Data processing method and device based on block chain, equipment and storage medium

By distributing the private keys of institutions in custodial equipment and institutional equipment, and using the blockchain network's signature verification mechanism, the problems of illegal behavior and private key loss in institutional transactions are solved, achieving higher transaction security and efficiency.

CN120258803APending Publication Date: 2025-07-04TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410014701.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-02
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

Institutions may have illegal behaviors during transactions, such as illegal money laundering, illegal fundraising and loss of transaction private keys, resulting in low transaction security.

Method used

By distributing the private key of an institution to the custodial equipment and institutional equipment in P signature device groups in fragments, the custodial equipment and institutional equipment in the target signature device group jointly verify the legality of the custodial transaction information and sign the transaction, and verify the signature using the blockchain network to ensure the legality and security of the transaction.

Benefits of technology

It avoids institutions to execute illegal transactions, improves the security and efficiency of transactions, and ensures the security of private keys and fairness of transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120258803A_ABST
    Figure CN120258803A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data processing method and device based on a block chain, equipment and a storage medium, which can be applied to various scenes such as cloud technology, artificial intelligence, smart traffic and auxiliary driving, and the method comprises the following steps: according to a first transaction signature and a second transaction signature of hosting transaction information about a resource hosting task of an institution, establishing a resource hosting task of the institution; counting the number of signature devices corresponding to the devices signing the hosting transaction information in the target signature device group; when the number of the signature devices is greater than or equal to the number of the limited device signatures, verifying the first transaction signature and the second transaction signature according to the hosting transaction information and the public key of the mechanism to obtain a verification result; and when the verification result indicates that the first transaction signature and the second transaction signature pass verification, executing a resource hosting task associated with the hosting transaction information to obtain an execution result, and uploading the execution result to the block chain. According to the invention, illegal transactions of the institution can be avoided, and the security of the transaction of the institution can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of blockchain technology, and in particular, to a data processing method, apparatus, device, and storage medium based on blockchain. Background Art

[0002] Blockchain technology is a new distributed infrastructure and computing method that uses a block-chain data structure to verify and store data, uses a distributed node consensus algorithm to generate and update data, uses cryptography to ensure the security of data transmission and access, and uses smart contracts composed of automated script codes to program and operate data. Simply put, blockchain is a decentralized distributed ledger. A resource client is a tool for managing and storing user digital resources, which can be used to implement resource management business functions. Digital resources refer to those owned or controlled by an enterprise or an individual and existing in the form of electronic data.

[0003] Currently, when an institution conducts a transaction, there may be malicious behaviors, such as illegal money laundering, illegal fundraising, illegal asset transfer, etc. Moreover, the private key of the institution's transaction is prone to being lost, resulting in the institution being unable to conduct transactions, and thus the security of the transaction is relatively low. Summary of the Invention

[0004] The embodiments of this application provide a data processing method, apparatus, device, and storage medium based on blockchain, which can avoid illegal transactions by institutions and improve the security of institutional transactions.

[0005] On the one hand, the embodiments of this application provide a data processing method based on blockchain, including:

[0006] Obtain escrow transaction information about a resource escrow task of an institution, as well as a first transaction signature and a second transaction signature of the escrow transaction information; the first transaction signature is obtained by an institutional device in a target signature device group that determines the legality of the escrow transaction information, signing the escrow transaction information with a first private key shard of the institution, and the second transaction signature is obtained by a escrow device in the target signature device group that determines the legality of the escrow transaction information, signing the escrow transaction information with a second private key shard of the institution. The target signature device group is a signature device group in which all devices in P signature device groups of the institution are in a working state; P is a positive integer greater than 1;

[0007] According to the first transaction signature and the second transaction signature, count the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group;

[0008] Obtain the restricted device signature quantity of the institution and the public key of the institution from the blockchain of the blockchain network. When the signature device quantity is greater than or equal to the restricted device signature quantity, verify the first transaction signature and the second transaction signature according to the escrow transaction information and the public key of the institution to obtain a verification result;

[0009] When the verification result indicates that the first transaction signature and the second transaction signature pass the verification, execute the resource escrow task associated with the escrow transaction information to obtain an execution result, and upload the execution result to the blockchain.

[0010] One aspect of the embodiments of the present application provides a data processing method based on a blockchain, including:

[0011] Obtain the escrow transaction information of the resource escrow task regarding an institution, and the first transaction signature of the escrow transaction information; the first transaction signature is obtained by an institution device in the target signature device group that determines the legality of the escrow transaction information using the first private key shard of the institution to sign the escrow transaction information, and the target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in a working state; P is a positive integer greater than 1;

[0012] Verify the legality of the escrow transaction information through the escrow device in the target signature device group. When it is determined that the escrow transaction information is legal, use the second private key shard of the institution to sign the escrow transaction information to obtain a second transaction signature;

[0013] Send the escrow transaction information, the first transaction signature, and the second transaction signature to a blockchain node in the blockchain network; the blockchain node is used to execute the resource escrow task associated with the escrow transaction information to obtain an execution result and upload the execution result to the blockchain when the signature device quantity corresponding to the device that signs the escrow transaction information in the target signature device group is greater than or equal to the restricted device signature quantity and the first transaction signature and the second transaction signature pass the verification.

[0014] One aspect of the embodiments of the present application provides a data processing method based on a blockchain, including:

[0015] Obtain the escrow transaction information of the resource escrow task regarding an institution, and the P signature device groups of the institution; P is a positive integer greater than 1;

[0016] Determine the signature device group in which the devices are in a working state from the P signature device groups as the target signature device group;

[0017] The institutional device in the target signature device group signs the escrow transaction information with the first private key shard of the institution to obtain a first transaction signature.

[0018] Send the escrow transaction information and the first transaction signature to the escrow device in the target signature device group; the escrow device in the target signature device group is used to sign the escrow transaction information with the second private key shard of the institution to obtain a second signature information when determining that the escrow transaction information is legal, and send the first signature information, the second signature information, and the escrow transaction information to the blockchain node in the blockchain network.

[0019] One aspect of the embodiments of the present application provides a blockchain-based data processing device, including:

[0020] A first acquisition module, configured to acquire escrow transaction information about a resource escrow task of an institution, as well as a first transaction signature and a second transaction signature of the escrow transaction information; the first transaction signature is obtained by an institutional device in the target signature device group that determines the legality of the escrow transaction information signing the escrow transaction information with the first private key shard of the institution, and the second transaction signature is obtained by an escrow device in the target signature device group that determines the legality of the escrow transaction information signing the escrow transaction information with the second private key shard of the institution, and the target signature device group is the signature device group in which all devices in P signature device groups of the institution are in a working state; P is a positive integer greater than 1;

[0021] A statistics module, configured to count the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group according to the first transaction signature and the second transaction signature.

[0022] A signature verification module, configured to obtain the restricted device signature number of the institution and the public key of the institution from the blockchain of the blockchain network, and when the number of signature devices is greater than or equal to the restricted device signature number, verify the first transaction signature and the second transaction signature according to the escrow transaction information and the public key of the institution to obtain a signature verification result.

[0023] An on-chain module, configured to execute the resource escrow task associated with the escrow transaction information to obtain an execution result when the verification result indicates that the first transaction signature and the second transaction signature pass the signature verification, and upload the execution result to the blockchain.

[0024] One aspect of the embodiments of the present application provides a blockchain-based data processing device, including:

[0025] A second acquisition module, configured to acquire escrow transaction information about a resource escrow task of an institution, and a first transaction signature of the escrow transaction information; the first transaction signature is obtained by an institution device in a target signature device group that determines the escrow transaction information to be legal, using a first private key shard of the institution to sign the escrow transaction information, and the target signature device group is a signature device group in which all devices in P signature device groups of the institution are in a working state; P is a positive integer greater than 1;

[0026] A first signature module, configured to verify the legality of the escrow transaction information through an escrow device in the target signature device group, and when it is determined that the escrow transaction information is legal, use a second private key shard of the institution to sign the escrow transaction information to obtain a second transaction signature;

[0027] A first sending module, configured to send the escrow transaction information, the first transaction signature, and the second transaction signature to a blockchain node in a blockchain network; the blockchain node is configured to execute a resource escrow task associated with the escrow transaction information to obtain an execution result when the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group is greater than or equal to a restricted device signature number, and the first transaction signature and the second transaction signature pass the signature verification, and upload the execution result to the blockchain.

[0028] On the one hand, an embodiment of the present application provides a data processing device based on a blockchain, including:

[0029] A third acquisition module, configured to acquire escrow transaction information about a resource escrow task of an institution, and the P signature device groups of the institution; P is a positive integer greater than 1;

[0030] A determination module, configured to determine, from the P signature device groups, a signature device group in which the devices are in a working state as a target signature device group;

[0031] A second signature module, configured to sign the escrow transaction information by an institution device in the target signature device group using a first private key shard of the institution to obtain a first transaction signature;

[0032] A fourth sending module, configured to send the escrow transaction information and the first transaction signature to an escrow device in the target signature device group; the escrow device in the target signature device group is configured to, when it is determined that the escrow transaction information is legal, use a second private key shard of the institution to sign the escrow transaction information to obtain a second signature information, and send the first signature information, the second signature information, and the escrow transaction information to a blockchain node in a blockchain network.

[0033] In one aspect, an embodiment of the present application provides a computer-readable storage medium storing a computer program, which is adapted to be loaded and executed by a processor so that a computer device having the processor executes the method provided by the embodiment of the present application.

[0034] In one aspect, an embodiment of the present application provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions so that the computer device executes the method provided by the embodiment of the present application.

[0035] The embodiment of the present application provides a distributed resource security hosting method, which may include but is not limited to the following beneficial effects: First, the private key of the institution is sharded and distributed to the hosting devices and institution devices in P signature device groups, avoiding the problem that the private key shards held by the signature devices in a single signature device group are abnormal, resulting in the inability to perform transaction signatures normally, and having a high disaster tolerance. Second, by jointly verifying the legality of the hosted transaction information and performing transaction signatures by the hosting devices and institution devices in the target signature device group, it is possible to avoid the institution from executing illegal transactions while also improving the security of task execution. Third, the target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in a working state. In this way, it is possible to avoid the situation where signature failures occur when signing by signature device groups in a non-working state, and improve the efficiency of signing the hosted transaction information. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings without creative efforts based on these drawings.

[0037] Figure 1a It is a schematic diagram of a blockchain structure provided by an embodiment of the present application;

[0038] Figure 1b It is a schematic diagram of block generation provided by an embodiment of the present application;

[0039] Figure 2 It is a schematic diagram of the structure of a data processing system based on a blockchain provided by an embodiment of the present application;

[0040] Figure 3It is a schematic diagram of a scenario for processing resource hosting tasks based on blockchain provided by an embodiment of the present application;

[0041] Figure 4 It is a first flowchart of a data processing method based on blockchain provided by an embodiment of the present application;

[0042] Figure 5 It is a schematic diagram of private key sharding allocation provided by an embodiment of the present application;

[0043] Figure 6 It is a flowchart of a data processing method based on blockchain provided by an embodiment of the present application Figure 2 ;

[0044] Figure 7 It is a flowchart of a data processing method based on blockchain provided by an embodiment of the present application Figure 3 ;

[0045] Figure 8 It is a schematic structural diagram of a first data processing device based on blockchain provided by an embodiment of the present application;

[0046] Figure 9 It is a schematic structural diagram of a second data processing device based on blockchain provided by an embodiment of the present application;

[0047] Figure 10 It is a schematic structural diagram of a third data processing device based on blockchain provided by an embodiment of the present application;

[0048] Figure 11 It is a schematic diagram of a computer device provided by an embodiment of the present application. Specific embodiments

[0049] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0050] This application relates to the field of artificial intelligence technology. Specifically, in the embodiments of this application, a transaction verification model can be used to verify the legality of transaction parameter information in the escrow transaction information, which can improve the accuracy and efficiency of the legality verification of transaction parameter information.

[0051] The risk prediction model can predict the transaction risk level of resource transaction requests, improving the accuracy and efficiency of transaction risk level prediction and further enhancing the security of resource transactions. Meanwhile, the embodiments of this application can also verify the legitimacy of accounts through an anomaly detection model, improving the accuracy and efficiency of account legitimacy verification.

[0052] Among them, Artificial Intelligence (AI) utilizes digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, including theories, methods, technologies, and application systems for perceiving the environment, acquiring knowledge, and using knowledge to obtain optimal results. In other words, AI is a comprehensive technology in computer science that attempts to understand the essence of intelligence and produce a new intelligent machine that can react in a way similar to human intelligence. AI also studies the design principles and implementation methods of various intelligent machines, enabling machines to have functions of perception, reasoning, and decision-making. AI technology is an interdisciplinary subject with a wide range of fields, including both hardware-level and software-level technologies. AI basic technologies generally include technologies such as sensors, dedicated AI chips, cloud computing, distributed storage, large-scale speech data processing technology, operation / interaction systems, and mechatronics. AI software technologies mainly include several major directions such as computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning, autonomous driving, and intelligent transportation.

[0053] Specifically, this application specifically relates to machine learning under artificial intelligence technology. Machine Learning (ML) is an interdisciplinary subject that involves multiple disciplines such as probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers simulate or implement human learning behaviors to acquire new knowledge or skills and reorganize the existing knowledge structure to continuously improve their own performance. Machine learning is the core of artificial intelligence and the fundamental way to make computers intelligent, and its applications cover all fields of artificial intelligence. Machine learning and deep learning usually include technologies such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and rote learning.

