Content distribution method and device based on block chain system, equipment and storage medium

By verifying the identity and attributes of the subscription node in the blockchain system, ensuring that only nodes that meet the conditions can obtain content, solving the problem of information leakage in the Internet of Things environment and achieving efficient and secure content distribution.

CN120263416APending Publication Date: 2025-07-04TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410007152.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-02
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the Internet of Things environment, smart devices are vulnerable to attacks and lead to the leakage of sensitive information, and the privacy and security of user data cannot be effectively protected.

Method used

Using the content distribution method based on the blockchain system, by establishing a trusted execution environment between the subscription node and the distribution node, the digital identity certificate of the blockchain node is used to verify the target of the subscription node to verify the expression and signature information, ensuring that only nodes that meet the subscription conditions can obtain content.

Benefits of technology

It improves the security and privacy of content publishing, simplifies the verification process, improves the efficiency of information subscription and publishing, and protects sensitive data from being acquired by unverified nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263416A_ABST
    Figure CN120263416A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a content distribution method and device based on a block chain system, equipment and a storage medium. When the method is applied to a distribution node, the method comprises the following steps: after a subscription node verifies that a running environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node, sending a first verification request to a block chain node in a block chain system based on a subscription request sent by the subscription node through the subscription channel, and sending the first verification request to the block chain node, so that the block chain node verifies the target verifiable expression and the first signature information in the first verification request by using the digital identity certificate of the subscription node in the block chain to obtain a first verification result, and when the first verification result indicates that the verification is passed, adding the identification information of the subscription node to a subscription list of the target theme, after the publishing node of the target theme publishes the content, the content under the target theme is distributed to the subscription node through the subscription channel. By adopting the method, the security of content publishing can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of information processing, and more specifically, to a content distribution method, apparatus, device, and storage medium based on a blockchain system. Background Art

[0002] In today's information age, various information devices have emerged: there are fixed telephones and mobile phones for voice transmission; there are servers and personal computers for information resource sharing and processing; there are various televisions for video data display, and so on. These devices are all created to solve practical needs in specific fields. With the advent of the integration of electronics, computing, and communication (3C), people have increasingly focused on the research of comprehensively using information devices in different fields to make full use of existing resource devices to better serve people.

[0003] In the existing mobile terminal information acquisition technology, due to the openness of the Internet of Things environment, intelligent devices providing services are easily attacked, resulting in the leakage of sensitive information. For example, when a user or enterprise needs to store data externally to obtain storage or distribution services, the user or enterprise will lose full control of the data, and third-party service providers (i.e., the parties storing or processing the data) can access and operate on user data at will. This makes the privacy and security of user data not effectively protected. Summary of the Invention

[0004] In view of this, embodiments of this application propose a content distribution method, apparatus, device, and storage medium based on a blockchain system, which can effectively reduce the possibility of data leakage during the data synchronization process, thereby enhancing the security and privacy of content publishing.

[0005] In a first aspect, an embodiment of the present application provides a content distribution method based on a blockchain system, which is applied to a distribution node. The method includes: after a subscription node verifies that the running environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node, receiving a subscription request sent by the subscription node based on the subscription channel; the subscription request includes a target topic, a first signature information of the subscription node, and a target verifiable expression, where the target verifiable expression is determined according to a verifiable claim corresponding to a target attribute of the subscription node; the target attribute refers to an attribute that satisfies the subscription condition of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; based on the target verifiable expression and the first signature information, sending a first verification request to a blockchain node in the blockchain system, so that the blockchain node uses the digital identity certificate of the subscription node in the blockchain to verify the target verifiable expression and the first signature information, and obtains a first verification result; receiving the first verification result returned by the blockchain node; if the first verification result indicates that the verification is passed, adding the identification information of the subscription node to the subscription list of the target topic, so as to distribute the content under the target topic to the subscription node through the subscription channel after the content is published by the publishing node of the target topic.

