Block chain digital bond data processing method and device and service terminal
By pulling blockchain data into local databases and converting them into structured data, the problem of repeated encryption and decryption in blockchain networks is solved, and data query and transaction processing efficiency is improved.
Patent Information
- Application Number
- CN202510153450.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-02-12
AI Technical Summary
Repeated encryption and decryption processes in blockchain network consume a large amount of computing operation resources, resulting in low data query efficiency and thus reducing transaction processing efficiency.
The data on the blockchain is pulled into the local database of the service terminal, and the unstructured data is converted into structured data, and stored in a preset database for users with query permission to directly query, reducing the encryption and decryption process.
The data query needs can be met through one encryption and decryption process, which significantly reduces the consumption of computing operation resources and improves data query efficiency and transaction processing efficiency.
Smart Images

Figure CN120196665A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of blockchain data processing, and in particular, to a method, apparatus, and service terminal for processing blockchain digital bond data. Background Art
[0002] Each blockchain in a blockchain network is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. It is a tamper-proof and shared digital ledger used to record transactions in a public or private peer-to-peer network. Among them, the blockchain ledger data structure adopts a linked list structure, and the ledger is distributed to all transaction nodes in the network. In a blockchain of blocks linked by a hash cryptographic algorithm, asset transaction records occurring between transaction nodes in the network are permanently recorded. When querying data of a certain transaction node, blockchain positioning, transmission encryption, receiving decryption, and block data decryption are performed on the entire blockchain of each associated blockchain to implement querying of data related to the transaction node. However, the above repeated encryption and decryption processes consume a large amount of computing operation resources, resulting in low data query efficiency and thus greatly reducing the transaction processing efficiency. Summary of the Invention
[0003] The present invention provides a method, apparatus, and service terminal for processing blockchain digital bond data to at least solve the problem in the related art that the consumption of computing operation resources is large and the data query efficiency is low, resulting in a reduction in transaction processing efficiency. The technical solution of the present invention is as follows.
[0004] According to a first aspect of an embodiment of the present invention, a method for processing blockchain digital bond data is provided, which is applied to a service terminal of any one of multiple transaction nodes associated with a blockchain network. The method includes: obtaining first target data associated with a target transaction node from the blockchain network according to the data acquisition authority of the target transaction node to which the service terminal belongs; the blockchain network includes multiple blockchains; converting the first target data into second target data according to a preset data conversion rule; the second target data are all structured data; storing the second target data in a preset database so that a target user account can query the second target data from the preset database; the target user account is a user account having data query authority for the second target data in the preset database; the target transaction node represents any one of the following bond business nodes: a bond issuance node, a bond registration node, a bond custody node, a bond trading node, and a bond settlement node.
[0005] In one implementation, each blockchain in the blockchain network corresponds to a channel one by one; according to the data acquisition permission of the target transaction node to which the service terminal belongs, the first target data associated with the target transaction node is obtained from the blockchain network, including: determining the target channel associated with the target transaction node; determining the target blockchain corresponding to the target channel from the blockchain network; obtaining the target blockchain data from the target blockchain at a preset period; parsing the block data of each block in the target blockchain data to obtain the first target data.
[0006] In another implementation, parsing the block data of each block in the target blockchain data to obtain the first target data includes: parsing the data structure of the block data on the target blockchain in plaintext according to the first preset blockchain rule of the target transaction node to obtain the target block data of the target block and the target business data type of the target business data included in the target block data; determining the target decryption algorithm associated with the target business data type according to the association mapping relationship between the business data type and the encryption algorithm in the configuration file; using the target decryption algorithm to decrypt the target block data to obtain the first target data.
[0007] In another implementation, parsing the block data of each block in the target blockchain data to obtain the first target data includes: parsing the data structure on the target blockchain in plaintext according to the second preset blockchain rule of the target transaction node to obtain the target block data of the target block and the target algorithm identifier of the target decryption algorithm for decrypting the target block data; using the target decryption algorithm corresponding to the target algorithm identifier to decrypt the target block data to obtain the first target data.
[0008] In another implementation manner, the preset data conversion rules include a block data template, a transaction data template, an event data template, a contract data template, and a contract call data template, and the second target data includes second block data, second transaction data, second event data, second contract data, and second contract call data; converting the first target data into the second target data according to the preset data conversion template includes: extracting first block data, first transaction data, first event data, first contract data, and first contract call data from the first target data; converting the first block data into the second block data according to the first distribution sequence of the block data in the block data template; the second block data is distributed and arranged according to the first distribution sequence; and, converting the first transaction data into the second transaction data according to the second distribution sequence of the transaction data in the transaction data template; the second transaction data is distributed and arranged according to the second distribution sequence; and, converting the first event data into the second event data according to the third distribution sequence of the event data in the event data template; the second event data is distributed and arranged according to the third distribution sequence; and, converting the first contract data into the second contract data according to the fourth distribution sequence of the contract data in the contract data template; the second contract data is distributed and arranged according to the fourth distribution sequence; and, converting the first contract call data into the second contract call data according to the fifth distribution sequence of the contract call data in the contract call data template; the second contract call data is distributed and arranged according to the fourth distribution sequence.
[0009] In another implementation manner, the method further includes: associating the second block data in the second target data with a block index identifier; and, associating the second transaction data with a transaction index identifier; and, associating the second event data with an event index identifier; and, associating the second contract data with a contract index identifier; and, associating the second contract call data with a contract call identifier.
[0010] In another implementation manner, the method further includes: encrypting the data to be encrypted in the business data according to the encryption algorithm corresponding to the business type of the business data of the target transaction node in the configuration file; based on the first preset on-chain rule, uploading the encrypted data to be encrypted, the storage area information of the encrypted data to be encrypted, and the unencrypted data in the business data according to the first preset data structure; the unencrypted data includes the business data type.
