Feature value transfer method and related device
Through the method of independent signature of eigenvalue operation objects, the problem of frequent interactions in the prior art is solved, and more efficient eigenvalue transfer is achieved and user experience is improved.
Patent Information
- Application Number
- CN202311762499.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-19
- Publication Date
- 2025-06-20
AI Technical Summary
The existing eigenvalue transfer method requires the collaborative signature of the eigenvalue operation object and the object to which the eigenvalue belongs, resulting in frequent and complex interaction operations, consumes more interactive resources, is low efficiency, and affects the user experience.
After the eigenvalue operation object receives the transfer certificate sent by the target server, for the eigenvalue transfer event whose characteristic value to be transferred is less than or equal to the limiting eigenvalue value, the eigenvalue operation object is independently signed to reduce interaction operations and save interactive resources.
On the basis of ensuring the security of characteristic value transfer, improve the efficiency of characteristic value transfer and improve user experience.
Smart Images

Figure CN120180413A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a method for transferring eigenvalue and related devices. Background Art
[0002] With the rapid development of eigenvalue transfer technology, there is a specific scenario in the eigenvalue transfer scenario where the eigenvalue operation object is not the object to which the eigenvalue belongs; that is, an authorization transfer scenario where the object to which the eigenvalue belongs authorizes the eigenvalue operation object to perform actual operations on the eigenvalue.
[0003] In the related art, in order to ensure the security of the authorization transfer scenario, the eigenvalue transfer method generally refers to: for each eigenvalue transfer event, the eigenvalue operation object needs to interact with the object to which the eigenvalue belongs; after the object to which the eigenvalue belongs approves the eigenvalue transfer request, a complete signature is obtained through collaborative signature, so that the target server can execute the eigenvalue transfer event after verifying the complete signature.
[0004] However, the above method requires the eigenvalue operation object and the object to which the eigenvalue belongs to perform collaborative signature for each eigenvalue transfer event. The interaction operations are relatively frequent and complex, consuming a large amount of interaction resources, resulting in a low eigenvalue transfer efficiency, thus affecting the eigenvalue transfer experience. Summary of the Invention
[0005] To solve the above technical problems, this application provides a method for transferring eigenvalue and related devices. For each eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object of the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue, there is no need for the eigenvalue operation object and the object to which the eigenvalue belongs to perform collaborative signature. The eigenvalue operation object signs independently, reducing interaction operations, saving interaction resources, improving the transfer efficiency of eigenvalue transfer on the basis of ensuring the security of eigenvalue transfer, and thus enhancing the transfer experience of eigenvalue transfer.
[0006] The embodiments of this application disclose the following technical solutions:
[0007] On the one hand, the embodiments of this application provide a method for transferring eigenvalue, which is executed by a first device of an eigenvalue operation object. The method includes:
[0008] After receiving the transfer certificate for the restricted eigenvalue independently transferred by the eigenvalue operation object sent by the target server, for each eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object of the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue, generate an eigenvalue transfer request according to the eigenvalue transfer event;
[0009] Calculate the digest of the eigenvalue transfer request to obtain a first message digest;
[0010] Sign the first message digest according to the preset private key corresponding to the transfer certificate to obtain the preset signature of the eigenvalue transfer request;
[0011] Send the eigenvalue transfer request and the preset signature to the target server;
[0012] Receive the transfer result of the eigenvalue transfer event sent by the target server; the transfer result is determined by the target server based on the signature verification result of verifying the preset signature with the preset public key in the transfer certificate and the matching result of the eigenvalue transfer request matching the independent transfer parameters corresponding to the transfer certificate.
[0013] On the other hand, an embodiment of the present application provides an eigenvalue transfer method, which is executed by a target server. The method includes:
[0014] Receive an eigenvalue transfer request and a preset signature sent by a first device of an eigenvalue operation object; the eigenvalue transfer request represents an eigenvalue transfer event in which the to-be-transferred eigenvalue of the object to which the eigenvalue belongs transferred by the eigenvalue operation object is less than or equal to the limit eigenvalue, and the preset signature is signed by the first device for the eigenvalue transfer request according to the preset private key corresponding to the transfer certificate for independently transferring the limit eigenvalue of the object to which the eigenvalue belongs by the eigenvalue operation object;
[0015] Verify the preset signature according to the preset public key in the transfer certificate to obtain a signature verification result; match the eigenvalue transfer request with the independent transfer parameters corresponding to the transfer certificate to obtain a matching result;
[0016] Determine the transfer result of the eigenvalue transfer event according to the signature verification result and the matching result;
[0017] Send the transfer result to the first device.
[0018] On the other hand, an embodiment of the present application provides an eigenvalue transfer device, which is deployed on a first device of an eigenvalue operation object. The device includes: a generation unit, a calculation unit, a signature unit, a first sending unit, and a first receiving unit;
[0019] The generation unit is configured to, after receiving the transfer certificate for independently transferring the limit eigenvalue of the object to which the eigenvalue belongs by the eigenvalue operation object sent by the target server, for each eigenvalue transfer event in which the to-be-transferred eigenvalue of the object to which the eigenvalue belongs transferred by the eigenvalue operation object is less than or equal to the limit eigenvalue, generate an eigenvalue transfer request according to the eigenvalue transfer event;
[0020] The calculation unit is configured to perform a digest calculation on the eigenvalue transfer request to obtain a first message digest;
[0021] The signature unit is configured to sign the first message digest according to a preset private key corresponding to the transfer certificate, so as to obtain a preset signature of the eigenvalue transfer request;
[0022] The first sending unit is configured to send the eigenvalue transfer request and the preset signature to the target server;
[0023] The first receiving unit is configured to receive a transfer result of the eigenvalue transfer event sent by the target server; the transfer result is determined by the target server according to a signature verification result of verifying the preset signature with a preset public key in the transfer certificate and a matching result of the eigenvalue transfer request matching an independent transfer parameter corresponding to the transfer certificate.
[0024] On the other hand, an embodiment of the present application provides an eigenvalue transfer device deployed in a target server. The device includes: a second receiving unit, a signature verification unit, a matching unit, a determination unit, and a second sending unit;
[0025] The second receiving unit is configured to receive an eigenvalue transfer request and a preset signature sent by a first device of an eigenvalue operation object; the eigenvalue transfer request represents an eigenvalue transfer event that a to-be-transferred eigenvalue of an object to which an eigenvalue belongs of the eigenvalue operation object is less than or equal to a limit eigenvalue, and the preset signature is a signature of the eigenvalue transfer request by the first device according to a preset private key corresponding to a transfer certificate for independently transferring the limit eigenvalue of the object to which the eigenvalue belongs by the eigenvalue operation object;
[0026] The signature verification unit is configured to verify the preset signature with a preset public key in the transfer certificate to obtain a signature verification result;
[0027] The matching unit is configured to match the eigenvalue transfer request with an independent transfer parameter corresponding to the transfer certificate to obtain a matching result;
[0028] The determination unit is configured to determine a transfer result of the eigenvalue transfer event according to the signature verification result and the matching result;
[0029] The second sending unit is configured to send the transfer result to the first device.
[0030] On the other hand, an embodiment of the present application provides a computer device, which includes a processor and a memory:
[0031] The memory is configured to store a computer program and transmit the computer program to the processor;
[0032] The processor is configured to execute the method described in any of the foregoing aspects according to instructions in the computer program.
[0033] On the other hand, an embodiment of the present application provides a computer-readable storage medium for storing a computer program. When the computer program runs on a computer device, the computer device is caused to execute the method described in any of the foregoing aspects.
[0034] On the other hand, an embodiment of the present application provides a computer program product including a computer program. When the computer program runs on a computer device, the computer device is caused to execute the method described in any of the foregoing aspects.
[0035] As can be seen from the above technical solution, after the first device for the eigenvalue operation object receives the transfer certificate of the restricted eigenvalue for independently transferring the object to which the eigenvalue belongs sent by the target server, for each eigenvalue transfer event where the eigenvalue to be transferred for transferring the object to which the eigenvalue belongs by the eigenvalue operation object is less than or equal to the restricted eigenvalue, an eigenvalue transfer request for the eigenvalue transfer event is generated; the first message digest of the eigenvalue transfer request is calculated; the first message digest is signed with the preset private key corresponding to the transfer certificate to obtain the preset signature of the eigenvalue transfer request; and the eigenvalue transfer request and the preset signature are sent to the target server. The target server determines the transfer result of the eigenvalue transfer event based on the verification result of verifying the preset signature with the preset public key in the transfer certificate and the matching result of the eigenvalue transfer request matching the independent transfer parameter corresponding to the transfer certificate; and sends the transfer result to the first device so that the first device can receive the transfer result. It can be seen that based on the fact that the eigenvalue operation object pre-interacts with the object to which the eigenvalue belongs to obtain the transfer certificate of the restricted eigenvalue for independently transferring the object to which the eigenvalue belongs by the eigenvalue operation object, for each eigenvalue transfer event where the eigenvalue to be transferred is less than or equal to the restricted eigenvalue, the eigenvalue operation object does not need to interact with the object to which the eigenvalue belongs for collaborative signature, and can directly sign with the preset private key corresponding to the transfer certificate to obtain the preset signature and send it to the target server; so that based on the above transfer certificate, the target server can verify the preset signature with the preset public key and match the eigenvalue transfer request with the independent transfer parameter to obtain the transfer result of the eigenvalue transfer event and send it to the eigenvalue operation object, and ensure the security of the eigenvalue transfer.
[0036] Based on this, for each eigenvalue transfer event where the eigenvalue to be transferred for transferring the object to which the eigenvalue belongs by the eigenvalue operation object is less than or equal to the restricted eigenvalue, the method does not require collaborative signature between the eigenvalue operation object and the object to which the eigenvalue belongs, and the eigenvalue operation object signs independently, reducing interaction operations and saving interaction resources. On the basis of ensuring the security of the eigenvalue transfer, the transfer efficiency of the eigenvalue transfer is improved, thereby enhancing the transfer experience of the eigenvalue transfer. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0038] Figure 1 System schematic diagram of a feature value transfer method provided by an embodiment of the present application;
[0039] Figure 2 Flowchart of a feature value transfer method provided by an embodiment of the present application;
[0040] Figure 3 Flowchart of another feature value transfer method provided by an embodiment of the present application;
[0041] Figure 4 Interaction diagram of a feature value transfer method provided by an embodiment of the present application;
[0042] Figure 5 Interaction diagram of a transfer certificate acquisition method provided by an embodiment of the present application;
[0043] Figure 6 Interaction diagram of an operation certificate acquisition method provided by an embodiment of the present application;
[0044] Figure 7 Interaction diagram of a complete public key acquisition method provided by an embodiment of the present application;
[0045] Figure 8 Structural diagram of a feature value transfer device provided by an embodiment of the present application;
[0046] Figure 9 Structural diagram of another feature value transfer device provided by an embodiment of the present application;
[0047] Figure 10 Structural diagram of a server provided by an embodiment of the present application;
[0048] Figure 11 Structural diagram of a terminal provided by an embodiment of the present application. Detailed implementation manners
[0049] The following describes the embodiments of the present application in conjunction with the accompanying drawings.
[0050] At present, in the authorization transfer scenario where the object to which the eigenvalue belongs authorizes the object operating on the eigenvalue to perform an actual operation on the eigenvalue, for each eigenvalue transfer event, the object operating on the eigenvalue needs to interact with the object to which the eigenvalue belongs; after the object to which the eigenvalue belongs approves the eigenvalue transfer request, they jointly sign to obtain a complete signature, so that the target server can execute the eigenvalue transfer event after verifying the complete signature, thereby enhancing the security of the authorization transfer scenario.
[0051] As an example, in the authorization transaction scenario, for each amount transaction event, the account operator needs to interact with the account owner; after the account owner approves the amount transaction request, they jointly sign to obtain a complete signature, so that the target server can execute the amount transaction event after verifying the complete signature.
[0052] However, through research, it is found that the above method requires the object operating on the eigenvalue and the object to which the eigenvalue belongs to jointly sign for each eigenvalue transfer event. The interaction operations are relatively frequent and complex, consuming a large amount of interaction resources, resulting in a low eigenvalue transfer efficiency, thus affecting the eigenvalue transfer experience. That is, for each amount transaction event, the account operator and the account owner need to jointly sign, the interaction operations are relatively frequent and complex, consuming a large amount of interaction resources, resulting in a low amount transaction efficiency, thus affecting the amount transaction experience.
