Program security detection method based on block chain, related equipment and storage medium
By introducing blockchain technology into program security detection, acquiring and verifying program verification information is solved, and the problem of low reliability of program security detection in the existing technology is significantly improved.
Patent Information
- Application Number
- CN202311777206.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-24
AI Technical Summary
In the prior art, the detection results of program safety inspection are poor, resulting in a high security risk when running public programs on the program usage end.
A blockchain-based program security detection method is adopted to obtain public programs from program management services, obtain program verification information based on the target blockchain, and conduct signature verification to detect the security of the program.
It improves the reliability of program security detection, reduces the risk of running malicious programs on the application side, and ensures the integrity and security of public programs.
Smart Images

Figure CN120197166A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a program security detection method, related devices, and storage media based on blockchain. Background Art
[0002] To prevent a program from being tampered with, the program usage side usually performs program security detection on the publicly available programs (which can also be called open-source programs) downloaded from the program management service to check whether the publicly available programs have been tampered with by attackers. However, the reliability of the detection results of the program security detection methods adopted in the related technologies is poor, resulting in a relatively high security risk for the program usage side to run the corresponding publicly available programs. Summary of the Invention
[0003] To solve the problems of the prior art, embodiments of this application provide a program security detection method, related devices, and storage media based on blockchain. The technical solutions are as follows:
[0004] On the one hand, a program security detection method based on blockchain is provided, which is applied to the program usage side. The method includes:
[0005] Obtain a target publicly available program from the program management service; the target publicly available program is released by the program development side to the program management service;
[0006] Based on the identification information of the target publicly available program, obtain the target program verification information corresponding to the identification information from the target blockchain; the target blockchain is used to store the program verification information of each publicly available program in the program management service, and the program verification information of the publicly available program includes program signature information and the public key of the program development side that releases the publicly available program. The program signature information is obtained by encrypting the program hash value of the publicly available program based on the private key of the program development side;
[0007] Perform a hash calculation on the target publicly available program based on a preset hash function to obtain a program hash value to be verified; the preset hash function is the hash function used by the target program development side to generate the program hash value of the target publicly available program;
[0008] Perform a signature verification process based on the target program verification information and the program hash value to be verified to obtain the program security detection result of the target publicly available program; the program security detection result indicates whether there is a security risk in the target publicly available program.
[0009] On the other hand, a program security detection method based on blockchain is provided, which is applied to the program development side. The method includes:
[0010] In response to a release instruction for a target public program, generate a public key and a private key for the program development end;
[0011] Perform a hash calculation on the target public program based on a preset hash function to obtain a program hash value of the target public program;
[0012] Perform an encryption process on the program hash value based on the private key of the program development end to obtain program signature information;
[0013] Publish the target public program to the program management service so that the program usage end can obtain the target public program from the program management service;
[0014] Store the program signature information and the public key of the program development end as target program verification information corresponding to the target public program in a target blockchain, so that the program usage end can obtain the target program verification information from the target blockchain based on the obtained identification information of the target public program, perform a hash calculation on the target public program based on the preset hash function to obtain a program hash value to be verified, and perform a signature verification process based on the target program verification information and the program hash value to be verified to obtain a program security detection result of the target public program, where the program security detection result indicates whether there is a security risk in the target public program;
[0015] Wherein, the target blockchain is used to store the program verification information of each public program in the program management service.
[0016] On the other hand, a program security detection device based on a blockchain is provided, configured at the program usage end, and the device includes:
[0017] A program acquisition module, configured to acquire a target public program from a program management service; the target public program is published to the program management service by a program development end;
[0018] A program verification information acquisition module, configured to acquire target program verification information corresponding to the identification information from a target blockchain based on the identification information of the target public program; the target blockchain is used to store the program verification information of each public program in the program management service, and the program verification information of the public program includes program signature information and the public key of the program development end that publishes the public program, and the program signature information is obtained by performing an encryption process on the program hash value of the public program based on the private key of the program development end;
[0019] A first hash calculation module, configured to perform a hash calculation on the target public program based on a preset hash function to obtain a program hash value to be verified; the preset hash function is the hash function used by the target program development end to generate the program hash value of the target public program;
[0020] A signature verification module, configured to perform signature verification processing based on the target program verification information and the program hash value to be verified, so as to obtain a program security detection result of the target public program; the program security detection result indicates whether there is a security risk in the target public program.
[0021] In an exemplary embodiment, the identification information includes a program name and a program version number, the target blockchain stores the program verification information of each public program in the form of key-value pairs, the key in the key-value pair is the program name and program version number of the public program, and the value in the key-value pair is the program verification information of the public program; the program verification information acquisition module includes:
[0022] A query key generation module, configured to generate a query key based on the program name and program version number of the target public program;
[0023] A query request sending module, configured to send a query request to the target blockchain based on the query key, so that the target blockchain determines a target key matching the query key in response to the query request and returns the target value corresponding to the target key;
[0024] A target value acquisition module, configured to receive the target value returned by the target blockchain to obtain target program verification information.
[0025] On the other hand, a program security detection device based on a blockchain is provided, configured at a program development end, and the device includes:
[0026] A key generation module, configured to generate a public key and a private key of the program development end in response to a release instruction for a target public program;
[0027] A second hash calculation module, configured to perform hash calculation on the target public program based on a preset hash function to obtain a program hash value of the target public program;
[0028] A program signature module, configured to perform encryption processing on the program hash value based on the private key of the program development end to obtain program signature information;
[0029] A program release module, configured to release the target public program to a program management service, so that a program usage end can obtain the target public program from the program management service;
[0030] The program verification information publishing module is used to store the program signature information and the public key of the program development end as the target program verification information corresponding to the target public program in the target blockchain, so that the program using end can obtain the target program verification information from the target blockchain based on the obtained identification information of the target public program, calculate the hash value of the program to be verified by using the preset hash function for the target public program, and perform signature verification processing based on the target program verification information and the hash value of the program to be verified, so as to obtain the program security detection result of the target public program, and the program security detection result indicates whether there is a security risk in the target public program;
[0031] Wherein, the target blockchain is used to store the program verification information of each public program in the program management service.