[0011] In another implementation manner, the method further includes: encrypting the data to be encrypted in the business data according to a preset encryption algorithm; based on the second preset on-chain rule, uploading the encrypted data to be encrypted, the decryption algorithm corresponding to the preset encryption algorithm, and the unencrypted data in the business data according to the second preset data structure.
[0012] According to a second aspect of the embodiments of the present invention, there is provided a blockchain digital bond data processing device, which is applied to a service terminal of any one of multiple transaction nodes associated with a blockchain network; the device includes: a data acquisition unit, configured to acquire first target data associated with a target transaction node from the blockchain network according to the data acquisition authority of the target transaction node to which the service terminal belongs; the blockchain network includes multiple blockchains; a data conversion unit, configured to convert the first target data into second target data according to a preset data conversion rule; all the second target data are structured data; a data query unit, configured to store the second target data in a preset database so that a target user account can query the second target data from the preset database; the target user account is a user account that has the data query authority for the second target data in the preset database; the target transaction node represents any one of the following bond business nodes: a bond issuance node, a bond registration node, a bond custody node, a bond trading node, and a bond settlement node.
[0013] According to a third aspect of the embodiments of the present invention, there is provided a blockchain data processing system, which includes an encoder, a decoder, and a preset coding book, and the system is provided with an audio conversion model, and the system is configured to execute the blockchain digital bond data processing method as described in the first aspect and any one of its possible implementation manners.
[0014] According to a fourth aspect of the embodiments of the present invention, there is provided a service terminal, including: a processor and a memory for storing processor-executable instructions; wherein, the processor is configured to execute the executable instructions to implement the blockchain digital bond data processing method as described in the first aspect and any one of its possible implementation manners.
[0015] According to a fifth aspect of the embodiments of the present invention, there is provided a computer-readable storage medium, on which instructions are stored, and when the instructions in the computer-readable storage medium are executed by the processor of the service terminal, the service terminal is enabled to execute the blockchain digital bond data processing method as described in the first aspect and any one of its possible implementation manners.
[0016] According to a sixth aspect of the embodiments of the present disclosure, there is provided a computer program product, which includes computer instructions, and when the computer instructions run on the service terminal, the service terminal is enabled to execute the blockchain digital bond data processing method as described in the first aspect and any one of its possible implementation manners.
[0017] The technical solutions provided by the embodiments of the present invention at least bring the following beneficial effects: In this application, the first target data associated with the target transaction node is first obtained from the blockchain network. Since the first target data includes data from different blockchains in the blockchain network, and the encryption and decryption methods of different blockchain data are different, the first target data will include unstructured data. To avoid the problem of low indexing efficiency during data query caused by the above unstructured data, the first target data is further converted into the second target data that is all structured, and the second target data is stored in the preset database of the service terminal device, so that users with query permissions can directly obtain the data required by the users from the preset database without encryption and decryption, reducing the consumption of computing operation resources in the encryption and decryption processes and improving the data query efficiency, thereby improving the transaction processing efficiency.
[0018] Moreover, in the implementation manner of this application, the data associated with the transaction node obtained from the blockchain network is directly pulled to the service terminal of the transaction node (such as in the local database). Only one encryption and decryption process is required for the above data pulling process, which can ensure that users with data query permissions can repeatedly query the pulled data, and also greatly reduces the repeated consumption of computing operation resources in the repeated encryption and decryption processes.
[0019] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure, and do not constitute an improper limitation to the present disclosure.
[0021] Figure 1 is a flowchart of a method for processing blockchain digital bond data shown according to an exemplary embodiment;
[0022] Figure 2 is a block diagram of a device for processing blockchain digital bond data shown according to an exemplary embodiment;
[0023] Figure 3 is a schematic diagram of a service terminal shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] In order to enable those of ordinary skill in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings.
[0025] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present disclosure are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described here can be implemented in an order other than those illustrated or described here. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.
[0026] Before introducing the blockchain data processing method provided by the embodiments of the present application in detail, a brief introduction to the application scenarios involved in the embodiments of the present application will be given first.
[0027] Each blockchain in the blockchain network is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm. It is a tamper-proof and shared digital ledger used to record transactions in a public or private peer-to-peer network. Among them, the blockchain ledger data structure adopts a linked list structure, and the ledger is distributed to all transaction nodes in the network. In the blockchain of blocks linked by a hash cryptographic algorithm, the asset transaction records that occur between transaction nodes in the network are permanently recorded. When querying the data of a certain transaction node, by performing blockchain positioning, transmission encryption, receiving decryption, and block data decryption on the entire blockchain of each associated blockchain, the query of the data related to the transaction node is realized. However, the above-mentioned repeated encryption and decryption processes require a large amount of computing operation resources, resulting in low data query efficiency and thus greatly reducing the transaction processing efficiency.
[0028] In the related art, the blockchain ledger data structure adopts a linked list structure, and the ledger is distributed to all member nodes in the network. In the sequential chain of blocks linked by a hash cryptographic algorithm, the historical records of asset transactions that occur between peer nodes in the network are permanently recorded; its sequential chain is a linked list structure formed by connecting blocks through hash (also known as hashing), and each block consists of two parts: a block header and a block body. The block header is the hash value of the parent block, and the block body contains all the transaction lists (i.e., account page information) of the current block.
[0029] It has been found through research that blockchain is a distributed accounting process, which will be stored in the institutions of each transaction node. Each institution needs to store all the data on the blockchain, and each institution can only query and utilize the data of its own institution. When querying based on the data on the entire blockchain, its throughput is low, resulting in very low storage efficiency and retrieval efficiency of the blockchain.
[0030] Related blockchain systems usually only use hash and signature encryption algorithms to support underlying security. The security of business data needs to be ensured by using traditional symmetric and asymmetric encryption technologies and modern cryptographic algorithms. Moreover, the types of algorithms required for different business scenarios are inconsistent, which results in different types of data on the chain and makes it difficult to directly pull the blockchain ledger into the traditional local databases of institutions.