[0053] The embodiment of the present application provides an eigenvalue transfer method. For each eigenvalue transfer event where the eigenvalue to be transferred by the object operating on the eigenvalue belonging to the object is less than or equal to the restricted eigenvalue, there is no need for the object operating on the eigenvalue and the object to which the eigenvalue belongs to jointly sign. The object operating on the eigenvalue signs independently, reducing interaction operations and saving interaction resources. On the basis of ensuring the security of eigenvalue transfer, the transfer efficiency of eigenvalue transfer is improved, thereby enhancing the transfer experience of eigenvalue transfer.
[0054] Next, the system architecture of the eigenvalue transfer method will be introduced. See Figure 1 , Figure 1 is a system schematic diagram of an eigenvalue transfer method provided by an embodiment of the present application. The system includes a first device 101 of the object operating on the eigenvalue and a target server 102. The first device 101 and the server 102 are used to execute the eigenvalue transfer method.
[0055] After the first device 101 receives the transfer certificate for the restricted eigenvalue of the object to which the eigenvalue belongs independently transferred by the object operating on the eigenvalue sent by the target server 102, for each eigenvalue transfer event where the eigenvalue to be transferred by the object operating on the eigenvalue belonging to the object is less than or equal to the restricted eigenvalue, a eigenvalue transfer request is generated according to the eigenvalue transfer event.
[0056] As an example, in the eigenvalue transfer scenario of a financial transaction scenario, the eigenvalue operation object is the account operator, the eigenvalue belonging object is the account owner, the transfer certificate is the transaction certificate Trade_Cert, the restricted eigenvalue is the restricted amount X, the eigenvalue to be transferred is the amount to be traded, the eigenvalue transfer event is the amount transaction event, and the eigenvalue transfer request is the amount transaction request; after the first device 101 of the account operator receives the Trade_Cert for the account operator to independently trade the restricted amount X of the account owner sent by the target server 102, for each amount transaction event where the amount to be traded by the account operator for the account owner is less than or equal to the restricted amount X, the amount transaction request for the amount transaction event is generated as Trade_M.
[0057] The first device 101 calculates the digest of the eigenvalue transfer request to obtain the first message digest.
[0058] As an example, based on the above example, the first device 101 calculates the first message digest of the amount transaction request Trade_M as Trade_e.
[0059] The first device 101 signs the first message digest according to the preset private key corresponding to the transfer certificate to obtain the preset signature of the eigenvalue transfer request.
[0060] As an example, the preset private key corresponding to the transaction certificate Trade_Cert is Trade_S. Based on the above example, the first device 101 signs the first message digest Trade_e with Trade_S to obtain the preset signature of the amount transaction request Trade_M as Trade_s.
[0061] The first device 101 sends the eigenvalue transfer request and the preset signature to the target server 102.
[0062] As an example, based on the above example, the first device 101 sends the amount transaction request Trade_M and the preset signature Trade_s to the target server 102.
[0063] The first device 101 receives the transfer result of the eigenvalue transfer event sent by the target server 102; the transfer result is determined by the target server based on the signature verification result of verifying the preset signature with the preset public key in the transfer certificate and the matching result of the eigenvalue transfer request matching the independent transfer parameters corresponding to the transfer certificate.
[0064] As an example, based on the above example, if the preset public key corresponding to the preset private key Trade_S is Trade_P, the target server 102 determines the transfer result of the amount transaction event by verifying the signature result of the preset signature Trade_s with Trade_P in the transaction certificate Trade_Cert and the matching result of the amount transaction request Trade_M with the independent transfer parameters corresponding to Trade_Cert; and sends the transfer result to the first device 101. Then, the first device 101 receives the transfer result sent by the target server 102.
[0065] That is to say, based on the transfer certificate obtained by the eigenvalue operation object interacting with the object to which the eigenvalue belongs in advance to obtain the restricted eigenvalue of the object to which the eigenvalue belongs independently transferred by the eigenvalue operation object, for each eigenvalue transfer event where the eigenvalue to be transferred is less than or equal to the restricted eigenvalue, the eigenvalue operation object does not need to interact with the object to which the eigenvalue belongs for co-signature, and can directly obtain the preset signature by independent signature with the preset private key corresponding to the transfer certificate, and send it to the target server; so that the target server, based on the above transfer certificate, can verify the preset signature with the preset public key and match the eigenvalue transfer request with the independent transfer parameters, obtain the transfer result of the eigenvalue transfer event, and send it to the eigenvalue operation object, and ensure the security of the eigenvalue transfer.
[0066] Based on this, for each eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object of the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue, there is no need for the eigenvalue operation object and the object to which the eigenvalue belongs to co-sign, and the eigenvalue operation object signs independently, reducing the interaction operation, saving interaction resources, and improving the transfer efficiency of the eigenvalue transfer on the basis of ensuring the security of the eigenvalue transfer, thereby enhancing the transfer experience of the eigenvalue transfer.
[0067] It should be noted that in the embodiments of the present application, the first device may be a server or a terminal, the second device may be a server or a terminal, and the method provided in the embodiments of the present application may be executed in cooperation by the terminal and the server, or may be executed in cooperation by the server and the server. Among them, the terminal may be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart voice interaction device, a vehicle-mounted terminal, an extended reality device, an aircraft, etc., but is not limited thereto. The server may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services, but is not limited thereto. The terminal and the server may be directly or indirectly connected through wired or wireless communication methods, and the present application does not make any restrictions here. For example, the terminal and the server may be connected through a network, and the network may be a wired or wireless network.
[0068] In addition, the embodiments of the present application can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, intelligent transportation, assisted driving, autonomous driving, digital humans, virtual humans, virtual reality, augmented reality, mixed reality, audio and video, etc.
[0069] Next, taking the first device that operates on the eigenvalue object to execute the method provided by the embodiments of the present application as an example, the eigenvalue transfer method provided by the embodiments of the present application will be introduced in detail in combination with the accompanying drawings. Refer to Figure 2 , Figure 2 which is a flowchart of an eigenvalue transfer method provided by the embodiments of the present application. The method includes:
[0070] S201: After receiving the transfer certificate of the restricted eigenvalue of the object to which the eigenvalue belongs transferred by the eigenvalue operation object sent by the target server, for each eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue belongs transferred by the eigenvalue operation object is less than or equal to the restricted eigenvalue, generate an eigenvalue transfer request according to the eigenvalue transfer event.
[0071] S202: Calculate the message digest of the eigenvalue transfer request to obtain the first message digest.
[0072] S203: Sign the first message digest according to the preset private key corresponding to the transfer certificate to obtain the preset signature of the eigenvalue transfer request.
[0073] S204: Send the eigenvalue transfer request and the preset signature to the target server.
[0074] In the related art, for each eigenvalue transfer event represented by the eigenvalue of the object to which the eigenvalue belongs transferred by the eigenvalue operation object, the eigenvalue operation object needs to interact with the object to which the eigenvalue belongs; after the object to which the eigenvalue belongs approves the eigenvalue transfer request, they jointly sign to obtain a complete signature, so that the target server can execute the eigenvalue transfer event after verifying that the complete signature passes. However, through research, it is found that the above method requires the eigenvalue operation object and the object to which the eigenvalue belongs to jointly sign for each eigenvalue transfer event, and the interaction operations are relatively frequent and complex, consuming a lot of interaction resources, resulting in a low eigenvalue transfer efficiency, thus affecting the eigenvalue transfer experience.
[0075] Therefore, in the embodiments of the present application, to solve the above problems, it can be considered that for each eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue belongs transferred by the eigenvalue operation object is less than or equal to the restricted eigenvalue, on the basis of ensuring the security of the eigenvalue transfer, the independent signature of the eigenvalue operation object is used to replace the joint signature of the eigenvalue operation object and the object to which the eigenvalue belongs; to reduce the interaction operations and save the interaction resources, thereby improving the transfer efficiency of the eigenvalue transfer and enhancing the transfer experience of the eigenvalue transfer.
[0076] That is, the eigenvalue operation object needs to interact with the object to which the eigenvalue belongs in advance, apply to the target server to obtain a transfer certificate for the eigenvalue operation object to independently transfer the restricted eigenvalue of the object to which the eigenvalue belongs. Based on this transfer certificate, for each eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object is less than or equal to the restricted eigenvalue of the object to which the eigenvalue belongs, the eigenvalue operation object does not need to interact with the object to which the eigenvalue belongs for co-signature. The eigenvalue operation object can independently sign and send the signature to the target server for the target server to perform eigenvalue transfer.
[0077] Based on this, in practical applications, when the first device of the eigenvalue operation object executes the eigenvalue transfer method, after the first device of the eigenvalue operation object receives the transfer certificate for the eigenvalue operation object to independently transfer the restricted eigenvalue of the object to which the eigenvalue belongs sent by the target server, for each eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object is less than or equal to the restricted eigenvalue, first, generate an eigenvalue transfer request for the eigenvalue transfer event. Second, calculate the first message digest of the eigenvalue transfer request. Then, sign the first message digest with the preset private key corresponding to the transfer certificate to obtain the preset signature of the eigenvalue transfer request. Finally, send the eigenvalue transfer request and the preset signature to the target server.
[0078] Based on the fact that the eigenvalue operation object interacts with the object to which the eigenvalue belongs in advance to obtain a transfer certificate for the eigenvalue operation object to independently transfer the restricted eigenvalue of the object to which the eigenvalue belongs, for each eigenvalue transfer event where the eigenvalue to be transferred is less than or equal to the restricted eigenvalue, the eigenvalue operation object does not need to interact with the object to which the eigenvalue belongs for co-signature. It can directly obtain the preset signature by independently signing with the preset private key corresponding to the transfer certificate and send it to the target server, reducing interaction operations and saving interaction resources. This lays a foundation for improving the transfer efficiency of eigenvalue transfer and thus enhancing the transfer experience of eigenvalue transfer while ensuring the security of eigenvalue transfer.
[0079] As an example of S201 - S204, in the eigenvalue transfer scenario of a financial transaction scenario, the eigenvalue operation object is the account operator, the eigenvalue belonging object is the account owner, the transfer certificate is the transaction certificate Trade_Cert, the preset private key corresponding to the transaction certificate Trade_Cert is Trade_S, the restricted eigenvalue is the restricted amount X, the eigenvalue to be transferred is the amount to be traded, the eigenvalue transfer event is the amount transaction event, and the eigenvalue transfer request is the amount transaction request. Based on this, after the first device of the account operator receives the Trade_Cert for the account operator to independently trade the restricted amount X of the account owner sent by the target server, for each amount transaction event where the amount to be traded by the account operator for the account owner is less than or equal to the restricted amount X; first, generate the amount transaction request for the amount transaction event as Trade_M, second, calculate the first message digest of Trade_M as Trade_e; then, sign Trade_e with Trade_S to obtain the preset signature of Trade_M as Trade_s, and finally, send Trade_M and Trade_s to the target server.
[0080] S205: Receive the transfer result of the eigenvalue transfer event sent by the target server; the transfer result is determined by the target server based on the signature verification result of verifying the preset signature with the preset public key in the transfer certificate and the matching result of the eigenvalue transfer request matching the independent transfer parameters corresponding to the transfer certificate.
[0081] In the embodiment of the present application, after the first device of the eigenvalue operation object executes the above S201 - S204 and sends the eigenvalue transfer request and the preset signature to the target server, since the preset signature is obtained by signing the first message digest of the eigenvalue transfer request with the preset private key corresponding to the transfer certificate, and the eigenvalue transfer request represents the eigenvalue transfer event where the eigenvalue operation object transfers the eigenvalue to be transferred of the eigenvalue belonging object that is less than or equal to the restricted eigenvalue; then, based on the fact that the preset public key in the transfer certificate corresponds to the preset private key and the independent transfer parameters corresponding to the transfer certificate represent the configuration parameters for the eigenvalue operation object to independently transfer the restricted eigenvalue of the eigenvalue belonging object, the target server not only needs to verify whether the preset signature passes through the preset public key in the transfer certificate, but also needs to determine whether the eigenvalue transfer request matches the independent transfer parameters corresponding to the transfer certificate, so as to determine whether to execute the eigenvalue transfer event, obtain the transfer result of the eigenvalue transfer event, and return it to the first device of the eigenvalue operation object.
[0082] That is, the target server can obtain the signature verification result by verifying the preset signature with the preset public key in the transfer certificate, and obtain the matching result by matching the eigenvalue transfer request with the independent transfer parameter corresponding to the transfer certificate; determine the transfer result of the eigenvalue transfer event through the signature verification result and the matching result; and send the transfer result to the first device of the eigenvalue operation object. Based on this, the first device of the eigenvalue operation object can receive the transfer result sent by the target server.