[0032] In an exemplary embodiment, the program publishing module includes:
[0033] The name and version obtaining module is used to obtain the program name and program version number of the target public program;
[0034] The publishing module is used to use the program name and program version number as the identification information of the target public program, and publish the target public program to the program management service.
[0035] In an exemplary embodiment, the program verification information publishing module includes:
[0036] The transaction data generation module is used to generate transaction data based on the program name, program version number, program signature information of the target public program and the public key of the program development end;
[0037] The transaction request sending module is used to send a transaction request to the target blockchain based on the transaction data, so that the target blockchain responds to the transaction request and stores the transaction data in the form of key-value pairs, where the key in the key-value pair is the program name and program version number in the transaction data, and the value in the key-value pair is the program signature information and the public key of the program development end in the transaction data.
[0038] In an exemplary embodiment, the transaction data includes a transaction body and a transaction signature; the transaction data generation module includes:
[0039] The transaction body generation module is used to generate the transaction body of the transaction data based on the program name, program version number, program signature information of the target public program and the public key of the program development end;
[0040] A transaction signature generation module, which is used to encrypt the transaction body based on the private key of the program development end to obtain the transaction signature of the transaction data; the transaction signature of the transaction data is used for the target blockchain to verify the transaction request, and when the verification passes, the transaction body of the transaction data is stored in the form of key-value pairs.
[0041] In an exemplary embodiment, the device further includes:
[0042] A registration module, which is used to send a registration request to the target blockchain, so that the target blockchain returns a digital certificate when it determines that the registration is successful in response to the registration request;
[0043] Correspondingly, the transaction request sending module is specifically used for: sending a transaction request to the target blockchain based on the transaction data and the digital certificate, so that the target blockchain performs permission verification on the program development end based on the digital certificate, and when the permission verification passes, stores the transaction data in the form of key-value pairs.
[0044] On the other hand, an electronic device is provided, which includes a processor and a memory. At least one instruction or at least one program segment is stored in the memory, and the at least one instruction or the at least one program segment is loaded and executed by the processor to implement the blockchain-based program security detection method in any of the above aspects.
[0045] On the other hand, a computer-readable storage medium is provided. At least one instruction or at least one program segment is stored in the computer-readable storage medium, and the at least one instruction or the at least one program segment is loaded and executed by a processor to implement the blockchain-based program security detection method as described in any of the above aspects.
[0046] On the other hand, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the blockchain-based program security detection method in any of the above aspects.
[0047] Embodiments of the present application store program verification information of each public program in a target blockchain for program management services. The program verification information of a public program includes program signature information and the public key of the program development end that publishes the public program. The program signature information is obtained by encrypting the program hash value of the public program with the private key of the program development end. Further, after a program user obtains a target public program from the program management service, the target program verification information corresponding to the identification information can be obtained from the target blockchain based on the identification information of the target public program, and a program hash value to be verified is obtained by performing a hash calculation on the target public program based on a preset hash function. A program security detection result of the target public program is obtained by performing a signature verification process based on the target program verification information and the program hash value to be verified. Since the program verification information in the blockchain is not allowed to be tampered with, if the downloaded public program is replaced by a malicious program, it can also be detected through the corresponding program verification information in the blockchain, thereby greatly improving the reliability of program security detection and reducing the risk of the program user running a malicious program. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0049] Figure 1 is a schematic diagram of an implementation environment provided by an embodiment of the present application;
[0050] Figure 2 is a schematic flowchart of a method for program security detection based on a blockchain provided by an embodiment of the present application;
[0051] Figure 3 is a schematic flowchart of another method for program security detection based on a blockchain provided by an embodiment of the present application;
[0052] Figure 4 is a schematic flowchart of another method for program security detection based on a blockchain provided by an embodiment of the present application;
[0053] Figure 5 is a schematic flowchart of another method for program security detection based on a blockchain provided by an embodiment of the present application;
[0054] Figure 6 is a block diagram of the structure of a device for program security detection based on a blockchain provided by an embodiment of the present application;
[0055] Figure 7It is a structural block diagram of another program security detection device based on blockchain provided by an embodiment of the present application;
[0056] Figure 8 It is a hardware structural block diagram of an electronic device provided by an embodiment of the present application. Specific implementation manners
[0057] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0058] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any of their deformations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server including a series of steps or units does not necessarily need to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0059] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit including the function of the module or unit.
[0060] It can be understood that in the specific implementation manners of the present application, when it comes to data related to user information, etc., when the above embodiments of the present application are applied to specific products or technologies, user permission or consent needs to be obtained, and the collection, use and processing of relevant data need to comply with relevant laws, regulations and standards of relevant countries and regions.
[0061] In the related art, a program management service stores the publicly available programs uploaded by the program development side and the program verification information for security detection of the publicly available programs. The program usage side downloads the required publicly available programs and the corresponding program verification information from the program management service based on the query and download functions provided by the program management service for program security detection. However, in this method, once the program management service is attacked, an attacker can replace the program verification information in the program management service and generate malicious programs, resulting in the program usage side being unable to detect that the publicly available program has been tampered with during program security detection, posing a relatively high security risk; moreover, the replaced program verification information will cause the program security detection of legitimate publicly available programs to fail, reducing the reliability of the program security detection results.
[0062] Based on this, an embodiment of the present application provides a program security detection method based on a blockchain. Please refer to Figure 1 , which shows a schematic diagram of the implementation environment of the program security detection method based on a blockchain provided by an embodiment of the present application. The implementation environment may include a program development side 110, a program management service 120, a blockchain system 130, and a program usage side 140. Among them, the program development side 110, the program management service 120, the blockchain network 130, and the program usage side 140 can all communicate through wired or wireless network connections.
[0063] Among them, the program development side 110 and the program usage side 140 may each include, but are not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle terminals, aircraft, etc.
[0064] Specifically, the program development side 110 can edit a program and publish the edited program to the program management service 120. The program published to the program management service 120 is referred to as a publicly available program in the embodiment of the present application. It can be understood that in some other examples, it can also be referred to as an open-source program.