[0031] Therefore, to address the above problems, this application proposes a blockchain data processing method. First, the data on the blockchain is pulled to the local of the service terminal for storage. After converting the unstructured data in the pulled data into structured data, it is stored in a preset database to facilitate users to query data based on the preset database. Based on this, the data associated with the transaction nodes obtained from the blockchain network is directly pulled to the service terminal of the transaction node (such as in the local database). Only one encryption and decryption process is required for the above data pulling process, which can ensure that users with data query permissions can repeatedly query the pulled data, and also greatly reduce the repeated consumption of computing operation resources by the repeated encryption and decryption processes, improving the query efficiency.
[0032] Specifically, the structured ledger tool periodically synchronizes block data from the blockchain network, parses the block data into structured data, business information, and status data, and then stores them in the database. For the data that has been encrypted when it is uploaded to the chain, if there is decryption permission during parsing, plaintext parsing is performed.
[0033] For ease of understanding, the blockchain data processing method provided by this application will be specifically introduced below with reference to the accompanying drawings.
[0034] This blockchain data processing method is applied to the service terminal of any one of the multiple transaction nodes associated with the blockchain network. The service terminal can be a server.
[0035] Figure 1 It is a flowchart of a blockchain digital bond data processing method shown according to an exemplary embodiment. As Figure 1 shown, this blockchain data processing method includes the following steps.
[0036] S11, according to the data acquisition permission of the target transaction node to which the service terminal belongs, obtain the first target data associated with the target transaction node from the blockchain network.
[0037] The above target transaction node can be understood as any transaction node on any blockchain included in the blockchain network. Among them, one blockchain corresponds to multiple transaction nodes. One transaction node can also correspond to at least one blockchain.
[0038] The target transaction node may be any one of the following bond business nodes: bond issuance node, bond registration node, bond custody node, bond trading node, and bond settlement node.
[0039] It can be understood that the target transaction node may be any one of the following institutions: bond issuance institution, bond registration institution, bond custody institution, bond trading institution, and bond settlement institution.
[0040] Correspondingly, the first target data may be bond issuance data, bond registration data, bond custody data, bond trading data, and bond settlement data.
[0041] It should be noted that the data involved in this application can all be understood as bond data or bond business data.
[0042] In some embodiments, the specific process of obtaining the above first target data is as follows.
[0043] First, in the blockchain network, determine the target block data of the target block corresponding to the target transaction node.
[0044] In some embodiments, the above obtaining of the target block data specifically includes the following steps.
[0045] One, determine the target channel associated with the target transaction node.
[0046] In the blockchain network, each blockchain corresponds to a channel one by one. There is an association relationship between the transaction node and the channel.
[0047] The target channel associated with the target transaction node indicates that the target transaction node has the data acquisition permission to obtain the data of the blockchain corresponding to the target channel.
[0048] Two, determine the target blockchain corresponding to the target channel from the blockchain network.
[0049] Different channels correspond to different blockchains one by one. Therefore, when the target channel is determined, the target blockchain can also be correspondingly determined.
[0050] Three, at a preset period, obtain the target blockchain data from the target blockchain.
[0051] In some embodiments, in order to improve the speed of obtaining the target blockchain data. Each time a block is obtained through the target channel, block data transmission is performed according to the maximum number of blocks allowed by the target channel to obtain the target blockchain data.
[0052] In some embodiments, a ledger structuring tool with the function of obtaining first target data is set in the service terminal. The ledger structuring tool has the function of periodically obtaining blocks from the blockchain and standardizing the structure of the block data obtained on the blocks for storage in the database.
[0053] Exemplarily, first set the synchronization period and the maximum number of synchronized blocks, then start the ledger structuring tool to obtain all the channel numbers in the blockchain network according to the synchronization period in the configuration file, and finally query the number of blockchains that have been synchronized for each channel in the database. Within one synchronization period, all channels concurrently synchronize blocks with the maximum number of blocks.
[0054] Specifically, trigger the ledger structuring tool to synchronize blocks periodically, traverse all channels associated with the target transaction node in the blockchain network, so that the ledger structuring tool can obtain the block data of the target block with the block number of the target blockchain synchronized each time for the target channel based on the association relationship between each target blockchain and the target block in the configuration file of the unified cryptographic service engine, to obtain the first target block data.
[0055] In a method for obtaining target blockchain data, a method of sending a full - volume data acquisition request to the target blockchain is adopted, and the block data on all blocks in the target blockchain obtained by the request is used as the target blockchain data. Considering that the target transaction node only has partial parsing permissions for this target blockchain data, directly parse the target blockchain data, and determine the block data that can be successfully parsed as the first target data.
[0056] In another method for obtaining target blockchain data, for the scenario where the association relationship between the block number identifier and the transaction node has been configured during the process of uploading to the chain, a method of sending a target block data acquisition request to the target blockchain is adopted, and the target block data composed of each target block in the target blockchain obtained by the request is used as the target blockchain data. Then, considering that the target transaction node has all parsing permissions for this target blockchain data, directly parse the target blockchain data to obtain the first target data, which can improve the data request and data parsing speed, thereby improving the acquisition speed of the first target data.
[0057] Secondly, parse the ciphertext of the bond business data of each block in the target blockchain data to obtain the first target data.
[0058] Exemplarily, a unified cryptographic service engine with the function of parsing block data is set in the service terminal. The unified cryptographic service engine includes various block data decryption and encryption algorithms. The unified cryptographic service engine can include six types of tool sets: key generation, key derivation, key import and transformation, encryption, decryption, and key storage.
[0059] As a decryption method, the data structure of the block data on the target blockchain is parsed in plaintext to obtain the target block data of the target block and the target business data type of the target business data included in the target block data; according to the association mapping relationship between the business data type and the encryption algorithm in the configuration file, the target decryption algorithm associated with the target business data type is determined; the target decryption algorithm is used to decrypt the target block data to obtain the first target data.