[0083] Based on the above transfer certificate, the target server in S205 can obtain the transfer result of the eigenvalue transfer event by verifying the preset signature with the preset public key and matching the eigenvalue transfer request with the independent transfer parameter, and send it to the eigenvalue operation object; on the basis of ensuring the security of the eigenvalue transfer, improve the transfer efficiency of the eigenvalue transfer, thereby enhancing the transfer experience of the eigenvalue transfer.
[0084] As an example of S205, the preset public key corresponding to the preset private key Trade_S is Trade_P; based on this, the target server determines the transfer result of the amount transaction event through the signature verification result of verifying the preset signature Trade_s with Trade_P in the transaction certificate Trade_Cert and the matching result of matching the amount transaction request Trade_M with the independent transfer parameter corresponding to Trade_Cert; the target server sends the transfer result to the first device of the account operator; then the first device of the account operator receives the transfer result sent by the target server.
[0085] As can be seen from the above technical solution, after the first device of the eigenvalue operation object receives the transfer certificate for restricting the eigenvalue of the object to which the eigenvalue belongs independently transferred by the target server, for each eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue during the transfer of the eigenvalue operation object, an eigenvalue transfer request for the eigenvalue transfer event is generated; the first message digest of the eigenvalue transfer request is calculated; the first message digest is signed with the preset private key corresponding to the transfer certificate to obtain the preset signature of the eigenvalue transfer request; and the eigenvalue transfer request and the preset signature are sent to the target server. The target server determines the transfer result of the eigenvalue transfer event based on the verification result of verifying the preset signature with the preset public key in the transfer certificate and the matching result of the eigenvalue transfer request matching the independent transfer parameters corresponding to the transfer certificate; and sends the transfer result to the first device so that the first device can receive the transfer result. It can be seen that based on the fact that the eigenvalue operation object interacts with the object to which the eigenvalue belongs in advance to obtain the transfer certificate for restricting the eigenvalue of the object to which the eigenvalue belongs independently transferred by the eigenvalue operation object, for each eigenvalue transfer event where the eigenvalue to be transferred is less than or equal to the restricted eigenvalue, the eigenvalue operation object does not need to interact with the object to which the eigenvalue belongs for collaborative signature, and can directly sign with the preset private key corresponding to the transfer certificate to obtain the preset signature and send it to the target server; so that based on the above transfer certificate, the target server can verify the preset signature with the preset public key and match the eigenvalue transfer request with the independent transfer parameters to obtain the transfer result of the eigenvalue transfer event and send it to the eigenvalue operation object, and ensure the security of the eigenvalue transfer.
[0086] Based on this, for each eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue during the transfer of the eigenvalue operation object, there is no need for the eigenvalue operation object and the object to which the eigenvalue belongs to perform collaborative signature. The eigenvalue operation object signs independently, reducing the interaction operation and saving interaction resources. On the basis of ensuring the security of the eigenvalue transfer, the transfer efficiency of the eigenvalue transfer is improved, thereby enhancing the transfer experience of the eigenvalue transfer.
[0087] In the embodiments of the present application, the process by which the first device of the eigenvalue operation object obtains the transfer certificate of the restricted eigenvalue of the object to which the eigenvalue operation object independently transfers the eigenvalue refers to: on the basis that the first device of the eigenvalue operation object obtains the operation certificate of the eigenvalue of the object to which the eigenvalue operation object operates the eigenvalue sent by the target server, the eigenvalue operation object uses the private key shard of the eigenvalue operation object corresponding to the operation certificate, and the eigenvalue belonging object uses the private key shard of the eigenvalue belonging object corresponding to the operation certificate to jointly sign the independent transfer permission request indicating the restricted eigenvalue of the object to which the eigenvalue operation object independently transfers the eigenvalue, and then applies to the target server to obtain the transfer certificate of the restricted eigenvalue of the object to which the eigenvalue operation object independently transfers the eigenvalue. The operation certificate stored in the target server includes the private key shard of the eigenvalue operation object and the complete public key corresponding to the private key shard of the eigenvalue belonging object.
[0088] First, the first device of the eigenvalue operation object not only needs to generate an independent transfer permission request indicating the restricted eigenvalue of the object to which the eigenvalue operation object independently transfers the eigenvalue through a preset private key, a preset public key, and an independent transfer parameter corresponding to the restricted eigenvalue of the object to which the eigenvalue operation object independently transfers the eigenvalue, and send it to the second device of the eigenvalue belonging object; but also needs to calculate the second message digest of the independent transfer permission request and generate the first intermediate parameter related to the signature of the eigenvalue operation object, and send them to the second device of the eigenvalue belonging object. Specifically, the transfer request certificate can be obtained by signing the preset public key with the preset private key first, and then the independent transfer permission request can be generated through the transfer request certificate and the independent transfer parameter corresponding to the restricted eigenvalue.
[0089] Second, after the second device of the eigenvalue belonging object approves the independent transfer permission request through the eigenvalue belonging object, it generates the first signature shard of the eigenvalue belonging object through the private key shard of the eigenvalue belonging object, the second message digest, and the first intermediate parameter, and sends it to the first device of the eigenvalue operation object; then the first device of the eigenvalue operation object receives the first signature shard of the eigenvalue belonging object sent by the second device of the eigenvalue belonging object.
[0090] Then, the first device of the eigenvalue operation object needs to generate the first complete signature through the first signature shard of the eigenvalue belonging object and the second signature shard of the eigenvalue operation object generated by the private key shard of the eigenvalue operation object; send the independent transfer permission request and the first complete signature to the target server.
[0091] Finally, after the target server determines that the complete public key in the operation certificate of the eigenvalue of the object to which the eigenvalue operation object belongs verifies that the first complete signature passes, it issues a transfer certificate for the independent transfer permission request and sends it to the first device of the eigenvalue operation object; then the first device of the eigenvalue operation object receives the transfer certificate sent by the target server.
[0092] Based on this, the present application provides a possible implementation manner. The steps for obtaining the transfer certificate in S201 include the following S1-S8 (not shown in the figure):
[0093] S1: Sign the preset public key according to the preset private key to obtain a transfer certificate request.
[0094] S2: Generate an independent transfer permission request according to the transfer certificate request and the independent transfer parameters corresponding to the restricted eigenvalue.
[0095] S3: Calculate the digest of the independent transfer permission request to obtain a second message digest; generate a first intermediate parameter.
[0096] Among them, generating the first intermediate parameter may specifically be: generating the first intermediate parameter according to the first random number. The first intermediate parameter refers to a signature intermediate parameter or a signature shard of the eigenvalue operation object.
[0097] S4: Send the independent transfer permission request, the second message digest, and the first intermediate parameter to the second device of the object to which the eigenvalue belongs.
[0098] S5: Receive the first signature shard sent by the second device; the first signature shard is generated according to the private key shard of the object to which the eigenvalue belongs, the second message digest, and the first intermediate parameter after the object to which the eigenvalue belongs approves the independent transfer permission request.
[0099] Among them, the first signature shard may specifically be generated according to the second random number, the third random number, the private key shard of the object to which the eigenvalue belongs, the second message digest, and the first intermediate parameter after the object to which the eigenvalue belongs approves the independent transfer permission request.
[0100] S6: Generate a first complete signature according to the first signature shard and the second signature shard; the second signature shard is generated according to the private key shard of the eigenvalue operation object.
[0101] S7: Send the independent transfer permission request and the first complete signature to the target server.
[0102] S8: Receive the transfer certificate sent by the target server; the transfer certificate is issued by the target server for the independent transfer permission request after the complete public key in the operation certificate of the eigenvalue of the object to which the eigenvalue operation object belongs verifies that the first complete signature passes.
[0103] The S1 - S8 eigenvalue operation object applies to the target server to obtain a transfer certificate for restricting the transfer of the eigenvalue of the object to which the eigenvalue belongs by interacting with the object to which the eigenvalue belongs in advance; for each subsequent eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object of the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue, the eigenvalue operation object does not need to interact with the object to which the eigenvalue belongs for co - signature, and the eigenvalue operation object can independently sign and send the signature to the target server so that the target server can perform eigenvalue transfer and provide certificate data to ensure the security of eigenvalue transfer.
[0104] As an example of the S1 - S8, the first random number is K1, the second random number is K2, the third random number is K3, the private key shard of the account operator is D1, the private key shard of the account owner is D2, the complete public key is P, and the operation certificate is Cert; based on the examples of S201 - S204 and the example of S205 above, first, the first device of the account operator first signs the preset public key Trade_P with the preset private key Trade_S to obtain a transaction certificate request Trade_CSR, and then generates an independent transaction permission request M from Trade_CSR and the independent transaction parameters corresponding to the restricted amount X; calculates the second message digest of M as e; generates the first intermediate parameter Q1 through K1; sends M, e, and Q1 to the second device of the account owner. Among them, Q1 = K1·G, and G is the base point of order n on the elliptic curve parameter E of the elliptic curve public key cryptography algorithm (SM2 algorithm).
[0105] Secondly, after the account owner approves M on the second device of the account owner, the second device of the account owner generates the first signature shards S2, S3, and r of the account owner through K2, K3, D2, e, and Q1, and sends S2, S3, and r to the first device of the account operator; then the first device of the account operator receives S2, S3, and r of the account owner sent by the second device of the account owner. Among them, r≠0, r=(X1 + e)mod n, X1+X2 = K3·Q1+Q2, Q2 = K2·G, S2=(D2·K3)mod n, S3 = D2·((r + K2)mod n), and mod represents the modulo operation.
[0106] Then, the first device of the account operator generates the first complete signature s through the second signature shard D1·K1 of the account operator generated by S2, S3, r of the object to which the eigenvalue belongs, and D1; sends M and s to the target server. Among them, s = ((D1·K1)·S2+D1·S3 - r)mod n.
[0107] Finally, after the target server determines that the P-signature in the Cert for the amount of the account operator operating the account owner passes, it issues a trading certificate Trade_Cert for M and sends Trade_Cert to the first device of the account operator; then the first device of the account operator receives the Trade_Cert sent by the target server.
[0108] In the embodiment of the present application, the process for the first device of the eigenvalue operation object to obtain the operation certificate of the eigenvalue of the object to which the eigenvalue operation object belongs is as follows: the eigenvalue operation object uses the private key shard of the eigenvalue operation object, and the object to which the eigenvalue belongs uses the private key shard of the object to which the eigenvalue belongs corresponding to the operation certificate to jointly sign a preset operation certificate request that represents the eigenvalue of the object to which the eigenvalue operation object belongs and carries the complete public key, and then applies to the target server to obtain the operation certificate of the eigenvalue of the object to which the eigenvalue operation object belongs.
[0109] First, the first device of the eigenvalue operation object not only needs to generate a preset operation certificate request that represents the eigenvalue of the object to which the eigenvalue operation object belongs through the complete public key and send it to the second device of the object to which the eigenvalue belongs; it also needs to calculate the third message digest of the preset operation certificate request and generate the second intermediate parameter related to the signature of the eigenvalue operation object, and send them to the second device of the object to which the eigenvalue belongs.
[0110] Second, after the second device of the object to which the eigenvalue belongs approves the preset operation certificate request, it generates the third signature shard of the object to which the eigenvalue belongs through the private key shard of the object to which the eigenvalue belongs, the third message digest, and the second intermediate parameter, and sends it to the first device of the eigenvalue operation object; then the first device of the eigenvalue operation object receives the third signature shard of the object to which the eigenvalue belongs sent by the second device of the object to which the eigenvalue belongs.
[0111] Then, the first device of the eigenvalue operation object needs to generate the second complete signature through the third signature shard of the object to which the eigenvalue belongs and the fourth signature shard of the eigenvalue operation object generated by the private key shard of the eigenvalue operation object; and generate the target operation certificate request through the preset operation certificate request and the second complete signature, and send it to the target server.
[0112] Finally, the target server issues an operation certificate for the target operation certificate request and sends it to the first device of the eigenvalue operation object; then the first device of the eigenvalue operation object receives the operation certificate sent by the target server.
[0113] Based on this, the present application provides a possible implementation manner. The steps for obtaining the operation certificate in S8 include the following S9-S16 (not shown in the figure):
[0114] S9: Generate a preset operation certificate request based on the complete public key.
[0115] S10: Calculate the digest of the preset operation certificate request to obtain the third message digest; generate the second intermediate parameter.
[0116] Among them, generating the second intermediate parameter can specifically be: generating the second intermediate parameter according to the fourth random number. This second intermediate parameter refers to the signature intermediate parameter or the signature shard of the eigenvalue operation object.