[0065] The program management service 120 is used to store multiple publicly available programs that have been published. The program management service 120 includes a website, an FTP service, etc. that can be publicly accessed. For example, the program management service 120 can be github, or gitlab, or a personal homepage. The program management service 120 provides a download interface for publicly available programs, and the program usage side 140 can obtain the required publicly available programs from the program management service 120 through this download interface.
[0066] The blockchain system 130 may include multiple node devices 131. The multiple node devices 131 may refer to each client in the blockchain system 130. When each node device 131 is operating normally, it can receive input information and maintain the shared data within the blockchain system based on the received input information. The multiple node devices 131 in the blockchain system 130 may be configured with a target blockchain, which is used to store the program verification information of each public program in the program management service 120. Among them, the program verification information of the public program includes program signature information and the public key of the program development end that releases the public program. The program signature information is obtained by encrypting the program hash value of the public program based on the private key of the program development end.
[0067] The target blockchains in the multiple node devices 131 are all composed of multiple blocks, and the adjacent blocks before and after have an associated relationship, so that when the data in any block is tampered with, it can be detected by the next block, thereby avoiding the data in the blockchain from being tampered with and ensuring the security and reliability of the data in the blockchain.
[0068] Among them, the blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm. Blockchain, in essence, is a decentralized database, a series of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity (anti-counterfeiting) of the information and generate the next block. The blockchain may include the blockchain underlying platform, the platform product service layer, and the application service layer.
[0069] The underlying blockchain platform may include processing modules such as user management, basic services, smart contracts, and operation detection. Among them, the user management module is responsible for the identity information management of all blockchain participants, including maintaining the generation of public and private keys (account management), key management, and the maintenance of the correspondence between the real identity of users and blockchain addresses (permission management). And under authorized circumstances, it supervises and audits the transaction situations of certain real identities, and provides the rule configuration for risk control (risk control and audit); the basic service module is deployed on all blockchain node devices to verify the validity of business requests, and after reaching a consensus on valid requests, records them in storage. For a new business request, the basic service first performs interface adaptation parsing and authentication processing (interface adaptation), then encrypts the business information through a consensus algorithm (consensus management), transmits it intact and consistently to the shared ledger after encryption (network communication), and performs record storage; the smart contract module is responsible for the registration and issuance of contracts, as well as contract triggering and contract execution. Developers can define contract logic through a certain programming language, publish it to the blockchain (contract registration), trigger the execution according to the logic of the contract terms by calling keys or other events, complete the contract logic, and at the same time also provide functions for contract upgrade and cancellation; the operation detection module is mainly responsible for the deployment, configuration modification, contract setting, cloud adaptation during the product release process, and the visual output of the real-time status during product operation, such as: alarm, detecting network conditions, detecting the health status of node devices, etc.
[0070] The platform product service layer provides the basic capabilities and implementation frameworks of typical applications. Developers can build on these basic capabilities and overlay the characteristics of the business to complete the blockchain implementation of the business logic. The application service layer provides application services based on the blockchain solution for business participants to use.
[0071] It should be noted that the server involved in the embodiments of this application may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0072] Please refer to Figure 2 , which shows a schematic flowchart of a program security detection method based on blockchain provided by the embodiments of this application. This method can be applied to Figure 1The architecture shown. It should be noted that this specification provides method operation steps as described in the embodiments or flowcharts, but based on routine or non-creative labor, it may include more or fewer operation steps. The step order listed in the embodiments is only one way among the execution orders of numerous steps and does not represent the only execution order. When the actual system or product is executed, it can be executed in the order of the method shown in the embodiments or the drawings or in parallel (for example, in an environment with parallel processors or multi-threaded processing). Specifically, as Figure 2 shown, the method may include:
[0073] S201, in response to a release instruction for a target public program, the program development end generates a public key and a private key of the program development end.
[0074] Among them, the target public program refers to a program that has been edited and is to be released to the program management service for public disclosure.
[0075] Specifically, after the program developer edits the target public program based on the program development end, a release instruction for releasing the target public program can be initiated. Thus, in response to this release instruction, the program development end generates a public key and the corresponding private key locally. In a specific implementation, an asymmetric encryption algorithm (Rivest-Shamir-Adleman, RSA) can be used to generate the public-private key pair of the program development end.
[0076] S203, the program development end performs a hash calculation on the target public program based on a preset hash function to obtain the program hash value of the target public program.
[0077] Among them, the preset hash function can be any hash function, such as common hash functions like MD5, SHA-2 series (such as SHA-256), and the national cryptography algorithm SM3.
[0078] S205, the program development end encrypts the program hash value based on the private key of the program development end to obtain program signature information.
[0079] Specifically, the above program hash value can be encrypted based on the private key of the program development end using an asymmetric encryption algorithm to obtain the program signature information of the target public program.
[0080] S207, the program development end publishes the target public program to the program management service.
[0081] S209, the program development end stores the program signature information and the public key of the program development end as the target program verification information corresponding to the target public program in the target blockchain.
[0082] In some exemplary embodiments, to implement periodic automated program security detection, such as Figure 3 shown, when the program development side publishes the target public program to the program management service in step S207 above, it may include:
[0083] S301, The program development side obtains the program name and program version number of the target public program.
[0084] S303, The program development side uses the program name and program version number as the identification information of the target public program, and publishes the target public program to the program management service.
[0085] Specifically, when the program development side publishes the target public program to the program management service, it can name the target public program file according to the following program file name specification:
[0086] Program file name = program name _ program version number _ other custom fields.bin
[0087] Among them, the other custom fields can be determined by the program development side according to the actual situation for extension.
[0088] Based on this, in some exemplary embodiments, continue to refer to Figure 3 , when the program development side stores the program signature information and the public key of the program development side as the target program verification information corresponding to the target public program in step S209 above, it may include:
[0089] S305, The program development side generates transaction data based on the program name, program version number, program signature information of the target public program, and the public key of the program development side.
[0090] S307, The program development side sends a transaction request to the target blockchain based on the transaction data, so that the target blockchain responds to the transaction request and stores the above transaction data in the form of key-value pairs.