[0060] The above-mentioned target block data includes bond business data in the form of a block, that is, its data is included in the block. The above-mentioned target block data includes ciphertext data in ciphertext form and plaintext data in plaintext form.
[0061] Specifically, when the target block data includes a retrieval block, the retrieval block includes a ciphertext field indicating ciphertext information and a key ciphertext. A keyword indicating the encrypted field of the ciphertext information is stored on the service terminal, and based on this keyword, the ciphertext field is determined from the retrieval block.
[0062] (1) According to the first preset chain-up rule of the bond business data (in the following example: BaseInvi), where the bond business data consists of a plaintext bond business data field (a sensitive field set to "empty" in the following example) and a business data ciphertext field (in the following example: BaseInvi.Ciphertext), and the business data key ciphertext (in the following example: BaseCipher), retrieve the bond business data on the retrieval block, and then extract the ciphertext field therein; the central custodian combines {tender document serial number, customer account identifier, bond business type, calling user's affiliated institution, investor account number} as a keyword to retrieve the central custodian's key ciphertext (in the following example: BaseCipher.Ciphertext) on the retrieval block.
[0063] (2) Obtain the module name field (in the following example: MODENAME) from the retrieved business data key ciphertext (in the following example: BaseCipher), the same module name (in the following example: module_name) field in the configuration file, and then obtain the encryption type (in the following example: enc_type), the encrypted field (in the following example: enc_feilds), and the data ciphertext field (in the following example: ciphertext_field) in the configuration file.
[0064] (3) Call the corresponding encryption algorithm interface in the unified password service engine according to the encryption algorithm type (in the following example: enc_type), input the private key of the central custodian institution locally, decrypt the ciphertext of the key of the central custodian institution (in the following example: BaseCipher.Ciphertext), obtain the data key, and then decrypt the data ciphertext field (in the following example: ciphertext_field) with the data key to obtain the plaintext of the bond business data.
[0065] In this decryption method, since the data type of the business data in the data structure of the business data can be directly parsed in plaintext, an association mapping relationship between different business types and different decryption algorithms is preset in the configuration file. First, based on this association mapping relationship in the configuration file, determine the target decryption algorithm corresponding to the target business type, and then call the target decryption algorithm to decrypt the encrypted business data in the target block data to obtain the first target data.
[0066] This decryption method is applicable to the business data of the target trading node. The indication information of the corresponding target decryption algorithm is not included in the on-chain data structure. Based on the association mapping relationship in the configuration file, call the target decryption algorithm.
[0067] Specifically, through the configuration file for unified encryption and decryption services, ledger structuring is supported. The ledger structuring tool uses dynamic decryption according to the configuration file during data decryption. It is necessary to configure the encryption algorithm, encrypted fields, encrypted ciphertext, etc. in the configuration file, and the configurations for multiple business scenarios are different.
[0068] Exemplarily, the following programming language is used to parse the on-chain ciphertext data structure that calls the configuration file.
[0069] type Basecipher struct{
[0070] Txids[]stringjson:"txids,omitempty"
[0071] ZBSXHstringjson:"ZB5SXH" / / Bidding document serial number
[0072] ID string json:"ID" / / Customer account identifier
[0073] MODNAMEstringjson:"MODNAME" / / Bond business type
[0074] ORG stringjson:"ORG" / / Organization to which the calling user belongs
[0075] TZRZH string `json:"TZRZH" / / Investor account number`
[0076] Ciphertext []byte `json:"ciphertext" / / Ciphertext`
[0077] }}
[0078] The above on-chain business data structure does not show which configured encryption algorithm is used. Instead, the data that needs to be encrypted in the business data (such as age and transfer information) is encrypted and stored in the ciphertext of the above on-chain ciphertext data structure, and the combined information of keywords is made in the ciphertext to let the user know where the keywords are; the secret key corresponding to the ciphertext is also transmitted to the chain. Therefore, it is necessary to call different business data decryption algorithms for business data of different business types based on the configuration file.
[0079] The ledger structuring tool uses dynamic decryption according to the configuration file during data decryption. It is necessary to configure the encryption algorithm, encrypted fields, encrypted ciphertext, etc. in the configuration file, and the configurations of multiple business scenarios are different.
[0080]
[0081] The on-chain user identity certificate data structure is as follows.
[0082]
[0083]
[0084] In some embodiments, the on-chain data structure includes a business contract. The function of this business contract is to store the user identity certificate and business data on the blockchain ledger.
[0085] The structure of the business data decryption configuration file is as follows.
[0086]
[0087]
[0088] The json content is as shown above.
[0089] Org_name is the organization name, and confgs contains an array of decryption configuration contents for different contracts: where contract name is the contract name, and settings are the relevant decryption configurations for different business modules: Taking the invi - invitation module (configuration file) as an example above, env conigs is an array of encryption configuration blocks: where enc type is the name of the encryption algorithm: encfield is the encryption configuration for the specific algorithm. For example, fields such as "ZDCXE" and "ZDSGXE" under baseInviInvestorlist.InvestorControl in the example are encrypted: ciphertest field represents the positioning of the encrypted ciphertext field. According to the read configuration, select the corresponding decryption function of BBSSDK to decrypt and return the decryption result.
[0090] The specific data decryption steps are as follows.
[0091] First, based on the parsed business data, determine the type of the data key and whether it is an encrypted business scenario.
[0092] Second, if it is an encrypted scenario, request the decryption interface.
[0093] Third, decrypt the encrypted fields according to the configuration and return them to the ledger structuring tool.
[0094] Fourth, the structuring tool obtains the decrypted data returned, and updates the corresponding business data record.