[0117] S11: Send the preset operation certificate request, the third message digest, and the second intermediate parameter to the second device.
[0118] S12: Receive the third signature shard sent by the second device; the third signature shard is generated according to the private key shard of the eigenvalue-owned object, the third message digest, and the second intermediate parameter after the eigenvalue-owned object audits and passes the preset operation certificate request.
[0119] Among them, the third signature shard can specifically be generated according to the fifth random number, the sixth random number, the private key shard of the eigenvalue-owned object, the third message digest, and the second intermediate parameter after the eigenvalue-owned object audits and passes the preset operation certificate request.
[0120] S13: Generate the second complete signature according to the third signature shard and the fourth signature shard; the fourth signature shard is generated according to the private key shard of the eigenvalue operation object.
[0121] S14: Generate the target operation certificate request according to the preset operation certificate request and the second complete signature.
[0122] S15: Send the target operation certificate request to the target server.
[0123] S16: Receive the operation certificate sent by the target server; the operation certificate is issued by the target server according to the target operation certificate request.
[0124] Through the interaction between the eigenvalue operation object and the eigenvalue-owned object in advance, the S9-S16 eigenvalue operation object applies to the target server to obtain the operation certificate for the eigenvalue operation object to operate on the eigenvalue of the eigenvalue-owned object; it provides certificate data to ensure the accuracy and security of the transfer certificate for the subsequent eigenvalue operation object to apply to the target server to obtain the transfer certificate for independently transferring the restricted eigenvalue of the eigenvalue-owned object through the interaction with the eigenvalue-owned object in advance. In addition, for each subsequent eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object of the eigenvalue-owned object is greater than the restricted eigenvalue, the eigenvalue operation object and the eigenvalue-owned object interact to perform collaborative signature and send the signature to the target server, so that the target server can perform eigenvalue transfer, providing certificate data to ensure the security of eigenvalue transfer.
[0125] As an example of S9 - S16, the fourth random number is K4, the fifth random number is K5, and the sixth random number is K6; based on the above example of S1 - S8, first, the first device of the account operator first obtains the preset operation certificate request CSR' through the complete public key P; calculates the third message digest of CSR' as e'; generates the second intermediate parameter Q4 through K4; and sends CSR', e', and Q4 to the second device of the account owner. Wherein, Q4 = K4·G.
[0126] Secondly, after the account owner's second device approves CSR' upon review by the account owner, it generates the third signature shards S5, S6, and r' of the account owner through K5, K6, D2, e, and Q4, and sends S5, S6, and r' to the first device of the account operator; then the first device of the account operator receives S5, S6, and r' of the account owner sent by the second device of the account owner. Wherein, r'≠0, r'=(X3 + e') mod n, X3 + X4 = K6·Q4 + Q5, Q5 = K4·G, S5=(D2·K6) mod n, S6 = D2·((r' + K5) mod n).
[0127] Then, the first device of the account operator generates the second complete signature s' through S5, S6, and r' of the object to which the eigenvalue belongs, and the fourth signature shard D1·K4 generated by D1; generates the target operation certificate request CSR through CSR' and s', and sends CSR to the target server. Wherein, s'=((D1·K4)·S5 + D1·S6 - r') mod n.
[0128] Finally, the target server issues the operation certificate Cert for CSR and sends Cert to the first device of the account operator; then the first device of the account operator receives Cert sent by the target server.
[0129] In the embodiment of the present application, the process by which the first device of the eigenvalue operation object obtains the complete public key means that: the eigenvalue operation object calculates the public key shard through the private key shard of the eigenvalue operation object, and applies to the object to which the eigenvalue belongs for the permission to operate the eigenvalue of the object to which the eigenvalue belongs, so that the object to which the eigenvalue belongs calculates the complete public key through the private key shard and public key shard of the object to which the eigenvalue belongs, and discloses the complete public key.
[0130] First, the first device of the eigenvalue operation object needs to generate a request for the permission to operate the eigenvalue of the object to which the eigenvalue belongs and send it to the second device of the object to which the eigenvalue belongs; it also needs to generate the private key shard of the eigenvalue operation object to calculate the public key shard and send it to the second device of the object to which the eigenvalue belongs.
[0131] Then, after the audit operation permission request of the object to which the eigenvalue belongs is passed by the second device of the object to which the eigenvalue belongs, a private key shard of the object to which the eigenvalue belongs is generated, and the complete public key is calculated by combining the public key shards and sent to the first device of the object for eigenvalue operation; then the first device of the object for eigenvalue operation receives the complete public key sent by the second device of the object to which the eigenvalue belongs.
[0132] Based on this, the present application provides a possible implementation manner. The steps for obtaining the complete public key in S8 or S9 include the following S17-S20 (not shown in the figure):
[0133] S17: Generate an operation permission request for the eigenvalue of the object for eigenvalue operation to operate on the object to which the eigenvalue belongs and a private key shard of the object for eigenvalue operation.
[0134] S18: Calculate the public key shard according to the private key shard of the object for eigenvalue operation.
[0135] S19: Send the operation permission request and the public key shard to the second device.
[0136] S20: Receive the complete public key sent by the second device; the complete public key is calculated according to the public key shard and the private key shard of the object to which the eigenvalue belongs after the audit operation permission request of the object to which the eigenvalue belongs is passed.
[0137] Through the interaction between the object for eigenvalue operation and the object to which the eigenvalue belongs in advance, the object for eigenvalue operation obtains the private key shard of the object for eigenvalue operation and the complete public key corresponding to the private key shard of the object to which the eigenvalue belongs, providing public key data to ensure the accuracy and security of the operation certificate for the object for eigenvalue operation to apply to the target server for obtaining the operation certificate for the eigenvalue of the object for eigenvalue operation to operate on the object to which the eigenvalue belongs through the interaction with the object to which the eigenvalue belongs in advance.
[0138] As an example of S17-S20, in the above S1-S8 or the above S9-S16 example, first, the first device of the account operator generates an operation permission request for the account operator to operate on the amount of the account owner and a private key shard D1 of the account operator, calculates the public key shard P1 through D1, and sends the operation permission request and P1 to the second device of the account owner.
[0139] Then, after the audit operation permission request of the account owner is passed by the second device of the account owner, a private key shard D2 of the account owner is generated, the complete public key P is calculated by combining P1, and P is sent to the first device of the account operator; then the first device of the account operator receives P sent by the second device of the account owner.
[0140] In the embodiment of the present application, the transfer result in S205 is determined by the signature verification result of the target server verifying the preset signature with the preset public key in the transfer certificate and the matching result of the eigenvalue transfer request matching the independent transfer parameters corresponding to the transfer certificate; wherein, the signature verification result can be that the preset public key verifies the preset signature successfully or unsuccessfully, and the matching result can be that the eigenvalue transfer request matches the independent transfer parameters or the eigenvalue transfer request does not match the independent transfer parameters. Only when the signature verification result is that the preset public key verifies the preset signature successfully and the matching result is that the eigenvalue transfer request matches the independent transfer parameters, the target server determines that the eigenvalue transfer request is correct and secure, and then executes the eigenvalue transfer event. Correspondingly, the transfer result is that the eigenvalue transfer event is executed successfully; otherwise, when the signature verification result is that the preset public key verifies the preset signature unsuccessfully or the eigenvalue transfer request does not match the independent transfer parameters, the target server determines that there is a problem with the eigenvalue transfer request, and there is no need to execute the eigenvalue transfer event. Correspondingly, the transfer result is that the eigenvalue transfer event is executed unsuccessfully. Therefore, the present application provides a possible implementation manner. When the signature verification result is that the preset public key verifies the preset signature successfully and the matching result is that the eigenvalue transfer request matches the independent transfer parameters, the transfer result is that the eigenvalue transfer event is executed successfully; when the signature verification result is that the preset public key verifies the preset signature unsuccessfully or the eigenvalue transfer request does not match the independent transfer parameters, the transfer result is that the eigenvalue transfer event is executed unsuccessfully.
[0141] In the embodiment of the present application, for the eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue operation object transfers the eigenvalue is less than or equal to the restricted eigenvalue, it is necessary to represent the eigenvalue to be transferred that is less than or equal to the restricted eigenvalue of the object to which the eigenvalue operation object transfers the eigenvalue. Then, it is necessary to include an event identifier, the eigenvalue to be transferred, the transfer time, the operation object identifier of the eigenvalue operation object, the belonging object identifier of the object to which the eigenvalue belongs, and the transfer object identifier of the eigenvalue transfer object. Correspondingly, the eigenvalue transfer request for the eigenvalue transfer event representing that the eigenvalue to be transferred of the object to which the eigenvalue operation object transfers the eigenvalue is less than or equal to the restricted eigenvalue also needs to include an event identifier, the eigenvalue to be transferred, the transfer time, the operation object identifier, the belonging object identifier, and the transfer object identifier. Therefore, the present application provides a possible implementation manner. The eigenvalue transfer event includes an event identifier, the eigenvalue to be transferred, the transfer time, the operation object identifier of the eigenvalue operation object, the belonging object identifier of the object to which the eigenvalue belongs, and the transfer object identifier of the eigenvalue transfer object; the eigenvalue transfer request includes an event identifier, the eigenvalue to be transferred, the transfer time, the operation object identifier, the belonging object identifier, and the transfer object identifier.
[0142] Among them, the independent transfer parameters corresponding to the transfer certificate include a restricted eigenvalue and a restricted time range; then, the eigenvalue transfer request matching the independent transfer parameters means that the eigenvalue to be transferred is less than or equal to the restricted eigenvalue and the transfer time conforms to the restricted time range.
[0143] Next, taking the target server executing the method provided in the embodiments of the present application as an example, the eigenvalue transfer method provided in the embodiments of the present application will be introduced in detail in combination with the accompanying drawings. Refer to Figure 3 , Figure 3 which is a flowchart of another eigenvalue transfer method provided in the embodiments of the present application. The method includes:
[0144] S301: Receive an eigenvalue transfer request and a preset signature sent by a first device of an eigenvalue operation object; the eigenvalue transfer request represents an eigenvalue transfer event in which the to-be-transferred eigenvalue of the object to which the eigenvalue belongs transferred by the eigenvalue operation object is less than or equal to a limit eigenvalue. The preset signature is the first device's signature of the eigenvalue transfer request with a preset private key corresponding to a transfer certificate for independently transferring the limit eigenvalue of the object to which the eigenvalue belongs by the eigenvalue operation object.
[0145] In the related art, for each eigenvalue transfer event represented by the eigenvalue of the object to which the eigenvalue belongs transferred by the eigenvalue operation object, the eigenvalue operation object needs to interact with the object to which the eigenvalue belongs; after the eigenvalue transfer request is approved by the object to which the eigenvalue belongs, a complete signature is obtained through collaborative signature so that the target server can execute the eigenvalue transfer event after verifying that the complete signature passes. However, through research, it is found that the above method requires collaborative signature by the eigenvalue operation object and the object to which the eigenvalue belongs for each eigenvalue transfer event, and the interaction operations are relatively frequent and complex, consuming a lot of interaction resources, resulting in low eigenvalue transfer efficiency, thus affecting the eigenvalue transfer experience.
[0146] Therefore, in the embodiments of the present application, to solve the above problems, it can be considered that for each eigenvalue transfer event in which the to-be-transferred eigenvalue of the object to which the eigenvalue belongs transferred by the eigenvalue operation object is less than or equal to the limit eigenvalue, on the basis of ensuring the security of eigenvalue transfer, the eigenvalue operation object independently signs instead of the collaborative signature of the eigenvalue operation object and the object to which the eigenvalue belongs, so as to reduce interaction operations, save interaction resources, thereby improving the transfer efficiency of eigenvalue transfer and enhancing the transfer experience of eigenvalue transfer.
[0147] That is, the eigenvalue operation object needs to interact with the object to which the eigenvalue belongs in advance, apply to the target server to obtain a transfer certificate for independently transferring the limit eigenvalue of the object to which the eigenvalue belongs by the eigenvalue operation object. On the basis of this transfer certificate, for each eigenvalue transfer event in which the to-be-transferred eigenvalue of the object to which the eigenvalue belongs transferred by the eigenvalue operation object is less than or equal to the limit eigenvalue, the target server receives the signature independently signed by the eigenvalue operation object without interacting with the object to which the eigenvalue belongs for collaborative signature, and performs eigenvalue transfer.