[0091] Among them, the key in the key-value pair is the program name and program version number in the transaction data, and the value in the key-value pair is the program signature information and the public key of the program development side in the transaction data. Exemplarily, the transaction data can be stored on the target blockchain in the following form:
[0092] Key = program name + program version number
[0093] Value = program signature value + developer public key
[0094] In some examples, the transaction data structure in the embodiments of the present application may include a transaction body and a transaction signature. Among them, the transaction body may include the program name of the target public program, the program version number, the program signature information, and the public key of the program development end; the transaction signature may be obtained by using a digital signature cryptographic algorithm based on the private key of the program development end and the above transaction body.
[0095] Based on this, the implementation of the above step S305 may include: generating the transaction body of the transaction data based on the program name of the target public program, the program version number, the program signature information, and the public key of the program development end; encrypting the transaction body based on the private key of the program development end to obtain the transaction signature of the transaction data, and the transaction signature of the transaction data is used for the target blockchain to verify the transaction request, and in the case of successful verification, storing the transaction body of the transaction data in the form of the key-value pair.
[0096] In specific implementation, after generating the above transaction request, the program development end may send the transaction request to the node device in the blockchain system, and the node device may verify the transaction data carried in the transaction request to ensure the reliability of the program transaction information therein. In order to be able to verify the transaction request, at least one verification node device may be included in multiple node devices of the blockchain system for verifying the transaction request, and the blockchain system may also set a verification policy, and the verification policy may stipulate the number of verification node devices used for verification, the verification method, the verification passing condition, etc. Among them, the verification method may be to verify whether the transaction data is generated in a preset format, whether required information such as the program name and the program version number is missing, etc.; the verification passing condition may be the minimum number of verification node devices that pass the verification or the minimum proportion of the verification node devices that pass the verification in all node devices of the blockchain system.
[0097] In some exemplary implementation manners, in order to further improve the reliability of the transaction data, before storing the transaction data in the form of a key-value pair, the target blockchain may also perform permission verification on the program development end, and through this permission verification, it can be verified whether the program development end has the permission to publish the program verification information. Based on this, the method in the embodiments of the present application may further include:
[0098] The program development end sends a registration request to the target blockchain so that the target blockchain returns a digital certificate in the case of determining successful registration;
[0099] The program development end sends a transaction request to the target blockchain based on the transaction data and the digital certificate, so that the target blockchain verifies the permissions of the program development end based on the digital certificate, and stores the transaction data in the form of key-value pairs when the permission verification is passed.
[0100] Specifically, the program development end can use the digital certificate applied from the target blockchain as an identity identifier, and send a transaction request to the node device of the specific target blockchain based on the transaction data and the digital certificate. Thus, when the node device receives the transaction request, it can call the digital certificate authentication service of the blockchain system for authentication. When the authentication is passed, it indicates that the identity of the program development end is legal, that is, the permission verification of the program development end is passed; on the contrary, when the authentication fails, it indicates that the identity of the program development end is illegal, that is, the permission verification of the program development end fails. When the permission verification is passed, the node device stores the transaction data on the target blockchain in the form of key-value pairs.
[0101] In a specific implementation, the node device can generate a corresponding block based on the transaction data, add the block to the target blockchain, and after the node device adds the generated block to the target blockchain, all node devices configured with the target blockchain in the blockchain system synchronize the updated target blockchain, thereby completing the addition of a new block.
[0102] S211, The program user end obtains the target public program from the program management service.
[0103] S213, The program user end obtains the target program verification information corresponding to the identification information from the target blockchain based on the identification information of the target public program.
[0104] In some exemplary embodiments, continue to refer to Figure 3 , in the above step S213, when the program user end searches for the target program verification information corresponding to the identification information from the target blockchain based on the identification information of the target public program, it may include:
[0105] S309, The program user end generates a query key based on the program name and program version number of the target public program.
[0106] S311, The program user end sends a query request to the target blockchain based on the query key, so that the target blockchain determines a target key matching the query key in response to the query request and returns the target value corresponding to the target key.
[0107] S313, The program user end receives the target value returned by the target blockchain to obtain the target program verification information.
[0108] Specifically, the query key can be carried in the query request, so that when the target blockchain receives the query request, it can extract the query key therein, find the target key that matches the query key, and then return the target value corresponding to the target key to the program usage end. Correspondingly, when the program usage end receives the target value, it obtains the target program verification information.
[0109] In some examples, when the target blockchain stores the program verification information in the form of key-value pairs, it can calculate the hash value of the key and then store the hash value of the key and the corresponding value. Then, when the program usage end obtains the target program verification information from the target blockchain, it can also use the hash value of the above query key, that is, after generating the query key, calculate the hash value of the query key, and generate the query request based on the hash value of the query key when generating the query request. When the target blockchain receives the query request, it extracts the hash value of the query key from the query request, finds the target hash value that matches the hash value of the query key, and then returns the target value corresponding to the target hash value to the program usage end.
[0110] S215. The program usage end performs a hash calculation on the target public program based on a preset hash function to obtain a program hash value to be verified.
[0111] Exemplarily, when the program development end publishes the target public program to the program management service, it can publish the hash function information along with it. The hash function information is used to indicate the hash function for the program development end to calculate the program hash value of the target public program. Thus, when the program usage end obtains the target public program from the program management service, it can simultaneously obtain the corresponding hash function information, and then determine the preset hash function based on the hash function information, and use the preset hash function to perform a hash calculation on the target public program already obtained from the program management service to obtain the program hash value to be verified.
[0112] In another example, the program hash value generated by the program development end can carry the hash function information, which is used to indicate the hash function for the program development end to calculate the program hash value of the target public program. For example, the form of the program hash value can be: xxxx hash.sha256, where the suffix is the hash function information, indicating that the program hash value is calculated using the sha256 function. Thus, after the program usage end obtains the target program verification information from the target blockchain, it can determine the preset hash function based on the program hash value of the target program verification information, and then can use the preset hash function to perform a hash calculation on the target public program already obtained from the program management service to obtain the program hash value to be verified.
[0113] S217. The program usage end performs a signature verification process based on the target program verification information and the program hash value to be verified to obtain the program security detection result of the target public program.
[0114] Among them, the program security detection result indicates whether there is a security risk in the target public program.