[0095] Compared with the first decryption method, the data is chained as follows: Encrypt the data to be encrypted in the business data according to the encryption algorithm corresponding to the business type of the business data of the target transaction node in the configuration file; Based on the first preset chaining rule, chain the encrypted data to be encrypted, the storage area information of the encrypted data to be encrypted, and the unencrypted data in the business data according to the first preset data structure; The unencrypted data includes the business data type.
[0096] In some embodiments, after combining the encrypted data to be encrypted, the storage area information of the encrypted data to be encrypted, and the unencrypted data in the business data according to the first preset chaining rule, input them into the target blockchain through the target channel.
[0097] As the second decryption method, according to the second preset chaining rule of the target transaction node, perform plaintext parsing on the data structure on the target blockchain to obtain the target block data of the target block and the target algorithm identifier of the target decryption algorithm for decrypting the target block data, and use the target decryption algorithm corresponding to the target algorithm identifier to decrypt the target block data to obtain the first target data.
[0098] For this second decryption method, the data is uploaded to the chain according to the following data uploading process: Encrypt the data to be encrypted in the service data according to a preset encryption algorithm; Based on the second preset uploading rule, upload the encrypted data to be encrypted, the decryption algorithm corresponding to the preset encryption algorithm, and the unencrypted data in the service data according to the second preset data structure.
[0099] In some embodiments, a target algorithm identifier of a target decryption algorithm for decrypting the target block data of the target transaction node is set. After combining the target algorithm identifier and the encrypted target block data according to the second preset uploading rule, it is input into the target blockchain through the target channel.
[0100] In this decryption method, the data structure of the target block data includes the decryption algorithm of the encrypted data. By parsing the data structure of the target blockchain, the target decryption algorithm is obtained. This decryption method does not require a configuration file. By formulating a consistent data uploading rule, a unified encryption and decryption service is realized, supporting ledger structuring. By unifying the encryption and decryption interfaces and the encrypted ciphertext data structure in the business scenario, the consistency of the data uploaded to the chain is ensured, and encryption and decryption strategies are formulated, so that the encryption and decryption interfaces can automatically execute and identify the type of cryptographic algorithm when called. Exemplarily, the following programming language is used to parse a chain ciphertext data structure that does not call a configuration file and directly calls the decryption algorithm.
[0101] type Ciphertext struct{
[0102] EncType string / / Encryption algorithm
[0103] Fields []string / / Encrypted fields
[0104] Value string / / Encrypted ciphertext
[0105] Params interface{} / / Decryption parameters,
[0106] }
[0107] The above Params field is of interface type and can dynamically store ciphertext information according to the actual encryption type. For example, hybrid encryption can be KeyList and attribute encryption can be Policy.
[0108] EncType refers to the type of cryptographic algorithm.
[0109] Fields refers to the protected business data fields.
[0110] Value refers to the encrypted ciphertext.
[0111] Params refers to that the extended information dynamically stores ciphertext information according to the actual cryptographic algorithm type. For example, for hybrid encryption, it can be KeyList, and for attribute encryption, it can be Policy.
[0112] For the hybrid encryption algorithm Hybrid, add the public key encrypted ciphertext KeyList sub-field structure of the symmetric key to the param field in the business contract and chain it together with the business data ontology. Compared with BaseCipher in Solution 1, Keylist does not include "MODNAME / / invi-", that is, the name of the bond business where the configuration file is located does not need to be defined.
[0113] The corresponding on-chain business data structure is as follows.
[0114]
[0115]
[0116] Among them, the on-chain ciphertext is embedded in the business data.
[0117] The content in [] in the above "cipertexts" is the on-chain ciphertext data structure. Specifically: [{"enctype":"hybrid","fileds":["address","phone"],"value":"sssssssssssssssss'","params":[{"id":"ccdc","org":"ccdc","secret":"bbbbbbbbbbbbbbbbb","keylist":["a","a"]}].
[0118] The corresponding on-chain user identity certificate data structure is the same as the on-chain user identity certificate data structure in the above scenario of calling the configuration file.
[0119] The decryption process of business data is as follows. That is, no configuration is required in the specific process, and a unified decryption interface is used. The decryption process is as follows. First, for the Hybrid decryption process: Obtain the bond business data (BaseInvi) on the chain, extract the data ciphertext field (BaseInvi.cipertexts.value) from it, obtain the key ciphertext (keylist) of the central custody institution through the user identification (id) and user organization (org) fields, then call the sm2 algorithm decryption interface in the unified password service, input the key ciphertext (keylist) of the central custody institution and the private key of the central custody institution locally, decrypt the key ciphertext to obtain the data encryption key, and finally call the sm4 algorithm decryption interface in the unified password service, input the data ciphertext field (BaseInvi.cipertexts.value) and the data encryption key to obtain the plaintext of the sensitive field of the bond business data.
[0120] Second, for the decryption process of homomorphic encryption: Obtain the ciphertext of the bond business data (BaseInvi) on the chain, call the sm4 algorithm decryption interface in the unified password service, input the decryption key (sharded) obtained locally, and decrypt the data ciphertext to obtain the plaintext of the sensitive field of the bond business data.
[0121] The type of the above target decryption algorithm can be the algorithm types supported by the unified password service engine.
[0122] Exemplarily, such as national cipher algorithms: SM2, SM4, SM9; non-national cipher algorithms: RSA, AES; related cryptographic algorithms: homomorphic Paillier, fully homomorphic CKKS, attribute-based encryption algorithms cp-abe, kp-abe; hybrid encryption Hybrid (SM4+SM2; SM4+SM9); quantum-resistant public key cryptographic algorithms Kyber, Dilithium.
[0123] S12. Convert the first target data into the second target data according to the preset data conversion rules.
[0124] The above second target data are all structured data.
[0125] The second target data is standardized plaintext data. In some embodiments, the preset data conversion rules include block data templates, transaction data templates, event data templates, contract data templates, and contract call data templates, and the second target data includes second block data, second transaction data, second event data, second contract data, and second contract call data.
