Physical equipment data uplink method and device, equipment and storage medium

Digital signature processing is carried out through the SDK and data is sent to the blockchain service platform, which solves the problem of on-chain and proof-keeping of physical equipment data, realizes the security, integrity and reliability of data, and provides dual security guarantees of classic and post-quantum digital signature algorithms.

CN120128343APending Publication Date: 2025-06-10ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510349617.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

It is difficult for the prior art to effectively carry out data from physical devices on the link and verify, ensuring the integrity, authenticity and reliability of the data.

Method used

By using the SDK for digital signature processing, the first key pair of classic digital signature processing and the second key pair of post-quantum digital signature processing are obtained, and the nested form of hybrid digital signature mechanism is realized, and the device data, first signature data and second signature data are sent to the blockchain service platform for on-chain storage.

Benefits of technology

It realizes the safe way to put the equipment data of physical equipment on the link and store evidence, ensures the integrity, authenticity and reliability of the data, and provides dual security guarantees of classic and post-quantum digital signature algorithms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128343A_ABST
    Figure CN120128343A_ABST
Patent Text Reader

Abstract

One or more embodiments of the invention provide a physical equipment data uplink method and device, equipment and a storage medium, which are applied to physical equipment. The method comprises the following steps: initializing an SDK (Software Development Kit), and acquiring a first key pair and a second key pair by the SDK; sending the acquired device data to an SDK, performing classical digital signature processing on the device data by the SDK based on a private key in a first key pair to obtain first signature data, and performing post-quantum digital signature processing on the device data and the first signature data based on a private key in a second key pair to obtain second signature data; and sending the device data, the first signature data and the second signature data to a block chain service platform, verifying the second signature data based on a public key in the second key pair by the block chain service platform, verifying the first signature data based on a public key in the first key pair after the verification of the second signature data is passed, and sending the verification result to the block chain service platform. And after the verification of the first signature data is passed, publishing the device data to a block chain for uplink evidence storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present application relate to the field of information security technology, and in particular, to a method, device, equipment, and storage medium for uploading physical device data to a blockchain. Background Art

[0002] The Internet of Things (IoT) refers to a network that connects various information sensing devices (such as radio frequency identification, infrared sensors, laser scanners, global positioning systems, etc.) to objects (such as home appliances, cars, mechanical equipment, energy equipment, etc.) through the Internet for communication and information exchange to achieve intelligent identification, positioning, tracking, monitoring, and management. It expands the concept of the Internet, no longer limited to information exchange between people, but also enabling information interaction between things and between things and people. IoT devices refer to those physical objects that can be connected through the Internet and exchange data with other devices or systems. These devices are usually embedded with sensors, software, and other technologies to achieve data collection, data interaction with the Internet or other devices, and automation functions. With the development of information technology, the IoT has become a bridge connecting the physical world and the digital world, greatly promoting the intelligent process of all industries.

[0003] Similarly to IoT devices, in actual applications, there are also various physical devices that not only have certain value attributes themselves but can also continuously generate valuable data through their internal sensors and systems. Generally, these physical devices can be regarded as physical assets, and the data that can reflect the authenticity and value of the physical devices, such as data on the unique identifier, operating status, and performance indicators of the physical devices, can be regarded as physical asset data.

[0004] Blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus protocols, and cryptographic algorithms. In a blockchain system, data blocks are connected in sequence according to time order to form a chain-like data structure, and are ensured to be tamper-proof and forgery-proof through cryptographic methods, constituting a distributed ledger. In the wave of industrial digitalization development, the blockchain system, with its unique characteristics of decentralization, immutability, and transparency and security, is becoming an ideal platform for the value transfer of physical assets. This usually means that physical asset data needs to be uploaded to the blockchain for deposit to achieve the link and integration of physical assets and digital assets on the chain. Summary of the Invention

[0005] One or more embodiments of the present application provide the following technical solutions:

[0006] The present application provides a method for uploading physical device data, which is applied to a physical device; the method includes:

[0007] Initialize an SDK for digitally signing the device data of the physical device, so that the SDK obtains a first key pair for classical digital signature processing and a second key pair for post-quantum digital signature processing;

[0008] Obtain the device data, and call the SDK to send the device data to the SDK, so that the SDK performs classical digital signature processing on the device data based on the classical digital signature algorithm and the private key in the first key pair to obtain first signature data, and performs post-quantum digital signature processing on the device data and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair to obtain second signature data;

[0009] Send the device data, the first signature data, and the second signature data to the blockchain service platform accessed by the physical device, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the verification of the second signature data passes, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the verification of the first signature data passes, publishes the device data to the blockchain for on-chain storage.

[0010] This application also provides a method for uploading physical device data to the blockchain, which is applied to the blockchain service platform accessed by the physical device; the method includes:

[0011] Obtain the public key in the first key pair for classical digital signature processing and the public key in the second key pair for post-quantum digital signature processing, and obtain the device data, the first signature data, and the second signature data of the physical device sent by the physical device; wherein, the first key pair and the second key pair are obtained by the SDK for digitally signing the device data of the physical device during initialization; the first signature data is obtained by the SDK performing classical digital signature processing on the device data based on the classical digital signature algorithm and the private key in the first key pair; the second signature data is obtained by the SDK performing post-quantum digital signature processing on the device data and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair;

[0012] Verify the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair;

[0013] After the verification of the second signature data passes, verify the first signature data based on the classical digital signature algorithm and the public key in the first key pair;

[0014] After the first signature data passes the verification, the device data is published to the blockchain for on-chain storage and evidence preservation.

[0015] This application also provides a device for uploading physical device data to the blockchain, which is applied to a physical device; the device includes:

[0016] An initialization module initializes an SDK for digitally signing the device data of the physical device, so that the SDK obtains a first key pair for classical digital signature processing and a second key pair for post-quantum digital signature processing;

[0017] A signature module obtains the device data and calls the SDK to send the device data to the SDK, so that the SDK performs classical digital signature processing on the device data based on the classical digital signature algorithm and the private key in the first key pair to obtain first signature data, and performs post-quantum digital signature processing on the device data and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair to obtain second signature data;

[0018] A sending module sends the device data, the first signature data, and the second signature data to the blockchain service platform accessed by the physical device, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the second signature data passes the verification, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the first signature data passes the verification, publishes the device data to the blockchain for on-chain storage and evidence preservation.

[0019] This application also provides a device for uploading physical device data to the blockchain, which is applied to the blockchain service platform accessed by the physical device; the device includes:

[0020] An acquisition module acquires the public key in the first key pair for classical digital signature processing and the public key in the second key pair for post-quantum digital signature processing, and acquires the device data, the first signature data, and the second signature data of the physical device sent by the physical device; wherein, the first key pair and the second key pair are acquired by the SDK for digitally signing the device data of the physical device during initialization; the first signature data is obtained by the SDK performing classical digital signature processing on the device data based on the classical digital signature algorithm and the private key in the first key pair; the second signature data is obtained by the SDK performing post-quantum digital signature processing on the device data and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair;

[0021] The first verification module verifies the second signature data based on the post - quantum digital signature algorithm and the public key in the second key pair;

[0022] The second verification module, after the second signature data passes the verification, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair;

[0023] The on - chain module, after the first signature data passes the verification, publishes the device data to the blockchain for on - chain storage and evidence preservation.

[0024] This application also provides an electronic device, including:

[0025] A processor;

[0026] A memory for storing instructions executable by the processor;

[0027] Wherein, the processor realizes the steps of the method as described in any one of the above by running the executable instructions.

[0028] This application also provides a computer - readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method as described in any one of the above are realized.

[0029] In the above technical solution, first, an SDK for digitally signing the device data of a physical device can obtain a first key pair for classical digital signature processing and a second key pair for post - quantum digital signature processing; then, the SDK can be called to send the device data of the physical device to the SDK. The SDK first performs classical digital signature processing on the device data of the physical device based on the classical digital signature algorithm and the private key in the first key pair to obtain first signature data, and then performs post - quantum digital signature processing on the device data of the physical device and the first signature data based on the post - quantum digital signature algorithm and the private key in the second key pair to obtain second signature data, thereby implementing a nested - form hybrid digital signature mechanism; finally, the physical device can send its device data, first signature data, and second signature data to the blockchain service platform accessed by the physical device. The blockchain service platform first verifies the second signature data based on the aforementioned post - quantum digital signature algorithm and the public key in the second key pair. After the second signature data passes the verification, it then verifies the first signature data based on the aforementioned digital signature algorithm and the public key in the first key pair. After the first signature data also passes the verification, the device data of the physical device can be published to the blockchain for on - chain storage and evidence preservation.