[0054] This application involves Blockchain, which is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. Blockchain is essentially a decentralized database, a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity (anti-counterfeiting) of the information and generate the next block. Blockchain can include the blockchain underlying platform, the platform product service layer, and the application service layer. Blockchain consists of multiple blocks, see Figure 1a ,Figure 1a This is a schematic diagram of a blockchain structure provided by an embodiment of the present application. As Figure 1a shown, the blockchain consists of multiple blocks. The genesis block includes a block header and a block body. The block header stores the input information feature value, version number, timestamp, and difficulty value. The block body stores the input information. The next block of the genesis block uses the genesis block as its parent block. The next block also includes a block header and a block body. The block header stores the input information feature value of the current block, the block header feature value of the parent block, version number, timestamp, and difficulty value, and so on. This ensures that the block data stored in each block in the blockchain is associated with the block data stored in the parent block, guaranteeing the security of the input information in the block.

[0055] When generating each block in the blockchain, refer to Figure 1b , Figure 1b This is a schematic diagram of block generation provided by an embodiment of the present application. When the node where it is located receives the input information, it verifies the input information. After the verification is completed, it stores the input information in the memory pool and updates the hash tree used to record the input information. Then, it updates the timestamp to the time when the input information is received and tries different random numbers, performing eigenvalue calculations multiple times so that the calculated eigenvalue can satisfy the following formula:

[0056] SHA256(SHA256(version+prev_hash+merkle_root+ntime+nbits+x))<TARGET

[0057] Among them, SHA256 in the formula is the eigenvalue algorithm used to calculate the eigenvalue; version (version number) is the version information of the relevant block protocol in the blockchain; prev_hash is the block header feature value of the parent block of the current block; merkle_root is the eigenvalue of the input information; ntime is the update time of the updated timestamp; nbits is the current difficulty, which is a fixed value within a certain period of time and is determined again after exceeding the fixed time period; x is a random number; TARGET is the eigenvalue threshold, and this eigenvalue threshold can be determined according to nbits.

[0058] Among them, when a random number that satisfies the above formula is calculated, the information can be stored correspondingly to generate a block header and a block body, obtaining the current block. Subsequently, the blockchain can broadcast the newly generated current block externally, that is, send the current block to other nodes in the data sharing system where it is located. Each node in the data sharing system stores an identical blockchain. Other nodes verify the current block and add the current block to the blockchain they store after the verification is completed.

[0059] Please refer toFigure 2 , Figure 2 is a schematic structural diagram of a blockchain-based data processing system provided by an embodiment of the present application. As Figure 2 shown, the blockchain-based data processing system may include a blockchain network 1X, a terminal device cluster 1Y, and a hosting device 1R. Among them, the blockchain network 1X may include: blockchain nodes 200a, blockchain nodes 200b, blockchain nodes 200c... and blockchain nodes 200n. It can be understood that the blockchain network 1X may include one or more blockchain nodes, and the embodiment of the present application does not limit the number of blockchain nodes. It can be understood that in this blockchain network 1X, data interaction can be carried out between the blockchain nodes 200a, blockchain nodes 200b, blockchain nodes 200c... and blockchain nodes 200n through network connections. It should be understood that each blockchain node in the blockchain network 1X (for example, blockchain nodes 200a, blockchain nodes 200b, blockchain nodes 200c... and blockchain nodes 200n) can be used to maintain the same blockchain. A peer-to-peer network can be formed between any two blockchain nodes in this blockchain network 1X, and the peer-to-peer network can adopt a peer-to-peer transmission protocol. Among them, the peer-to-peer transmission protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP). In a distributed system, any device such as a server, a terminal, etc. can join and become a blockchain node.

[0060] Among them, the terminal device cluster 1Y may include one or more terminal devices, and the number of terminal devices will not be limited here. As Figure 2 shown, it may specifically include terminal devices 100a, terminal devices 100b, terminal devices 100c,..., terminal devices 100n. As Figure 2 shown, the terminal devices 100a, terminal devices 100b, terminal devices 100c,..., terminal devices 100n can be respectively network-connected to the blockchain nodes (such as blockchain node 200a) in the blockchain network 1X, so that each terminal device can perform data interaction with the blockchain nodes in the blockchain network 1X through this network connection.

[0061] Among them, each terminal device in the terminal device cluster 1Y may include: intelligent terminals with blockchain-based data processing functions such as smartphones, tablets, laptops, desktop computers, intelligent voice interaction devices, intelligent home appliances (such as intelligent TVs), wearable devices, in-vehicle terminals, etc. It should be understood that as Figure 2Each terminal device in the terminal device cluster 1Y shown can be installed with an application client having a blockchain-based data processing function. When the application client runs on each terminal device, it can perform data interaction with the blockchain nodes (such as blockchain node 200a) in the blockchain network 1X shown above. It can be understood that through the application client with a blockchain-based data processing function in the terminal device, the escrow transaction information in the terminal device can be sent to the blockchain nodes in the blockchain network 1X. For example, the application client can specifically include a transaction client, a resource client, an escrow client, etc. Among them, the application client in the embodiments of the present application can be integrated in a certain application client (such as the resource client is integrated in the transaction client), and the application client can also be an independent application client. The embodiments of the present application do not limit the type of the application client. Figure 2 When the application client runs on each terminal device, it can perform data interaction with the blockchain nodes (such as blockchain node 200a) in the blockchain network 1X shown above. It can be understood that through the application client with a blockchain-based data processing function in the terminal device, the escrow transaction information in the terminal device can be sent to the blockchain nodes in the blockchain network 1X. For example, the application client can specifically include a transaction client, a resource client, an escrow client, etc. Among them, the application client in the embodiments of the present application can be integrated in a certain application client (such as the resource client is integrated in the transaction client), and the application client can also be an independent application client. The embodiments of the present application do not limit the type of the application client.

[0062] For ease of understanding, an embodiment of the present application can select one terminal device as the target terminal device from the Figure 2 multiple terminal devices shown. For example, an embodiment of the present application can use the Figure 2 terminal device 100a shown as the target terminal device. The target terminal device can be installed with an application client having a blockchain-based data processing function. At this time, the target terminal device can send the escrow transaction information in the terminal device to the blockchain nodes in the blockchain network 1X through this application client.

[0063] It should be noted that all blockchain nodes in the blockchain network involved in the embodiments of the present application can be mobile phones, tablet computers, laptop computers, palmtop computers, mobile internet devices (MIDs), vehicles, roadside devices, aircraft, wearable devices, such as smart watches, smart bracelets, pedometers, etc., which are intelligent devices with data processing functions. All node devices in the blockchain network can also be independent physical servers, or a server cluster or distributed system composed of multiple physical servers, or cloud servers providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The device types corresponding to each node device can be the same or different.

[0064] Among them, the managed device 1R may include managed devices, such as the managed device 300a. Of course, it may also include other managed devices. The managed device 1R may include one or more managed devices, and the number of managed devices will not be limited here. The managed devices in the managed device 1R are configured with a resource hosting platform, which is used to provide hosting services for the resource clients installed in the terminal devices, such as resource hosting, resource hosting transfer out, querying the resources hosted by the managed device, etc. A network connection is established between the managed devices in the managed device 1R and the terminal devices in the terminal device cluster 1Y, and data interaction between the managed device and the terminal device can be realized through this network connection. It can be understood that when the resource hosting platform runs in each managed device, it can respectively interact with the terminal devices in the terminal device 1Y shown above Figure 2 for data interaction.

[0065] At the same time, a network connection is also established between the managed devices in the managed device 1R and the blockchain nodes, and data interaction between the managed device and the blockchain nodes can be realized through this network connection. It can be understood that when the resource hosting platform runs in each managed device, it can respectively interact with the blockchain nodes (such as the blockchain node 200a) in the blockchain network 1X shown above Figure 2 for data interaction. In other words, through the resource hosting platform in the managed device, the hosting transaction information sent by the terminal device can be received, and the hosting transaction information can be sent to the blockchain nodes in the blockchain network 1X. Among them, the managed devices in the managed device 1R can be terminal devices or servers, and the device type of the managed device is not limited in the embodiments of the present application.

[0066] Among them, the resource client is used to handle services related to digital resources, such as digital resource transfer, exchange, extraction, information viewing, etc. Among them, digital resources can refer to resources stored digitally on the blockchain, including but not limited to virtual pets, digital assets, props, character skins, diamonds, vouchers, as well as virtual pets, famous paintings, buildings, etc. The resource client can be used to implement the resource management service function and achieve communication connection with the decentralized application client based on this resource management service function. The resource client is a tool for managing and storing users' digital resources. For example, digital resources can be transferred to other accounts based on the resource client, and digital resources transferred from other accounts can be received based on the resource client. The resource client can be a hardware device or a software program. The resource hosting platform is used to provide hosting services for the resource client, such as hosting the digital resources and account keys in the resource client and managing the risk of resource transactions. In this application, an institution can conduct resource transactions through an institutional resource client (i.e., the resource client of the institution). The institutional resource client is a resource client serving the institution and can manage the digital resources of the institution in dimensions such as institutions, organizations, and employees.

[0067] Specifically, the embodiment of this application can adopt a distributed resource security hosting method to achieve the secure hosting of the institution's digital resources. In the distributed security hosting method, the private key of the institution can be distributed in the institutional device and the hosting device in the form of private key sharding. Among them, the institutional device is the institutional resource client installed for the institution to conduct transactions, and the hosting device is the terminal device of the resource hosting platform that provides hosting services for the resource client. Both the institutional device and the hosting device can be the signature devices of the institution. It can be understood that a private key shard can be generated for each signature device, and one signature device holds one private key shard. In this way, the institutional device holds some private key shards, and the hosting device holds some private key shards. The private key shards held by the institutional device and the hosting device respectively can be used for the institution's transactions. In this way, the private key of the institution can be distributed and deployed in the institutional device and the hosting device to improve the security of the institution's private key and the security of transactions.

[0068] Among them, the institutional device can obtain the hosting transaction information of the resource hosting task of the institution. The hosting transaction information can be triggered and generated by each institution (such as the administrator and operator of the institution) in the institutional resource client in the institutional device. Among them, the resource hosting task can be a resource transfer task, a resource hosting task, etc. The hosting transaction information can be the transaction parameter information required to implement the resource hosting task. Taking the resource hosting task as a resource transfer task as an example, the hosting transaction information of the resource transfer task can include resource identification information, resource quantity information, recipient information, etc.

[0069] Specifically, when implementing the distributed security hosting method in the embodiments of the present application, multiple private key shard groups can be generated. The private key shards in one private key shard group can have the ability to sign a transaction to obtain a complete signature, while the private key shards in different private key shard groups cannot obtain a complete signature when signing a transaction. It can be understood that the private key shards in the same private key shard group can achieve successful transaction signing, while the private key shards in different private key shard groups cannot achieve successful transaction signing. Among them, one private key shard group can include multiple private key shards, and the multiple private key shards in one private key shard can be distributed in institutional devices and hosting devices. Taking the private key shard group K100 as an example, the institutional device can hold some private key shards in the private key shard group K100, and the hosting device can also hold some private key shards in the private key shard group K100. For example, the private key shard group K100 can include private key shard K101, private key shard K102, and private key shard K103. The private key shard K101 and the private key shard K102 can be assigned to two institutional devices, with one institutional device holding one private key shard, and the private key shard K103 can be assigned to the hosting device.

[0070] Among them, the signature devices holding the private key shards in one private key shard group form a signature device group. Therefore, the P signature device groups of the institution can be the signature devices holding multiple private key shard groups of the institution, where P is a positive integer greater than 1. Specifically, when the institutional device obtains the hosting transaction information about the resource hosting task of the institution, it can use the first private key shard of the institution it holds to sign the hosting transaction information to obtain a first transaction signature, and send the first transaction signature and the hosting transaction information to the hosting device. The hosting device can use the second private key shard of the institution it holds to sign the hosting transaction information to obtain a second transaction signature, and send the first transaction signature, the second transaction signature, and the hosting transaction information to the blockchain node in the blockchain network.

[0071] Furthermore, the blockchain node can verify the signatures of the first transaction signature and the second transaction signature. Only when the verification of the first transaction signature and the second transaction signature is successful, the resource hosting task associated with the hosting transaction information is executed to obtain an execution result, and the execution result is uploaded to the blockchain. In this way, distributing the private key of the institution to the institutional device and the hosting device can ensure the security of the private key and the security of transaction execution. At the same time, the hosting device can verify the legality of the hosting transaction information, which can prevent the institution from conducting illegal transactions and damaging the public interest, and can ensure the fairness of the transaction. At the same time, the blockchain node performs transaction signature verification and uploads the execution result to the blockchain, which can ensure the security and fairness of the transaction.

[0072] Among them, the blockchain nodes of the above blockchain network 1X include consensus nodes and business nodes. The network structure of the blockchain network 1X can be a hierarchical structure, that is, the business nodes of the blockchain network 1X belong to the business network in the blockchain network 1X, and the consensus nodes of the blockchain network 1X belong to the consensus network in the blockchain network 1X. The business network and the consensus network are network-isolated, and communication between the consensus network and the business network is carried out through proxy nodes in the routing proxy network. The proxy node can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms, which is not limited here. Among them, the business node does not need to participate in the accounting consensus and is mainly used to execute transaction services to obtain transaction data associated with the transaction service.

[0073] Among them, the business node here can be a full node containing a complete blockchain database or a lightweight node that stores part of the data in the blockchain database, which will not be limited here. To reduce the waste of storage space of the business node, the business node in the embodiment of the present application can take a lightweight node (Simplified Payment Verification, abbreviated as SPV) as an example. The business node does not need to store complete transaction data, but obtains block header data and partially authorized visible block data (for example, transactions associated with the business node itself) from the consensus network through a proxy node. In this way, the blockchain network 1X can be network-layered through the proxy node to form a hierarchical structure of "business network - consensus network", which can further improve the confidentiality and security of data on the blockchain.