[0148] Based on this, in actual applications, when the target server executes the eigenvalue transfer method, after the first device of the eigenvalue operation object receives the transfer certificate of the restricted eigenvalue of the object to which the eigenvalue belongs sent by the target server and independently transfers the eigenvalue of the object to which the eigenvalue belongs, for each eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue; since the first device of the eigenvalue operation object obtains the preset signature of the eigenvalue transfer request by signing the eigenvalue transfer request with the preset private key corresponding to the transfer certificate and sends the eigenvalue transfer request and the preset signature to the target server, the target server receives the eigenvalue transfer request and the preset signature sent by the first device of the eigenvalue operation object.
[0149] Based on the fact that the eigenvalue operation object pre-interacts with the object to which the eigenvalue belongs to obtain the transfer certificate of the restricted eigenvalue of the object to which the eigenvalue belongs independently, for each eigenvalue transfer event where the eigenvalue to be transferred is less than or equal to the restricted eigenvalue, the target server receives the eigenvalue operation object and does not need to interact with the object to which the eigenvalue belongs for collaborative signature, and can independently sign to obtain the preset signature through the preset private key corresponding to the transfer certificate; reducing interaction operations and saving interaction resources lays a foundation for improving the transfer efficiency of eigenvalue transfer and thus enhancing the transfer experience of eigenvalue transfer while ensuring the security of eigenvalue transfer.
[0150] As an example of this S301, in the eigenvalue transfer scenario of a financial transaction scenario, the eigenvalue operation object is an account operator, the object to which the eigenvalue belongs is the account owner, the transfer certificate is the transaction certificate Trade_Cert, the preset private key corresponding to the transaction certificate Trade_Cert is Trade_S, the restricted eigenvalue is the restricted amount X, the eigenvalue to be transferred is the amount to be traded, the eigenvalue transfer event is the amount transaction event, and the eigenvalue transfer request is the amount transaction request. Based on this, the target server receives the amount transaction request Trade_M and the preset signature Trade_s sent by the first device of the account operator; where Trade_M represents the amount transaction event where the account operator transfers the amount to be traded of the account owner that is less than or equal to the restricted amount X, and Trade_s is the signature of Trade_M by the first device of the account operator using Trade_S corresponding to Trade_Cert for the account operator to independently trade the restricted amount X of the account owner.
[0151] S302: Verify the preset signature according to the preset public key in the transfer certificate to obtain the verification result; match the independent transfer parameters corresponding to the transfer certificate according to the eigenvalue transfer request to obtain the matching result.
[0152] S303: Determine the transfer result of the eigenvalue transfer event according to the verification result and the matching result.
[0153] S304: Send the transfer result to the first device.
[0154] In the embodiments of the present application, after the target server receives the eigenvalue transfer request and the preset signature sent by the first device of the eigenvalue operation object when executing the above S301, since the preset signature is obtained by signing the eigenvalue transfer request with the preset private key corresponding to the transfer certificate, and the eigenvalue transfer request represents an eigenvalue transfer event in which the eigenvalue to be transferred of the object to which the eigenvalue belongs is less than or equal to the limit eigenvalue; then on the basis that the preset public key in the transfer certificate corresponds to the preset private key in the transfer certificate, and the independent transfer parameter corresponding to the transfer certificate represents the configuration parameter of the limit eigenvalue for the object to which the eigenvalue operation object independently transfers the eigenvalue, the target server not only needs to verify whether the preset signature passes through the preset public key in the transfer certificate, but also needs to determine whether the eigenvalue transfer request matches the independent transfer parameter corresponding to the transfer certificate, so as to determine whether to execute the eigenvalue transfer event to obtain the transfer result of the eigenvalue transfer event.
[0155] That is, the target server can obtain the signature verification result by verifying the preset signature with the preset public key in the transfer certificate, and obtain the matching result by matching the eigenvalue transfer request with the independent transfer parameter corresponding to the transfer certificate; determine the transfer result of the eigenvalue transfer event through the signature verification result and the matching result; send the transfer result to the first device of the eigenvalue operation object so that the first device of the eigenvalue operation object can obtain the transfer result of the eigenvalue transfer event.
[0156] Based on the above transfer certificate, the target server in S302 - S304 can obtain the transfer result of the eigenvalue transfer event by verifying the preset signature with the preset public key and matching the eigenvalue transfer request with the independent transfer parameter, and send it to the eigenvalue operation object; on the basis of ensuring the security of the eigenvalue transfer, improve the transfer efficiency of the eigenvalue transfer, thereby enhancing the transfer experience of the eigenvalue transfer.
[0157] As an example of S302 - S304, the preset public key corresponding to the preset private key Trade_S is Trade_P; based on this, the target server obtains the signature verification result by verifying the preset signature Trade_s with Trade_P in the transaction certificate Trade_Cert, obtains the matching result by matching the amount transaction request Trade_M with the independent transfer parameter corresponding to Trade_Cert; determines the transfer result of the amount transaction event through the signature verification result and the matching result; sends the transfer result to the first device of the account operator.
[0158] As can be seen from the above technical solution, the target server receives a feature value transfer request and a preset signature sent by a first device of a feature value operation object; the feature value transfer request indicates a feature value transfer event in which the feature value to be transferred of the object to which the feature value belongs transferred by the feature value operation object is less than or equal to a limit feature value, and the preset signature is a signature of the feature value transfer request by the first device using a preset private key corresponding to a transfer certificate for independently transferring the limit feature value of the object to which the feature value belongs by the feature value operation object; the preset signature is verified using the preset public key in the transfer certificate to obtain a verification result, and the transfer certificate corresponding independent transfer parameters are matched with the feature value transfer request to obtain a matching result; the transfer result of the feature value transfer event is determined based on the verification result and the matching result; and the transfer result is sent to the first device of the feature value operation object. Based on the fact that the feature value operation object pre-interacts with the object to which the feature value belongs to obtain a transfer certificate for independently transferring the limit feature value of the object to which the feature value belongs by the feature value operation object, for each feature value transfer event in which the feature value to be transferred is less than or equal to the limit feature value, the target server receives the signature independently signed by the feature value operation object without the need for the feature value operation object to interact with the object to which the feature value belongs for collaborative signature; based on the above transfer certificate, the transfer result of the feature value transfer event can be obtained by verifying the preset signature using the preset public key and matching the feature value transfer request with the independent transfer parameters, and sent to the feature value operation object, and the security of the feature value transfer is ensured.
[0159] Based on this, for each feature value transfer event in which the feature value to be transferred of the object to which the feature value belongs transferred by the feature value operation object is less than or equal to the limit feature value, there is no need for collaborative signature between the feature value operation object and the object to which the feature value belongs, and the feature value operation object signs independently, reducing interaction operations and saving interaction resources. On the basis of ensuring the security of the feature value transfer, the transfer efficiency of the feature value transfer is improved, thereby enhancing the transfer experience of the feature value transfer.
[0160] In the embodiment of the present application, the process by which the target server obtains a transfer certificate for independently transferring the limit feature value of the object to which the feature value belongs by the feature value operation object means that: after the feature value operation object and the object to which the feature value belongs collaboratively sign an independent transfer permission request indicating the independent transfer of the limit feature value of the object to which the feature value belongs by the feature value operation object, they apply to the target server for a transfer certificate for independently transferring the limit feature value of the object to which the feature value belongs by the feature value operation object; after the target server passes the verification using the complete public key in the operation certificate for the feature value of the object to which the feature value belongs operated by the feature value operation object, it issues a transfer certificate for the independent transfer permission request.
[0161] First, the first device of the eigenvalue operation object not only needs to generate an independent transfer permission request representing the restricted eigenvalue of the object to which the eigenvalue belongs for the eigenvalue operation object to independently transfer the eigenvalue, by using a preset private key, a preset public key, and an independent transfer parameter corresponding to the restricted eigenvalue for independently transferring the object to which the eigenvalue belongs; but also interacts with the second device of the object to which the eigenvalue belongs, and the eigenvalue operation object and the object to which the eigenvalue belongs jointly sign the independent transfer permission request to obtain a first complete signature; then send the independent transfer permission request and the first complete signature to the target server, and the target server receives the independent transfer permission request and the first complete signature sent by the first device of the eigenvalue operation object. Then, after the target server determines that the first complete signature is verified through the complete public key in the operation certificate for the eigenvalue of the object to which the eigenvalue operation object operates the eigenvalue, it issues a transfer certificate for the independent transfer permission request. In addition, the target server also needs to record the independent transfer parameter corresponding to the transfer certificate, and send the transfer certificate to the first device of the eigenvalue operation object, so that the first device of the eigenvalue operation object can obtain the transfer certificate. Therefore, the present application provides a possible implementation manner, and the steps for obtaining the transfer certificate in S301 include the following S21 - S24 (not shown in the figure):
[0162] S21: Receive the independent transfer permission request and the first complete signature sent by the first device; the independent transfer permission request is generated by the first device based on the transfer certificate request for signing the preset public key with the preset private key and the independent transfer parameter corresponding to the restricted eigenvalue, and the first complete signature is jointly signed by the eigenvalue operation object and the object to which the eigenvalue belongs for the independent transfer permission request.
[0163] S22: If the first complete signature is verified through the complete public key in the operation certificate for the eigenvalue of the object to which the eigenvalue operation object operates the eigenvalue, issue a transfer certificate according to the independent transfer permission request.
[0164] S23: Record the independent transfer parameter corresponding to the transfer certificate.
[0165] S24: Send the transfer certificate to the first device.
[0166] The target server pre-issues a transfer certificate for the restricted eigenvalue of the object to which the eigenvalue operation object independently transfers the eigenvalue; for each subsequent eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object of the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue, the target server receives the independent signature of the eigenvalue operation object without the need to interact with the object to which the eigenvalue belongs for joint signature, and provides certificate data to ensure the security of the eigenvalue transfer.
[0167] As an example of S21 - S24, the complete public key is P and the operation certificate is Cert. Based on the examples of S301 and the examples of S302 - S304 above, the first device of the account operator generates an independent transfer permission request M for the account operator to independently transfer the restricted amount X of the account owner through a preset private key Trade_S, a preset public key Trade_P, and an independent transfer parameter corresponding to the restricted amount X of the account owner; interacts with the second device of the account owner, and the account operator and the account owner obtain the first complete signature s for M; sends M and s to the target server, and the target server receives M and s sent by the account operator. After the target server determines that the signature verification of s by P in Cert for the amount by which the account operator operates the account owner passes, it issues a transaction certificate Trade_Cert for M. In addition, the target server records the independent transfer parameter corresponding to Trade_Cert and sends Trade_Cert to the first device of the account operator so that the first device of the account operator can obtain Trade_Cert.
[0168] In the embodiments of the present application, the process for the target server to obtain the operation certificate for the eigenvalue operation object to operate the eigenvalue of the object to which the eigenvalue belongs means that: the eigenvalue operation object and the object to which the eigenvalue belongs jointly sign a preset operation certificate request for the eigenvalue operation object to operate the eigenvalue of the object to which the eigenvalue belongs to obtain a target operation certificate request, and apply to the target server for the operation certificate for the eigenvalue operation object to operate the eigenvalue of the object to which the eigenvalue belongs; the target server issues a transfer certificate for the target operation certificate request.
[0169] First, the first device of the eigenvalue operation object not only needs to generate a preset operation certificate request for the eigenvalue operation object to operate the eigenvalue of the object to which the eigenvalue belongs through the complete public key; but also interacts with the second device of the object to which the eigenvalue belongs, and the eigenvalue operation object and the object to which the eigenvalue belongs jointly sign the preset operation certificate request to obtain the second complete signature; thus, a target operation certificate request is generated through the preset operation certificate request and the second complete signature, and the target operation certificate request is sent to the target server, and the target server receives the target operation certificate request sent by the first device of the eigenvalue operation object. Then, the target server issues an operation certificate for the target operation certificate request. In addition, the target server also needs to send the operation certificate to the first device of the eigenvalue operation object so that the first device of the eigenvalue operation object can obtain the operation certificate. Therefore, the present application provides a possible implementation manner, and the steps for obtaining the operation certificate in S22 include the following S25 - S27 (not shown in the figure):
[0170] S25: Receive a target operation certificate request sent by a first device; the target operation certificate request is generated by the first device based on a complete public key, a preset operation certificate request, and a second complete signature jointly signed by an eigenvalue operation object and an object to which the eigenvalue belongs for the preset operation certificate request.
[0171] S26: Issue an operation certificate according to the target operation certificate request.
[0172] S27: Send the operation certificate to the first device.