[0115] Specifically, the program usage end invokes a signature verification algorithm for signature verification processing based on the hash value of the program to be verified, the public key in the target program verification information, and the program signature information. This signature verification processing can be expressed as: result = Verify(hash value of the program to be verified, public key of the program development end, program signature information), where result represents the result of the signature verification. result = true indicates that the signature verification is successful, and result = false indicates that the signature verification fails; Verify() represents the signature verification algorithm, which can be selected according to implementation needs, such as NIST_P256, SM2, RSA and other signature verification algorithms.
[0116] Since the target program verification information (i.e., the public key of the program development end and the program signature information) comes from the target blockchain and has the characteristics of being immutable, publicly trusted. When the signature verification fails (i.e., result = false), it indicates that the hash value of the program to be verified is different from the program hash value used when generating the program signature information, and the target public program has been tampered with, generating a first program security detection result, and this first program security detection result indicates that the target public program has a risk; on the contrary, when the signature verification is successful (i.e., result = true), it indicates that the hash value of the program to be verified is the same as the program hash value used when generating the program signature information, and the target public program is legal, that is, not tampered with, generating a second program security detection result, and this second program security detection result indicates that the target public program has no risk.
[0117] It can be understood that when the program security detection result is the first program security detection result, the program usage end can also output a reminder message to prompt that there is a security risk in the target public program; of course, the program usage end can also detect the running situation of the target public program. If it is detected that the target public program is running, the target public program can be automatically stopped from running.
[0118] Next, taking the program usage end as the execution subject, the method for program security detection based on blockchain in the embodiments of the present application is introduced, as Figure 4 shown, this method may include:
[0119] S401, Obtain a target public program from the program management service, and the target public program is published to the program management service by the program development end.
[0120] S403, Based on the identification information of the target public program, obtain the target program verification information corresponding to the identification information from the target blockchain.
[0121] Among them, the target blockchain is used to store the program verification information of each public program in the program management service. The program verification information of the public program includes program signature information and the public key of the program development end that releases the public program. The program signature information is obtained by encrypting the program hash value of the public program based on the private key of the program development end.
[0122] S405, perform a hash calculation on the target public program based on a preset hash function to obtain a program hash value to be verified.
[0123] Among them, the preset hash function is the hash function used by the target program development end to generate the program hash value of the target public program.
[0124] S407, perform a signature verification process based on the target program verification information and the program hash value to be verified, and obtain a program security detection result of the target public program. The program security detection result indicates whether there is a security risk in the target public program.
[0125] It should be noted that for the detailed implementation processes of the above steps S401 to S407, reference can be made to the relevant steps in the foregoing method embodiments of this application Figure 2 and Figure 3 shown, which will not be elaborated here.
[0126] Next, taking the program development end as the execution subject, the method for program security detection based on blockchain in the embodiments of this application will be introduced. As Figure 5 shown, the method may include:
[0127] S501, in response to a release instruction for a target public program, generate a public key and a private key of the program development end;
[0128] S503, perform a hash calculation on the target public program based on a preset hash function to obtain the program hash value of the target public program;
[0129] S505, encrypt the program hash value based on the private key of the program development end to obtain program signature information;
[0130] S507, publish the target public program to the program management service so that the program user end can obtain the target public program from the program management service;
[0131] S509. Store the program signature information and the public key of the program development end as the target program verification information corresponding to the target public program in the target blockchain, so that the program user end can obtain the target program verification information from the target blockchain based on the obtained identification information of the target public program, calculate the hash value of the program to be verified for the target public program based on the preset hash function, perform signature verification processing based on the target program verification information and the hash value of the program to be verified, and obtain the program security detection result of the target public program, where the program security detection result indicates whether there is a security risk in the target public program;
[0132] Among them, the target blockchain is used to store the program verification information of each public program in the program management service.
[0133] It should be noted that for the detailed implementation processes of the above steps S501 to S509, reference can be made to the relevant steps of the method embodiments described above in this application. Figure 2 and Figure 3 They will not be elaborated here.
[0134] Corresponding to the blockchain-based program security detection methods provided in the above several embodiments, the embodiments of the present application also provide a blockchain-based program security detection device. Since the blockchain-based program security detection device provided in the embodiments of the present application corresponds to the blockchain-based program security detection methods provided in the above several embodiments, the implementation manners of the foregoing blockchain-based program security detection methods are also applicable to the blockchain-based program security detection device provided in this embodiment and will not be described in detail in this embodiment.
[0135] Please refer to Figure 6 , which shows a schematic structural diagram of a blockchain-based program security detection device provided in an embodiment of the present application. This device can be configured at the program user end, and this device has the function of implementing the blockchain-based program security detection method of the program user end in the above method embodiment. The function can be implemented by hardware or by hardware executing corresponding software. As Figure 6 shown, the blockchain-based program security detection device 600 may include:
[0136] A program acquisition module 610, configured to acquire a target public program from a program management service; the target public program is published by a program development end to the program management service;
[0137] A program verification information acquisition module 620, configured to obtain target program verification information corresponding to the identification information from a target blockchain based on the identification information of the target public program; the target blockchain is used to store program verification information of each public program in the program management service, and the program verification information of the public program includes program signature information and a public key of the program development end that releases the public program, and the program signature information is obtained by encrypting the program hash value of the public program based on the private key of the program development end;
[0138] A first hash calculation module 630, configured to perform hash calculation on the target public program based on a preset hash function to obtain a program hash value to be verified; the preset hash function is the hash function used by the target program development end to generate the program hash value of the target public program;
[0139] A signature verification module 640, configured to perform signature verification processing based on the target program verification information and the program hash value to be verified to obtain a program security detection result of the target public program; the program security detection result indicates whether there is a security risk in the target public program.
[0140] In an exemplary embodiment, the identification information includes a program name and a program version number, and the target blockchain stores program verification information of each public program in the form of key-value pairs, where the key in the key-value pair is the program name and program version number of the public program, and the value in the key-value pair is the program verification information of the public program; the program verification information acquisition module includes:
[0141] A query key generation module, configured to generate a query key based on the program name and program version number of the target public program;
[0142] A query request sending module, configured to send a query request to the target blockchain based on the query key, so that the target blockchain determines a target key matching the query key in response to the query request and returns the target value corresponding to the target key;
[0143] A target value acquisition module, configured to receive the target value returned by the target blockchain to obtain target program verification information.