[0074] For ease of understanding, further, please refer to Figure 3 , Figure 3 which is a schematic diagram of a scenario for processing resource hosting tasks based on blockchain provided by the embodiment of the present application. As Figure 3 shown, taking the resource transfer task of the resource hosting service of an institution as an example, the terminal device 30a can be the terminal device held by the institution management object 30b, that is, the terminal device 30a is an institution device. The terminal device 30a can be Figure 2 any terminal device in the terminal device cluster 1Y in Figure 2 , such as the terminal device 100b in Figure 2 . The hosting device 30e can be Figure 2A blockchain node of the blockchain network 1X, such as the blockchain node 200a. Among them, the terminal device 30a and the hosting device 30e belong to the target signature device group, and the target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in a working state, where P is a positive integer greater than 1.

[0075] It can be understood that specifically, an institutional resource client can be installed in the terminal device 30a. The institutional resource client is a resource client serving the institution and can manage the digital resources of the institution in dimensions such as institutions, organizations, and employees. The hosting transaction information of the resource hosting task is displayed in the task interface 30c provided by the institutional resource client. For example, for a resource hosting task of transferring resources to the institutional management object 30 of the resource hosting platform, the hosting transaction information of the resource hosting task can be input in the task interface 30c provided by the institutional resource client. Or, the hosting transaction information displayed in the task interface 30c is generated by the terminal device 30a. Taking the resource hosting task as a resource transfer-out task as an example, the hosting transaction information of the resource transfer-out task can include the resource identification information to be transferred out, the resource quantity data, the resource transfer-out time, and the receiving account information, etc. When the institutional management object 30b triggers the execution control 30d regarding the resource hosting task, the terminal device 30a can use the first private key shard of the institution to sign the hosting transaction information of the resource hosting task of the institution to obtain the first transaction signature. Among them, the first private key shard of the institution can be the private key shard of the institution held by the institutional device in the target signature device group.

[0076] Furthermore, the terminal device 30a can send the hosting transaction information and the first transaction signature to the hosting device 30e. The hosting device 30e can verify the legality of the hosting transaction information. When it is determined that the hosting transaction information is legal, it can use the second private key shard of the institution to sign the hosting transaction information to obtain the second transaction signature. In this way, by verifying the legality of the hosting transaction information by the hosting device 30e, it can prevent the institution from conducting illegal transactions, implementing unfair behaviors, damaging the public interest, and improving the security of transactions. Among them, the second private key shard of the institution can be the private key shard of the institution held by the hosting device in the target signature device group. In this way, by having the institutional device and the hosting device respectively hold the private key shards of the institution, the security of private key storage can be provided.

[0077] Specifically, the escrow device 30e can send the first transaction signature, the second transaction signature, and the escrow transaction information to the blockchain node 30f. The blockchain node 30f can count the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group based on the first transaction signature and the second transaction signature, that is, count how many signature devices sign the escrow transaction information. The restricted device signature quantity of the institution is stored on the blockchain of the blockchain network, and the restricted device signature quantity is used to indicate that only when the number of signature devices is greater than or equal to the restricted device signature quantity can the resource escrow task of the corresponding transaction escrow information be performed to ensure the security of the execution of the resource escrow task. The blockchain node 30f can obtain the restricted device signature quantity of the institution and the public key of the institution from the blockchain of the blockchain network, compare the restricted device signature quantity with the number of signature devices, and obtain a comparison result.

[0078] When the comparison result indicates that the number of signature devices is greater than or equal to the restricted device signature quantity, the first transaction signature and the second transaction signature are verified based on the escrow transaction information and the public key of the institution to obtain a verification result. In this way, malicious tampering of the escrow transaction information can be avoided, and the security of the execution of the resource escrow task can be improved. It can be understood that the private key shards of the institution are all generated based on the same private key, so the public key of the institution can be used to verify the first transaction signature and the second transaction signature. Among them, the blockchain node 30f can determine the signature algorithms for signing the escrow transaction information with the first private key shard and the second private key shard, and verify the first transaction signature and the second transaction signature based on the signature algorithms, the public key, and the escrow transaction information.

[0079] When the verification result indicates that the first transaction signature and the second transaction signature pass the verification, the blockchain node 30f executes the resource escrow task for managing the escrow transaction information to obtain an execution result, and uploads the execution result to the blockchain. In this way, by uploading the execution result to the blockchain and utilizing the immutability and transparency of the blockchain, the authenticity and fairness of the execution of the resource escrow task can be guaranteed, and the problem of data asymmetry can be eliminated. Further, the blockchain node 30f can return the execution result to the escrow device 30e, and the escrow device 30e can return the execution result to the terminal device 30a.

[0080] Further, please refer to Figure 4 , Figure 4 which is the first schematic flowchart of a blockchain-based data processing method provided by an embodiment of the present application. As Figure 4 shown, this method can be executed by any blockchain node in the blockchain network 1X in Figure 2 and the blockchain-based data processing method can at least include but is not limited to the following steps:

[0081] S101, obtain escrow transaction information about the resource escrow task of an institution, as well as a first transaction signature and a second transaction signature of the escrow transaction information.

[0082] Specifically, when performing resource transactions in the institutional resource client (i.e., the resource client of the institution), there will be transaction risks that one cannot be aware of and the risk of loss of transaction private keys. Therefore, the private keys and digital resources of the institution can be escrowed through the resource escrow platform, which can reduce certain transaction risks. At the same time, the resource escrow platform can perform legality verification on the resource transactions initiated by the institution, which can prevent the institution from conducting illegal transactions and harming the public interest. The resource escrow tasks of the institution may include, but are not limited to, resource escrow tasks, resource transfer tasks, information query tasks, etc. The resource escrow task may refer to escrowing the digital resources of the institution through the resource escrow platform. The resource transfer task may refer to transferring the digital resources of the institution through the resource escrow platform, and the information query task may refer to querying the detailed information of the digital resources of the institution (such as the type of digital resources, the quantity of digital resources, the status of digital resources, etc.) in the resource escrow platform.

[0083] Among them, the escrow transaction information of the resource escrow task may be the transaction parameter information required to implement the resource escrow task. Taking the resource escrow task as the resource transfer task as an example, the escrow transaction information of the resource transfer task may include the resource identification information, resource quantity information, recipient information, resource transfer time, etc. of the digital resources to be transferred. It can be understood that the device installed with the institutional resource client can be called an institutional device, and the device configured with the resource escrow platform can be called an escrow device.

[0084] Specifically, the blockchain node can obtain the escrow transaction information about the resource escrow task of the institution. The escrow transaction information may be sent by the institutional device or the escrow device. At the same time, the blockchain node can also obtain the first transaction signature and the second transaction signature of the escrow transaction information. The first transaction signature is obtained by the institutional device that determines the legality of the escrow transaction information in the target signature device group using the first private key shard of the institution to sign the escrow transaction information. The second transaction signature is obtained by the escrow device that determines the legality of the escrow transaction information in the target signature device group using the second private key shard of the institution to sign the escrow transaction information. The target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in a working state, and P is a positive integer greater than 1.

[0085] Among them, a private key shard of a holding institution of a signature device group is held by one signature device, which is used to sign the entrusted transaction information of the institution. The number of signature devices in each of the P signature device groups may be the same or different. For example, among the P signature device groups, there are a first signature device group and a second signature device group. The number of signature devices in the first signature device group is 5, and the number of signature devices in the second signature device group is 3. Of course, the signature weights of the private key shards held by each signature device in a signature device group may be the same or different. For example, the first signature device group included in the P signature device groups includes a first signature device and a second signature device. The signature weight of the private key shard held by the first signature device is 0.4, and the signature weight of the private key shard held by the second signature device is 0.6. In this way, by configuring different signature weights for different signature devices, a heavier signature weight can be configured for more important devices, realizing diversified signatures.

[0086] It can be understood that in the embodiments of the present application, the private key of the institution can be distributed in the institution devices and the entrusted devices in the form of private key shards. In this way, the private key of the institution will not be exposed, improving the security of the private key of the institution. At the same time, the private key shards of the institution are grouped to obtain P private key shard groups. A private key shard group includes multiple private key shards. Among them, the private key shards in the same private key shard group can achieve successful transaction signature, and the private key shards in different private key shard groups cannot achieve successful transaction signature. That is, the private key shards in any one private key shard group can cooperate to sign a transaction, and cross-group signature is not possible. The devices holding the private key shards in the same private key shard group form a signature device group. A signature device holds one private key shard, that is, one private key shard group corresponds to one signature device group. The signature devices in the signature device group may refer to institution devices or entrusted devices that sign the transactions of the institution. In this way, the private key of the institution can be distributed and deployed in the institution devices and the entrusted devices to improve the security of the private key of the institution and the security of transactions.

[0087] Among them, the target signature device group may be a signature device group in which the devices selected from the P signature device groups are all in a working state. In this way, by setting P signature device groups for the institution, when a signature device group fails, a normal signature device group can be used to sign the entrusted transaction information of the transaction, avoiding the situation that the resource entrustment task of the institution cannot be carried out normally when a single signature device group fails, realizing disaster tolerance, and improving the security and efficiency of the execution of the resource entrustment task of the institution.

[0088] Optionally, when each signature device generates a private key shard of the institution it holds, the signature devices in each signature device group may execute a distributed key generation protocol according to a pre-executed limit on the number of signature devices (i.e., threshold) t and the total number of devices N in a signature device group. Among them, the distributed key generation protocol may include, but is not limited to, the MPC key generation protocol. MPC is multi-party secure computation, a collection of cutting-edge distributed encryption computing technologies. Through the computation of multiple participants, while exposing some necessary information, it hides other key information and obtains a public result, thus ensuring the security or privacy of the computation result. The MPC key generation protocol can generate a private key shard for all signature devices in a signature device group, and can use the respective private key shards to sign the escrow transaction information of the institution.

[0089] When the distributed key generation protocol is executed and completed, each signature device can obtain a private key shard of the institution, and each signature device cannot know the private key shards of others, which can ensure the security of the private key shards. Based on the same distributed key generation protocol, all signature devices in the same signature device group can obtain a private key shard of the institution and a common public key, and the public key can be used to verify the transaction signature obtained by signing based on the corresponding multiple private key shards. In this way, the digital resources of the institution can be jointly managed by multiple signature devices. When there are N or more (i.e., the limit on the number of signature devices) signature devices in a signature device group jointly signing the escrow transaction information, the signature can be successful (i.e., the public key of the institution can successfully verify the signatures of N or more signature devices). It can be understood that after the private key shards are distributed, each signature device only holds one private key shard. To obtain the real private key, the attacker needs to obtain no less than the limit number of signature device private key shards to restore the real private key, which can ensure the security of the private key.

[0090] Optionally, to further improve the security of the private key of the institution, the private key shard group corresponding to each signature device group can be refreshed based on the key refreshing protocol corresponding to the distributed key generation protocol. That is, all the signature devices in a signature device group can execute the key refreshing protocol at regular intervals. When the key refreshing protocol is completed, all the signature devices in the signature device group will obtain a new private key shard of the institution, and all the old private key shards will be invalidated. For example, the signature devices in the signature device group hold the private key shard F001 of the institution in the first time period. After executing the key refreshing protocol at the specified time, the signature devices in the signature device group hold the private key shard F002 of the institution in the second time period, and the private key shard F001 is invalidated. In this way, it can effectively prevent the attacker from stealing the private key shards of each person respectively and then restoring the private key. Since all the old private key shards are invalidated after each key refresh, the attacker's previous efforts are wasted and they have to start the stealing attack again, thus exponentially increasing the attack difficulty.

[0091] Optionally, the number of private key shards held by the institution devices in each signature device group and the number of private key shards held by the escrow devices can also be refreshed at regular intervals. For example, in the third time period, the number of private key shards held by the institution in the signature device group is 2, and the number of private key shards held by the escrow devices is 3. After refreshing with the key refreshing protocol, in the fourth time period, the number of private key shards held by the institution in the signature device group is 3, and the number of private key shards held by the escrow devices is 2. In this way, the security of the private key of the institution can be further improved.

[0092] Optionally, to prevent the institution devices from bypassing the escrow devices (i.e., without going through the escrow devices) and directly submitting the escrow transaction information about the institution to the blockchain node, resulting in illegal transaction behaviors of the institution devices and damaging the public interest. And to prevent the escrow devices from privately sending the escrow transaction information about the institution directly to the blockchain node. If there is malicious behavior in resource escrow, such as illegally transferring the digital resources of the institution, the security of the digital resources of the institution cannot be guaranteed. In the embodiment of the present application, when distributing the private key shards in a private key shard group to the signature devices in a signature device group, it can be ensured that the number of private key shards held by the institution devices and the escrow devices in a signature device group does not exceed the number of restricted signature devices.

[0093] For example, the embodiments of the present application may adopt a 3-3 threshold signature scheme. The 3-3 threshold signature scheme means that the number of private key shards in a private key shard group is 3, and the number of signature devices is limited to 3. That is, 3 private key shards need to jointly perform a transaction signature to succeed. When distributing the 3 private key shards to institutional devices or trustee devices, two private key shards in a private key shard group can be distributed to two institutional devices, and one private key shard can be distributed to one trustee device. The devices (institutional devices or trustee devices) holding the private key shards in the private key shard group belong to the same signature device group. Of course, two private key shards in a private key shard group can also be distributed to two trustee devices, and one private key shard can be distributed to one institutional device. It can be seen that the number of private key shards held by institutional devices and trustee devices in the same signature device group does not exceed 3 respectively.