[0173] The target server in S25 - S27 pre - issues an operation certificate for the eigenvalue of the eigenvalue operation object operating on the object to which the eigenvalue belongs; this provides certificate data to ensure the accuracy and security of the transfer certificate for the subsequent target server to receive a transfer certificate for the restricted eigenvalue independently transferred by the eigenvalue operation object through prior interaction with the object to which the eigenvalue belongs. In addition, for each subsequent eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object to the object to which the eigenvalue belongs is greater than the restricted eigenvalue, the target server receives the signature jointly signed by the eigenvalue operation object and the object to which the eigenvalue belongs for eigenvalue transfer, providing certificate data to ensure the security of eigenvalue transfer.
[0174] As an example of S25 - S27, based on the example of S21 - S24 above, the first device of the account operator generates a preset operation certificate request CSR' for the account operator to operate on the amount of the account owner through the complete public key P; interacts with the second device of the account owner, and the account operator and the account owner jointly sign CSR' to obtain the second complete signature s'; generates a target operation certificate request CSR through CSR' and s', and sends CSR to the target server, then the target server receives CSR sent by the first device of the account operator. The target server issues an operation certificate Cert for CSR. In addition, the target server also needs to send Cert to the first device of the account operator.
[0175] In the embodiments of the present application, the signature verification result may be that the preset public key verifies the preset signature as passed or not passed, and the matching result may be that the eigenvalue transfer request matches the independent transfer parameter or the eigenvalue transfer request does not match the independent transfer parameter. Only when the signature verification result is that the preset public key verifies the preset signature as passed and the matching result is that the eigenvalue transfer request matches the independent transfer parameter, the target server determines that the eigenvalue transfer request is correct and secure, and then executes the eigenvalue transfer event, thereby determining that the transfer result is that the eigenvalue transfer event is executed successfully; conversely, when the signature verification result is that the preset public key verifies the preset signature as not passed or the eigenvalue transfer request does not match the independent transfer parameter, the target server determines that there is a problem with the eigenvalue transfer request, and then there is no need to execute the eigenvalue transfer event, thereby determining that the transfer result is that the eigenvalue transfer event is executed failed. Therefore, the present application provides a possible implementation manner, and S303 includes the following S3031 or S3032 (not shown in the figure):
[0176] S2031: If the signature verification result is that the preset public key verifies the preset signature as passed and the matching result is that the eigenvalue transfer request matches the independent transfer parameter, by executing the eigenvalue transfer event, determine that the transfer result is that the eigenvalue transfer event is executed successfully.
[0177] S2032: If the signature verification result is that the preset public key verifies the preset signature as not passed or the matching result is that the eigenvalue transfer request does not match the independent transfer parameter, determine that the transfer result is that the eigenvalue transfer event is executed failed.
[0178] S2031 and S2032 accurately determine whether the eigenvalue transfer request is correct and secure by whether the preset public key verifies the preset signature as passed or not passed, and whether the eigenvalue transfer request matches the independent transfer parameter or the eigenvalue transfer request does not match the independent transfer parameter, thereby accurately determining whether to execute the eigenvalue transfer event and obtaining the accurate transfer result of the eigenvalue transfer event to ensure the correctness and security of the eigenvalue transfer.
[0179] In summary, taking the cooperation between the first device with the eigenvalue operation object and the target server to execute the method provided by the embodiments of the present application as an example, the eigenvalue transfer method provided by the embodiments of the present application will be introduced in detail with reference to the accompanying drawings. Refer to Figure 4 , Figure 4 which is an interaction diagram of an eigenvalue transfer method provided by the embodiments of the present application. The method includes:
[0180] S401: After the first device with the eigenvalue operation object receives the transfer certificate of the restricted eigenvalue of the object to which the eigenvalue of the eigenvalue operation object independently belongs sent by the target server, for each eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue of the eigenvalue operation object belongs is less than or equal to the restricted eigenvalue, generate an eigenvalue transfer request according to the eigenvalue transfer event.
[0181] S402: The first device of the eigenvalue operation object calculates a digest of the eigenvalue transfer request to obtain a first message digest.
[0182] S403: The first device of the eigenvalue operation object signs the first message digest according to the preset private key corresponding to the transfer certificate to obtain a preset signature of the eigenvalue transfer request.
[0183] S404: The first device of the eigenvalue operation object sends the eigenvalue transfer request and the preset signature to the target server.
[0184] S405: The target server verifies the preset signature according to the preset public key in the transfer certificate to obtain a verification result.
[0185] S406: The target server matches the independent transfer parameters corresponding to the transfer certificate according to the eigenvalue transfer request to obtain a matching result.
[0186] S407: The target server determines the transfer result of the eigenvalue transfer event according to the verification result and the matching result.
[0187] S408: The target server sends the transfer result to the first device of the eigenvalue operation object.
[0188] It can be seen from the above technical solution that for each eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue belongs is less than or equal to the limit eigenvalue, there is no need for the eigenvalue operation object and the object to which the eigenvalue belongs to jointly sign. The eigenvalue operation object signs independently, reducing interactive operations and saving interactive resources. On the basis of ensuring the security of eigenvalue transfer, the transfer efficiency of eigenvalue transfer is improved, thereby enhancing the transfer experience of eigenvalue transfer.
[0189] Taking the method of obtaining a transfer certificate by the cooperation of the first device of the eigenvalue operation object, the second device of the object to which the eigenvalue belongs, and the target server as an example, the method for obtaining a transfer certificate provided in the embodiments of the present application will be introduced in detail with reference to the accompanying drawings. See Figure 5 , Figure 5 is an interaction diagram of a method for obtaining a transfer certificate provided in the embodiments of the present application. The method includes:
[0190] S501: The first device of the eigenvalue operation object signs the preset public key according to the preset private key to obtain a transfer certificate request.
[0191] S502: The first device of the eigenvalue operation object generates an independent transfer permission request according to the transfer certificate request and the independent transfer parameters corresponding to the limit eigenvalue.
[0192] S503: The first device of the eigenvalue operation object calculates a digest of the independent transfer permission request to obtain a second message digest.
[0193] S504: The first device of the eigenvalue operation object generates a first intermediate parameter.
[0194] S505: The first device of the eigenvalue operation object sends an independent transfer permission request, a second message digest, and a first intermediate parameter to the second device of the object to which the eigenvalue belongs.
[0195] S506: After the second device of the object to which the eigenvalue belongs approves the independent transfer permission request, the second device generates a first signature shard according to the private key shard of the object to which the eigenvalue belongs, the second message digest, and the first intermediate parameter.
[0196] In addition, the second device of the object to which the eigenvalue belongs can also calculate the digest of the independent transfer permission request to obtain a fourth message digest; determine whether the fourth message digest matches the second message digest, and if so, it means that the second message digest is correct.
[0197] S507: The second device of the object to which the eigenvalue belongs sends the first signature shard to the first device of the eigenvalue operation object.
[0198] S508: The first device of the eigenvalue operation object generates a first complete signature according to the first signature shard and the second signature shard; the second signature shard is generated according to the private key shard of the eigenvalue operation object.
[0199] S509: The first device of the eigenvalue operation object sends an independent transfer permission request and the first complete signature to the target server.
[0200] S510: If the target server verifies the first complete signature through the complete public key in the operation certificate for the eigenvalue operation object to operate on the eigenvalue of the object to which the eigenvalue belongs, the target server issues a transfer certificate according to the independent transfer permission request.
[0201] S511: The target server records the independent transfer parameters corresponding to the transfer certificate.
[0202] S512: The target server sends the transfer certificate to the first device of the eigenvalue operation object.
[0203] Taking the method of obtaining an operation certificate by the cooperation of the first device of the eigenvalue operation object, the second device of the object to which the eigenvalue belongs, and the target server as an example, the method of obtaining an operation certificate provided in the embodiments of the present application will be introduced in detail with reference to the accompanying drawings. See Figure 6 , Figure 6 is an interaction diagram of a method for obtaining an operation certificate provided in the embodiments of the present application. The method includes:
[0204] S601: The first device of the eigenvalue operation object generates a preset operation certificate request according to the complete public key.
[0205] S602: The first device of the eigenvalue operation object calculates the digest of the preset operation certificate request to obtain a third message digest.
[0206] S603: The first device of the eigenvalue operation object generates a second intermediate parameter.
[0207] S604: The first device of the eigenvalue operation object sends the preset operation certificate request, the third message digest, and the second intermediate parameter to the second device of the object to which the eigenvalue belongs.
[0208] S605: After the second device of the object to which the eigenvalue belongs approves the preset operation certificate request, the second device generates a third signature shard according to the private key shard of the object to which the eigenvalue belongs, the third message digest, and the second intermediate parameter.
[0209] In addition, the second device of the object to which the eigenvalue belongs can also calculate the digest of the preset operation certificate request to obtain a fifth message digest; determine whether the fifth message digest matches the third message digest, and if so, it means that the third message digest is correct.
[0210] S606: The second device of the object to which the eigenvalue belongs sends the third signature shard to the first device of the eigenvalue operation object.
[0211] S607: The first device of the eigenvalue operation object generates a second complete signature according to the third signature shard and the fourth signature shard; the fourth signature shard is generated according to the private key shard of the eigenvalue operation object.
[0212] S608: The first device of the eigenvalue operation object generates a target operation certificate request according to the preset operation certificate request and the second complete signature.
[0213] S609: The first device of the eigenvalue operation object sends the target operation certificate request to the target server.
[0214] S610: The target server issues an operation certificate according to the target operation certificate request.
[0215] S611: The target server sends the operation certificate to the first device of the eigenvalue operation object.
[0216] Taking the method for the first device of the eigenvalue operation object and the second device of the object to which the eigenvalue belongs to obtain the complete public key as an example, and in combination with the accompanying drawings, the method for obtaining the complete public key provided by the embodiments of the present application will be introduced in detail. See Figure 7 , Figure 7 is an interaction diagram of a method for obtaining a complete public key provided by the embodiments of the present application. The method includes:
[0217] S701: The first device of the eigenvalue operation object generates an operation permission request for the eigenvalue of the object to which the eigenvalue operation object belongs and a private key shard of the eigenvalue operation object.
[0218] S702: The first device of the eigenvalue operation object calculates a public key shard based on the private key shard of the eigenvalue operation object.
[0219] S703: The first device of the eigenvalue operation object sends the operation permission request and the public key shard to the second device of the object to which the eigenvalue belongs.
[0220] S704: The second device of the object to which the eigenvalue belongs generates a private key shard of the object to which the eigenvalue belongs.
[0221] S705: After the second device of the object to which the eigenvalue belongs approves the operation permission request, the second device calculates a complete public key based on the public key shard and the private key shard of the object to which the eigenvalue belongs.
[0222] S706: The second device of the object to which the eigenvalue belongs sends the complete public key to the first device of the eigenvalue operation object.
[0223] It should be noted that, based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners.
[0224] Based on Figure 2 the eigenvalue transfer method provided in the corresponding embodiment, the embodiment of the present application further provides an eigenvalue transfer device. Refer to Figure 8 , Figure 8 which is the structural diagram of an eigenvalue transfer device provided in the embodiment of the present application. The eigenvalue transfer device 800 includes: a generating unit 801, a calculating unit 802, a signing unit 803, a first sending unit 804, and a first receiving unit 805;
[0225] The generating unit 801 is configured to, after receiving a transfer certificate for the eigenvalue operation object to independently transfer the restricted eigenvalue of the object to which the eigenvalue belongs sent by the target server, for each eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object to the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue, generate an eigenvalue transfer request according to the eigenvalue transfer event;
[0226] The calculating unit 802 is configured to perform a digest calculation on the eigenvalue transfer request to obtain a first message digest;
[0227] The signing unit 803 is configured to sign the first message digest according to the preset private key corresponding to the transfer certificate to obtain a preset signature of the eigenvalue transfer request;
[0228] The first sending unit 804 is configured to send a feature value transfer request and a preset signature to the target server;
[0229] The first receiving unit 805 is configured to receive the transfer result of the feature value transfer event sent by the target server; the transfer result is determined by the target server based on the signature verification result of verifying the preset signature with the preset public key in the transfer certificate and the matching result of the feature value transfer request matching the independent transfer parameter corresponding to the transfer certificate.