[0030] By adopting the above method, it is possible to securely publish the device - related data of the physical device or the business data generated during the device operation to the blockchain for on - chain storage and proof, ensuring the integrity, authenticity, and reliability of the device data of the physical device. Moreover, during the process of storing the device data on the chain, a nested hybrid digital signature mechanism constructed by a classical digital signature algorithm and a post - quantum digital signature algorithm can be introduced. Based on this hybrid digital signature mechanism, digital signature processing and digital signature verification are performed on the device data to be chained. Thus, it can be ensured that the security of the device data is not lower than the security provided by the classical digital signature algorithm, and further security protection can be provided by the post - quantum digital signature algorithm. In addition, the nested hybrid digital signature mechanism can ensure that when an attacker cannot break both the classical digital signature algorithm and the post - quantum digital signature algorithm simultaneously, the final signature data cannot be forged. Description of the Drawings

[0031] The drawings required for the description of the exemplary embodiments will be described below, where:

[0032] Figure 1 is a schematic diagram of a network environment related to the blockchain shown in an exemplary embodiment of this specification.

[0033] Figure 2 is a flowchart of a method for chaining physical device data shown in an exemplary embodiment of this application.

[0034] Figure 3 is a flowchart of another method for chaining physical device data shown in an exemplary embodiment of this application.

[0035] Figure 4 is a multi - party interaction diagram during the process of chaining physical device data shown in an exemplary embodiment of this application.

[0036] Figure 5 is a schematic structural diagram of a device shown in an exemplary embodiment of this application.

[0037] Figure 6 is a block diagram of a device for chaining physical device data shown in an exemplary embodiment of this application.

[0038] Figure 7 is a block diagram of another device for chaining physical device data shown in an exemplary embodiment of this application. Detailed Embodiments

[0039] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with one or more embodiments of the present application. On the contrary, they are merely examples consistent with some aspects of one or more embodiments of the present application.

[0040] It should be noted that in other embodiments, the steps of the corresponding methods are not necessarily executed in the order shown and described in the present application. In some other embodiments, the steps included in the method may be more or fewer than those described in the present application. In addition, a single step described in the present application may be decomposed into multiple steps for description in other embodiments; and multiple steps described in the present application may also be combined into a single step for description in other embodiments.

[0041] In the present application, a physical device refers to a device existing in a physical form, which has certain value attributes by itself and can continuously generate valuable data through its internal sensors and systems. For data that can reflect the authenticity and value of a physical device, such as data on the unique identifier, operating status, and performance indicators of the physical device, using a blockchain system with characteristics such as decentralization, immutability, and transparency and security to store such data on the chain for certification helps the process of digitalization of physical assets on the chain.

[0042] Blockchains are generally divided into three types: public blockchains, private blockchains, and consortium blockchains. In addition, there can also be combinations of the above multiple types, such as the combination of a private blockchain and a consortium blockchain, the combination of a consortium blockchain and a public blockchain, etc.

[0043] Among the above three types of blockchains, the public blockchain has the highest degree of decentralization. The participants who join the public blockchain (which can also be called nodes in the blockchain) can read the data records on the chain, participate in transactions, compete for the right to record new blocks, etc. Moreover, each node can freely join or exit the network and perform related operations.

[0044] On the contrary, for a private blockchain, the write permission of the network is controlled by a certain organization (or entity institution), and the data read permission is subject to the organization's regulations. That is to say, a private blockchain can be regarded as a weakly centralized system, which has strict restrictions on nodes and a small number of nodes. This type of blockchain is more suitable for internal use within a specific institution.

[0045] Alliance chains lie between public chains and private chains and can achieve "partial decentralization". Each node in an alliance chain usually corresponds to an organization (or entity); nodes join the network through authorization and form an interest-related alliance to jointly maintain the operation of the blockchain.

[0046] In a blockchain network, a node is a logical communication entity; multiple blockchain nodes of different types can run on the same physical server or on different physical servers.

[0047] Based on the basic characteristics of the blockchain, a blockchain is usually composed of several blocks. Each of these blocks records a timestamp corresponding to the creation moment of the block, and all the blocks strictly form an ordered data chain in terms of time according to the timestamps recorded in the blocks.

[0048] For the data generated outside the blockchain, these data can be constructed into the standard transaction format supported by the blockchain and then published to the blockchain. The nodes participating in the consensus in the blockchain system conduct consensus on this transaction and execute this transaction after the consensus is completed, so that this transaction and the execution result can be persistently stored and certified in the blockchain.

[0049] In a blockchain system, different participating parties can establish a distributed blockchain network through the deployed nodes. In practical applications, the connection relationships between each node and different nodes can be regarded as the blockchain network, and the connection relationships, data interactions, etc. between each node and different nodes can be regarded as the blockchain system. Among them, a decentralized (or multi-centered) distributed ledger constructed using a chained block structure is stored on each node (or most nodes, such as consensus nodes) in the distributed blockchain network. This type of blockchain system needs to solve the problems of consistency and correctness of the ledger data on each of the decentralized (or multi-centered) multiple nodes. A blockchain program runs on each node in the blockchain system. Under the design of a certain fault tolerance requirement, the consensus protocol ensures that all loyal nodes have the same transactions, so as to ensure that all loyal nodes have the same execution results for the same transactions, and the transactions and execution results are packaged to generate blocks.

[0050] The nodes in a blockchain system can usually be divided into two categories: consensus nodes and non-consensus nodes. Among them, a consensus node is a node that runs the consensus protocol. A non-consensus node can forward the transactions sent by the client received to the consensus node. The consensus node can propose transactions, attempt to construct blocks, and send the constructed blocks to other nodes, so that both the consensus node and the non-consensus node can store the block.

[0051] Specifically, the consensus nodes in the blockchain system can, based on the consensus protocol, reach a consensus on the transactions included in the new block to be connected to the chained block structure, so as to ensure that all consensus nodes reach an agreement on the content and order of the transactions included in the block, thereby realizing the construction of the block. After the consensus is completed, the consensus nodes can send the constructed block to other nodes, so that each node can execute the transactions included in the block in sequence, and complete the finalization of the block when it is confirmed that the transaction execution results of all nodes are consistent. Among them, finalization means that the transactions included in the block are executed and the transaction execution results are recognized by all nodes (or a certain number of nodes, such as two-thirds of the nodes).

[0052] Any consensus node in the blockchain system can broadcast a message every time it finishes executing the transactions included in a block that has completed consensus. This message can indicate that the block has completed consensus and the included transactions have been executed. Therefore, based on this message, it can be confirmed whether the transaction execution results of all consensus nodes for this block are consistent, so that the finalization of the block can be completed when it is confirmed that the transaction execution results of all consensus nodes are consistent.

[0053] Please refer to Figure 1 , Figure 1 which is a schematic diagram of a network environment related to blockchain shown in an exemplary embodiment of this specification.

[0054] In the network environment as Figure 1 shown, it may include client-side computing devices 101, a server-side 102, and at least one blockchain system; for example, blockchain systems 103, 104, and 105.

[0055] The client-side computing devices 101 can include various different types of client-side computing devices; for example, the client-side computing devices 101 can include, such as PC computing devices, mobile computing devices, Internet of Things devices, and other forms of intelligent devices with certain computing capabilities, and so on.

[0056] It should be noted that the client-side computing devices 101 do not mean that all of these client-side computing devices are in the same communication network, but are only a general term for these client-side computing devices.

[0057] Some of the computing devices in the client-side computing devices 101 can be coupled to the server-side 102 through various communication networks; for example, device 3 is coupled to the server-side 102. Some of the computing devices in the client-side computing devices 101 can also be not coupled to the server-side 102, but directly coupled to the blockchain system; for example, device 4 can be directly coupled to the blockchain system 103.

[0058] The client-side computing device 101 may also include one or more user-side servers; for example, Device 5 and Device 6. Some of the computing devices in the client-side computing device 101 may be coupled to the user-side server; for example, Device 1 is coupled to Device 5, and Device 2 is coupled to Device 6. The user-side server may be further directly coupled to the blockchain system, or may be further coupled to the server-side 102 through various communication networks; for example, Device 5 may be further directly coupled to the blockchain system, and Device 6 is further coupled to the server-side 102.

[0059] The above user-side server may be implemented by a service entity that has built a user account system; the above service entity may include an operating entity of a service carrier that provides various online and / or offline services to users. Accordingly, the above operating entity may include the operator corresponding to the above service carrier; for example, the above operating entity may include individuals, organizations, companies, and enterprises that operate and manage the above service carrier, and so on.

[0060] The server-side 102 may also be coupled to one or more blockchain systems through various communication networks; for example, the server-side 102 is respectively coupled to the blockchain system 103, the blockchain system 104, and the blockchain system 105, and so on.

[0061] The above communication network may include a wired and / or wireless communication network; for example, it may be a local area network (LAN), a wide area network (WAN), the Internet, or a combination thereof implemented based on a wired access network or a wireless access network provided by an operator (such as a mobile cellular network, etc.).