[0094] Specifically, in the 3-3 threshold signature scheme, institutional devices and trustee devices that hold 3 private key shards in the same private key shard group need to sign together to obtain a complete signature and execute the transaction. In this way, institutional devices cannot bypass trustee devices, and trustee devices cannot bypass institutional devices. It is necessary for institutional devices and trustee devices to jointly use their respective held private key shards for signature to execute the transaction. It can avoid institutional devices from privately executing illegal transactions and also prevent the resource trustee platform from illegally transferring institutional digital resources, which can improve the security of resource transactions.

[0095] As Figure 5 shown, Figure 5 is a schematic diagram of private key shard distribution provided by the embodiments of the present application. As Figure 5 shown, the private key of the institution can be divided into two groups, namely the private key shard group K100 and the private key shard group F100. Among them, two private key shards in each private key shard group can be distributed on the resource client side, that is, two private key shards in each private key shard group are stored in institutional devices installed with resource clients (i.e., institutional resource clients), and one private key shard is stored in one institutional device. One private key shard in each private key shard group is distributed on the resource trustee platform side, that is, one private key shard in each private key shard group is stored in trustee devices configured with resource trustee platforms. The private key shard K101 and the private key shard K102 in the private key shard group K100 are distributed to the resource client. For example, the private key shard K101 can be distributed to the first institutional device installed with the resource client, and the private key shard K102 can be distributed to the second institutional device installed with the resource client.

[0096] The private key shard K103 in the private key shard group K100 is allocated to the resource hosting platform. For example, the private key shard K103 can be allocated to the first hosting device configured with the resource hosting platform. In this way, the first institutional device, the second institutional device, and the first hosting device form a signature device group of the institution. Only by jointly signing with the private key shards in the private key shard group K100 can the signature be successful. Similarly, the private key shards F101 and F102 in the private key shard group F100 are allocated to the resource client. For example, the private key shard F101 can be allocated to the third institutional device installed with the resource client, and the private key shard F102 can be allocated to the fourth institutional device installed with the resource client. The private key shard F103 in the private key shard group F100 is allocated to the resource hosting platform. For example, the private key shard F103 can be allocated to the second hosting device configured with the resource hosting platform. In this way, the third institutional device, the fourth institutional device, and the second hosting device form a signature device group of the institution. Only by jointly signing with the private key shards in the private key shard group F100 can the signature be successful.

[0097] S102. According to the first transaction signature and the second transaction signature, count the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group.

[0098] Specifically, the first transaction signature is obtained by an institutional device in the target signature device group signing the escrow transaction information. The number of institutional devices in the target signature device group can be one or more. Therefore, the number of first transaction signatures can be one or more. Thus, the number of institutional devices that sign the escrow transaction information in the target signature device group can be determined according to the first transaction signature. Similarly, the second transaction signature is obtained by a hosting device in the target signature device group signing the escrow transaction information. The number of hosting devices in the target signature device group can be one or more. Therefore, the number of second transaction signatures can also be one or more. Thus, the number of hosting devices that sign the escrow transaction information in the target signature device group can be determined according to the second transaction signature. Further, the blockchain node can count the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group according to the number of hosting devices and institutional devices that sign the escrow transaction information in the target signature device group.

[0099] Optionally, each device in the target signature device group holds a private key shard, and a private key shard is used to sign the escrow transaction information to obtain a transaction signature, that is, a signature device in the target signature device group uses the private key shard it holds to sign the escrow transaction information to obtain a transaction signature. The specific method for the blockchain node to count the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group according to the first transaction signature and the second transaction signature may include: determining the number of the first transaction signatures as the number of the first devices corresponding to the institutional devices that sign the escrow transaction information in the target signature device group. Determining the number of the second transaction signatures as the number of the second devices corresponding to the escrow devices that sign the escrow transaction information in the target signature device group. Summing the number of the first devices and the number of the second devices to obtain the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group.

[0100] Specifically, since one of the transaction signatures in the first transaction signature is obtained by an institutional device in the target signature device group signing the escrow transaction information with the first private key shard of the institution, the blockchain node can count the number of transaction signatures in the first transaction signature and determine the number of the first devices corresponding to the institutional devices that sign the escrow transaction information in the target signature device group based on the number in the first transaction signature. Similarly, since one of the transaction signatures in the second transaction signature is obtained by an escrow device in the target signature device group signing the escrow transaction information with the second private key shard of the institution, the blockchain node can count the number of transaction signatures in the second transaction signature and determine the number of the second devices corresponding to the escrow devices that sign the escrow transaction information in the target signature device group based on the number in the second transaction signature. Further, the blockchain node can sum the number of the first devices and the number of the second devices to obtain the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group.

[0101] S103. Obtain the restricted device signature number of the institution and the public key of the institution from the blockchain of the blockchain network. When the number of signature devices is greater than or equal to the restricted device signature number, verify the first transaction signature and the second transaction signature according to the escrow transaction information and the public key of the institution to obtain a verification result.

[0102] Specifically, the number of restricted device signatures of an institution can be stored on the blockchain of a blockchain network, which can ensure the storage security and access security of the number of restricted device signatures of the institution, and also facilitate the blockchain nodes in the blockchain network to quickly and conveniently obtain the number of restricted device signatures of the institution. At the same time, the public key of the institution is also stored on the blockchain, while ensuring the storage security and access security of the public key of the institution. Among them, the number of restricted device signatures of the institution can be determined based on the number of signature devices in P signature device groups of the institution. Specifically, when the total number of signature devices included in each of the P signature device groups is the same, the number of restricted device signatures of the institution can be configured according to the total number of signature devices included in the signature device group and specific requirements. For example, when the total number of signature devices included in each signature device group is 5, the number of restricted device signatures of the institution can be 1, 2, 3, 4, or 5.

[0103] Furthermore, the number of restricted device signatures of the institution can be further determined according to the institutional business requirements of the institution, the importance level of the resource hosting task, the type of the institution (such as a private enterprise or an important national institution, etc.). For example, if the institution is an important national institution, the number of restricted device signatures of the institution can be determined to be 5. Of course, the number of restricted device signatures of the institution can also be determined according to the total number of hosting devices in the signature device group and the total number of institutional devices. For example, the number of restricted device signatures of the institution is greater than the total number of hosting devices in the signature device group and the total number of institutional devices. For example, if the target signature device group includes 3 institutional devices and 2 signature devices, the number of restricted device signatures of the institution can be 4 or 5.

[0104] Of course, the total number of signature devices included in each of the P signature device groups can be the same or different. Therefore, the number of restricted device signatures of the institution can be configured according to the total number of signature devices included in each signature device group and specific requirements. For example, the P signature device groups include a first signature device group and a second signature device group. The total number of signature devices included in the first signature device group is 5, and the total number of signature devices included in the second signature device group is 3. Then, the number of restricted device signatures of the institution corresponding to each can be determined according to the total number of signature devices included in each and specific requirements. For example, the number of restricted device signatures corresponding to the first signature device group is 5, and the number of display device signatures corresponding to the second signature device group is 3. In this way, adaptively configuring the number of restricted device signatures of the institution according to each signature device group can improve the determination accuracy of the number of restricted device signatures.

[0105] Specifically, the blockchain node can compare the number of signature devices with the restricted device signature number. Only when the number of signature devices is greater than or equal to the restricted device signature number is it necessary to sign the first transaction and the second transaction. Specifically, when the number of signature devices is greater than or equal to the restricted device signature number, the blockchain node can obtain the restricted device signature number of the institution and the public key of the institution from the blockchain, and verify the signatures of the first transaction and the second transaction based on the escrow transaction information and the public key of the institution to obtain a signature verification result. Of course, when the number of signature devices is less than the restricted device signature number, the blockchain node will not execute the resource escrow task associated with the escrow transaction information. At the same time, it can also return a message indicating that the resource escrow task does not have the qualification to be executed and the resource escrow task will not be executed to the escrow devices or institutional devices in the target signature device group. In this way, by verifying the signatures of the first transaction and the second transaction through the blockchain node, the illegal tampering of the escrow transaction information can be avoided, the accuracy of the first transaction signature and the second transaction signature can be ensured, and the security of the execution of the resource escrow task can be improved.

[0106] Optionally, the specific method for the blockchain node to verify the signatures of the first transaction and the second transaction may include: when the number of signature devices is greater than or equal to the restricted device signature number, merge the first transaction signature and the second transaction signature to obtain a merged transaction signature. Decrypt the merged transaction signature based on the public key of the institution to obtain signature decryption information, and verify the signatures of the first transaction and the second transaction based on the signature decryption information and the escrow transaction information to obtain a signature verification result.

[0107] Specifically, when the number of signature devices is greater than or equal to the restricted device signature number, the blockchain node can merge the first transaction signature and the second transaction signature to obtain a merged transaction signature. Among them, the blockchain node can execute the signature merging algorithm in the distributed key generation protocol (i.e., the protocol for generating the private key shards of each signature device) to merge the first transaction signature and the second transaction signature to obtain a merged transaction signature. Further, the blockchain node can obtain the transaction signature algorithm used to sign the escrow transaction information to obtain the first transaction signature and the second transaction signature, decrypt the merged transaction signature based on the public key of the institution and this transaction signature algorithm to obtain decrypted signature information. Based on the signature decryption information and the escrow transaction information, verify the first transaction signature and the second transaction signature to obtain a signature verification result.

[0108] It can be understood that the above transaction signature algorithms may include the ECDSA signature algorithm (Elliptic Curve Digital Signature Algorithm), the BLS signature algorithm (Boneh-Lynn-Shacham Signature), and the Schnorr signature algorithm. Among them, the signature algorithm of ECDSA is an asymmetric encryption algorithm based on the mathematical theory of elliptic curves. The BLS signature algorithm is an encryption algorithm based on elliptic curves, and the length of the BLS signature algorithm is shorter (the signature is a point on the elliptic curve rather than two).

[0109] Among them, in the ECDSA and Schnorr signature algorithms, after performing a hash calculation on the message to be signed, the result (hash value) is a number. The BLS signature algorithm uses the hash value obtained based on the transaction data as the x value of a point to find the corresponding point on the elliptic curve, and further signs the found point with the private key. The BLS signature algorithm does not require a random number generator, can aggregate all the signatures in a block into one, is easy to implement multi-signature, and can also avoid redundant communication between signers. In addition, the length of the BLS signature algorithm is shorter (the signature is a point on the elliptic curve rather than two), which is half of that of Schnorr or ECDSA.

[0110] Specifically, taking the BLS signature algorithm as an example of the transaction signature algorithm, the BLS signature algorithm includes an elliptic curve and a numerical mapping function for generating private key shards. When signing the escrow transaction information, the signature device can map the escrow transaction information to a point on the elliptic curve as the signature curve point, and perform a point multiplication on the signature curve point and the private key shard of the institution to obtain the transaction signature of the escrow transaction information. When verifying the first transaction signature and the second transaction signature, the blockchain node can obtain a first value according to the signature curve point and the public key of the institution through the numerical mapping function in the BLS signature algorithm. Through the numerical mapping function, a second value is obtained according to the curve generation point and the combined transaction signature. If the first value is the same as the second value, it can be determined that the verification of the first transaction signature and the second transaction signature is successful. If the first value is different from the second value, it can be determined that the verification of the first transaction signature and the second transaction signature fails.

[0111] S104, when the verification result indicates that the verification of the first transaction signature and the second transaction signature passes, execute the resource escrow task associated with the escrow transaction information to obtain an execution result, and upload the execution result to the blockchain.

[0112] Specifically, when the signature verification result indicates that the first transaction signature and the second transaction signature pass the signature verification, the blockchain node may execute the resource escrow task associated with the escrow transaction information to obtain an execution result. For example, taking the resource escrow task as the escrow resource transfer-out task, the blockchain node may transfer the digital resources indicated by the escrow resource transfer-out task from the escrow account of the escrow device to the transfer-out account indicated by the escrow resource transfer-out task. Of course, the blockchain node may also call the escrow device in the target signature device group to execute the resource escrow task for escrow transaction information management to obtain an execution result. The blockchain node may generate a chain-upload request for the execution result and send the chain-upload request to the consensus nodes in the blockchain network.

[0113] The consensus nodes in the blockchain network may perform consensus on the execution result in the chain-upload request to detect whether the execution result is accurate, obtain a consensus result, and return the consensus result to the blockchain node. If the consensus result indicates that the consensus on the execution result is successful, a transaction block for the execution result is generated and the transaction block is uploaded to the blockchain. Among them, the execution result may include information such as escrow transaction information, the first transaction signature, the second transaction signature, and the execution status (execution success or execution failure). In this way, uploading the execution result to the blockchain and leveraging the immutability and transparency of the blockchain can ensure the authenticity and fairness of the execution of the resource escrow task and eliminate the problem of data asymmetry.

[0114] In the embodiment of the present application, an institutional device that determines the legality of the escrow transaction information regarding the institutional resource escrow task in the target signature device group signs the escrow transaction information with the first private key shard of the institution to obtain a first transaction signature. At the same time, an escrow device that determines the legality of the escrow transaction information in the target signature device group signs the escrow transaction information with the second private key shard of the institution to obtain a second transaction signature. It can be seen that by jointly performing the legality verification and signature of the escrow transaction information by the institutional device and the escrow device in the target signature device group, it is possible to avoid illegal transactions by the institution while also improving the security of the execution of the resource escrow task. At the same time, the target signature device group is a signature device group in which all the devices in the P signature device groups of the institution are in a working state. In this way, configuring multiple signature device groups for the institution can avoid the problem that the private key shards held by the signature devices in a single signature device group are abnormal, resulting in the inability to perform transaction signatures normally, and at the same time, it can avoid the situation where the signature device group in a non-working state signs the escrow transaction information, resulting in signature failure, and can improve the efficiency of signing the escrow transaction information. Further, the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group is counted. When the number of signature devices is greater than or equal to the restricted number of device signatures and the verification of the first transaction signature and the second transaction signature passes, the resource escrow task is executed, and the execution result of the resource escrow task is uploaded to the blockchain. In this way, it is possible to avoid the tampering of the escrow transaction information and improve the security of the execution of the resource escrow task.