[0126] The specific process of converting the first target data into the second target data according to the preset data conversion template in the above step S12 is as follows.
[0127] First, extract the first block data, first transaction data, first event data, first contract data, and first contract call data from the first target data.
[0128] Second, convert the first block data into second block data according to the first distribution sequence of the block data in the block data template, so that the second block data is distributed and arranged according to the first distribution sequence.
[0129] Third, convert the first transaction data into second transaction data according to the second distribution sequence of the transaction data in the transaction data template, so that the second transaction data is distributed and arranged according to the second distribution sequence.
[0130] Fourth, convert the first event data into second event data according to the third distribution sequence of the event data in the event data template, so that the second event data is distributed and arranged according to the third distribution sequence.
[0131] Fifth, convert the first contract data into second contract data according to the fourth distribution sequence of the contract data in the contract data template, so that the second contract data is distributed and arranged according to the fourth distribution sequence.
[0132] Sixth, convert the first contract call data into second contract call data according to the fifth distribution sequence of the contract call data in the contract call data template, so that the second contract call data is distributed and arranged according to the fourth distribution sequence.
[0133] In some specific embodiments, using regular rules, the originally decrypted block data is re-split into several data chains composed of data of standard structured data structures. Specifically, after obtaining the block from the blockchain network, the parsed and decrypted block data needs to be disassembled into multiple data templates of standard structures. The above standard structures include the following types of data templates.
[0134] First, the original block - block original information, mainly including the following block data, that is, for the original block information, the first distribution sequence of the block data in the block data template is as follows: primary key ID, block number, channel name, block Hash, previous block Hash, block data, block metadata, verification signature.
[0135] Second, the parsed block - block parsed data, mainly including the following block data, that is, for the block parsed data, the first distribution sequence of the block data in the block data template is as follows: primary key ID, block number, channel name, block Hash, previous block Hash, data Hash, number of transactions, on-chain timestamp, verification signature.
[0136] Third, the parsed transaction - transaction parsing data mainly includes the following transaction data, that is, the second distribution sequence of the transaction data in the transaction data template is as follows: primary key ID, block number to which it belongs, transaction Hash, channel name, creating organization identity, transaction timestamp, contract name, transaction type, contract version, verification, read - write set, verification signature.
[0137] Fourth, the parsed event - event parsing data mainly includes the following event data, that is, the third distribution sequence of the event data in the event data template is as follows: primary key ID, block number to which it belongs, block generation time, event name, event payload, channel name, transaction ID, verification signature.
[0138] Fifth, the parsed contract - contract parsing data mainly includes the following contract data, that is, the fourth distribution sequence of the contract data in the contract data template is as follows: primary key ID, contract name, contract version, contract channel, contract type, verification signature.
[0139] Sixth, the parsed request - contract call record mainly includes the following contract call data, that is, the fifth distribution sequence of the contract call data in the contract call data template is as follows: primary key ID, contract name, contract version, contract channel, request parameters, verification signature.
[0140] For the convenience of subsequent retrieval and query and to improve the data query speed, different index identifiers are constructed for data of different business data types. Specifically, the second block data in the second target data is associated with the block index identifier; and, the second transaction data is associated with the transaction index identifier; and, the second event data is associated with the event index identifier; and, the second contract data is associated with the contract index identifier; and, the second contract call data is associated with the contract call identifier.
[0141] S13, store the second target data in a preset database so that the target user account can query the second target data from the preset database.
[0142] Among them, the target user account is the user account that has the data query permission for the second target data in the preset database.
[0143] For each different type of data, a corresponding index is constructed, and the constructed index and the standard structure data are stored in the preset database.
[0144] Specifically, the specific process of storing business data is as follows. Business data is the data related to the business in the parameters of each transaction request and can be obtained by parsing the read-write set in the transaction data. Specific logic: Locate the write-set data in a transaction, and then locate the state-key and state-value fields in the write-set data. The state-key corresponds to the actual business scenario, and the state-value corresponds to the business data.
[0145] Through the above implementation, first obtain the first target data associated with the target transaction node from the blockchain network. Since the first target data includes data from different blockchains in the blockchain network and the encryption and decryption methods of different blockchain data are different, the first target data will include unstructured data. To avoid the problem of low indexing efficiency during data query caused by the above unstructured data, further convert the first target data into the second target data that are all structured, and store the second target data in the preset database of the service terminal device, so that users with query permissions can directly obtain the data they need from the preset database without encryption and decryption, reducing the consumption of computing operation resources in the encryption and decryption processes and improving the data query efficiency, thereby improving the transaction processing efficiency.
[0146] Moreover, in the implementation of this application, the data associated with the transaction node obtained from the blockchain network is directly pulled to the service terminal of the transaction node (such as in the local database). Only one encryption and decryption process is required for the above data pulling process, which can ensure that users with data query permissions can repeatedly query the pulled data, and also greatly reduce the repeated consumption of computing operation resources in the repeated encryption and decryption processes.
[0147] To implement the above functions, the blockchain data processing device includes the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments disclosed in this article, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0148] The embodiment of the present disclosure also provides a Figure 2 blockchain digital bond data processing device as shown, which is applied to the service terminal of any one of multiple transaction nodes associated with the blockchain network; the device includes: a data acquisition unit 201, a data conversion unit 202, and a data query unit 203.
[0149] A data acquisition unit 201 is configured to acquire first target data associated with a target transaction node from a blockchain network according to the data acquisition authority of the target transaction node to which the service terminal belongs; the blockchain network includes multiple blockchains; the target transaction node represents any one of the following bond business nodes: a bond issuance node, a bond registration node, a bond custody node, a bond trading node, and a bond settlement node.
[0150] A data conversion unit 202 is configured to convert the first target data into second target data according to a preset data conversion rule; all the second target data are structured data.