[0062] Each blockchain system may maintain one or more blockchains (such as a public blockchain, a private blockchain, a consortium blockchain, etc.), and include multiple blockchain nodes for hosting the above one or more blockchains; for example, the blockchain nodes 1, 2, 3, 4, i, etc. shown in Figure 1 may jointly host one or more blockchains. Cross-chain data access may also be performed between the blockchains included in each blockchain system, and between each blockchain system.

[0063] A blockchain node can be a physical device or a virtual device implemented in a server or a server cluster. For example, a blockchain node can be a physical host in a server cluster or a virtual machine created after virtualizing the hardware resources carried by a server or a server cluster based on virtualization technology. Each blockchain node can be coupled together through various types of communication methods (such as TCP / IP, etc.) to form a network to host one or more blockchains.

[0064] The server side 102 may include a blockchain service platform. For example, a BaaS platform (also known as BaaS cloud) for providing blockchain services (BaaS, Blockchain as a Service). The BaaS platform can provide blockchain services to client-side computing devices coupled to the BaaS platform by providing pre-written software for activities occurring on the blockchain (such as subscription and notification, user authentication, database management, remote update, etc.).

[0065] In practical applications, blockchain services can be deployed on the blockchain in the form of smart contracts. When an application running on a client-side computing device uses blockchain services, it can send a request to the blockchain system to call the corresponding smart contract deployed on the blockchain to invoke the smart contract deployed on the blockchain.

[0066] As a distributed ledger technology, blockchain has attracted much attention due to its unique features. Its main advantages include a decentralized architecture, immutability, security, transparency, and traceability, etc. Among them, the decentralized architecture means that the blockchain adopts a peer-to-peer network structure without a single control node, which reduces the risk of single-point failures and enhances the system's anti-censorship ability. Immutability means that the blockchain ensures that once each transaction record is confirmed and added to the chain, it cannot be easily modified or deleted, thus ensuring the integrity and authenticity of the data. Security means that through the consensus protocol, the blockchain effectively prevents unauthorized access and malicious tampering, providing a highly secure data storage and transmission solution. Transparency and traceability mean that all transaction information is publicly transparent, permanently stored, and can be traced, which is of great significance for improving supply chain transparency, tracing product sources, etc.

[0067] Given the characteristics of the above blockchain system, uploading physical device data to the blockchain for evidence storage has many advantages and helps the digitalization process of physical assets on the blockchain. The immutability of the blockchain provides strong guarantee for the authenticity of physical device data, ensuring the consistency and reliability of data at every link from source collection to final use. With the security protection measures of the blockchain, unauthorized data access and malware intrusion can be effectively prevented. By recording physical device data on the blockchain, the full life cycle tracking of products can be achieved, facilitating the rapid location of the problem source and taking corresponding measures. Based on the blockchain platform, different enterprises and institutions can share valuable information without sacrificing their respective data sovereignty, jointly promoting industry standards and technological progress.

[0068] One or more embodiments of the present application provide a technical solution for uploading physical device data to the blockchain. In this technical solution, first, an SDK for digitally signing the device data of a physical device can obtain a first key pair for classical digital signature processing and a second key pair for post-quantum digital signature processing. Then, the SDK can be called to send the device data of the physical device to the SDK. The SDK first performs classical digital signature processing on the device data of the physical device based on the classical digital signature algorithm and the private key in the first key pair to obtain first signature data, and then performs post-quantum digital signature processing on the device data of the physical device and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair to obtain second signature data, thereby implementing a nested hybrid digital signature mechanism. Finally, the physical device can send its device data, first signature data, and second signature data to the blockchain service platform accessed by the physical device. The blockchain service platform first verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair. After the second signature data is verified, it then verifies the first signature data based on the digital signature algorithm and the public key in the first key pair. After the first signature data is also verified, the device data of the physical device can be published to the blockchain for uploading and evidence storage.

[0069] By adopting the above method, it is possible to securely publish the device - related data of the physical device or the business data generated during the device operation to the blockchain for on - chain storage and evidence, ensuring the integrity, authenticity, and reliability of the device data of the physical device. Moreover, during the process of storing the device data on the blockchain as evidence, a nested hybrid digital signature mechanism constructed by a classical digital signature algorithm and a post - quantum digital signature algorithm can be introduced. Based on this hybrid digital signature mechanism, digital signature processing and digital signature verification are performed on the device data to be uploaded to the chain. Thus, it can be ensured that the security of the device data is not lower than the security provided by the classical digital signature algorithm, and further security protection can be provided by the post - quantum digital signature algorithm. In addition, the nested hybrid digital signature mechanism can ensure that when an attacker cannot break both the classical digital signature algorithm and the post - quantum digital signature algorithm simultaneously, they cannot forge the final signature data.

[0070] The technical solutions for uploading physical device data to the chain provided by one or more embodiments of the present application will be described in detail below.

[0071] Refer to Figure 2 , Figure 2 which is a flowchart of a method for uploading physical device data shown in an exemplary embodiment of the present application.

[0072] In this embodiment, the above - mentioned method for uploading physical device data can be applied to physical devices that need to store their device data on the blockchain as evidence.

[0073] As Figure 2 shown, the above - mentioned method for uploading physical device data may specifically include the following steps:

[0074] Step 202: Initialize the SDK for digital signature processing of the device data of the physical device, so that the SDK obtains a first key pair for classical digital signature processing and a second key pair for post - quantum digital signature processing.

[0075] In this embodiment, for a physical device that needs to upload its device data to the blockchain for deposit and certification, specifically, the blockchain service platform accessed by the physical device can send the device data of the physical device to the blockchain for deposit and certification. Before uploading the device data of the physical device to the blockchain for deposit and certification, the SDK (Software Development Kit) used to perform digital signature processing on the device data of the physical device can first perform digital signature processing on the device data of the physical device (specifically, it can be an application on the physical device) sent by the physical device to the SDK. Then, the device data of the physical device as the original data and the digital signature data corresponding to the original data can be sent to the blockchain service platform. The blockchain service platform verifies the digital signature data, and after the digital signature verification passes, the device data of the physical device is published to the blockchain for deposit and certification.

[0076] An SDK is a collection of a series of predefined code frameworks, library files, documents, sample codes, and tools, which is used to assist in the rapid implementation of application development for specific functions or platforms. The SDK in this application can be encapsulated with functions for performing digital signature processing on the device data of physical devices; that is, the SDK can implement the function of performing digital signature processing on the device data of physical devices.

[0077] In practical applications, the logical code for performing digital signature processing on the device data of physical devices can be encapsulated to form an SDK. In practical applications, different SDKs can be used to perform digital signature processing on the device data of different physical devices. For example, different physical devices may use different chips for intelligent processing such as data collection, data transmission, and data calculation, or they may use the same chip. In this case, the same SDK can be used to perform digital signature processing on the device data of physical devices with the same chip, while different SDKs can be used to perform digital signature processing on the device data of physical devices with different chips.

[0078] For physical devices that need to upload and store their device data on the blockchain, the above SDK can be integrated into the application deployed on the physical device and provide pre-packaged functions as part of the application. Among them, the application can be an application that implements the business functions corresponding to the physical device; for example, when the physical device is a new energy vehicle, the application can be an application that implements vehicle control functions; when the physical device is an energy storage battery, the application can be an application that implements power control functions. In this case, the application can collect the device data of the physical device, call the SDK, and transfer the device data of the physical device to the SDK, and the SDK performs digital signature processing on the device data of the physical device. The physical device can further send the device data of the physical device and the corresponding digital signature data to the blockchain service platform accessed by the physical device. The blockchain service platform verifies the digital signature data, and after the digital signature verification passes, it publishes the device data of the physical device to the blockchain for uploading and storing evidence.

[0079] It should be noted that in order to ensure the security of data transfer, the above physical device can send the device data of the physical device and the corresponding digital signature data to the above blockchain service platform through the secure communication module deployed on it. Among them, the secure communication module refers to a relatively independent code unit that implements a set of functions or services related to secure communication.

[0080] Alternatively, after encapsulating the logic code for digitally signing the device data of a physical device into an SDK, the SDK can be further used for firmware development, and the generated firmware can be burned into the hardware device, enabling the hardware device to implement the function of digitally signing the device data of the physical device. At the same time, a secure communication module that implements a set of functions or services related to secure communication can also be deployed on the physical device. In this case, corresponding deployment can be performed for the hardware device with respect to the physical device, so that the hardware device can provide a digital signature service for the device data of the physical device. For example, the hardware device can be an expansion card, there can be an expansion card slot on the physical device, and the hardware device can be inserted into the expansion card slot as an expansion card to provide a digital signature service for the device data of the physical device by the hardware device. Specifically, the device data of the physical device can be collected by an application on the physical device, and the SDK can be called to transfer the device data of the physical device to the SDK, and the SDK digitally signs the device data of the physical device. The physical device can further send the device data of the physical device and the corresponding digital signature data to the blockchain service platform accessed by the physical device. The blockchain service platform verifies the digital signature data, and after the digital signature verification passes, the device data of the physical device is published to the blockchain for on-chain storage and evidence.