[0115] Further, please refer to Figure 6 , Figure 6 which is a schematic flowchart of a blockchain-based data processing method provided by an embodiment of the present application. Figure 2 . As Figure 6 shown, this method can be executed by any escrow device in the escrow device 1R in Figure 2 . The blockchain-based data processing method can at least include but is not limited to the following steps:

[0116] S201, obtain the escrow transaction information regarding the institutional resource escrow task and the first transaction signature of the escrow transaction information.

[0117] Specifically, the institutional device in the target signature device group may send the escrow transaction information regarding the institutional resource escrow task and the first transaction signature of the escrow transaction information to the escrow device. The institutional device in the target signature device group is installed with an institutional resource client for obtaining the escrow transaction information regarding the institutional resource escrow task. Among them, the first transaction signature is obtained by the institutional device that determines the legality of the escrow transaction information in the target signature device group by signing the escrow transaction information with the first private key shard of the institution. The target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in working state, and P is a positive integer greater than 1. The specific contents regarding the escrow transaction information and the first transaction signature in step S201 in the embodiments of the present application may refer to the content of the above step S101, and will not be elaborated herein in the embodiments of the present application.

[0118] S202. Verify the legality of the escrow transaction information through the escrow device in the target signature device group. When it is determined that the escrow transaction information is legal, sign the escrow transaction information with the second private key shard of the institution to obtain a second transaction signature.

[0119] Specifically, the legality of the escrow transaction information can be verified through the escrow device in the target signature device group. In this way, it is possible to prevent the institution from conducting illegal transactions and harming the public interest, and at the same time, it is also possible to avoid losses to the institution caused by illegal transactions. Further, when it is determined that the escrow transaction information is legal, sign the escrow transaction information with the second private key shard of the institution to obtain a second transaction signature. Among them, both the escrow device and the institutional device in the target signature device group hold the private key shards of the institution, that is, the escrow device in the target signature device group holds the second private key shard of the institution, and the institutional device in the target signature device group holds the first private key shard of the institution for signing the escrow transaction information regarding the institution. Among them, the generation methods of the escrow device and the institutional device in the target signature device group, as well as the private key shards held by the institutional device and the escrow device in the target signature device group, may refer to the content of the above step S101, and will not be elaborated herein in the embodiments of the present application. Among them, the number of escrow devices in the target signature device group may be one or more.

[0120] Optionally, when the number of managed devices in the target signature device group can be one, the managed device in the target signature device group is the device for obtaining the managed transaction information and the first transaction signature of the managed transaction information. The managed transaction information includes the institutional account information of the institution and the transaction parameter information. Taking the resource escrow task as the escrow resource transfer task as an example, the transaction parameter information may include the amount of escrow resources to be transferred, the type of escrow resources, the transfer account address, etc. The blockchain node verifies the legality of the managed transaction information through the managed device in the target signature device group. When it is determined that the managed transaction information is legal, the specific method of signing the managed transaction information with the second private key shard of the institution may include: The managed device in the target signature device group performs a legality check on the institutional account of the institution according to the institutional account information to obtain an account check result. If the account check result indicates that the institutional account of the institution is legal, a transaction check model is called to check the legality of the transaction parameter information to obtain a transaction check result. If the transaction check result indicates that the transaction parameter information is legal, it is determined that the managed transaction information is legal, and the managed transaction information is signed with the second private key shard of the institution to obtain a second transaction signature.

[0121] Specifically, the managed device in the target signature device group can perform a legality check on the institutional account of the institution according to the institutional account information, that is, check whether the institutional account of the institution is an illegal account to obtain an account check result. If the institutional account of the institution is not legal (i.e., an illegal account), the institution may perform illegal transactions (such as illegal fundraising, illegal asset transfer, etc.), harming the public interest. If the account check result indicates that the institutional account of the institution is not legal, it is determined that the managed transaction information is not legal, and the resource escrow task associated with the managed transaction information is not executed. In this way, illegal transactions by the institution can be avoided.

[0122] If the account check result indicates that the institutional account of the institution is legal, the managed device in the target signature device group can call a transaction check model to check the legality of the transaction parameter information to obtain a transaction check result. This transaction check model is used to check the legality of the transaction parameter information, which can improve the accuracy and efficiency of the legality check of the transaction parameter information. Among them, this transaction check model can be trained based on the sample transaction parameter information and the legality label on the blockchain until the convergence condition is reached, and the model performance is relatively high.

[0123] Further, if the transaction verification result indicates that the transaction parameter information is legal, it is determined that the escrow transaction information is legal, and the escrow devices in the target signature device group use the second private key shard of the institution to sign the escrow transaction information to obtain a second transaction signature. The transaction signature algorithm for signing the escrow transaction information with the second private key shard of the institution may include, but is not limited to, the ECDSA signature algorithm (Elliptic Curve Digital Signature Algorithm), the BLS signature algorithm (Boneh-Lynn-Shacham Signature), and the Schnorr signature algorithm.

[0124] Optionally, the specific method for verifying the legality of the institutional account of the institution may include: Method 1: The escrow devices in the target signature device group may obtain the account transaction data of the institutional account within a historical time period, input the account transaction data into the legality verification model, and the legality verification model verifies the legality of the institutional account based on the account transaction data. Method 2: The escrow devices in the target signature device group may obtain a list of illegal accounts from the blockchain. The list of illegal accounts includes illegal account information that is not legal, and the legality of the institutional account is verified through the list of illegal accounts.

[0125] Optionally, in the above Method 2, the specific method for the escrow devices in the target signature device group to verify the legality of the institutional account of the institution according to the institutional account information may include: Obtain a list of illegal accounts from the blockchain of the blockchain network. The list of illegal accounts includes illegal account information that is not legal, and store the illegal account information on the blockchain. In this way, it is possible to prevent the list of illegal accounts from being tampered with, improve the security and accuracy of the list of illegal accounts, and at the same time facilitate the escrow devices to obtain the list of illegal accounts. The escrow devices in the target signature device group may obtain a list of illegal accounts from the blockchain, compare the institutional account information with the illegal account information in the list of illegal accounts to obtain an account comparison result. If the account comparison result indicates that there is no illegal account information in the list of illegal accounts that matches the institutional account information, it is determined that the institutional account of the institution is legal and an account verification result is generated to indicate that the institutional account of the institution is legal.

[0126] Optionally, when the number of managed devices in the target signature device group is multiple, the managed devices in the target signature group include the target managed device, and the target managed device is the device that obtains the managed transaction information of the institution and the first transaction signature of the managed transaction information. The target managed device verifies the legality of the managed transaction information through the managed devices in the target signature device group. When it is determined that the managed transaction information is legal, the specific method of signing the managed transaction information with the second private key shard of the institution to obtain the second transaction signature may further include: the target managed device sends the managed transaction information to the remaining managed devices; the remaining managed devices are used to sign the managed transaction information with the second private key shard of the institution to obtain the second transaction signature when it is determined that the managed transaction information is legal, and send the second transaction signature to the blockchain node; the remaining managed devices are the managed devices other than the target managed device in the target signature device group. Verify the legality of the managed transaction information. When it is determined that the managed transaction information is legal, sign the managed transaction information with the second private key shard of the institution to obtain the second transaction signature.

[0127] Specifically, after receiving the managed transaction information, the target managed device can send the managed transaction information to the remaining managed devices, and the remaining managed devices can verify the legality of the managed transaction information. The remaining managed devices are the managed devices other than the target managed device in the target signature device group. When the remaining managed devices determine that the managed transaction information is legal, they sign the managed transaction information with the second private key shard of the institution to obtain the second transaction signature and send the second transaction signature to the blockchain node. It can be seen that by verifying the legality of the managed transaction information through multiple managed devices, the accuracy of the legality verification of the managed transaction information can be ensured, and the situation of a single managed device acting maliciously, such as determining illegal managed transaction information as legal managed transaction information, can be avoided. Among them, the specific content of the remaining managed devices verifying the legality of the managed transaction information can refer to the verification content of the managed transaction information when there is one managed device in the target signature device group described above. This application embodiment will not elaborate here.

[0128] At the same time, the target managed device can also verify the legality of the managed transaction information. Similarly, the specific method of the managed device verifying the legality of the managed transaction information can refer to the verification content of the managed transaction information when there is one managed device in the target signature device group described above. This application embodiment will not elaborate here. When it is determined that the managed transaction information is legal, sign the managed transaction information with the second private key shard of the institution to obtain the second transaction signature.

[0129] Optionally, if the managed device in the target signature device group determines that the managed transaction information is not legal, a transaction illegal indication information about the managed transaction information is generated, and the transaction illegal indication information is sent to the institutional device in the target signature device group. The transaction illegal indication information is used to indicate that the managed transaction information is not legal. The managed device in the target signature device group determines the managed transaction information as illegal managed transaction information and reports the illegal managed transaction information to the blockchain node. In this way, by verifying the legality of the managed transaction information of the institution by the managed device, illegal transactions by the institution can be avoided and the security of transactions can be improved.

[0130] Optionally, if the second private key shard of the institution is not obtained by the managed device in the target signature device group, it indicates that the managed device in the target signature device group may have lost the second private key shard of the institution, or the second private key shard has an abnormality (such as being different from the original state, such as the second private key shard becoming garbled), then a re-signature request can be generated. Further, the managed device in the target signature device group can send the re-signature request to the institutional device in the backup signature device group. Specifically, the backup signature device group belongs to one of the P signature device groups of the institution, and the institutional device in the backup signature device group is used to sign the managed transaction information with the third private key shard of the institution to obtain a third transaction signature, and send the third transaction signature and the managed transaction information to the managed device in the backup signature device group.

[0131] The backup signature device group is different from the target signature device group. It can be understood that the private key shards of the institution held by the managed device and the institutional device in the backup signature device group are different from the private key shards of the institution held by the managed device and the institutional device in the target signature device group respectively. Among them, the backup signature device group can be the signature device group in which the devices in the P signature device groups of the institution are in a working state. In this way, the efficiency of transaction signing can be improved, and the problem that transaction signing cannot be performed due to an abnormal state of the signature device can be avoided. The device being in a working state can refer to the network state of the device being in a normal state (such as the network connection state), or the shard holding state of the private key shard of the institution being in a normal state. Among them, the backup signature device group can be the managed device of the target signature device group screened from the P signature device groups.

[0132] S203, send the managed transaction information, the first transaction signature, and the second transaction signature to the blockchain node in the blockchain network.

[0133] Specifically, the managed devices in the target signature device group can send the managed transaction information, the first transaction signature, and the second transaction signature to the blockchain nodes in the blockchain network. The blockchain nodes are used to execute the resource escrow task associated with the managed transaction information and obtain an execution result when the number of signature devices corresponding to the devices for signing the managed transaction information in the target signature device group is greater than or equal to the restricted device signature number, and the first transaction signature and the second transaction signature pass the signature verification, and then upload the execution result to the blockchain. For the specific execution content of the blockchain nodes, reference can be made to the specific content of the above steps S102 - S104, which will not be elaborated in this embodiment of the present application. It can be seen that in this embodiment of the present application, the managed devices in the target signature device group are used to verify the legality of the institution's managed transaction information, which can prevent the institution from executing illegal transactions.

[0134] In the embodiment of the present application, the institution devices that determine the legality of the managed transaction information regarding the resource escrow task in the target signature device group use the first private key shard of the institution to sign the managed transaction information to obtain the first transaction signature. At the same time, the managed devices in the target signature device group verify the legality of the managed transaction information. Only when it is determined that the managed transaction information is legal, the second private key shard of the institution is used to sign the managed transaction information to obtain the second transaction signature. It can be seen that by jointly verifying the legality and signing the managed transaction information by the institution devices and the managed devices in the target signature device group, it is possible to prevent the institution from conducting illegal transactions and improve the security of the execution of the resource escrow task. At the same time, the target signature device group is the signature device group in which all the devices in the P signature device groups of the institution are in the working state. In this way, configuring multiple signature device groups for the institution can prevent the problem that the private key shards held by the signature devices in a single signature device group are abnormal, resulting in the inability to sign transactions normally, and at the same time can prevent the signature device group in the non - working state from signing the managed transaction information, resulting in signature failure, and can improve the efficiency of signing the managed transaction information. Further, the number of signature devices corresponding to the devices that sign the managed transaction information in the target signature device group is counted. When the number of signature devices is greater than or equal to the restricted device signature number, and the first transaction signature and the second transaction signature pass the signature verification, the resource escrow task is executed, and the execution result of the resource escrow task is uploaded to the blockchain. In this way, it is possible to prevent the managed transaction information from being tampered with and improve the security of the execution of the resource escrow task.

[0135] Further, please refer to Figure 7 , Figure 7 is a schematic flowchart of a data processing method based on blockchain provided by an embodiment of the present application Figure 2 As Figure 7 shown, this method can be performed byFigure 2 It is executed by any terminal device in the terminal device cluster 1Y in

[0136] S301, Obtain the escrow transaction information of the resource escrow task of the institution, and the P signature device groups of the institution.

[0137] Specifically, when the administrator or operator of the institution needs to execute the resource escrow task of the institution, the resource escrow task of the institution can be triggered through the terminal device. The terminal device can be a terminal device installed with the institution resource client, and can also be called an institution device. The terminal device can respond to the trigger operation for the resource escrow task of the institution and obtain the escrow transaction information of the resource escrow task of the institution. The escrow transaction information can be generated by the terminal device or input by the administrator or operator of the institution. Among them, the resource escrow task and the escrow transaction information can refer to the specific description in step S101 above, and will not be elaborated in this embodiment of the present application.