[0230] In a possible implementation manner, the signature unit 803 is further configured to sign the preset public key according to the preset private key to obtain a transfer certificate request;
[0231] The generating unit 801 is further configured to generate an independent transfer permission request according to the transfer certificate request and the independent transfer parameter corresponding to the restricted feature value;
[0232] The calculating unit 802 is further configured to perform a digest calculation on the independent transfer permission request to obtain a second message digest; and generate a first intermediate parameter;
[0233] The first sending unit 804 is further configured to send the independent transfer permission request, the second message digest, and the first intermediate parameter to the second device of the object to which the feature value belongs;
[0234] The first receiving unit 805 is further configured to receive the first signature shard sent by the second device; the first signature shard is generated according to the private key shard of the object to which the feature value belongs, the second message digest, and the first intermediate parameter after the object to which the feature value belongs approves the independent transfer permission request;
[0235] The generating unit 801 is further configured to generate a first complete signature according to the first signature shard and the second signature shard; the second signature shard is generated according to the private key shard of the feature value operation object;
[0236] The first sending unit 804 is further configured to send the independent transfer permission request and the first complete signature to the target server;
[0237] The first receiving unit 805 is further configured to receive the transfer certificate sent by the target server; the transfer certificate is issued by the target server for the independent transfer permission request after verifying the first complete signature with the complete public key in the operation certificate of the feature value of the object to which the feature value operation object operates on the object to which the feature value belongs.
[0238] In a possible implementation manner, the generating unit 801 is further configured to generate a preset operation certificate request according to the complete public key;
[0239] The calculating unit 802 is further configured to perform a digest calculation on the preset operation certificate request to obtain a third message digest; and generate a second intermediate parameter;
[0240] The first sending unit 804 is further configured to send a preset operation certificate request, a third message digest, and a second intermediate parameter to a second device;
[0241] The first receiving unit 805 is further configured to receive a third signature shard sent by the second device; the third signature shard is generated according to the private key shard of the object to which the eigenvalue belongs, the third message digest, and the second intermediate parameter after the object to which the eigenvalue belongs approves the preset operation certificate request.
[0242] The generating unit 801 is further configured to generate a second complete signature according to the third signature shard and a fourth signature shard; the fourth signature shard is generated according to the private key shard of the eigenvalue operating object.
[0243] The generating unit 801 is further configured to generate a target operation certificate request according to the preset operation certificate request and the second complete signature.
[0244] The first sending unit 804 is further configured to send the target operation certificate request to a target server.
[0245] The first receiving unit 805 is further configured to receive an operation certificate sent by the target server; the operation certificate is issued by the target server according to the target operation certificate request.
[0246] In a possible implementation manner, the generating unit 801 is further configured to generate an operation permission request for the eigenvalue operating object to operate on the eigenvalue of the object to which the eigenvalue belongs and a private key shard of the eigenvalue operating object.
[0247] The calculating unit 802 is further configured to calculate a public key shard according to the private key shard of the eigenvalue operating object.
[0248] The first sending unit 804 is further configured to send the operation permission request and the public key shard to the second device.
[0249] The first receiving unit 805 is further configured to receive a complete public key sent by the second device; the complete public key is calculated according to the public key shard and the private key shard of the object to which the eigenvalue belongs after the object to which the eigenvalue belongs approves the operation permission request.
[0250] In a possible implementation manner, the signature verification result is that the preset public key verifies the preset signature and passes, and the matching result is that the eigenvalue transfer request matches the independent transfer parameter, and the transfer result is that the eigenvalue transfer event is executed successfully; the signature verification result is that the preset public key verifies the preset signature and fails, or the eigenvalue transfer request does not match the independent transfer parameter, and the transfer result is that the eigenvalue transfer event is executed failed.
[0251] In a possible implementation, the eigenvalue transfer event includes an event identifier, an eigenvalue to be transferred, a transfer time, an operation object identifier of the eigenvalue operation object, an object identifier of the object to which the eigenvalue belongs, and a transfer object identifier of the eigenvalue transfer object; the eigenvalue transfer request includes an event identifier, an eigenvalue to be transferred, a transfer time, an operation object identifier, an object identifier of the object to which the eigenvalue belongs, and a transfer object identifier.
[0252] As can be seen from the above technical solution, after the first device of the eigenvalue operation object receives the transfer certificate of the restricted eigenvalue for independently transferring the object to which the eigenvalue belongs sent by the target server, for each eigenvalue transfer event where the eigenvalue to be transferred for transferring the object to which the eigenvalue belongs by the eigenvalue operation object is less than or equal to the restricted eigenvalue, an eigenvalue transfer request for the eigenvalue transfer event is generated; the first message digest of the eigenvalue transfer request is calculated; the first message digest is signed with the preset private key corresponding to the transfer certificate to obtain the preset signature of the eigenvalue transfer request; the eigenvalue transfer request and the preset signature are sent to the target server. The target server determines the transfer result of the eigenvalue transfer event based on the verification result of verifying the preset signature with the preset public key in the transfer certificate and the matching result of the eigenvalue transfer request matching the independent transfer parameters corresponding to the transfer certificate; and sends the transfer result to the first device so that the first device can receive the transfer result. It can be seen that based on the interaction between the eigenvalue operation object and the object to which the eigenvalue belongs in advance to obtain the transfer certificate of the restricted eigenvalue for the eigenvalue operation object to independently transfer the object to which the eigenvalue belongs, for each eigenvalue transfer event where the eigenvalue to be transferred is less than or equal to the restricted eigenvalue, the eigenvalue operation object does not need to interact with the object to which the eigenvalue belongs for collaborative signature, and can directly sign with the preset private key corresponding to the transfer certificate to obtain the preset signature and send it to the target server; so that the target server can, based on the above transfer certificate, verify the preset signature with the preset public key and match the eigenvalue transfer request with the independent transfer parameters to obtain the transfer result of the eigenvalue transfer event and send it to the eigenvalue operation object, and ensure the security of the eigenvalue transfer.
[0253] Based on this, for each eigenvalue transfer event where the eigenvalue to be transferred for transferring the object to which the eigenvalue belongs by the eigenvalue operation object is less than or equal to the restricted eigenvalue, there is no need for collaborative signature between the eigenvalue operation object and the object to which the eigenvalue belongs. The eigenvalue operation object signs independently, reducing interaction operations and saving interaction resources. On the basis of ensuring the security of the eigenvalue transfer, the transfer efficiency of the eigenvalue transfer is improved, thereby enhancing the transfer experience of the eigenvalue transfer.
[0254] Based Figure 3 Corresponding to the eigenvalue transfer method provided in the embodiment, the embodiment of the present application also provides another eigenvalue transfer device. See Figure 9 , Figure 9The following is a structural diagram of another eigenvalue transfer device provided by an embodiment of the present application. The eigenvalue transfer device 900 includes: a second receiving unit 901, a signature verification unit 902, a matching unit 903, a determination unit 904, and a second sending unit 905;
[0255] The second receiving unit 901 is configured to receive an eigenvalue transfer request and a preset signature sent by a first device of an eigenvalue operation object; the eigenvalue transfer request represents an eigenvalue transfer event in which the eigenvalue to be transferred of the object to which the eigenvalue of the eigenvalue operation object belongs is less than or equal to a limit eigenvalue, and the preset signature is a signature of the eigenvalue transfer request by the first device using a preset private key corresponding to a transfer certificate of the limit eigenvalue of the object to which the eigenvalue of the eigenvalue operation object belongs independently transferred;
[0256] The signature verification unit 902 is configured to verify the preset signature according to the preset public key in the transfer certificate to obtain a signature verification result;
[0257] The matching unit 903 is configured to match the independent transfer parameter corresponding to the transfer certificate according to the eigenvalue transfer request to obtain a matching result;
[0258] The determination unit 904 is configured to determine a transfer result of the eigenvalue transfer event according to the signature verification result and the matching result;
[0259] The second sending unit 905 is configured to send the transfer result to the first device.
[0260] In a possible implementation manner, the device further includes: a signing unit and a recording unit;
[0261] The second receiving unit 901 is further configured to receive an independent transfer permission request and a first complete signature sent by the first device; the independent transfer permission request is generated by the first device according to a transfer certificate request for signing a preset public key using a preset private key and an independent transfer parameter corresponding to the limit eigenvalue, and the first complete signature is a collaborative signature of the eigenvalue operation object and the object to which the eigenvalue belongs for the independent transfer permission request;
[0262] The signing unit is configured to, if the verification of the first complete signature passes according to the complete public key in the operation certificate of the eigenvalue of the object to which the eigenvalue operation object operates on the eigenvalue, sign and issue a transfer certificate according to the independent transfer permission request;
[0263] The recording unit is configured to record the independent transfer parameter corresponding to the transfer certificate;
[0264] The second sending unit 905 is further configured to send the transfer certificate to the first device.
[0265] In a possible implementation, the second receiving unit 901 is further configured to receive a target operation certificate request sent by the first device; the target operation certificate request is generated based on a preset operation certificate request generated by the first device according to the complete public key, and a second complete signature jointly signed by the eigenvalue operation object and the object to which the eigenvalue belongs for the preset operation certificate request;
[0266] The signing unit is further configured to sign an operation certificate according to the target operation certificate request;
[0267] The second sending unit 905 is further configured to send the operation certificate to the first device.
[0268] In a possible implementation, the determining unit 904 is specifically configured to:
[0269] If the signature verification result is that the preset public key verifies the preset signature successfully and the matching result is that the eigenvalue transfer request matches the independent transfer parameter, by executing the eigenvalue transfer event, determine that the transfer result is that the eigenvalue transfer event is executed successfully;
[0270] If the signature verification result is that the preset public key verifies the preset signature fails or the matching result is that the eigenvalue transfer request does not match the independent transfer parameter, determine that the transfer result is that the eigenvalue transfer event is executed failed.
[0271] It can be seen from the above technical solution that the target server receives the eigenvalue transfer request and the preset signature sent by the first device of the eigenvalue operation object; the eigenvalue transfer request represents an eigenvalue transfer event in which the eigenvalue to be transferred of the object to which the eigenvalue belongs transferred by the eigenvalue operation object is less than or equal to the restricted eigenvalue, and the preset signature is the first device's signature of the eigenvalue transfer request according to the preset private key corresponding to the transfer certificate of the restricted eigenvalue for independently transferring the object to which the eigenvalue belongs by the eigenvalue operation object; the signature verification result is obtained by verifying the preset signature with the preset public key in the transfer certificate, and the matching result is obtained by matching the eigenvalue transfer request with the independent transfer parameter corresponding to the transfer certificate; the transfer result of the eigenvalue transfer event is determined through the signature verification result and the matching result; and the transfer result is sent to the first device of the eigenvalue operation object. Based on the fact that the eigenvalue operation object pre-interacts with the object to which the eigenvalue belongs to obtain the transfer certificate of the restricted eigenvalue for independently transferring the object to which the eigenvalue belongs by the eigenvalue operation object, for each eigenvalue transfer event where the eigenvalue to be transferred is less than or equal to the restricted eigenvalue, the target server receives the signature independently signed by the eigenvalue operation object without the need for the eigenvalue operation object to interact with the object to which the eigenvalue belongs for joint signature; based on the above transfer certificate, by verifying the preset signature with the preset public key and matching the eigenvalue transfer request with the independent transfer parameter, the transfer result of the eigenvalue transfer event can be obtained and sent to the eigenvalue operation object, and the security of the eigenvalue transfer is ensured.
[0272] Based on this, for each eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue operation object transfers the eigenvalue is less than or equal to the limit eigenvalue, the device does not require the collaborative signature of the eigenvalue operation object and the object to which the eigenvalue belongs. The eigenvalue operation object signs independently, reducing interactive operations and saving interactive resources. On the basis of ensuring the security of eigenvalue transfer, the transfer efficiency of eigenvalue transfer is improved, thereby enhancing the transfer experience of eigenvalue transfer.
[0273] The embodiment of the present application also provides a computer device, which may be a server. Refer to Figure 10 , Figure 10 which is a structural diagram of a server provided by the embodiment of the present application. The server 1000 may vary greatly due to configuration or performance differences, and may include one or more processors, such as the CPU 1022, and a memory 1032, and one or more storage media 1030 (such as one or more mass storage devices) for storing application programs 1042 or data 1044. Among them, the memory 1032 and the storage media 1030 may be transient storage or persistent storage. The program stored in the storage media 1030 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the server. Further, the central processing unit 1022 may be configured to communicate with the storage media 1030 and execute a series of instruction operations in the storage media 1030 on the server 1000.
[0274] The server 1000 may also include one or more power supplies 1026, one or more wired or wireless network interfaces 1050, one or more input / output interfaces 1058, and / or one or more operating systems 1041, such as Windows Server TM , Mac OS X TM , Unix TM , Linux TM , FreeBSD TM and so on.
[0275] In this embodiment, the central processing unit 1022 in the server 1000 may execute the methods provided in various optional implementation manners of the above embodiments.