[0081] In this embodiment, the SDK for digitally signing the device data of a physical device can first obtain a key pair for classical digital signature (which can be referred to as the first key pair) and a key pair for post-quantum digital signature (which can be referred to as the second key pair).

[0082] Specifically, to ensure that the above SDK can interact correctly and securely with external services or systems, after the above physical device is powered on, the SDK can be initialized. The initialization process of the SDK can include: configuring some necessary parameters, such as API keys, server addresses, etc.; preparing specific resources, such as establishing a database connection, loading necessary library files, or allocating memory space; setting the internal state to the initial state and preparing to process subsequent requests; completing the user authentication and authorization process to prove that the caller has the right to access the requested service; and so on.

[0083] The above SDK can obtain the first key pair for classical digital signature and the second key pair for post-quantum digital signature during the initialization phase.

[0084] It should be noted that classical digital signature algorithms refer to digital signature algorithms that are not specifically designed to resist quantum computer attacks. Classical digital signature algorithms include RSA (Rivest-Shamir-Adleman), DSA (Digital Signature Algorithm), ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm), etc. They rely on traditional mathematical problems, such as the large integer factorization problem, the discrete logarithm problem over a finite field, the elliptic curve discrete logarithm problem, etc.

[0085] Among them, RSA is an algorithm based on public-key cryptography that can be used for both encrypting data and generating digital signatures. The security of RSA depends on the difficulty of the large integer factorization problem. The signature process includes: the signer encrypts the hash value of the message using its private key to generate a signature; the verifier decrypts the signature using the signer's public key and compares it with the hash value of the message to verify the validity of the signature.

[0086] DSA is designed specifically for digital signatures and does not provide encryption functionality. DSA is based on the discrete logarithm problem over a finite field. The signature process includes: the signer generates a random number k and calculates the signature R and S using its private key and k; the verifier uses the signer's public key and the signature (R, S) to verify the integrity of the message.

[0087] ECDSA is a variant of DSA, but it is based on elliptic curve cryptography (ECC), specifically the elliptic curve discrete logarithm problem. ECDSA relies on the addition operation between points on the elliptic curve to construct key pairs, and its security is based on the difficulty of the elliptic curve discrete logarithm problem. The signature process includes: the signer generates a temporary key k and calculates the signature R and S on the elliptic curve using its private key and k; the verifier uses the signer's public key and the signature (R, S) to verify the authenticity of the message.

[0088] EdDSA is a signature scheme designed specifically for high performance and high security, based on specific forms of elliptic curves, such as Twisted Edwards curves or Montgomery curves, etc. Its security also depends on the difficulty of the elliptic curve discrete logarithm problem. It uses a deterministic method to generate signatures and does not require an external random number generator. During the signature generation process, the hash value of the message is combined with the private key to generate the signature R and S. The verification process is simple and efficient, directly using the public key and the signature (R, S) to verify the authenticity of the message.

[0089] The classical digital signature algorithm adopted in this embodiment can be any classical digital signature algorithm, and this application does not impose special restrictions on this.

[0090] Classical digital signature algorithms are considered secure under current computing capabilities. However, with the development of quantum computers, the security of traditional classical digital signature algorithms based on the problems of large integer factorization and discrete logarithm will be threatened because quantum computers can effectively solve these traditional mathematical problems using Shor's algorithm.

[0091] Post-Quantum Cryptography (PQC) is dedicated to developing a new generation of encryption technologies that can withstand attacks from quantum computers. These technologies rely on mathematical problems that are considered difficult to solve even for quantum computers. And new digital signature algorithms based on these mathematical problems and capable of maintaining security in the era of quantum computing are generally referred to as post-quantum digital signature algorithms.

[0092] The main types of post-quantum digital signature algorithms include hash-based digital signature algorithms, code-based digital signature algorithms, multivariate-based digital signature algorithms, lattice-based digital signature algorithms, etc.

[0093] Among them, hash-based digital signature algorithms utilize the security of hash functions to achieve digital signatures. The security of such algorithms is mainly based on the collision resistance assumption of hash functions.

[0094] Code-based digital signature algorithms are based on error-correcting code theory. Although mainly used for encryption, they can also be used to construct signature schemes. The security of such algorithms is mainly based on the problem of decoding random linear codes.

[0095] Multivariate-based digital signature algorithms use a system of quadratic polynomials of multiple variables over a finite field to construct signature schemes. The security of such algorithms is based on the difficulty of solving randomly generated systems of multivariate quadratic equations.

[0096] Lattice-based digital signature algorithms use problems in lattice theory, such as the Shortest Vector Problem (SVP), the NTRU problem (including the problem of finding approximately the shortest vector in a polynomial ring (which is related to the shortest vector problem in lattices), and the problem of factoring polynomials under certain specific conditions), the LWE (Learning With Errors) problem, the Ring-LWE problem (a variant of the LWE problem), as the basis for their security. These problems are considered difficult to solve even in the quantum computing environment.

[0097] The post-quantum digital signature algorithm adopted in this embodiment can be any post-quantum digital signature algorithm, and this application does not impose special restrictions on this.

[0098] A complete digital signature algorithm usually consists of three main algorithms: the Key Generation algorithm, the Signing algorithm, and the Verification algorithm.

[0099] Among them, the Key Generation algorithm is responsible for generating a pair of keys, namely a private key and a corresponding public key. The private key is used to generate digital signatures, while the public key is used to verify these digital signatures. The key pair is generated based on the mathematical problems that serve as the security basis of the digital signature algorithm. In classical digital signature algorithms, these mathematical problems can be: the large integer factorization problem, the discrete logarithm problem over a finite field, the elliptic curve discrete logarithm problem, etc.; in post-quantum digital signature algorithms, these mathematical problems can be: the collision resistance assumption of hash functions, decoding random linear codes, solving randomly generated multivariate quadratic equations, and the shortest vector problem in lattices, the NTRU problem, the LWE problem, etc.

[0100] The signer (i.e., the sender of the message) can use the Signing algorithm to encrypt the message or the message digest using its own private key, thereby creating a digital signature. This process ensures the uniqueness and non-repudiation of the signature because only the individual with the specific private key can generate a valid signature.

[0101] The verifier (i.e., the receiver of the message) can use the Verification algorithm to verify the validity of the digital signature using the public key of the signer. If the digital signature is valid, it indicates that the message has not been tampered with during transmission and indeed comes from the claimed sender.

[0102] In some embodiments, the above SDK can pre-generate a first key pair for classical digital signature for the above physical device based on the key generation algorithm included in a specific classical digital signature algorithm, and store the first key pair. After the initialization of the SDK is completed, the SDK can obtain the stored first key pair and use the first key pair for subsequent classical digital signature of the device data for the physical device.

[0103] Similarly, the above SDK can pre-generate a second key pair for post-quantum digital signature for the above physical device based on the key generation algorithm included in a specific post-quantum digital signature algorithm, and store the second key pair. After the initialization of the SDK is completed, the SDK can obtain the stored second key pair and use the second key pair for subsequent post-quantum digital signature of the device data for the physical device.

[0104] In some embodiments, after the initialization of the above SDK is completed, it can also generate a first key pair for classical digital signature for the above physical device based on the key generation algorithm included in a specific classical digital signature algorithm, and use the first key pair for subsequent classical digital signature of the device data for the physical device.

[0105] Similarly, after the initialization of the above SDK is completed, it can also generate a second key pair for post-quantum digital signature for the above physical device based on the key generation algorithm included in a specific post-quantum digital signature algorithm, and use the second key pair for subsequent post-quantum digital signature of the device data for the physical device.

[0106] In practical applications, after the above SDK successfully obtains the above first key pair and the above second key pair, it can return a key generation success response to the above physical device.

[0107] Step 204: Obtain the device data, call the SDK, and send the device data to the SDK, so that the SDK performs classical digital signature processing on the device data based on the classical digital signature algorithm and the private key in the first key pair to obtain first signature data, and performs post-quantum digital signature processing on the device data and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair to obtain second signature data.

[0108] In this embodiment, a physical device that needs to upload its device data to the blockchain for evidence storage can transmit device data of the physical device, such as the device identifier of the physical device (e.g., International Mobile Equipment Identity, IMEI, International Mobile Equipment Identity Code), the physical asset type, the physical asset code, as well as the operating status and performance indicators of the physical device and the business data generated thereby, to the SDK used for digitally signing the device data of the physical device. The SDK digitally signs the device data of the physical device.

[0109] Specifically, the above physical device can obtain its own device data and call the above SDK to transmit the device data of the physical device to the SDK.

[0110] In the case where the above SDK obtains the device data of the above physical device, it can first perform classical digital signature processing on the device data of the physical device using the private key in the first key pair based on the signature algorithm included in the classical digital signature algorithm (specifically, the classical digital signature algorithm used to generate the above first key pair). The obtained classical digital signature result can be used as the first signature data.