[0138] At the same time, the terminal device can obtain the P signature device groups of the institution. The terminal device can input the institution device in any one of the P signature device groups. P is a positive integer greater than 1. Similarly, the P signature device groups can refer to the specific description in step S101 above, and will not be elaborated in this embodiment of the present application.

[0139] S302, Determine the signature device group in which the devices are in the working state from the P signature device groups as the target signature device group.

[0140] Specifically, the terminal device can determine the signature device group in which the devices are in the working state from the P signature device groups as the target signature device group. In this way, the signature efficiency of the escrow transaction information can be ensured, and the situation of signature failure caused by the signature device group in the non-working state signing the escrow transaction information can be avoided.

[0141] Optionally, the specific method for the terminal device to determine the signature device group in which the devices are in the working state from the P signature device groups may include: determining the signature device group with the highest signature priority from the P signature device groups as the initial signature device group. Detect the device status of the institution devices included in the initial signature device group to obtain a status detection result. If the status detection result indicates that the devices in the initial signature device group are in the working state, determine the initial signature device group as the target signature device group.

[0142] Specifically, each of the P signature device groups has a corresponding signature priority. For example, the P signature device groups include a first signature device group and a second signature device group, and the signature priority of the first signature device group is higher than that of the second signature device group. In this way, when determining the target signature device group from the first signature device group and the second signature device group, if the devices in the first signature device group are in the working state, the first signature device group can be determined as the target signature device group. The terminal device can determine the signature device group with the highest signature priority from the P signature device groups as the initial signature device group, and detect the device status of the institutional devices included in the initial signature device group to obtain a status detection result. If the status detection result indicates that the devices in the initial signature device group are in the working state, the initial signature device group is determined as the target signature device group. In this way, it is possible to avoid the problem of signature failure of the escrow transaction information when determining the target signature device group with the devices in the non-working state, and improve the signature efficiency of the escrow transaction information.

[0143] Optionally, the device status includes the device network status and the shard holding status of the first private key shard of the institution. The specific manner in which the terminal device detects the device status of the institutional devices included in the initial signature device group to obtain a status detection result may include: obtaining the device network status and the shard holding status of the institutional devices included in the initial signature device group. If the device network status and the shard holding status of the institutional devices included in the initial signature device group are both in the normal state, it is determined that the devices in the initial signature device group are in the normal working state. Generate a status detection result for indicating that the devices in the initial signature device group are in the normal working state.

[0144] Specifically, the terminal device can obtain the device network status and the shard holding status of the institutional devices included in the initial signature device group. If the device network status and the shard holding status of the institutional devices included in the initial signature device group are both in the normal state, it is determined that the devices in the initial signature device group are in the normal working state, and a status detection result for indicating that the devices in the initial signature device group are in the normal working state is generated. Among them, the device network status being in the normal state may mean that the institutional device has a network connection status and can perform data interaction with other devices, such as data interaction with the escrow device or the blockchain node. The shard holding status being in the normal state may mean that the institutional device holds the first private key shard of the institution, and there is no loss or abnormal private key shard situation, etc.

[0145] S303, sign the escrow transaction information with the first private key shard of the institution by the institutional devices in the target signature device group to obtain a first transaction signature.

[0146] Specifically, through the institutional devices in the target signature device group, the first private key shard of the institution is used to sign the escrow transaction information, obtaining a first transaction signature. The generation process of the first private key shard of the institution held by the institutional device can refer to the content of step S101 above, which will not be elaborated in this embodiment of the present application.

[0147] Among them, the number of institutional devices in the target signature device group can be one or more. When the number of institutional devices in the target signature device group is one, the terminal device can be the institutional device in the target signature device group, that is, the device for obtaining the escrow transaction information of the resource escrow task of the institution. The institutional devices in the target signature device group can sign the escrow transaction information based on the first private key shard of the institution they hold, obtaining a first transaction signature. When the number of institutional devices in the target signature device group is one, the target signature device group includes the target institutional device. At this time, the target institutional device is the terminal device, that is, the device for obtaining the escrow transaction information of the resource escrow task of the institution.

[0148] When the target institutional device is the device for obtaining the escrow transaction information of the resource escrow task of the institution, the target institutional device can send the escrow transaction information to the remaining institutional devices. The remaining institutional devices are the institutional devices in the target signature device group other than the target institutional device. The remaining institutional devices can use the first private key shard of the institution to sign the escrow transaction information, obtaining a first transaction signature. Among them, the remaining institutional devices can send the first transaction signature they signed to the escrow device in the target signature device group, or can send the first transaction signature they signed to the target institutional device. At the same time, the target institutional device can also use the second private key shard it holds to sign the escrow transaction information, obtaining a first transaction signature.

[0149] S304. Send the escrow transaction information and the first transaction signature to the escrow device in the target signature device group.

[0150] Specifically, the terminal device can send the escrow transaction information and the first transaction signature to the escrow device in the target signature device group. The escrow device in the target signature device group is used to, when determining that the escrow transaction information is legal, sign the escrow transaction information using the second private key shard of the institution, obtaining a second signature information, and send the first signature information, the second signature information, and the escrow transaction information to the blockchain node in the blockchain network. The specific execution process of the escrow device in the target signature device group can refer to the content of step S201 - step S203 above, which will not be elaborated in this embodiment of the present application.

[0151] In the embodiment of the present application, the institutional device in the target signature device group determines the signature device group in which the devices are in the working state from the P signature device groups of the institution as the target signature device group. In this way, configuring multiple signature device groups for the institution can avoid the problem that the private key shards held by the signature devices in a single signature device group are abnormal, resulting in the inability to normally perform transaction signatures. At the same time, it can avoid the situation where the signature device group in the non-working state signs the escrow transaction information, resulting in signature failure, and can improve the efficiency of signing the escrow transaction information. At the same time, the first private key shard of the institution is used to sign the escrow transaction information to obtain the first transaction signature. The escrow device that determines the legality of the escrow transaction information in the target signature device group uses the second private key shard of the institution to sign the escrow transaction information to obtain the second transaction signature. It can be seen that the institutional device and the escrow device in the target signature device group jointly perform the legality verification and signature of the escrow transaction information, which can avoid illegal transactions by the institution and improve the security of the execution of the resource escrow task. At the same time, the target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in the working state. Further, the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group is counted. When the number of signature devices is greater than or equal to the restricted number of device signatures and the first transaction signature and the second transaction signature pass the signature verification, the resource escrow task is executed, and the execution result of the resource escrow task is uploaded to the blockchain. In this way, it can avoid the tampering of the escrow transaction information and improve the security of the execution of the resource escrow task.

[0152] Further, please refer to Figure 8 , Figure 8 which is a schematic structural diagram of a blockchain-based data processing device 1 provided by an embodiment of the present application. The blockchain-based data processing device 1 can be a computer program (including program code) running in a computer device. For example, the blockchain-based data processing device 1 is an application software; the blockchain-based data processing device 1 can be used to execute the corresponding steps in the method provided by the embodiment of the present application. As Figure 8 shown, the blockchain-based data processing device 1 can be any blockchain node in the blockchain network. The blockchain-based data processing device 1 can include: a first acquisition module 11, a statistics module 12, a signature verification module 13, and an upload module 14.

[0153] The first acquisition module 11 is configured to acquire escrow transaction information about the resource escrow task of the institution, as well as the first transaction signature and the second transaction signature of the escrow transaction information; the first transaction signature is obtained by an institution device in the target signature device group that determines the legality of the escrow transaction information, using the first private key shard of the institution to sign the escrow transaction information, and the second transaction signature is obtained by a escrow device in the target signature device group that determines the legality of the escrow transaction information, using the second private key shard of the institution to sign the escrow transaction information. The target signature device group is a signature device group in which all devices in the P signature device groups of the institution are in a working state; P is a positive integer greater than 1.

[0154] The statistics module 12 is configured to count the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group according to the first transaction signature and the second transaction signature.

[0155] The signature verification module 13 is configured to obtain the restricted device signature quantity of the institution and the public key of the institution from the blockchain of the blockchain network. When the number of signature devices is greater than or equal to the restricted device signature quantity, it verifies the first transaction signature and the second transaction signature according to the escrow transaction information and the public key of the institution to obtain a signature verification result.

[0156] The blockchain uploading module 14 is configured to, when the verification result indicates that the first transaction signature and the second transaction signature pass the signature verification, execute the resource escrow task associated with the escrow transaction information to obtain an execution result, and upload the execution result to the blockchain.

[0157] Wherein, each device in the target signature device group holds a private key shard, and one private key shard is used to sign the escrow transaction information to obtain a transaction signature.

[0158] The statistics module 12 includes:

[0159] The first determination unit 1201 is configured to determine the number of the first device corresponding to the institution device that signs the escrow transaction information in the target signature device group according to the number of the first transaction signatures.

[0160] The second determination unit 1202 is configured to determine the number of the second device corresponding to the escrow device that signs the escrow transaction information in the target signature device group according to the number of the second transaction signatures.

[0161] The summation unit 1203 is configured to sum the number of the first device and the number of the second device to obtain the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group.

[0162] Among them, the signature verification module 13 includes:

[0163] A merging unit 1301, configured to merge the first transaction signature and the second transaction signature to obtain a merged transaction signature when the number of the signature devices is greater than or equal to the restricted device signature number;

[0164] A decryption unit 1302, configured to decrypt the merged transaction signature according to the public key of the institution to obtain signature decryption information;

[0165] A signature verification unit 1303, configured to verify the first transaction signature and the second transaction signature according to the signature decryption information and the escrow transaction information to obtain a signature verification result.

[0166] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit including the function of the module or unit. According to an embodiment of the present application, Figure 8 Each module in the blockchain-based data processing device 1 shown can be separately or entirely combined into one or several units to form, or a certain one (or some) of the units can be further split into at least two smaller sub-units in terms of function, and the same operations can be achieved without affecting the realization of the technical effects of the embodiments of the present application. The above modules are divided based on logical functions. In practical applications, the function of one module can also be implemented by at least two units, or the functions of at least two modules can be implemented by one unit. In other embodiments of the present application, the blockchain-based data processing device 1 can also include other units. In practical applications, these functions can also be assisted by other units and can be achieved by the cooperation of at least two units.

[0167] According to an embodiment of the present application, it can be achieved by running a computer program (including program code) capable of executing the respective steps involved in the corresponding method shown in Figure 4 on a general computer device such as a computer including processing elements and storage elements such as a central processing unit (CPU), a random access storage medium (RAM), and a read-only storage medium (ROM), to construct as shown in Figure 8The data processing device 1 based on blockchain shown in the figure, and the data processing method based on blockchain for implementing the embodiments of the present application. The above computer program can be recorded on a computer-readable recording medium, for example, and loaded into the above computer device through the computer-readable recording medium and run therein.

[0168] In the embodiments of the present application, an institutional device that determines the legality of the escrow transaction information regarding the resource escrow task of the institution in the target signature device group signs the escrow transaction information with the first private key shard of the institution to obtain the first transaction signature. At the same time, an escrow device that determines the legality of the escrow transaction information in the target signature device group signs the escrow transaction information with the second private key shard of the institution to obtain the second transaction signature. It can be seen that by jointly performing the legality verification and signature of the escrow transaction information by the institutional device and the escrow device in the target signature device group, it is possible to avoid illegal transactions by the institution while also improving the security of the execution of the resource escrow task. At the same time, the target signature device group is a signature device group in which all the devices in the P signature device groups of the institution are in a working state. In this way, configuring multiple signature device groups for the institution can avoid the problem that the private key shards held by the signature devices in a single signature device group are abnormal, resulting in the inability to sign transactions normally. At the same time, it can avoid the situation where the signature device group in a non-working state signs the escrow transaction information, resulting in signature failure, and can improve the signature efficiency of the escrow transaction information. Further, the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group is counted. When the number of signature devices is greater than or equal to the restricted number of device signatures and the verification of the first transaction signature and the second transaction signature passes, the resource escrow task is executed, and the execution result of the resource escrow task is uploaded to the blockchain. In this way, it is possible to avoid the tampering of the escrow transaction information and improve the security of the execution of the resource escrow task.

[0169] Further, please refer to Figure 9 , Figure 9 is a schematic structural diagram of a data processing device 2 based on blockchain provided by the embodiments of the present application. The data processing device 2 based on blockchain can be a computer program (including program code) running in a computer device. For example, the data processing device 2 based on blockchain is an application software; the data processing device 2 based on blockchain can be used to execute the corresponding steps in the method provided by the embodiments of the present application. As Figure 9 shown, the data processing device 2 based on blockchain can be any blockchain node in the blockchain network. The data processing device 2 based on blockchain can include: a second acquisition module 21, a first signature module 22, a first sending module 23, a second sending module 24, a reporting module 25, a generation module 26, and a third sending module 27.

[0170] A second acquisition module 21, configured to acquire escrow transaction information about the resource escrow task of the institution, and a first transaction signature of the escrow transaction information; the first transaction signature is obtained by an institution device in a target signature device group that determines the legality of the escrow transaction information signing the escrow transaction information with a first private key shard of the institution, and the target signature device group is a signature device group in which all devices in P signature device groups of the institution are in a working state; P is a positive integer greater than 1;

[0171] A first signature module 22, configured to verify the legality of the escrow transaction information through an escrow device in the target signature device group, and when it is determined that the escrow transaction information is legal, sign the escrow transaction information with a second private key shard of the institution to obtain a second transaction signature;

[0172] A first sending module 23, configured to send the escrow transaction information, the first transaction signature, and the second transaction signature to a blockchain node in the blockchain network; the blockchain node is configured to execute the resource escrow task associated with the escrow transaction information to obtain an execution result when the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group is greater than or equal to a restricted device signature number, and the first transaction signature and the second transaction signature pass the signature verification, and upload the execution result to the blockchain.