[0144] Please refer to Figure 7 , which shows a schematic structural diagram of a program security detection device based on a blockchain provided by an embodiment of the present application. The device can be configured at a program development end, and the device has the function of implementing the program security detection method based on the blockchain at the program development end in the above method embodiment. The function can be implemented by hardware or by hardware executing corresponding software. As Figure 7 shown, the program security detection device 700 based on the blockchain may include:
[0145] A key generation module 710, configured to generate a public key and a private key of the program development end in response to a release instruction for a target public program;
[0146] A second hash calculation module 720, configured to perform a hash calculation on the target public program based on a preset hash function to obtain a program hash value of the target public program;
[0147] A program signature module 730, configured to encrypt the program hash value based on the private key of the program development end to obtain program signature information;
[0148] A program release module 740, configured to release the target public program to a program management service, so that a program usage end can obtain the target public program from the program management service;
[0149] A program verification information release module 750, configured to store the program signature information and the public key of the program development end as target program verification information corresponding to the target public program in a target blockchain, so that the program usage end can obtain the target program verification information from the target blockchain based on the obtained identification information of the target public program, perform a hash calculation on the target public program based on the preset hash function to obtain a program hash value to be verified, and perform a signature verification process based on the target program verification information and the program hash value to be verified to obtain a program security detection result of the target public program, where the program security detection result indicates whether there is a security risk in the target public program;
[0150] Wherein, the target blockchain is used to store the program verification information of each public program in the program management service.
[0151] In an exemplary embodiment, the program release module includes:
[0152] A name and version acquisition module, configured to acquire a program name and a program version number of the target public program;
[0153] A release module, configured to use the program name and the program version number as identification information of the target public program, and release the target public program to a program management service.
[0154] In an exemplary embodiment, the program verification information release module includes:
[0155] A transaction data generation module, configured to generate transaction data based on the program name, the program version number, the program signature information of the target public program, and the public key of the program development end;
[0156] A transaction request sending module, configured to send a transaction request to the target blockchain based on the transaction data, so that the target blockchain stores the transaction data in the form of key-value pairs in response to the transaction request, where the key in the key-value pair is the program name and program version number in the transaction data, and the value in the key-value pair is the program signature information in the transaction data and the public key of the program development end.
[0157] In an exemplary embodiment, the transaction data includes a transaction body and a transaction signature; the transaction data generation module includes:
[0158] A transaction body generation module, configured to generate the transaction body of the transaction data based on the program name, program version number, program signature information of the target public program, and the public key of the program development end;
[0159] A transaction signature generation module, configured to encrypt the transaction body based on the private key of the program development end to obtain the transaction signature of the transaction data; the transaction signature of the transaction data is used for the target blockchain to verify the transaction request, and store the transaction body of the transaction data in the form of the key-value pair when the verification is passed.
[0160] In an exemplary embodiment, the device further includes:
[0161] A registration module, configured to send a registration request to the target blockchain, so that the target blockchain returns a digital certificate when it determines that the registration is successful in response to the registration request;
[0162] Correspondingly, the transaction request sending module is specifically configured to: send a transaction request to the target blockchain based on the transaction data and the digital certificate, so that the target blockchain performs permission verification on the program development end based on the digital certificate, and store the transaction data in the form of the key-value pair when the permission verification is passed.
[0163] It should be noted that when the device provided in the above embodiment realizes its functions, only the above-mentioned division of each functional module is used for illustration. In actual application, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device provided in the above embodiment and the method embodiment belong to the same concept, and the specific implementation process can be seen in the method embodiment, which will not be repeated here.
[0164] An embodiment of the present application provides an electronic device, which includes a processor and a memory. At least one instruction or at least one program segment is stored in the memory, and the at least one instruction or the at least one program segment is loaded and executed by the processor to implement any one of the blockchain-based program security detection methods provided in the above method embodiments.
[0165] The memory can be used to store software programs and modules. The processor runs the software programs and modules stored in the memory to execute various functional applications and data processing. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for functions, etc.; the data storage area can store data created according to the use of the device, etc. In addition, the memory can include high-speed random access memory, and can also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices. Correspondingly, the memory can also include a memory controller to provide the processor with access to the memory.
[0166] The method embodiments provided in the embodiments of the present application can be executed on a computer terminal, a server, or a similar computing device, that is, the above electronic device can include a computer terminal, a server, or a similar computing device. Taking running on a terminal as an example, Figure 8 is a hardware structure block diagram of an electronic device for running a blockchain-based program security detection method provided in an embodiment of the present application. Specifically:
[0167] The terminal may include an RF (Radio Frequency) circuit 810, a memory 820 including one or more computer-readable storage media, an input unit 830, a display unit 840, a sensor 850, an audio circuit 860, a WiFi (wireless fidelity) module 870, a processor 880 including one or more processing cores, and a power supply 890, etc. Those skilled in the art can understand that Figure 8 the terminal structure shown in does not constitute a limitation on the terminal, and may include more or fewer components than shown in the figure, or combine certain components, or different component arrangements. Among them:
[0168] The RF circuit 810 can be used for receiving and transmitting information or signals during a call. Specifically, after receiving the downlink information from the base station, it is handed over to one or more processors 880 for processing. Additionally, data related to the uplink is sent to the base station. Generally, the RF circuit 810 includes, but is not limited to, an antenna, at least one amplifier, a tuner, one or more oscillators, a subscriber identity module (SIM) card, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, etc. Moreover, the RF circuit 810 can also communicate with the network and other terminals via wireless communication. The wireless communication can use any communication standard or protocol, including but not limited to GSM (Global System of Mobile communication), GPRS (General Packet Radio Service), CDMA (Code Division Multiple Access), WCDMA (Wideband Code Division Multiple Access), LTE (Long Term Evolution), email, SMS (Short Messaging Service), etc.