[0111] Furthermore, the above first signature data and the device data of the above physical device can be combined and used together as the input for post-quantum digital signature. Based on the signature algorithm included in the post-quantum digital signature algorithm (specifically, the post-quantum digital signature algorithm used to generate the above second key pair), the private key in the second key pair is used to perform post-quantum digital signature processing on the first signature data and the device data of the physical device. The obtained post-quantum digital signature result can be used as the second signature data.

[0112] That is, in this application, a nested form of hybrid digital signature processing can be performed using a classical digital signature algorithm and a post-quantum digital signature algorithm.

[0113] In practical applications, after successful digital signature processing, the above SDK can return the device data of the above physical device, the above first signature data, and the above second signature data that have undergone digital signature processing to the physical device.

[0114] Step 206: Send the device data, the first signature data, and the second signature data to the blockchain service platform accessed by the physical device, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the verification of the second signature data passes, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the verification of the first signature data passes, publishes the device data to the blockchain for on-chain storage and evidence preservation.

[0115] In this embodiment, when the above physical device obtains the device data of the above physical device, the above first signature data, and the above second signature data that have undergone digital signature processing, it can send the device data, the first signature data, and the second signature data of the physical device that have undergone digital signature processing to the blockchain service platform accessed by the physical device.

[0116] For example, the signature data can be directly attached to the original data, that is, the first signature data is first attached to the device data of the physical device, and then the second signature data is attached to the device data and the first signature data of the physical device, so as to send the device data, the first signature data, and the second signature data of the physical device to the blockchain service platform together. Or, a specific encapsulation format (for example: embedding the signature data into the original data in XML format, or encoding the original data and the signature data into JSON format) can be used to organize the original data and the signature data, that is, first encapsulate the device data and the first signature data of the physical device, and then perform secondary encapsulation on the encapsulated device data, the first signature data, and the second signature data, so as to send the encapsulated device data, the first signature data, and the second signature data to the blockchain service platform.

[0117] Since a hybrid digital signature process in a nested form using a classical digital signature algorithm and a post-quantum digital signature algorithm is used, that is, the second post-quantum digital signature is a re-signature of the first classical digital signature, this means that the post-quantum digital signature actually protects the result of the classical digital signature plus the device data of the above physical device as the original data. In this case, due to the existence of the second-layer signature, it is usually impossible to directly access the content of the first-layer signature, that is, the above first signature data and the device data of the physical device. Therefore, it is necessary to first verify the second-layer signature, and after the verification of the second-layer signature is successful, it indicates that the first signature data and the device data of the physical device have not been tampered with, and thus a secure trust in the content of the first-layer signature is obtained, and the first-layer signature can be safely verified continuously. At this time, after the verification of the first-layer signature is successful, it can be indicated that the device data of the physical device has not been tampered with.

[0118] Therefore, when the above blockchain service platform receives the device data of the physical device, the first signature data, and the second signature data, it can first verify the second signature data based on the verification algorithm included in the post-quantum digital signature used to generate the second key pair, using the public key in the second key pair, to verify the validity of the second signature data.

[0119] If the above second signature data is valid, that is, the verification of the second signature data passes, then the above blockchain service platform can further verify the first signature data based on the verification algorithm included in the classical digital signature algorithm used to generate the first key pair, using the public key in the first key pair, to verify the validity of the first signature data.

[0120] If the above first signature data is valid, that is, the verification of the first signature data passes, then the authenticity and reliability of the device data of the above physical device can be guaranteed. Therefore, the above blockchain service platform can publish the device data of the physical device to the blockchain for on-chain storage and evidence preservation.

[0121] In some embodiments, the device data of the above physical device mainly includes two types of data. One is the registration information of the physical device, such as device identification (e.g., IMEI), physical asset type, physical asset code, etc.; the other is the business data generated during the operation of the physical device.

[0122] When the device data of the above physical device includes the above registration information (specifically, it may include the above device identification), it can not only send the registration information, the first signature data, and the second signature data to the above blockchain service platform together, but also send the public key in the first key pair and the public key in the second key pair to the blockchain service platform.

[0123] In this case, the above blockchain service platform can first verify the second signature data based on the above post-quantum digital signature algorithm and the public key in the second key pair, and after the verification of the second signature data passes, verify the first signature data based on the above classical digital signature algorithm and the public key in the first key pair. After the verification of the first signature data passes, the blockchain service platform can not only publish the above registration information to the blockchain for the above-mentioned evidence preservation, but also store the corresponding relationship between the device identification and the public key in the first key pair, and store the corresponding relationship between the device identification and the public key in the second key pair, so as to facilitate subsequent use of the device identification to directly find the public key in the first key pair and the public key in the second key pair based on the stored corresponding relationship.

[0124] In practical applications, after successfully publishing the above registration information to the blockchain for on-chain storage and evidence, the above blockchain service platform can also return a physical device registration success response to the above physical device.

[0125] When the device data of the above physical device includes the above service data, the above device identifier can be sent to the above blockchain service platform together with the service data, the above first signature data, and the above second signature data.

[0126] In this case, the above blockchain service platform can respectively query in the corresponding relationships between the stored device identifiers and the public keys for post-quantum digital signatures, and between the device identifiers and the public keys for classical digital signatures, using the above device identifier to obtain the public key in the above second key pair corresponding to the device identifier, and the public key in the above first key pair corresponding to the device identifier.

[0127] Subsequently, the above blockchain service platform can first verify the above second signature data based on the above post-quantum digital signature algorithm and the public key in the above second key pair, and after the verification of the second signature data passes, verify the first signature data based on the above classical digital signature algorithm and the public key in the above first key pair. After the verification of the first signature data passes, the blockchain service platform can publish the above service data to the blockchain for the above evidence storage.

[0128] In practical applications, after successfully publishing the above service information to the blockchain for on-chain storage and evidence, the above blockchain service platform can also return a service data on-chain success response to the above physical device.

[0129] In some embodiments, the post-quantum digital signature algorithm adopted in this application can specifically be a lattice-based digital signature algorithm. Among them, a lattice is a set of all points generated by integer coefficient linear combinations of a group of linearly independent vectors (usually called basis vectors).

[0130] The lattice in the above post-quantum digital signature algorithm can specifically be a lattice constructed based on elements in a polynomial ring, that is, a lattice generated by a group of polynomials (i.e., elements in the polynomial ring) as basis vectors. For example, a lattice can be constructed based on elements in the polynomial ring Z q [X] / (X n +1). Among them, Z q represents the ring of integers modulo q (i.e., the result of taking the modulo of all integers by q), and X n +1 is an irreducible polynomial. Specifically, Z q [X] refers to the set of all polynomials with coefficients in Z q . X n +1 means considering all polynomials that can be divided by Xn Polynomials divisible by +1. Z q [X] / (X n +1) means taking all polynomials in Z q [X] and classifying these polynomials according to the congruence of multiples of X n +1. The result is that the degree of polynomials in each equivalence class does not exceed n - 1, because higher-degree terms can be simplified by dividing by X n +1 and taking the remainder. Using lattices constructed from elements in the ring, post-quantum digital signature algorithms based on the LWE problem or its ring version, the Ring-LWE problem, can be constructed.

[0131] When constructing a lattice based on elements in a polynomial ring, some specific polynomials can be selected from these elements as the basis vectors of the lattice. These basis vectors usually satisfy certain conditions to facilitate the construction of secure and efficient cryptographic schemes. For example, in the Ring-LWE problem, small error polynomials (which are also elements in the polynomial ring) are usually randomly selected from a certain probability distribution (e.g., Gaussian distribution) as part of the basis vectors.

[0132] It should be noted that when performing calculations based on the above post-quantum digital signature algorithm, the calculation method adopted can specifically be the method of stream computing. Among them, stream computing is a technology for processing continuous data streams or real-time data. It mainly targets scenarios that require rapid processing of instantaneously generated data to achieve almost zero-latency information processing and decision support.

[0133] In traditional big data processing, the batch processing method is usually adopted, that is, a certain amount of data is collected first and then processed uniformly. This method cannot meet the application scenarios with high real-time requirements. Stream computing, on the other hand, is data-stream oriented. Once new data arrives, it can be processed immediately, which can greatly reduce the time difference between data generation and the feedback of processing results.

[0134] For the above post-quantum digital signature algorithm, several temporary variables (Temporary Variable) for temporarily storing elements in the polynomial ring can be preset. Among them, a temporary variable refers to a variable used to temporarily store data. They are usually used within the local scope of a piece of code, such as inside a function, method, or loop, and their lifespan is limited to this local scope. Once the program execution flow leaves the scope where the temporary variable is defined, the temporary variable is usually automatically destroyed, releasing the memory resources it occupies.