[0173] Wherein, the number of escrow devices in the target signature device group is one, and the escrow device in the target signature device group is the device that acquires the escrow transaction information and the first transaction signature; the escrow transaction information includes the institution account information and transaction parameter information of the institution;

[0174] The first signature module 22 includes:

[0175] A first verification unit 2201, configured to verify the legality of the institution account of the institution by the escrow device in the target signature device group according to the institution account information to obtain an account verification result;

[0176] A second verification unit 2202, configured to, if the account verification result indicates that the institution account of the institution is legal, call a transaction verification model to verify the legality of the transaction parameter information to obtain a transaction verification result;

[0177] A first signature unit 2203, configured to, if the transaction verification result indicates that the transaction parameter information is legal, determine that the escrow transaction information is legal, and sign the escrow transaction information with a second private key shard of the institution to obtain a second transaction signature.

[0178] Among them, the first verification unit 2201 is specifically configured to:

[0179] The managed devices in the target signature device group obtain the list of illegal accounts from the blockchain of the blockchain network; the list of illegal accounts includes illegal account information that is not legitimate;

[0180] Compare the institutional account information with the illegal account information in the list of illegal accounts to obtain an account comparison result;

[0181] If the account comparison result indicates that there is no illegal account information in the list of illegal accounts that matches the institutional account information, it is determined that the institutional account of the institution is legitimate;

[0182] Generate an account verification result for indicating that the institutional account of the institution is legitimate.

[0183] Among them, the number of managed devices in the target signature device group is multiple, and the managed devices in the target signature group include target managed devices, and the target managed device is the device that obtains the managed transaction information and the first transaction signature;

[0184] The first signature module 22 further includes:

[0185] A sending unit 2204, configured to enable the target managed device to send the managed transaction information to the remaining managed devices; the remaining managed devices are configured to, when determining that the managed transaction information is legitimate, sign the managed transaction information using the second private key shard of the institution to obtain a second transaction signature, and send the second transaction signature to the blockchain node; the remaining managed devices are the managed devices other than the target managed device in the target signature device group;

[0186] A second signature unit 2205, configured to verify the legitimacy of the managed transaction information, and when determining that the managed transaction information is legitimate, sign the managed transaction information using the second private key shard of the institution to obtain a second transaction signature.

[0187] Among them, the data processing device two based on the blockchain further includes:

[0188] A second sending module 24, configured to, if the managed transaction information is not legitimate, generate transaction illegal indication information about the managed transaction information, and send the transaction illegal indication information to the institutional device in the target signature device group; the transaction illegal indication information is used to indicate that the managed transaction information is not legitimate;

[0189] A reporting module 25 is configured to determine the escrow transaction information as illegal escrow transaction information and report the illegal escrow transaction information to the blockchain node.

[0190] Among them, the blockchain-based data processing device two further includes:

[0191] A generation module 26 is configured to generate a re-signature request if the second private key shard of the institution cannot be obtained through the escrow device in the target signature device group;

[0192] A third sending module 27 is configured to send the re-signature request to the institution device in the backup signature device group; the backup signature device group belongs to one of the P signature device groups of the institution, and the institution device in the backup signature device group is configured to sign the escrow transaction information with the third private key shard of the institution to obtain a third transaction signature, and send the third transaction signature and the escrow transaction information to the escrow device in the backup signature device group; the backup signature device group is different from the target signature device group.

[0193] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit that includes the function of the module or unit. According to an embodiment of the present application, Figure 9 Each module in the blockchain-based data processing device two shown can be separately or entirely combined into one or several units to form, or a certain (some) unit can be further split into at least two smaller functional sub-units, and the same operation can be achieved without affecting the realization of the technical effects of the embodiments of the present application. The above modules are divided based on logical functions. In actual applications, the function of one module can also be implemented by at least two units, or the functions of at least two modules can be implemented by one unit. In other embodiments of the present application, the blockchain-based data processing device two can also include other units. In actual applications, these functions can also be assisted by other units and can be achieved by the cooperation of at least two units.

[0194] According to an embodiment of the present application, it can be achieved by running on a general computer device such as a computer including processing elements and storage elements such as a central processing unit (CPU), a random access storage medium (RAM), and a read-only storage medium (ROM) that can execute as Figure 6A computer program (including program code) for each step involved in the corresponding method shown in the text is used to construct a blockchain-based data processing device II as shown in Figure 9 and to implement the blockchain-based data processing method of the embodiments of the present application. The above computer program can be recorded on, for example, a computer-readable recording medium, loaded into the above computer device through the computer-readable recording medium, and run therein.

[0195] In the embodiments of the present application, an institutional device that determines the legality of the escrow transaction information regarding the resource escrow task of the institution in the target signature device group uses the first private key shard of the institution to sign the escrow transaction information to obtain a first transaction signature. At the same time, the escrow device in the target signature device group verifies the legality of the escrow transaction information. Only when it is determined that the escrow transaction information is legal, the second private key shard of the institution is used to sign the escrow transaction information to obtain a second transaction signature. It can be seen that by jointly verifying the legality and signing the escrow transaction information by the institutional device and the escrow device in the target signature device group, it is possible to avoid illegal transactions by the institution and improve the security of the execution of the resource escrow task. At the same time, the target signature device group is a signature device group in which all the devices in the P signature device groups of the institution are in a working state. In this way, configuring multiple signature device groups for the institution can avoid the problem that the private key shards held by the signature devices in a single signature device group are abnormal, resulting in the inability to sign transactions normally, and at the same time can avoid the situation where the signature device group in a non-working state signs the escrow transaction information, resulting in signature failure, and can improve the signature efficiency of the escrow transaction information. Further, the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group is counted. When the number of signature devices is greater than or equal to the restricted number of device signatures and the verification of the first transaction signature and the second transaction signature passes, the resource escrow task is executed, and the execution result of the resource escrow task is uploaded to the blockchain. In this way, it is possible to avoid the tampering of the escrow transaction information and improve the security of the execution of the resource escrow task.

[0196] Further, please refer to Figure 10 , Figure 10 is a schematic structural diagram of a blockchain-based data processing device III provided by the embodiments of the present application. The blockchain-based data processing device III can be a computer program (including program code) running in a computer device. For example, the blockchain-based data processing device III is an application software; the blockchain-based data processing device III can be used to execute the corresponding steps in the method provided by the embodiments of the present application. As Figure 10As shown, the third blockchain-based data processing device can be any blockchain node in the blockchain network. The third blockchain-based data processing device may include: a third acquisition module 31, a determination module 32, a second signature module 33, and a fourth sending module 34.

[0197] The third acquisition module 31 is configured to acquire escrow transaction information about the resource escrow task of the institution, and P signature device groups of the institution; P is a positive integer greater than 1;

[0198] The determination module 32 is configured to determine, from the P signature device groups, the signature device group in which the devices are in a working state as the target signature device group;

[0199] The second signature module 33 is configured to sign the escrow transaction information by using the first private key shard of the institution through the institution devices in the target signature device group to obtain a first transaction signature;

[0200] The fourth sending module 34 is configured to send the escrow transaction information and the first transaction signature to the escrow devices in the target signature device group; the escrow devices in the target signature device group are configured to, when determining that the escrow transaction information is legal, sign the escrow transaction information by using the second private key shard of the institution to obtain a second signature information, and send the first signature information, the second signature information, and the escrow transaction information to the blockchain nodes in the blockchain network.

[0201] Wherein, the determination module 32 includes:

[0202] A second determination unit 3201 is configured to determine, from the P signature device groups, the signature device group with the highest signature priority as the initial signature device group;

[0203] A detection unit 3202 is configured to detect the device status of the institution devices included in the initial signature device group to obtain a status detection result;

[0204] A third determination unit 3203 is configured to, if the status detection result indicates that the devices in the initial signature device group are in a working state, determine the initial signature device group as the target signature device group.

[0205] Wherein, the device status includes the device network status and the shard holding status of the first private key shard of the institution;

[0206] The detection unit 3202 is specifically configured to:

[0207] Acquire the device network status and the shard holding status of the institution devices included in the initial signature device group;

[0208] If the device network status and shard holding status of the institutional devices included in the initial signature device group are both in normal status, it is determined that the devices in the initial signature device group are in normal working status;

[0209] Generate a status detection result for indicating that the devices in the initial signature device group are in normal working status.

[0210] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other relevant parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the function of the module or unit. According to an embodiment of the present application, Figure 10 Each module in the blockchain-based data processing device three shown can be separately or entirely combined into one or several units to form, or a certain one (or some) of the units can be further split into at least two smaller functional subunits, and the same operations can be achieved without affecting the realization of the technical effects of the embodiments of the present application. The above modules are divided based on logical functions. In practical applications, the function of one module can also be implemented by at least two units, or the functions of at least two modules can be implemented by one unit. In other embodiments of the present application, the blockchain-based data processing device three can also include other units. In practical applications, these functions can also be assisted by other units and can be cooperatively implemented by at least two units.

[0211] According to an embodiment of the present application, it can be achieved by running a computer program (including program code) capable of executing the respective steps involved in the corresponding method shown in Figure 7 on a general computer device such as a computer including processing elements and storage elements such as a central processing unit (CPU), a random access storage medium (RAM), and a read-only storage medium (ROM), to construct the blockchain-based data processing device three shown in Figure 10 and to implement the blockchain-based data processing method of the embodiments of the present application. The above computer program can be recorded on, for example, a computer-readable recording medium, loaded into the above computer device through the computer-readable recording medium, and run therein.

[0212] In the embodiment of the present application, the institutional device in the target signature device group determines the signature device group in which the devices are in the working state from the P signature device groups of the institution as the target signature device group. In this way, configuring multiple signature device groups for the institution can avoid the problem that the private key shards held by the signature devices in a single signature device group are abnormal, resulting in the inability to sign transactions normally. At the same time, it can avoid the situation where the signature device group in the non-working state signs the escrow transaction information, resulting in signature failure, and can improve the efficiency of signing the escrow transaction information. At the same time, the first private key shard of the institution is used to sign the escrow transaction information to obtain the first transaction signature. The escrow device that determines the legality of the escrow transaction information in the target signature device group uses the second private key shard of the institution to sign the escrow transaction information to obtain the second transaction signature. It can be seen that by jointly verifying the legality and signing the escrow transaction information by the institutional device and the escrow device in the target signature device group, it is possible to avoid illegal transactions by the institution and improve the security of the execution of the resource escrow task. At the same time, the target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in the working state. Further, the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group is counted. When the number of signature devices is greater than or equal to the restricted number of device signatures and the first transaction signature and the second transaction signature pass the signature verification, the resource escrow task is executed, and the execution result of the resource escrow task is uploaded to the blockchain. In this way, it is possible to avoid the tampering of the escrow transaction information and improve the security of the execution of the resource escrow task.

[0213] Further, please refer to Figure 11 , Figure 11 which is a schematic diagram of a computer device provided by an embodiment of the present application. As Figure 8 shown, the computer device 3000 can be the terminal device, the escrow device, or the blockchain node corresponding to the above Figure 2 embodiment. The computer device 3000 may include: at least one processor 3001, such as a CPU, at least one network interface 3004, a user interface 3003, a memory 3005, and at least one communication bus 3002. Among them, the communication bus 3002 is used to realize the connection and communication between these components. Among them, the user interface 3003 may include a display screen (Display) and a keyboard (Keyboard). The network interface 3004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 3005 may be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The storage 3005 may optionally also be at least one storage device located far from the aforementioned processor 3001. As Figure 11As shown in the figure, the memory 3005, which is a computer storage medium, may include an operating system, a network communication module, a user interface module, and a computer program control application.

[0214] In Figure 11 In the computer device 3000 shown in the figure, the network interface 3004 is mainly used for the second node device to communicate with the target relay server and the target oracle server; the user interface 3003 is mainly used to provide an interface for users to input; and the processor 3001 can be used to call the computer program control application stored in the memory 3005 to implement:

[0215] Obtain the escrow transaction information of the resource escrow task regarding the institution, as well as the first transaction signature and the second transaction signature of the escrow transaction information; the first transaction signature is obtained by an institution device in the target signature device group that determines the legality of the escrow transaction information using the first private key shard of the institution to sign the escrow transaction information, and the second transaction signature is obtained by an escrow device in the target signature device group that determines the legality of the escrow transaction information using the second private key shard of the institution to sign the escrow transaction information. The target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in working state; P is a positive integer greater than 1;

[0216] According to the first transaction signature and the second transaction signature, count the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group;

[0217] Obtain the restricted device signature number of the institution and the public key of the institution from the blockchain of the blockchain network. When the number of signature devices is greater than or equal to the restricted device signature number, verify the first transaction signature and the second transaction signature according to the escrow transaction information and the public key of the institution to obtain a verification result;

[0218] When the verification result indicates that the first transaction signature and the second transaction signature pass the verification, execute the resource escrow task associated with the escrow transaction information to obtain an execution result, and upload the execution result to the blockchain.

[0219] It should be understood that the computer device 3000 described in the embodiments of the present application can also execute the descriptions of the data processing method based on the blockchain in the foregoing Figure 6 Or Figure 7 In the corresponding embodiments respectively. The computer device 3000 described in the embodiments of the present application can also execute the foregoing Figure 8 、 Figure 9 And Figure 10This respectively corresponds to the description of the blockchain-based data processing device in the embodiments, which will not be elaborated here. Additionally, the description of the beneficial effects of adopting the same method will not be elaborated either.