[0276] The computer device provided by the embodiment of the present application may also be a terminal. Refer to Figure 11 , Figure 11The structural diagram of a terminal provided by an embodiment of the present application. Taking the terminal as a smart phone as an example, the smart phone includes: a Radio Frequency (RF) circuit 1110, a memory 1120, an input unit 1130, a display unit 1140, a sensor 1150, an audio circuit 1160, a Wireless Fidelity (WiFi) module 1170, a processor 1180, and a power supply 1190, etc. The input unit 1130 may include a touch panel 1131 and other input devices 1132, the display unit 1140 may include a display panel 1141, and the audio circuit 1160 may include a speaker 1161 and a microphone 1162. Those skilled in the art can understand that Figure 11 the smart phone structure shown in
[0277] does not limit the smart phone, and may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements. The memory 1120 can be used to store software programs and modules. The processor 1180 executes various functional applications and data processing of the smart phone by running the software programs and modules stored in the memory 1120. The memory 1120 may mainly include a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area can store data created according to the use of the smart phone (such as audio data, phone book, etc.), etc. In addition, the memory 1120 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0278] The processor 1180 is the control center of the smart phone, connecting various parts of the entire smart phone through various interfaces and lines. By running or executing the software programs and / or modules stored in the memory 1120, and by calling the data stored in the memory 1120, it executes various functions of the smart phone and processes data. Optionally, the processor 1180 may include one or more processing units; preferably, the processor 1180 may integrate an application processor and a modulation and demodulation processor. Among them, the application processor mainly processes the operating system, user interface, and application programs, etc., and the modulation and demodulation processor mainly processes wireless communication. It can be understood that the above modulation and demodulation processor may not be integrated into the processor 1180.
[0279] In this embodiment, the processor 1180 in the smart phone can execute the methods provided in various optional implementation manners of the above embodiments.
[0280] According to one aspect of the present application, there is provided a computer-readable storage medium for storing a computer program. When the computer program runs on a computer device, the computer device is caused to execute the methods provided in the various alternative implementations of the above embodiments.
[0281] According to one aspect of the present application, there is provided a computer program product. The computer program product includes a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, causing the computer device to execute the methods provided in the various alternative implementations of the above embodiments.
[0282] The descriptions of the processes or structures corresponding to the above respective drawings each have their own focuses. For parts not detailed in a certain process or structure, reference may be made to the relevant descriptions of other processes or structures.
[0283] Terms such as "first" and "second" in the specification of the present application and the above drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0284] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.
[0285] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0286] In addition, in each embodiment of the present application, each functional unit may be integrated into a processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0287] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), RAM, magnetic disks, or optical discs that can store computer programs.
[0288] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of each embodiment of the present application.
Claims
1. A method for eigenvalue transfer, characterized in that, Performed by a first device for an eigenvalue operation object, the method includes: After receiving a transfer certificate of a restricted eigenvalue of an object to which the eigenvalue of the eigenvalue operation object independently transfers, for each eigenvalue transfer event where the eigenvalue to be transferred of the object to which the eigenvalue of the eigenvalue operation object transfers is less than or equal to the restricted eigenvalue, generating an eigenvalue transfer request according to the eigenvalue transfer event; Calculating a digest of the eigenvalue transfer request to obtain a first message digest; Signing the first message digest with a preset private key corresponding to the transfer certificate to obtain a preset signature of the eigenvalue transfer request; Sending the eigenvalue transfer request and the preset signature to the target server; Receiving a transfer result of the eigenvalue transfer event sent by the target server; the transfer result is determined by the target server based on a signature verification result of verifying the preset signature with a preset public key in the transfer certificate and a matching result of the eigenvalue transfer request matching independent transfer parameters corresponding to the transfer certificate.
2. The method according to claim 1, characterized in that, The step of obtaining the transfer certificate includes: Signing the preset public key with the preset private key to obtain a transfer certificate request; Generating an independent transfer permission request according to the transfer certificate request and independent transfer parameters corresponding to the restricted eigenvalue; Calculating a digest of the independent transfer permission request to obtain a second message digest; generating a first intermediate parameter; Sending the independent transfer permission request, the second message digest, and the first intermediate parameter to a second device of the object to which the eigenvalue belongs; Receiving a first signature shard sent by the second device; the first signature shard is generated by the object to which the eigenvalue belongs according to a private key shard of the object to which the eigenvalue belongs, the second message digest, and the first intermediate parameter after the independent transfer permission request is approved; Generating a first complete signature according to the first signature shard and a second signature shard; the second signature shard is generated according to a private key shard of the eigenvalue operation object; Sending the independent transfer permission request and the first complete signature to the target server; Receiving the transfer certificate sent by the target server; the transfer certificate is issued by the target server for the independent transfer permission request after the first complete signature is verified to pass by a complete public key in an operation certificate of the eigenvalue of the object to which the eigenvalue operation object operates on the object to which the eigenvalue belongs.
3. The method according to claim 2, characterized in that, The step of obtaining the operation certificate includes: Generating a preset operation certificate request according to the complete public key; Calculating a digest of the preset operation certificate request to obtain a third message digest; generating a second intermediate parameter; Sending the preset operation certificate request, the third message digest, and the second intermediate parameter to the second device; Receiving a third signature shard sent by the second device; the third signature shard is generated by the object to which the eigenvalue belongs according to a private key shard of the object to which the eigenvalue belongs, the third message digest, and the second intermediate parameter after the preset operation certificate request is approved; Generate a second complete signature based on the third signature shard and the fourth signature shard; the fourth signature shard is generated based on the private key shard of the eigenvalue operation object; Generate a target operation certificate request based on the preset operation certificate request and the second complete signature; Send the target operation certificate request to the target server; Receive the operation certificate sent by the target server; the operation certificate is issued by the target server according to the target operation certificate request.
4. The method according to claim 2 or 3, characterized in that, The steps for obtaining the complete public key include: Generate an operation permission request for the eigenvalue operation object to operate on the eigenvalue of the object to which the eigenvalue belongs and the private key shard of the eigenvalue operation object; Calculate the public key shard according to the private key shard of the eigenvalue operation object; Send the operation permission request and the public key shard to the second device; Receive the complete public key sent by the second device; the complete public key is calculated according to the public key shard and the private key shard of the object to which the eigenvalue belongs after the object to which the eigenvalue belongs approves the operation permission request.
5. The method according to claim 1, characterized in that, The signature verification result is that the preset public key verifies the preset signature successfully, and the matching result is that the eigenvalue transfer request matches the independent transfer parameter, and the transfer result is that the eigenvalue transfer event is executed successfully; The signature verification result is that the preset public key fails to verify the preset signature, or the eigenvalue transfer request does not match the independent transfer parameter, and the transfer result is that the eigenvalue transfer event fails to be executed.
6. The method according to any one of claims 1 - 5, characterized in that, The eigenvalue transfer event includes an event identifier, the eigenvalue to be transferred, the transfer time, the operation object identifier of the eigenvalue operation object, the belonging object identifier of the object to which the eigenvalue belongs, and the transfer object identifier of the eigenvalue transfer object; the eigenvalue transfer request includes the event identifier, the eigenvalue to be transferred, the transfer time, the operation object identifier, the belonging object identifier, and the transfer object identifier.
7. A method for eigenvalue transfer, characterized in that, Executed by the target server, the method includes: Receive an eigenvalue transfer request and a preset signature sent by a first device of an eigenvalue operation object; the eigenvalue transfer request represents an eigenvalue transfer event in which the eigenvalue operation object transfers an eigenvalue to be transferred of an object to which the eigenvalue belongs that is less than or equal to a limit eigenvalue, and the preset signature is the first device's signature of the eigenvalue transfer request using a preset private key corresponding to a transfer certificate for the limit eigenvalue independently transferred by the eigenvalue operation object of the object to which the eigenvalue belongs; Verify the preset signature using the preset public key in the transfer certificate to obtain a signature verification result; match the eigenvalue transfer request with the independent transfer parameter corresponding to the transfer certificate to obtain a matching result; Determine the transfer result of the eigenvalue transfer event according to the signature verification result and the matching result; Send the transfer result to the first device.
8. The method according to claim 7, wherein The steps for obtaining the transfer certificate include: Receive the independent transfer permission request and the first complete signature sent by the first device; the independent transfer permission request is generated by the first device based on the transfer certificate request for signing the preset public key with the preset private key and the independent transfer parameters corresponding to the restricted eigenvalue, and the first complete signature is jointly signed by the eigenvalue operation object and the object to which the eigenvalue belongs for the independent transfer permission request; If the verification of the first complete signature passes using the complete public key in the operation certificate for operating the eigenvalue of the object to which the eigenvalue belongs by the eigenvalue operation object, issue the transfer certificate according to the independent transfer permission request; Record the independent transfer parameters corresponding to the transfer certificate; Send the transfer certificate to the first device.
9. The method according to claim 8, wherein The steps for obtaining the operation certificate include: Receive the target operation certificate request sent by the first device; the target operation certificate request is generated by the first device based on the preset operation certificate request generated from the complete public key and the second complete signature jointly signed by the eigenvalue operation object and the object to which the eigenvalue belongs for the preset operation certificate request; Issue the operation certificate according to the target operation certificate request; Send the operation certificate to the first device.
10. The method according to claim 7, wherein The determining of the transfer result of the eigenvalue transfer event according to the verification result and the matching result includes: If the verification result is that the preset public key passes the verification of the preset signature and the matching result is that the eigenvalue transfer request matches the independent transfer parameters, determine the transfer result as the successful execution of the eigenvalue transfer event by executing the eigenvalue transfer event; If the verification result is that the preset public key fails to verify the preset signature or the matching result is that the eigenvalue transfer request does not match the independent transfer parameters, determine the transfer result as the failure of the eigenvalue transfer event to execute.
11. An eigenvalue transfer device, characterized in that The first device deployed on the eigenvalue operation object, the device includes: a generation unit, a calculation unit, a signature unit, a first sending unit and a first receiving unit; The generation unit is configured to, after receiving the transfer certificate for the restricted eigenvalue of the object to which the eigenvalue belongs independently transferred by the eigenvalue operation object sent by the target server, for each eigenvalue transfer event where the eigenvalue to be transferred by the eigenvalue operation object to the object to which the eigenvalue belongs is less than or equal to the restricted eigenvalue, generate an eigenvalue transfer request according to the eigenvalue transfer event; The calculation unit is configured to perform a digest calculation on the eigenvalue transfer request to obtain a first message digest; The signature unit is configured to sign the first message digest with the preset private key corresponding to the transfer certificate to obtain the preset signature of the eigenvalue transfer request; The first sending unit is configured to send the eigenvalue transfer request and the preset signature to the target server; The first receiving unit is configured to receive the transfer result of the eigenvalue transfer event sent by the target server; the transfer result is determined by the target server based on the verification result of verifying the preset signature with the preset public key in the transfer certificate and the matching result of the eigenvalue transfer request matching the independent transfer parameter corresponding to the transfer certificate.
12. An eigenvalue transfer device, characterized in that Deployed on the target server, the device includes: a second receiving unit, a verification unit, a matching unit, a determination unit, and a second sending unit; The second receiving unit is configured to receive an eigenvalue transfer request and a preset signature sent by a first device of an eigenvalue operation object; the eigenvalue transfer request represents an eigenvalue transfer event that the eigenvalue to be transferred of the object to which the eigenvalue of the eigenvalue operation object belongs is less than or equal to a limit eigenvalue, and the preset signature is the first device's signature of the eigenvalue transfer request with the preset private key corresponding to the transfer certificate for independently transferring the limit eigenvalue of the object to which the eigenvalue belongs by the eigenvalue operation object. The verification unit is configured to verify the preset signature with the preset public key in the transfer certificate to obtain a verification result. The matching unit is configured to match the eigenvalue transfer request with the independent transfer parameter corresponding to the transfer certificate to obtain a matching result. The determination unit is configured to determine the transfer result of the eigenvalue transfer event based on the verification result and the matching result. The second sending unit is configured to send the transfer result to the first device.
13. A computer device, characterized in that The computer device includes a processor and a memory: The memory is configured to store a computer program and transmit the computer program to the processor; The processor is configured to execute the method according to any one of claims 1-10 based on the instructions in the computer program.
14. A computer-readable storage medium, characterized in that The computer-readable storage medium is configured to store a computer program, and when the computer program runs on the computer device, the computer device is caused to execute the method according to any one of claims 1-10.
15. A computer program product, comprising a computer program, characterized in thatWhen the computer program runs on the computer device, the computer device is caused to execute the method according to any one of claims 1-10.