message authentication code is generated according to the fusion result and the first hash result.
4. The method according to claim 3, It is characterized in that The preset constants include a first preset constant and a second preset constant, the fusion result includes a first fusion result and a second fusion result, the first fusion result is obtained by fusion of the encryption key and the first preset constant, and the second fusion result is obtained by fusion of the encryption key and the second preset constant; The generating a second message authentication code according to the fusion result and the first hash result includes: Fusing the first fusion result and the first hash result to obtain a third fusion result; Performing hash processing on the third fusion result by using the hash function to obtain a second hash result; Fusing the second fusion result and the second hash result to obtain a fourth fusion result; The fourth fusion result is hashed by the hash function to obtain a second message authentication code.
5. The method according to claim 3, It is characterized in that The step of fusing the encryption key and the preset constant to obtain a fusion result includes: When the key length of the encryption key is inconsistent with the block length of the Hash function, the key length of the encryption key is adjusted to obtain an adjusted encryption key; the key length of the adjusted encryption key is consistent with the block length of the Hash function; The adjusted encryption key and the preset constant are merged to obtain a fusion result.
6. The method according to claim 5, It is characterized in that When the key length of the encryption key is inconsistent with the block length of the hash function, adjusting the key length of the encryption key to obtain the adjusted encryption key includes: When the key length of the encryption key is greater than the block length of the hash function, the encryption key is used as the object of the first round of hash processing, the first round is used as the current round, and the object is hashed through the hash function to obtain the hash value of the current round; The next round is taken as the current round, and the hash value is taken as the object of hash processing in this round. The steps of hashing the object through the hash function to obtain the hash value of this round are returned and iteratively executed until the length of the obtained hash value is consistent with the block length, and the adjusted encryption key is determined based on the hash value obtained in the last round of hash processing.
7. The method according to claim 5, It is characterized in that When the key length of the encryption key is inconsistent with the block length of the hash function, adjusting the key length of the encryption key to obtain the adjusted encryption key includes: When the key length of the encryption key is less than the block length of the hash function, creating a byte array with a length consistent with the block length; Fill the byte array with the encryption key; In the byte array, unfilled byte positions are determined, and preset bytes are filled at the determined byte positions to obtain an adjusted encryption key.
8. The method according to claim 1, It is characterized in that Any message authentication code stored in the authentication code storage repository includes at least one character, and the characters in any message authentication code are taken from a preset character set. The obtaining of the first message authentication code indicated by the resource transfer request includes: Obtaining authentication code binary data indicated by the resource transfer request; The authentication code binary data is encoded to obtain a first message authentication code, wherein the first message authentication code includes at least one character, and the characters in the first message authentication code are taken from the preset character set.
9. The method according to claim 8, It is characterized in that The step of encoding the authentication code binary data to obtain a first message authentication code comprises: Grouping the binary bits contained in the authentication code binary data to obtain a plurality of binary bit combinations, each of which contains a plurality of binary bits; For each of the binary bit combinations, determine a character index corresponding to the binary bit combination according to a plurality of binary bits contained in the binary bit combination; Obtaining a coding comparison table, wherein the coding comparison table records a mapping relationship between a character index and a character in the preset character set; Determine the characters corresponding to the multiple binary bit combinations from the encoding comparison table according to the character indexes corresponding to the multiple binary bit combinations respectively; The characters corresponding to the multiple binary bit combinations are concatenated to obtain a first message authentication code, wherein the data length of the first message authentication code is smaller than the data length of the authentication code binary data.
10. The method according to claim 9, It is characterized in that The step of grouping the binary bits contained in the authentication code binary data to obtain a plurality of binary bit combinations includes: Determining the number of binary bits contained in the authentication code binary data; When the number is not an integer multiple of the preset number, the authentication code binary data is padded to obtain padded binary data, wherein the number of binary bits contained in the padded binary data is an integer multiple of the preset number; The padded binary data are grouped to obtain a plurality of binary bit combinations.
11. The method according to claim 9, It is characterized in that The character index is data represented in decimal, and for each binary bit combination, determining the character index corresponding to the binary bit combination according to a plurality of binary bits contained in the binary bit combination includes: For each of the binary bit combinations, multiple binary bits contained in the targeted binary bit combination are converted into data represented by decimal system, and a character index corresponding to the targeted binary bit combination is obtained.
12. The method according to any one of claims 1 to 11, It is characterized in that The method further comprises: When a message authentication code consistent with the first message authentication code is queried, execution of the smart contract is stopped, and prompt information is generated to indicate that the resource transfer request is a duplicate request.
13. A resource processing device based on blockchain, It is characterized in that A node applied to a blockchain network, wherein a smart contract is provided in the node, and the device comprises: A receiving module, used for receiving a resource transfer request from a client; An acquisition module, used to acquire at least one virtual resource indicated by the resource transfer request, and acquire a first message authentication code indicated by the resource transfer request; the first message authentication code is generated according to a preset authentication code generation strategy, based on at least one virtual resource to be submitted to the blockchain network and a preset encryption key; A query module, configured to query a message authentication code consistent with the first message authentication code from an authentication code repository, wherein the authentication code repository is configured to store a message authentication code that first appears in a received historical resource transfer request; A transfer module, configured to execute the smart contract when a message authentication code consistent with the first message authentication code is not found, so as to transfer resources based on the at least one virtual resource and obtain a resource transfer result; A storage module is used to store the resource transfer result in the blockchain network and store the first message authentication code in the authentication code repository.
14. A computer device comprising a memory and a processor, wherein the memory stores a computer program. It is characterized in that When the processor executes the computer program, the steps of the method according to any one of claims 1 to 12 are implemented.
15. A computer-readable storage medium storing a computer program, It is characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.
16. A computer program product comprising a computer program, It is characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.