[0135] In the process of streaming computation based on the above post-quantum digital signature algorithm (including the key generation process, the signature process, and / or the verification process), the elements in the polynomial ring temporarily stored in each temporary variable can be dynamically updated according to the actual requirements during the computation process. For example, assume that during the computation process of the post-quantum digital signature algorithm, at most 3 elements in the polynomial ring need to be used for computation simultaneously. Then, 3 temporary variables can be preset, namely ta, tb, and tc. For ta, when it is necessary to substitute the element A1 in the polynomial ring into ta for computation, the element in the polynomial ring temporarily stored in ta can be updated to the element A1, so that the element A1 temporarily stored in ta can be immediately used for computation. After the computation using the element A1 is completed, if it is necessary to substitute the element A2 in the polynomial ring into ta for computation, the element in the polynomial ring temporarily stored in ta can be updated to the element A2, so that the element A2 temporarily stored in ta can be immediately used for computation. The same applies to tb. When it is necessary to substitute the element B1 in the polynomial ring into tb for computation, the element in the polynomial ring temporarily stored in tb can be updated to the element B1, so that the element B1 temporarily stored in tb can be immediately used for computation. After the computation using the element B1 is completed, if it is necessary to substitute the element B2 in the polynomial ring into tb for computation, the element in the polynomial ring temporarily stored in tb can be updated to the element B2, so that the element B2 temporarily stored in tb can be immediately used for computation. And so on.

[0136] In this way, it is possible to avoid directly caching all the elements in the polynomial ring that need to be used during the entire computation process in the memory, thereby optimizing the memory requirements and actual consumption of the above post-quantum digital signature algorithm.

[0137] In some embodiments, the processor corresponding to the SDK used for digital signature processing of the device data of the physical device may specifically be a processor including a Cortex-M4 core. For example, assume that the SDK is integrated into the application deployed on the physical device. Then, the processor of the physical device can be a processor including a Cortex-M4 core. If the SDK is burned into the hardware device, the processor of the hardware device can be a processor including a Cortex-M4 core.

[0138] Cortex-M4 is a processor core, designed specifically for efficient digital signal control (DSC) and hybrid digital signal processing (DSP) and microcontroller applications. It is based on the ARMv7E-M architecture, supports a 32-bit RISC instruction set, and introduces a single-precision floating-point unit (FPU) and a series of DSP instruction enhancements, such as fast Fourier transform acceleration instructions, saturation operations, etc.

[0139] In a processor containing a Cortex-M4 core, using the ARMv7E-M instruction set, efficient operations such as 32-bit multiplication and accumulation can be completed within a single processor cycle. Therefore, the calculations based on the above post-quantum digital signature algorithm can be translated into an instruction set based on the ARMv7E-M architecture, such as: UMULL (Unsigned Multiply Long), SMULL (Signed Multiply Long), UMLAL (Unsigned Multiply-Accumulate Long), SMLAL (Signed Multiply-Accumulate Long), etc.

[0140] In this way, the computational performance of the above post-quantum digital signature algorithm can be improved.

[0141] Among them, the UMULL instruction performs the multiplication of two 32-bit unsigned numbers and produces a 64-bit result. The operands are treated as unsigned integers, and the lower 32 bits of the result are stored in one destination register, and the upper 32 bits are stored in another destination register.

[0142] SMULL is similar to UMULL, but the operands are treated as signed integers. It also performs the multiplication of two 32-bit signed numbers and generates a 64-bit result, with the lower 32 bits and upper 32 bits stored in two destination registers respectively.

[0143] The UMLAL instruction first performs the multiplication of two 32-bit unsigned numbers, and then adds the resulting 64-bit result to the 64-bit accumulator composed of two destination registers. This instruction is very useful for operations that require continuous summation.

[0144] SMLAL is similar to UMLAL, but the operands involved here are all signed. This instruction is used to perform the multiplication of two 32-bit signed numbers and add the result to the 64-bit accumulator represented by two destination registers.

[0145] Through the optimization of memory and performance for the above post-quantum digital signature algorithm as described above, it is possible to deploy and apply the physical device data on-chain scheme in this application on any resource-constrained physical device. Among them, a resource-constrained device refers to a physical device with strict limitations in computing power, memory capacity, storage space, or energy consumption.

[0146] Reference Figure 3 , Figure 3 is a flowchart of another physical device data on-chain method shown in an exemplary embodiment of this application.

[0147] In this embodiment, the above physical device data uploading method can be applied to a blockchain service platform accessed by physical devices that need to upload their device data to the blockchain for certification.

[0148] As Figure 3 shown, the above physical device data uploading method may specifically include the following steps:

[0149] Step 302: Obtain the public key in the first key pair for classical digital signature processing and the public key in the second key pair for post-quantum digital signature processing, and obtain the device data, the first signature data, and the second signature data sent by the physical device; wherein, the first key pair and the second key pair are obtained by the SDK for digital signature processing of the device data of the physical device during initialization; the first signature data is obtained by the SDK performing classical digital signature processing on the device data based on the classical digital signature algorithm and the private key in the first key pair; the second signature data is obtained by the SDK performing post-quantum digital signature processing on the device data and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair.

[0150] Step 304: Verify the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair.

[0151] Step 306: After the second signature data is verified, verify the first signature data based on the classical digital signature algorithm and the public key in the first key pair.

[0152] Step 308: After the first signature data is verified, publish the device data to the blockchain for uploading and certification.

[0153] As Figure 3 shown, the specific implementation of the embodiment can refer to the embodiment shown in Figure 2 This application will not elaborate here.

[0154] To more clearly illustrate the data interaction between the physical device that needs to upload its device data to the blockchain for certification, the SDK for digital signature processing of the device data of this physical device, the blockchain service platform accessed by this physical device, and the blockchain system, refer to Figure 4 , Figure 4 which is another multi-party interaction diagram in the process of physical device data uploading shown in an exemplary embodiment of this application.

[0155] As Figure 4 shown, the above physical device data uploading process may include the following steps:

[0156] Step 402: The physical device initializes the SDK.

[0157] Step 404: The SDK obtains a first key pair for classical digital signature processing and a second key pair for post-quantum digital signature processing.

[0158] Step 406: The SDK returns a key generation success response to the physical device.

[0159] Step 408: The physical device obtains its own registration information and sends the obtained registration information to the SDK.

[0160] Step 410: The SDK first performs classical digital signature processing on the registration information based on the classical digital signature algorithm and the private key in the first key pair to obtain first signature data, and then performs post-quantum digital signature processing on the registration information and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair to obtain second signature data, realizing nested hybrid digital signature processing.

[0161] Step 412: The SDK returns the registration information, the first signature data, and the second signature data that have undergone digital signature processing to the physical device.

[0162] Step 414: The physical device sends the registration information, the first signature data, the second signature data, the public key in the first key pair, and the public key in the second key pair that have undergone digital signature processing to the blockchain service platform.

[0163] Step 416: The blockchain service platform first verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the verification of the second signature data passes, it then verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, realizing the verification of the nested hybrid digital signature.

[0164] Step 418: After the verification of the first signature data passes, the blockchain service platform publishes the registration information to the blockchain for on-chain storage and evidence.

[0165] Step 420: The blockchain service platform stores the correspondence between the device identifier and the public key in the first key pair, and the correspondence between the device identifier and the public key in the second key pair.

[0166] Step 422: After the registration information is successfully uploaded to the chain, the blockchain service platform returns a physical device registration success response to the physical device.

[0167] Step 424: The physical device obtains its own business data and sends its own business data to the SDK.

[0168] Step 426: The SDK first performs classical digital signature processing on the service data based on the classical digital signature algorithm and the private key in the first key pair to obtain the first signature data, and then performs post-quantum digital signature processing on the service data and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair to obtain the second signature data, realizing nested hybrid digital signature processing.

[0169] Step 428: The SDK returns the service data, the first signature data, and the second signature data that have undergone digital signature processing to the physical device.

[0170] Step 430: The physical device sends the service data, the first signature data, the second signature data, and the device identifier that have undergone digital signature processing to the blockchain service platform.

[0171] Step 432: The blockchain service platform queries based on the device identifier in the stored corresponding relationship to obtain the public key in the first key pair and the public key in the second key pair corresponding to the device identifier.

[0172] Step 434: The blockchain service platform first verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair. After the second signature data is verified successfully, it then verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, realizing the verification of the nested hybrid digital signature.

[0173] Step 436: After the first signature data is verified successfully, the blockchain service platform publishes the service data to the blockchain for on-chain storage and evidence retention.

[0174] Step 438: After the service data is successfully uploaded to the blockchain, the blockchain service platform returns a service data on-chain success response to the physical device.

[0175] As Figure 4 shown, the specific implementation of the embodiment can refer to the embodiment as Figure 2 shown, and the present application will not elaborate here.

[0176] Corresponding to the embodiment of the foregoing method, the present application also provides an embodiment of a device.