[0220] Furthermore, it should be noted here that: The embodiments of the present application also provide a computer-readable storage medium, and the computer-readable storage medium stores the computer program executed by the aforementioned blockchain-based data processing device. The computer program includes program instructions. When the processor executes the program instructions, it can execute the Figure 4 , Figure 6 or Figure 7 description of the blockchain-based data processing method in the corresponding embodiments. Therefore, it will not be elaborated here. Additionally, the description of the beneficial effects of adopting the same method will not be elaborated either. For the technical details not disclosed in the embodiments of the computer-readable storage medium involved in the present application, please refer to the description of the method embodiments of the present application. As an example, the program instructions can be deployed to be executed on one computing device, or on multiple computing devices located at one location, or on multiple computing devices distributed at multiple locations and interconnected through a communication network. The multiple computing devices distributed at multiple locations and interconnected through a communication network can form a blockchain system.

[0221] On the one hand, the present application provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device can execute the Figure 4 , Figure 6 or Figure 7 description of the blockchain-based data processing method in the corresponding embodiments, which will not be elaborated here. Additionally, the description of the beneficial effects of adopting the same method will not be elaborated either.

[0222] It should be noted that in the practical application of the relevant data collection and processing in the present application, it should strictly comply with the requirements of relevant national laws and regulations, obtain the informed consent or separate consent of the personal information subject (or have a legal basis), and carry out subsequent data use and processing behaviors within the scope authorized by laws and regulations and the personal information subject. For example, when the present application obtains the entrusted transaction information and object attribute information input by the institutional management object, it is necessary to obtain the informed consent or separate consent of the institutional management object.

[0223] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.

[0224] The above-disclosed are only the preferred embodiments of the present invention. Of course, the scope of the rights of the present invention cannot be limited thereby. Therefore, equivalent changes made according to the claims of the present invention still fall within the scope covered by the present invention.

Claims

1. A blockchain-based data processing method, characterized in that, Including: Obtaining escrow transaction information about the resource escrow task of the institution, as well as a first transaction signature and a second transaction signature of the escrow transaction information; The first transaction signature is obtained by an institution device in the target signature device group that determines the legality of the escrow transaction information, signing the escrow transaction information with a first private key shard of the institution. The second transaction signature is obtained by an escrow device in the target signature device group that determines the legality of the escrow transaction information, signing the escrow transaction information with a second private key shard of the institution. The target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in a working state; P is a positive integer greater than 1; According to the first transaction signature and the second transaction signature, counting the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group; Obtaining the restricted device signature number of the institution and the public key of the institution from the blockchain of the blockchain network. When the number of signature devices is greater than or equal to the restricted device signature number, verifying the first transaction signature and the second transaction signature according to the escrow transaction information and the public key of the institution to obtain a verification result; When the verification result indicates that the first transaction signature and the second transaction signature pass the verification, executing the resource escrow task associated with the escrow transaction information to obtain an execution result, and uploading the execution result to the blockchain.

2. The method according to claim 1, wherein Each device in the target signature device group holds a private key shard, and one private key shard is used to sign the escrow transaction information to obtain a transaction signature; The counting the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group according to the first transaction signature and the second transaction signature includes: Determining the number of first devices corresponding to the institution devices that sign the escrow transaction information in the target signature device group based on the number of the first transaction signatures; Determining the number of second devices corresponding to the escrow devices that sign the escrow transaction information in the target signature device group as the number of the second transaction signatures; Summing the number of the first devices and the number of the second devices to obtain the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group.

3. The method according to claim 1, wherein When the number of signature devices is greater than or equal to the restricted device signature number, verifying the first transaction signature and the second transaction signature according to the escrow transaction information and the public key of the institution to obtain a verification result, including: When the number of signature devices is greater than or equal to the restricted device signature number, merging the first transaction signature and the second transaction signature to obtain a merged transaction signature; Decrypting the merged transaction signature according to the public key of the institution to obtain signature decryption information; Verifying the first transaction signature and the second transaction signature according to the signature decryption information and the escrow transaction information to obtain a verification result.

4. A data processing method based on blockchain, characterized in that, Including: Obtain the escrow transaction information of the resource escrow task of the institution, and the first transaction signature of the escrow transaction information; The first transaction signature is obtained by an institutional device in the target signature device group that determines the legality of the escrow transaction information, using the first private key shard of the institution to sign the escrow transaction information. The target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in working condition; P is a positive integer greater than 1; Verify the legality of the escrow transaction information through the escrow device in the target signature device group. When it is determined that the escrow transaction information is legal, use the second private key shard of the institution to sign the escrow transaction information to obtain a second transaction signature; Send the escrow transaction information, the first transaction signature, and the second transaction signature to the blockchain node in the blockchain network; The blockchain node is used to execute the resource escrow task associated with the escrow transaction information and obtain an execution result when the number of signature devices corresponding to the devices that sign the escrow transaction information in the target signature device group is greater than or equal to the restricted device signature number, and the first transaction signature and the second transaction signature pass the signature verification, and upload the execution result to the blockchain; 5. The method according to claim 4, characterized in that, The number of escrow devices in the target signature device group is one, and the escrow device in the target signature device group is the device that obtains the escrow transaction information and the first transaction signature; the escrow transaction information includes the institutional account information and transaction parameter information of the institution; The step of verifying the legality of the escrow transaction information through the escrow device in the target signature device group and, when it is determined that the escrow transaction information is legal, using the second private key shard of the institution to sign the escrow transaction information to obtain a second transaction signature includes: The escrow device in the target signature device group performs a legality check on the institutional account of the institution according to the institutional account information to obtain an account check result; If the account check result indicates that the institutional account of the institution is legal, call a transaction check model to check the legality of the transaction parameter information to obtain a transaction check result; If the transaction check result indicates that the transaction parameter information is legal, determine that the escrow transaction information is legal, and use the second private key shard of the institution to sign the escrow transaction information to obtain a second transaction signature.

6. The method according to claim 5, wherein The escrow device in the target signature device group performs a legality check on the institutional account of the institution according to the institutional account information to obtain an account check result, including: The escrow device in the target signature device group obtains a list of illegal accounts from the blockchain of the blockchain network; the list of illegal accounts includes illegal account information that is not legal; Compare the institutional account information with the illegal account information in the list of illegal accounts to obtain an account comparison result; If the account comparison result indicates that there is no illegal account information matching the institutional account information in the illegal account list, it is determined that the institutional account of the institution is legal; Generate an account verification result for indicating that the institutional account of the institution is legal.

7. The method according to claim 4, characterized in that, The number of escrow devices in the target signature device group is multiple, and the escrow devices in the target signature group include target escrow devices, and the target escrow device is the device for obtaining the escrow transaction information and the first transaction signature; Verifying the legality of the escrow transaction information through the escrow devices in the target signature device group, and when it is determined that the escrow transaction information is legal, signing the escrow transaction information with the second private key shard of the institution to obtain a second transaction signature, including: The target escrow device sends the escrow transaction information to the remaining escrow devices; the remaining escrow devices are used to sign the escrow transaction information with the second private key shard of the institution to obtain a second transaction signature when it is determined that the escrow transaction information is legal, and send the second transaction signature to the blockchain node; the remaining escrow devices are the escrow devices other than the target escrow device in the target signature device group; Verify the legality of the escrow transaction information, and when it is determined that the escrow transaction information is legal, sign the escrow transaction information with the second private key shard of the institution to obtain a second transaction signature.

8. The method according to claim 4, wherein The method further includes: If the escrow transaction information is not legal, generate transaction illegal indication information about the escrow transaction information, and send the transaction illegal indication information to the institutional device in the target signature device group; the transaction illegal indication information is used to indicate that the escrow transaction information is not legal; Determine the escrow transaction information as illegal escrow transaction information, and report the illegal escrow transaction information to the blockchain node.

9. The method according to claim 4, wherein The method further includes: If the second private key shard of the institution is not obtained through the escrow devices in the target signature device group, generate a re-signature request; Send the re-signature request to the institutional device in the backup signature device group; the backup signature device group belongs to one of the P signature device groups of the institution, and the institutional device in the backup signature device group is used to sign the escrow transaction information with the third private key shard of the institution to obtain a third transaction signature, and send the third transaction signature and the escrow transaction information to the escrow devices in the backup signature device group; the backup signature device group is different from the target signature device group.

10. A data processing method based on blockchain, characterized in that, Including: Obtain escrow transaction information about the resource escrow task of the institution, and the P signature device groups of the institution; P is a positive integer greater than 1; Determine the signature device group in which the device is in a working state from the P signature device groups as the target signature device group; Through the institutional device in the target signature device group, sign the escrow transaction information with the first private key shard of the institution to obtain a first transaction signature; Send the entrusted transaction information and the first transaction signature to the entrusted device in the target signature device group; When determining that the entrusted transaction information is legal, the entrusted device in the target signature device group uses the second private key shard of the institution to sign the entrusted transaction information to obtain second signature information, and sends the first signature information, the second signature information, and the entrusted transaction information to the blockchain node in the blockchain network.

11. The method according to claim 10, wherein The signature device group that determines that the device is in a working state from the P signature device groups is used as the target signature device group, and includes: Determine the signature device group with the highest signature priority from the P signature device groups as the initial signature device group; Detect the device status of the institution devices included in the initial signature device group to obtain a status detection result; If the status detection result indicates that the devices in the initial signature device group are in a working state, determine the initial signature device group as the target signature device group.

12. The method according to claim 11, wherein The device status includes the device network status and the shard holding status of the first private key shard of the institution; The detecting the device status of the institution devices included in the initial signature device group to obtain a status detection result includes: Obtain the device network status and shard holding status of the institution devices included in the initial signature device group; If the device network status and shard holding status of the institution devices included in the initial signature device group are both normal states, determine that the devices in the initial signature device group are in a normal working state; Generate a status detection result for indicating that the devices in the initial signature device group are in a normal working state.

13. A data processing device based on blockchain, characterized in that, Includes: A first acquisition module, configured to acquire entrusted transaction information about the resource entrustment task of the institution, as well as the first transaction signature and the second transaction signature of the entrusted transaction information; The first transaction signature is obtained by an institution device that determines that the entrusted transaction information is legal in the target signature device group using the first private key shard of the institution to sign the entrusted transaction information, and the second transaction signature is obtained by a entrusted device that determines that the entrusted transaction information is legal in the target signature device group using the second private key shard of the institution to sign the entrusted transaction information. The target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in a working state; P is a positive integer greater than 1; A statistics module, configured to count the number of signature devices corresponding to the devices that sign the entrusted transaction information in the target signature device group according to the first transaction signature and the second transaction signature; A signature verification module, configured to obtain the restricted device signature number of the institution and the public key of the institution from the blockchain of the blockchain network. When the number of signature devices is greater than or equal to the restricted device signature number, verify the first transaction signature and the second transaction signature according to the entrusted transaction information and the public key of the institution to obtain a signature verification result; The on-chain module is used to execute the resource escrow task associated with the escrow transaction information when the verification result indicates that the first transaction signature and the second transaction signature pass the signature verification, obtain an execution result, and upload the execution result to the blockchain.

14. A data processing device based on blockchain, characterized in that, It includes: The second acquisition module is used to acquire the escrow transaction information about the resource escrow task of the institution, and the first transaction signature of the escrow transaction information; The first transaction signature is obtained by the institutional device that determines the legality of the escrow transaction information in the target signature device group using the first private key shard of the institution to sign the escrow transaction information. The target signature device group is the signature device group in which all devices in the P signature device groups of the institution are in working state; P is a positive integer greater than 1; The first signature module is used to verify the legality of the escrow transaction information through the escrow device in the target signature device group. When it is determined that the escrow transaction information is legal, use the second private key shard of the institution to sign the escrow transaction information to obtain a second transaction signature; The first sending module is used to send the escrow transaction information, the first transaction signature, and the second transaction signature to the blockchain node in the blockchain network; The blockchain node is used to execute the resource escrow task associated with the escrow transaction information when the number of signature devices corresponding to the device that signs the escrow transaction information in the target signature device group is greater than or equal to the restricted device signature number, and the first transaction signature and the second transaction signature pass the signature verification, obtain an execution result, and upload the execution result to the blockchain.

15. A data processing device based on blockchain, characterized in that, It includes: The third acquisition module is used to acquire the escrow transaction information about the resource escrow task of the institution, and the P signature device groups of the institution; P is a positive integer greater than 1; The determination module is used to determine the signature device group in which the devices are in working state from the P signature device groups as the target signature device group; The second signature module is used to sign the escrow transaction information through the institutional device in the target signature device group using the first private key shard of the institution to obtain a first transaction signature; The fourth sending module is used to send the escrow transaction information and the first transaction signature to the escrow device in the target signature device group; The escrow device in the target signature device group is used to sign the escrow transaction information using the second private key shard of the institution when it is determined that the escrow transaction information is legal to obtain a second signature information, and send the first signature information, the second signature information, and the escrow transaction information to the blockchain node in the blockchain network.

16. A computer device, characterized in that, It includes: A processor and a memory; The processor is connected to the memory. Among them, the memory is used to store a computer program, and the processor is used to call the computer program so that the computer device executes the method according to any one of claims 1-12.

17. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and the computer program is adapted to be loaded and executed by a processor so that a computer device having the processor executes the method according to any one of claims 1-12.

18. A computer program product or computer program, characterized in that, The computer program product or computer program includes computer instructions, the computer instructions are stored in a computer-readable storage medium, and the computer instructions are adapted to be read and executed by a processor so that a computer device having the processor executes the method according to any one of claims 1-12.