[0151] A data query unit 203 is configured to store the second target data in a preset database so that a target user account can query the second target data from the preset database; the target user account is a user account that has the data query authority for the second target data in the preset database.
[0152] In one implementation, each blockchain in the blockchain network corresponds to a channel one by one; the data acquisition unit 201 is specifically configured to: determine a target channel associated with the target transaction node; determine a target blockchain corresponding to the target channel from the blockchain network; acquire target blockchain data from the target blockchain according to a preset period; and parse the block data of each block in the target blockchain data to obtain the first target data.
[0153] In another implementation, the data acquisition unit 201 is specifically configured to: perform plaintext parsing on the data structure of the block data on the target blockchain according to the first preset blockchain rule of the target transaction node to obtain the target block data of the target block and the target business data type of the target business data included in the target block data; determine the target decryption algorithm associated with the target business data type according to the association mapping relationship between the business data type and the encryption algorithm in the configuration file; and use the target decryption algorithm to decrypt the target block data to obtain the first target data.
[0154] In another implementation, the data acquisition unit 201 is specifically configured to: perform plaintext parsing on the data structure on the target blockchain according to the second preset blockchain rule of the target transaction node to obtain the target block data of the target block and the target algorithm identifier of the target decryption algorithm for decrypting the target block data; and use the target decryption algorithm corresponding to the target algorithm identifier to decrypt the target block data to obtain the first target data.
[0155] In another implementation, the preset data conversion rules include a block data template, a transaction data template, an event data template, a contract data template, and a contract call data template. The second target data includes second block data, second transaction data, second event data, second contract data, and second contract call data. The data conversion unit 202: extracts first block data, first transaction data, first event data, first contract data, and first contract call data from the first target data; converts the first block data into second block data according to the first distribution sequence of the block data in the block data template; the second block data is arranged according to the first distribution sequence; and, converts the first transaction data into second transaction data according to the second distribution sequence of the transaction data in the transaction data template; the second transaction data is arranged according to the second distribution sequence; and, converts the first event data into second event data according to the third distribution sequence of the event data in the event data template; the second event data is arranged according to the third distribution sequence; and, converts the first contract data into second contract data according to the fourth distribution sequence of the contract data in the contract data template; the second contract data is arranged according to the fourth distribution sequence; and, converts the first contract call data into second contract call data according to the fifth distribution sequence of the contract call data in the contract call data template; the second contract call data is arranged according to the fourth distribution sequence.
[0156] In another implementation, the data query unit is further configured to: associate the second block data in the second target data with a block index identifier; and, associate the second transaction data with a transaction index identifier; and, associate the second event data with an event index identifier; and, associate the second contract data with a contract index identifier; and, associate the second contract call data with a contract call identifier.
[0157] In another implementation, the apparatus is further configured to: encrypt the data to be encrypted in the service data according to the encryption algorithm corresponding to the service type of the service data of the target transaction node in the configuration file; based on the first preset blockchain rule, upload the encrypted data to be encrypted, the storage area information of the encrypted data to be encrypted, and the unencrypted data in the service data according to the first preset data structure; the unencrypted data includes the service data type.
[0158] In another implementation, the apparatus is further configured to: encrypt the data to be encrypted in the service data according to a preset encryption algorithm; based on the second preset blockchain rule, upload the encrypted data to be encrypted, the decryption algorithm corresponding to the preset encryption algorithm, and the unencrypted data in the service data according to the second preset data structure.
[0159] Regarding the device in the above embodiments, the specific manners in which each unit module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.
[0160] Figure 3 It is a schematic diagram of a service terminal provided by this application. As Figure 3 , the service terminal 50 may include at least one processor 501 and a memory 503 for storing instructions executable by the processor. Among them, the processor 501 is configured to execute the instructions in the memory 503 to implement the blockchain digital bond data processing method in the following embodiments.
[0161] This service terminal is also referred to as a service terminal device, such as a server.
[0162] In addition, the service terminal 50 may further include a communication bus 502, at least one communication interface 504, an input device 506, and an output device 505.
[0163] The processor 501 may be a central processing unit (CPU), a microprocessing unit, an ASIC, or one or more integrated circuits for controlling the execution of the program of this application solution.
[0164] The communication bus 502 may include a path for transmitting information between the above components.
[0165] The communication interface 504 uses any device such as a transceiver for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc.
[0166] The input device 506 is used to receive input signals and the output device 505 is used to output signals.
[0167] The memory 503 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can exist independently and be connected to the processing unit through a bus. The memory can also be integrated with the processing unit.
[0168] Among them, the memory 503 is used to store the instructions for executing the solution of this application and is controlled by the processor 501 for execution. The processor 501 is used to execute the instructions stored in the memory 503, thereby implementing the functions in the method of this application.
[0169] In a specific implementation, as an embodiment, the processor 501 can include one or more CPUs, such as Figure 3 CPU0 and CPU1 in
[0170] In a specific implementation, as an embodiment, the service terminal 50 can include multiple processors, such as Figure 3 the processor 501 and the processor 507 in
[0171] Each of these processors can be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0171] The service terminal, as shown in Figure 3 includes: a processor 501 and a memory 503 for storing executable instructions of the processor 501; among them, the processor 501 is configured to execute the executable instructions to implement the blockchain digital bond data processing method in any of the above possible implementation manners. And the same technical effects can be achieved. To avoid repetition, it will not be elaborated here.