[0177] Please refer to Figure 5 , Figure 5It is a schematic structural diagram of a device shown in an exemplary embodiment of the present application. At the hardware level, the device includes a processor 502, an internal bus 504, a network interface 506, a memory 508, and a non-volatile memory 510. Of course, it may also include other necessary hardware. One or more embodiments of the present application can be implemented in a software manner. For example, the processor 502 reads the corresponding computer program from the non-volatile memory 510 into the memory 508 and then runs it. Of course, in addition to the software implementation manner, one or more embodiments of the present application do not exclude other implementation manners, such as a logic device or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic module, and can also be hardware or a logic device.

[0178] Please refer to Figure 6 , Figure 6 It is a block diagram of a physical device data uploading device shown in an exemplary embodiment of the present application.

[0179] The above physical device data uploading device can be applied to Figure 5 the device shown in

[0180] An initialization module 602 initializes an SDK for digitally signing the device data of the physical device, so that the SDK obtains a first key pair for classical digital signature processing and a second key pair for post-quantum digital signature processing;

[0181] A signature module 604 obtains the device data and calls the SDK to send the device data to the SDK, so that the SDK performs classical digital signature processing on the device data based on the classical digital signature algorithm and the private key in the first key pair to obtain first signature data, and performs post-quantum digital signature processing on the device data and the first signature data based on the post-quantum digital signature algorithm and the private key in the second key pair to obtain second signature data;

[0182] A sending module 606 sends the device data, the first signature data, and the second signature data to the blockchain service platform accessed by the physical device, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the second signature data is verified, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the first signature data is verified, publishes the device data to the blockchain for on-chain storage and certification.

[0183] In some embodiments, initializing an SDK for digitally signing the device data of the physical device so that the SDK obtains a first key pair for classical digital signature processing, including:

[0184] Initializing an SDK for digitally signing the device data of the physical device so that the SDK obtains a stored first key pair for classical digital signature; or,

[0185] Initializing an SDK for digitally signing the device data of the physical device so that the SDK generates a first key pair for classical digital signature based on the classical digital signature algorithm.

[0186] In some embodiments, initializing an SDK for digitally signing the device data of the physical device so that the SDK obtains a second key pair for post-quantum digital signature processing, including:

[0187] Initializing an SDK for digitally signing the device data of the physical device so that the SDK obtains a stored second key pair for post-quantum digital signature; or,

[0188] Initializing an SDK for digitally signing the device data of the physical device so that the SDK generates a second key pair for post-quantum digital signature based on the post-quantum digital signature algorithm.

[0189] In some embodiments, the device data includes registration information; the registration information includes a device identifier;

[0190] Sending the device data, the first signature data, and the second signature data to the blockchain service platform accessed by the physical device, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the verification of the second signature data passes, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the verification of the first signature data passes, publishes the device data to the blockchain for on-chain storage, including:

[0191] Send the registration information, the first signature data, the second signature data, the public key in the first key pair, and the public key in the second key pair to the blockchain service platform accessed by the physical device, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the verification of the second signature data passes, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the verification of the first signature data passes, publishes the registration information to the blockchain for on-chain storage, and stores the correspondence between the device identifier and the public key in the first key pair, and the correspondence between the device identifier and the public key in the second key pair.

[0192] In some embodiments, the device data includes service data;

[0193] The sending the device data, the first signature data, and the second signature data to the blockchain service platform accessed by the physical device, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the verification of the second signature data passes, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the verification of the first signature data passes, publishes the device data to the blockchain for on-chain storage, includes:

[0194] Send the service data, the first signature data, the second signature data, and the device identifier to the blockchain service platform accessed by the physical device, so that the blockchain service platform obtains the public key in the first key pair and the public key in the second key pair corresponding to the device identifier, to verify the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the verification of the second signature data passes, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the verification of the first signature data passes, publishes the service data to the blockchain for on-chain storage.

[0195] In some embodiments, the post-quantum digital signature algorithm is a lattice-based digital signature algorithm; the lattice is a lattice constructed based on elements in a polynomial ring; the calculation based on the post-quantum digital signature algorithm is a streaming calculation; the elements in the polynomial ring are temporarily stored by a temporary variable; the elements temporarily stored in the temporary variable are dynamically updated during the calculation based on the post-quantum digital signature algorithm.

[0196] In some embodiments, the processor corresponding to the SDK is a processor including a Cortex-M4 core; and the calculation based on the post-quantum digital signature algorithm is converted into an instruction set based on the ARMv7E-M architecture.

[0197] Please refer to Figure 7 , Figure 7 It is a block diagram of another physical device data uplink device shown in an exemplary embodiment of the present application.

[0198] The above physical device data uplink device can be applied to Figure 5 The device shown in the figure is used to implement the technical solution of the present application. Among them, a blockchain service platform can be deployed on the device; the device includes:

[0199] An acquisition module 702 is configured to acquire a public key in a first key pair for classical digital signature processing and a public key in a second key pair for post-quantum digital signature processing, and acquire device data, first signature data, and second signature data of the physical device sent by the physical device; wherein the first key pair and the second key pair are acquired by an SDK for performing digital signature processing on device data of the physical device at the time of initialization; the first signature data is obtained by the SDK performing classical digital signature processing on the device data based on a classical digital signature algorithm and a private key in the first key pair; the second signature data is obtained by the SDK performing post-quantum digital signature processing on the device data and the first signature data based on a post-quantum digital signature algorithm and a private key in the second key pair;

[0200] A first verification module 704 verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair;

[0201] A second verification module 706, after the second signature data is verified, verifies the first signature data based on the classic digital signature algorithm and the public key in the first key pair;

[0202] The chain module 708 publishes the device data to the blockchain for chain storage after the first signature data is verified.

[0203] In some embodiments, the device data includes registration information; the registration information includes a device identification;

[0204] The obtaining of a public key in a first key pair for classical digital signature processing and a public key in a second key pair for post-quantum digital signature processing comprises:

[0205] Obtain the public key in the first key pair for classical digital signature and the public key in the second key pair for post-quantum digital signature sent by the physical device;

[0206] After the first signature data passes the verification, publishing the device data to the blockchain for on-chain storage and evidence preservation includes:

[0207] After the first signature data passes the verification, publishing the registration information to the blockchain for on-chain storage and evidence preservation, and storing the correspondence between the device identifier and the public key in the first key pair, and the correspondence between the device identifier and the public key in the second key pair.

[0208] In some embodiments, the device data includes service data;

[0209] The obtaining the public key in the first key pair for classical digital signature processing and the public key in the second key pair for post-quantum digital signature processing includes:

[0210] Obtain the device identifier sent by the physical device, and obtain the public key in the first key pair and the public key in the second key pair corresponding to the device identifier.

[0211] In some embodiments, the post-quantum digital signature algorithm is a lattice-based digital signature algorithm; the lattice is a lattice constructed based on elements in a polynomial ring; the calculation based on the post-quantum digital signature algorithm is a streaming calculation; the elements in the polynomial ring are temporarily stored by temporary variables; the elements temporarily stored in the temporary variables are dynamically updated during the calculation based on the post-quantum digital signature algorithm.

[0212] In some embodiments, the processor corresponding to the SDK is a processor including a Cortex-M4 core; the calculation based on the post-quantum digital signature algorithm is converted into an instruction set based on the ARMv7E-M architecture.

[0213] For the device embodiments, they basically correspond to the method embodiments, so for the relevant parts, refer to the partial descriptions of the method embodiments. The device embodiments described above are only illustrative, where the modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the technical solution of this application.

[0214] The systems, devices, modules, or units described in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, laptop computer, cellular phone, camera phone, smart phone, personal digital assistant, media player, navigation device, email transceiver, game console, tablet computer, wearable device, or a combination of any several of these devices.

[0215] In a typical configuration, a computer includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0216] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.

[0217] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassette tapes, magnetic disk storage, quantum memory, graphene-based storage media, or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0218] It should be noted that the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity, or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements that are inherent to such process, method, commodity, or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, commodity, or device comprising the element.

[0219] The above describes specific embodiments of the present application. Other embodiments are within the scope of the present application. In some cases, the acts or steps recited in the present application may be performed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0220] The terms used in one or more embodiments of the present application are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of the present application. The singular forms "a", "the", and "said" are also intended to include the plural forms unless the context clearly dictates otherwise. The term "and / or" refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0221] The description of terms such as "one embodiment", "some embodiments", "example", "specific example", or "a mode of implementation" in one or more embodiments of the present application means that the specific features or characteristics described in connection with the embodiment are included in at least one embodiment of the present application. The schematic descriptions of these terms do not necessarily refer to the same embodiment. Moreover, the specific features or characteristics described may be combined in a suitable manner in one or more embodiments of the present application. In addition, different embodiments and the specific features or characteristics in different embodiments may be combined without conflict.