[0169] The memory 820 can be used to store software programs and modules. The processor 880 executes various functional applications and data processing by running the software programs and modules stored in the memory 820. The memory 820 mainly includes a program storage area and a data storage area. Among them, the program storage area can store the operating system, application programs required for functions, etc.; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory 820 can include high-speed random access memory, and can also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. Correspondingly, the memory 820 can also include a memory controller to provide access to the memory 820 for the processor 880 and the input unit 830.
[0170] The input unit 830 can be used to receive input numerical or character information, and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control. Specifically, the input unit 830 can include a touch-sensitive surface 831 and other input devices 832. The touch-sensitive surface 831, also known as a touch display screen or a touchpad, can collect touch operations of a user thereon or nearby (such as operations of the user using any suitable object or accessory such as a finger or a stylus on or near the touch-sensitive surface 831), and drive corresponding connection devices according to a preset program. Optionally, the touch-sensitive surface 831 can include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the touch position of the user, detects signals brought by the touch operation, and transmits the signals to the touch controller; the touch controller receives touch information from the touch detection device, converts it into contact coordinates, and then sends it to the processor 880, and can also receive commands sent by the processor 880 and execute them. In addition, the touch-sensitive surface 831 can be implemented in multiple types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch-sensitive surface 831, the input unit 830 can also include other input devices 832. Specifically, the other input devices 832 can include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, a joystick, etc.
[0171] The display unit 840 can be used to display information input by the user or information provided to the user, as well as various graphical user interfaces of the terminal. These graphical user interfaces can be composed of graphics, text, icons, videos, and any combination thereof. The display unit 840 can include a display panel 841. Optionally, the display panel 841 can be configured in forms such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode). Further, the touch-sensitive surface 831 can cover the display panel 841. After the touch-sensitive surface 831 detects a touch operation thereon or nearby, it transmits the operation to the processor 880 to determine the type of touch event. Subsequently, the processor 880 provides corresponding visual output on the display panel 841 according to the type of touch event. Among them, the touch-sensitive surface 831 and the display panel 841 can be two independent components to implement input and input functions. However, in some embodiments, the touch-sensitive surface 831 and the display panel 841 can also be integrated to implement input and output functions.
[0172] The terminal may further include at least one sensor 850, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. Among them, the ambient light sensor can adjust the brightness of the display panel 841 according to the brightness of the ambient light, and the proximity sensor can turn off the display panel 841 and / or the backlight when the terminal is moved to the ear. As a kind of motion sensor, the gravity acceleration sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary, and can be used for applications that identify the posture of the terminal (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors that the terminal can also be configured with, they will not be elaborated here.
[0173] The audio circuit 860, the speaker 861, and the microphone 862 can provide an audio interface between the user and the terminal. The audio circuit 860 can transmit the electrical signal converted from the received audio data to the speaker 861, and the speaker 861 converts it into a sound signal for output; on the other hand, the microphone 862 converts the collected sound signal into an electrical signal, which is received by the audio circuit 860 and then converted into audio data. After the audio data is output to the processor 880 for processing, it is sent through the RF circuit 810 to, for example, another terminal, or the audio data is output to the memory 820 for further processing. The audio circuit 860 may also include an earphone jack to provide communication between the peripheral earphone and the terminal.
[0174] WiFi belongs to short - range wireless transmission technology. The terminal can help users send and receive emails, browse the web, and access streaming media through the WiFi module 870, which provides users with wireless broadband Internet access. Although Figure 8 the WiFi module 870 is shown, it can be understood that it does not belong to the essential components of the terminal and can be omitted completely within the scope of not changing the essence of the invention according to needs.
[0175] The processor 880 is the control center of the terminal, connecting various parts of the entire terminal through various interfaces and lines. By running or executing software programs and / or modules stored in the memory 820, and by calling the data stored in the memory 820, it executes various functions of the terminal and processes data. Optionally, the processor 880 may include one or more processing cores; preferably, the processor 880 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above - mentioned modem processor may not be integrated into the processor 880 either.
[0176] The terminal further includes a power supply 890 (such as a battery) for powering each component. Preferably, the power supply can be logically connected to the processor 880 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption management through the power management system. The power supply 890 may further include any components such as one or more DC or AC power supplies, a recharge system, a power failure detection circuit, a power converter or inverter, a power status indicator, etc.
[0177] Although not shown, the terminal may further include a camera, a Bluetooth module, etc., which will not be elaborated here. Specifically, in this embodiment, the terminal further includes a memory, and one or more programs, where one or more programs are stored in the memory and are configured to be executed by one or more processors. The above one or more programs include instructions for executing the blockchain-based program security detection method provided in the above method embodiment.
[0178] An embodiment of the present application further provides a computer-readable storage medium, which can be disposed in an electronic device to store at least one instruction or at least one segment of program related to implementing a blockchain-based program security detection method. The at least one instruction or the at least one segment of program is loaded and executed by the processor to implement any one of the blockchain-based program security detection methods provided in the above method embodiment.
[0179] An embodiment of the present application further provides a computer program product or a computer program, which includes computer instructions stored in a computer-readable storage medium. The processor of the electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes any one of the blockchain-based program security detection methods provided in the above method embodiment.
[0180] Optionally, in this embodiment, the above storage medium may include, but is not limited to: various media such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc that can store program codes.
[0181] It should be noted that: The above order of the embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above specific embodiments of this specification have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0182] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiments.
[0183] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by a program instructing the relevant hardware. The program can be stored in a computer-readable storage medium. The above-mentioned storage medium can be a read-only memory, a disk, an optical disc, or the like.
[0184] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included within the protection scope of the present application.
Claims
1. A program security detection method based on blockchain, characterized in that Applied to the program usage side, the method includes: Obtain a target public program from the program management service; the target public program is published by the program development side to the program management service; Based on the identification information of the target public program, obtain the target program verification information corresponding to the identification information from the target blockchain; the target blockchain is used to store the program verification information of each public program in the program management service, and the program verification information of the public program includes program signature information and the public key of the program development side that publishes the public program, and the program signature information is obtained by encrypting the program hash value of the public program based on the private key of the program development side; Perform a hash calculation on the target public program based on a preset hash function to obtain a program hash value to be verified; the preset hash function is the hash function used by the target program development side to generate the program hash value of the target public program; Perform a signature verification process based on the target program verification information and the program hash value to be verified to obtain the program security detection result of the target public program; the program security detection result indicates whether there is a security risk in the target public program.