[0172] The embodiments of the present application also provide a computer-readable storage medium. When the instructions in the computer-readable storage medium are executed by the processor of the blockchain data processing device or the service terminal, the blockchain digital bond data processing device or the service terminal can execute the blockchain digital bond data processing method of any of the above possible implementation manners, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0173] The embodiments of the present application also provide a computer program product, including a computer program or instructions. The computer program or instructions are executed by the processor to perform the blockchain digital bond data processing method of any of the above possible implementation manners, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0174] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present application. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include the common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0175] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A blockchain digital bond data processing method, characterized in that: A service terminal applied to any transaction node among a plurality of transaction nodes associated with a blockchain network; the method comprising: According to the data acquisition authority of the target transaction node to which the service terminal belongs, obtaining first target data associated with the target transaction node from the blockchain network; the blockchain network includes multiple blockchains; According to a preset data conversion rule, the first target data is converted into second target data; the second target data is all structured data; The second target data is stored in a preset database so that a target user account can query the second target data from the preset database; the target user account is a user account that has data query authority for the second target data in the preset database; the target transaction node represents any one of the following bond business nodes: a bond issuance node, a bond registration node, a bond custody node, a bond trading node, and a bond settlement node.
2. The blockchain digital bond data processing method according to claim 1 is characterized in that: Each blockchain in the blockchain network corresponds to a channel one by one; and obtaining the first target data associated with the target transaction node from the blockchain network according to the data acquisition authority of the target transaction node to which the service terminal belongs includes: Determining a target channel associated with the target transaction node; Determine a target blockchain corresponding to the target channel from the blockchain network; Obtain target blockchain data from the target blockchain according to a preset period; Parse the block data of each block in the target blockchain data to obtain the first target data.
3. The blockchain digital bond data processing method according to claim 1 is characterized in that: The parsing of the block data of each block in the target blockchain data to obtain the first target data includes: According to the first preset on-chain rule of the target transaction node, the data structure of the block data on the target blockchain is parsed in plain text to obtain the target block data of the target block and the target business data type of the target business data included in the target block data; Determine the target decryption algorithm associated with the target business data type according to the association mapping relationship between the business data type and the encryption algorithm in the configuration file; The target decryption algorithm is used to decrypt the target block data to obtain the first target data.
4. The blockchain digital bond data processing method according to claim 1 is characterized in that: The parsing of the block data of each block in the target blockchain data to obtain the first target data includes: According to the second preset on-chain rule of the target transaction node, the data structure on the target blockchain is parsed in plain text to obtain the target block data of the target block and the target algorithm identifier of the target decryption algorithm for decrypting the target block data; The target decryption algorithm corresponding to the target algorithm identifier is used to decrypt the target block data to obtain the first target data.
5. The blockchain digital bond data processing method according to claim 1 is characterized in that: The preset data conversion rule includes a block data template, a transaction data template, an event data template, a contract data template and a contract call data template, and the second target data includes second block data, second transaction data, second event data, second contract data and second contract call data; The converting the first target data into the second target data according to the preset data conversion template includes: Extracting first block data, first transaction data, first event data, first contract data and first contract call data from the first target data; According to a first distribution sequence of block data in a block data template, the first block data is converted into the second block data; the second block data is distributed and arranged according to the first distribution sequence; and, according to a second distribution sequence of transaction data in the transaction data template, converting the first transaction data into the second transaction data; the second transaction data is distributed and arranged according to the second distribution sequence; and, according to a third distribution sequence of event data in the event data template, converting the first event data into the second event data; the second event data is distributed and arranged according to the third distribution sequence; and, according to a fourth distribution sequence of the contract data in the contract data template, converting the first contract data into the second contract data; the second contract data is distributed and arranged according to the fourth distribution sequence; And, according to the fifth distribution sequence of the contract call data in the contract call data template, the first contract call data is converted into the second contract call data; the second contract call data is distributed and arranged according to the fourth distribution sequence.
6. The blockchain digital bond data processing method according to claim 5 is characterized in that: The method further comprises: Associating the second block data in the second target data with a block index identifier; and, associating the second transaction data with a transaction index identifier; and, associating the second event data with an event index identifier; and, associating the second contract data with the contract index identifier; And, associating the second contract call data with the contract call identifier.
7. The blockchain digital bond data processing method according to claim 3 is characterized in that: The method further comprises: Encrypt the data to be encrypted in the business data according to the encryption algorithm corresponding to the business type of the business data of the target transaction node in the configuration file; Based on the first preset chain-up rule, the encrypted data to be encrypted, the storage area information of the encrypted data to be encrypted and the unencrypted data in the business data are chain-up according to the first preset data structure; the unencrypted data includes the type of business data.
8. The blockchain digital bond data processing method according to claim 4 is characterized in that: The method further comprises: Encrypting the data to be encrypted in the business data according to a preset encryption algorithm; Based on the second preset chain-up rule, the encrypted data to be encrypted, the decryption algorithm corresponding to the preset encryption algorithm, and the unencrypted data in the business data are chained according to the second preset data structure.
9. A blockchain digital bond data processing device, characterized in that: A service terminal applied to any transaction node among a plurality of transaction nodes associated with a blockchain network; the device comprises: A data acquisition unit, configured to acquire first target data associated with the target transaction node from a blockchain network according to a data acquisition authority of the target transaction node to which the service terminal belongs; the blockchain network includes a plurality of blockchains; A data conversion unit, configured to convert the first target data into second target data according to a preset data conversion rule; the second target data are all structured data; A data query unit, configured to store the second target data in a preset database, so that a target user account queries the second target data from the preset database; the target user account is a user account having data query authority for the second target data in the preset database; The target transaction node represents any one of the following bond business nodes: a bond issuance node, a bond registration node, a bond custody node, a bond transaction node, and a bond settlement node.
10. A service terminal, characterized in that: Any transaction node among a plurality of transaction nodes associated with a blockchain network is configured to execute the blockchain digital bond data processing method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Private data query method and device based on blockchain account
CN110580418A
Managing user authorizations for blockchain-based custom clearance services
CN111989707A
Business processing method, device, equipment and system based on block chain
CN114612248A
Method and device for maintaining block chain data, electronic equipment and storage medium
CN115129785A
Method and apparatus for processing privacy data of block chain, device, and storage medium
US20210377038A1