[0222] It should be understood that although the terms first, second, third, etc. may be used in one or more embodiments of the present application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of one or more embodiments of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0223] The foregoing is only a preferred embodiment of one or more embodiments of the present application and is not intended to limit one or more embodiments of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of one or more embodiments of the present application shall be included within the scope of protection of one or more embodiments of the present application.

[0224] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or reject.

Claims

1. A method for uploading physical device data to a blockchain, applied to a physical device; the method comprises: Initializing an SDK for performing digital signature processing on device data of the physical device, so that the SDK acquires a first key pair for classical digital signature processing and a second key pair for post-quantum digital signature processing; Acquire the device data, call the SDK, and send the device data to the SDK, so that the SDK performs a classic digital signature process on the device data based on a classic digital signature algorithm and the private key in the first key pair to obtain first signature data, and performs a post-quantum digital signature process on the device data and the first signature data based on a post-quantum digital signature algorithm and the private key in the second key pair to obtain second signature data; The device data, the first signature data and the second signature data are sent to the blockchain service platform to which the physical device is connected, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the second signature data is verified, the first signature data is verified based on the classical digital signature algorithm and the public key in the first key pair, and after the first signature data is verified, the device data is published to the blockchain for on-chain storage.

2. The method according to claim 1, initializing an SDK for performing digital signature processing on device data of the physical device so that the SDK acquires a first key pair for classic digital signature processing, comprising: Initializing an SDK for performing digital signature processing on device data of the physical device, so that the SDK acquires a stored first key pair for classic digital signature; or, An SDK for performing digital signature processing on device data of the physical device is initialized so that the SDK generates a first key pair for a classic digital signature based on the classic digital signature algorithm.

3. The method according to claim 1, initializing an SDK for performing digital signature processing on device data of the physical device so that the SDK acquires a second key pair for post-quantum digital signature processing, comprising: Initializing an SDK for performing digital signature processing on device data of the physical device so that the SDK obtains a stored second key pair for post-quantum digital signature; or, Initialize an SDK for performing digital signature processing on device data of the physical device, so that the SDK generates a second key pair for post-quantum digital signature based on the post-quantum digital signature algorithm.

4. The method according to claim 1, wherein the device data comprises registration information; the registration information comprises a device identification; The sending of the device data, the first signature data and the second signature data to the blockchain service platform to which the physical device is connected, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the second signature data is verified, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the first signature data is verified, publishes the device data to the blockchain for on-chain storage, including: The registration information, the first signature data, the second signature data, the public key in the first key pair, and the public key in the second key pair are sent to the blockchain service platform to which the physical device is connected, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the second signature data is verified, the first signature data is verified based on the classical digital signature algorithm and the public key in the first key pair, and after the first signature data is verified, the registration information is published to the blockchain for on-chain storage, and the correspondence between the device identification and the public key in the first key pair, as well as the correspondence between the device identification and the public key in the second key pair, is stored.

5. The method according to claim 4, wherein the device data comprises business data; The sending of the device data, the first signature data and the second signature data to the blockchain service platform to which the physical device is connected, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the second signature data is verified, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the first signature data is verified, publishes the device data to the blockchain for on-chain storage, including: The business data, the first signature data, the second signature data and the device identification are sent to the blockchain service platform to which the physical device is connected, so that the blockchain service platform obtains the public key in the first key pair and the public key in the second key pair corresponding to the device identification, and verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the second signature data is verified, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the first signature data is verified, publishes the business data to the blockchain for on-chain storage.

6. According to the method of claim 1, the post-quantum digital signature algorithm is a lattice-based digital signature algorithm; the lattice is a lattice constructed based on elements in a polynomial ring; the calculation based on the post-quantum digital signature algorithm is a streaming calculation; the elements in the polynomial ring are temporarily stored by temporary variables; the elements temporarily stored in the temporary variables are dynamically updated during the calculation based on the post-quantum digital signature algorithm.

7. According to the method of claim 1, the processor corresponding to the SDK is a processor including a Cortex-M4 core; and the calculation based on the post-quantum digital signature algorithm is converted into an instruction set based on the ARMv7E-M architecture.

8. A method for uploading physical device data to a blockchain, applied to a blockchain service platform accessed by physical devices; the method comprises: Obtain a public key in a first key pair for classical digital signature processing and a public key in a second key pair for post-quantum digital signature processing, and obtain device data, first signature data, and second signature data of the physical device sent by the physical device; wherein the first key pair and the second key pair are obtained by an SDK for performing digital signature processing on device data of the physical device at the time of initialization; the first signature data is obtained by the SDK performing classical digital signature processing on the device data based on a classical digital signature algorithm and a private key in the first key pair; the second signature data is obtained by the SDK performing post-quantum digital signature processing on the device data and the first signature data based on a post-quantum digital signature algorithm and a private key in the second key pair; Verifying the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair; After the second signature data is verified, verifying the first signature data based on the classic digital signature algorithm and the public key in the first key pair; After the first signature data is verified, the device data is published to the blockchain for on-chain storage.

9. The method according to claim 8, wherein the device data comprises registration information; the registration information comprises a device identification; The obtaining of a public key in a first key pair for classical digital signature processing and a public key in a second key pair for post-quantum digital signature processing comprises: Obtaining a public key in a first key pair for a classical digital signature and a public key in a second key pair for a post-quantum digital signature sent by the physical device; After the first signature data is verified, the device data is published to the blockchain for on-chain storage, including: After the first signature data is verified, the registration information is published to the blockchain for on-chain storage, and the correspondence between the device identifier and the public key in the first key pair, as well as the correspondence between the device identifier and the public key in the second key pair, is stored.

10. The method according to claim 9, wherein the device data comprises business data; The obtaining of a public key in a first key pair for classical digital signature processing and a public key in a second key pair for post-quantum digital signature processing comprises: The device identification sent by the physical device is obtained, and a public key in the first key pair and a public key in the second key pair corresponding to the device identification are obtained.

11. According to the method of claim 8, the post-quantum digital signature algorithm is a lattice-based digital signature algorithm; the lattice is a lattice constructed based on elements in a polynomial ring; the calculation based on the post-quantum digital signature algorithm is a streaming calculation; the elements in the polynomial ring are temporarily stored by temporary variables; the elements temporarily stored in the temporary variables are dynamically updated during the calculation based on the post-quantum digital signature algorithm.

12. According to the method of claim 8, the processor corresponding to the SDK is a processor including a Cortex-M4 core; and the calculation based on the post-quantum digital signature algorithm is converted into an instruction set based on the ARMv7E-M architecture.

13. A physical device data uplink device, applied to a physical device; the device comprises: An initialization module, which initializes an SDK for performing digital signature processing on device data of the physical device, so that the SDK acquires a first key pair for classical digital signature processing and a second key pair for post-quantum digital signature processing; a signature module, acquiring the device data, calling the SDK, and sending the device data to the SDK, so that the SDK performs a classic digital signature process on the device data based on a classic digital signature algorithm and the private key in the first key pair to obtain first signature data, and performs a post-quantum digital signature process on the device data and the first signature data based on a post-quantum digital signature algorithm and the private key in the second key pair to obtain second signature data; A sending module sends the device data, the first signature data and the second signature data to the blockchain service platform to which the physical device is connected, so that the blockchain service platform verifies the second signature data based on the post-quantum digital signature algorithm and the public key in the second key pair, and after the second signature data is verified, verifies the first signature data based on the classical digital signature algorithm and the public key in the first key pair, and after the first signature data is verified, publishes the device data to the blockchain for on-chain storage.

14. A device for uploading physical device data to a blockchain, applied to a blockchain service platform accessed by physical devices; the device comprises: an acquisition module, acquiring a public key in a first key pair for classical digital signature processing and a public key in a second key pair for post-quantum digital signature processing, and acquiring device data, first signature data, and second signature data of the physical device sent by the physical device; wherein the first key pair and the second key pair are acquired by an SDK for performing digital signature processing on device data of the physical device at the time of initialization; the first signature data is obtained by the SDK performing classical digital signature processing on the device data based on a classical digital signature algorithm and a private key in the first key pair; the second signature data is obtained by the SDK performing post-quantum digital signature processing on the device data and the first signature data based on a post-quantum digital signature algorithm and a private key in the second key pair; A first verification module verifies the second signature data based on the post-quantum digital signature algorithm and a public key in the second key pair; A second verification module, after the second signature data is verified, verifies the first signature data based on the classic digital signature algorithm and the public key in the first key pair; The on-chain module publishes the device data to the blockchain for on-chain storage after the first signature data is verified.

15. An electronic device, comprising: processor; a memory for storing processor-executable instructions; The processor implements the method according to any one of claims 1 to 12 by running the executable instructions.

16. A computer-readable storage medium having computer instructions stored thereon, wherein the instructions are executed by a processor to implement the method according to any one of claims 1 to 12.

Citation Information

Cited By

  • Visual data traceability and integrity verification system based on block chain

    CN120811565A

  • Blockchain-based visual data provenance and integrity verification system

    CN120811565B