2. The method according to claim 1, characterized in that The identification information includes a program name and a program version number, and the target blockchain stores the program verification information of each public program in the form of key-value pairs. The key in the key-value pair is the program name and program version number of the public program, and the value in the key-value pair is the program verification information of the public program; The step of finding the target program verification information corresponding to the identification information from the target blockchain based on the identification information of the target public program includes: Generate a query key based on the program name and program version number of the target public program; Send a query request to the target blockchain based on the query key, so that the target blockchain determines a target key that matches the query key in response to the query request and returns the target value corresponding to the target key; Receive the target value returned by the target blockchain to obtain the target program verification information.
3. A program security detection method based on blockchain, characterized in that, Applied to the program development side, the method includes: In response to a release instruction for a target public program, generate the public key and private key of the program development side; Perform a hash calculation on the target public program based on a preset hash function to obtain the program hash value of the target public program; Encrypt the program hash value based on the private key of the program development side to obtain program signature information; Publish the target public program to the program management service, so that the program usage side can obtain the target public program from the program management service; Store the program signature information and the public key of the program development end as the target program verification information corresponding to the target public program in the target blockchain, so that the program user end can obtain the target program verification information from the target blockchain based on the obtained identification information of the target public program, calculate the hash value of the program to be verified by performing a hash calculation on the target public program based on the preset hash function, and perform a signature verification process based on the target program verification information and the hash value of the program to be verified to obtain the program security detection result of the target public program, where the program security detection result indicates whether there is a security risk in the target public program; Among them, the target blockchain is used to store the program verification information of each public program in the program management service.
4. The method according to claim 3, wherein The publishing of the target public program to the program management service includes: Obtain the program name and program version number of the target public program; Use the program name and program version number as the identification information of the target public program, and publish the target public program to the program management service.
5. The method according to claim 4, wherein The storing of the program signature information and the public key of the program development end as the target program verification information corresponding to the target public program in the target blockchain includes: Generate transaction data based on the program name, program version number, program signature information of the target public program, and the public key of the program development end; Send a transaction request to the target blockchain based on the transaction data, so that the target blockchain, in response to the transaction request, stores the transaction data in the form of a key-value pair, where the key in the key-value pair is the program name and program version number in the transaction data, and the value in the key-value pair is the program signature information and the public key of the program development end in the transaction data.
6. The method according to claim 5, characterized in that, The transaction data includes a transaction body and a transaction signature; the generating of the transaction data based on the program name, program version number, program signature information of the target public program, and the public key of the program development end includes: Generate the transaction body of the transaction data based on the program name, program version number, program signature information of the target public program, and the public key of the program development end; Encrypt the transaction body based on the private key of the program development end to obtain the transaction signature of the transaction data; the transaction signature of the transaction data is used for the target blockchain to verify the transaction request, and in the case of successful verification, store the transaction body of the transaction data in the form of the key-value pair.
7. The method according to claim 4, characterized in that The method further includes: Send a registration request to the target blockchain, so that the target blockchain returns a digital certificate in the case of determining successful registration in response to the registration request; The sending of the transaction request to the target blockchain based on the transaction data includes: Send a transaction request to the target blockchain based on the transaction data and the digital certificate, so that the target blockchain performs permission verification on the program development end based on the digital certificate, and in the case of successful permission verification, stores the transaction data in the form of the key-value pair.
8. A program security detection device based on blockchain, characterized in that, Configured at the program usage end, the device includes: A program acquisition module, configured to acquire a target public program from a program management service; the target public program is published to the program management service by a program development end; A program verification information acquisition module, configured to, based on the identification information of the target public program, acquire target program verification information corresponding to the identification information from a target blockchain; the target blockchain is used to store the program verification information of each public program in the program management service, and the program verification information of the public program includes program signature information and the public key of the program development end that publishes the public program, and the program signature information is obtained by encrypting the program hash value of the public program based on the private key of the program development end; A first hash calculation module, configured to perform hash calculation on the target public program based on a preset hash function to obtain a program hash value to be verified; the preset hash function is the hash function used by the target program development end to generate the program hash value of the target public program; A signature verification module, configured to perform signature verification processing based on the target program verification information and the program hash value to be verified to obtain a program security detection result of the target public program; the program security detection result indicates whether there is a security risk in the target public program.
9. A program security detection device based on blockchain, characterized in that, Configured at the program development end, the device includes: A key generation module, configured to generate a public key and a private key of the program development end in response to a release instruction for a target public program; A second hash calculation module, configured to perform hash calculation on the target public program based on a preset hash function to obtain the program hash value of the target public program; A program signature module, configured to encrypt the program hash value based on the private key of the program development end to obtain program signature information; A program release module, configured to publish the target public program to the program management service so that the program usage end can acquire the target public program from the program management service; A program verification information release module, configured to store the program signature information and the public key of the program development end as target program verification information corresponding to the target public program in the target blockchain, so that the program usage end can acquire the target program verification information from the target blockchain based on the acquired identification information of the target public program, perform hash calculation on the target public program based on the preset hash function to obtain a program hash value to be verified, and perform signature verification processing based on the target program verification information and the program hash value to be verified to obtain a program security detection result of the target public program, and the program security detection result indicates whether there is a security risk in the target public program; wherein, the target blockchain is used to store the program verification information of each public program in the program management service.
10. An electronic device, characterized in that, Including a processor and a memory, at least one instruction or at least one program is stored in the memory, and the at least one instruction or the at least one program is loaded and executed by the processor to implement the blockchain-based program security detection method according to any one of claims 1 to 7.
11. A computer-readable storage medium, characterized in that, At least one instruction or at least one segment of program is stored in the computer-readable storage medium, and the at least one instruction or the at least one segment of program is loaded and executed by a processor to implement the blockchain-based program security detection method according to any one of claims 1 to 7.
12. A computer program, characterized in that, When the computer program is executed by a processor, it implements the blockchain-based program security detection method according to any one of claims 1 to 7.