[0006] In a second aspect, an embodiment of the present application provides a content distribution method based on a blockchain system, which is applied to a blockchain node in the blockchain system. The method includes: receiving a first verification request sent by a distribution node; the first verification request is generated by the distribution node in response to a subscription request sent by a subscription node according to the target verifiable expression and the first signature information in the subscription request; the subscription request further includes a target topic; after the subscription node verifies that the running environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node, sending the subscription request to the distribution node based on the subscription channel; the target verifiable expression is determined according to a verifiable claim corresponding to a target attribute of the subscription node; the target attribute refers to an attribute that satisfies the subscription condition of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; obtaining the digital identity certificate of the subscription node from the blockchain; using the digital identity certificate of the subscription node to verify the target verifiable expression and the first signature information, and obtaining a first verification result; sending the first verification result to the distribution node, so that after the first verification result indicates that the verification is passed, the distribution node adds the identification information of the subscription node to the subscription list of the target topic, so as to distribute the content under the target topic to the subscription node through the subscription channel after the content corresponding to the target topic is published by the publishing node.

[0007] In a third aspect, an embodiment of the present application provides a content distribution device based on a blockchain system, which is applied to a distribution node. The device includes: a first request receiving module, a first request sending module, a verification result receiving module, and an identifier adding module. The first request receiving module is configured to receive a subscription request sent by the subscription node based on the subscription channel after the subscription node verifies that the running environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node; the subscription request includes a target topic, a first signature information of the subscription node, and a target verifiable expression, where the target verifiable expression is determined according to a verifiable claim corresponding to a target attribute of the subscription node; the target attribute refers to an attribute that satisfies the subscription condition of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; the first request sending module is configured to send a first verification request to a blockchain node in the blockchain system based on the target verifiable expression and the first signature information, so that the blockchain node uses the digital identity certificate of the subscription node in the blockchain to verify the target verifiable expression and the first signature information, and obtains a first verification result; the verification result receiving module is configured to receive the first verification result returned by the blockchain node; the identifier adding module is configured to add the identifier information of the subscription node to the subscription list of the target topic when the first verification result indicates that the verification is passed, so as to distribute the content under the target topic to the subscription node through the subscription channel after the publishing node publishes the content of the target topic.

[0008] In an implementable manner, the device further includes a content distribution module. The first request receiving module is further configured to receive a publishing request sent by the publishing node based on the publishing channel after the publishing node verifies that the running environment in the distribution node is a trusted execution environment and establishes a publishing channel with the distribution node; the publishing request includes the target topic, the subscription condition, and a second signature information of the publishing node; the first request sending module is further configured to send a second verification request to the blockchain node based on the second signature information, so that the blockchain node uses the digital identity certificate of the publishing node in the blockchain to verify the second signature information and obtains a second verification result; the verification result receiving module is further configured to receive the second verification result returned by the blockchain node; the content distribution module is configured to publish the publishing information of the target topic when the second verification result indicates that the verification is passed, where the publishing information includes the target topic and the subscription condition of the target topic.

[0009] In one implementable manner, the device further includes a publishing channel closing module, configured to send a publishing failure prompt message to the publishing node and close the publishing channel between the distribution node and the publishing node when the second verification result indicates that the verification fails.

[0010] In one implementable aspect, the device further includes a subscribing channel closing module, configured to send a subscribing failure prompt message to the subscribing node and close the subscribing channel between the distribution node and the subscribing node when the first verification result indicates that the verification fails.

[0011] In a fourth aspect, an embodiment of the present application provides a content distribution device based on a blockchain system, which is applied to a blockchain node in the blockchain system. The device includes: a second request receiving module, a certificate obtaining module, an information verification module, and a verification result sending module; the second request receiving module is configured to receive a first verification request sent by a distribution node; the first verification request is generated by the distribution node in response to a subscribing request sent by a subscribing node according to a target verifiable expression and first signature information in the subscribing request; the subscribing request further includes a target topic; after verifying that the running environment in the distribution node is a trusted execution environment and establishing a subscribing channel with the distribution node, the subscribing node sends the subscribing request to the distribution node based on the subscribing channel; the target verifiable expression is determined according to a verifiable claim corresponding to a target attribute of the subscribing node; the target attribute refers to an attribute that satisfies the subscribing condition of the target topic; the verifiable claim is obtained by attribute endorsement based on the digital identity certificate of the subscribing node in the blockchain; the certificate obtaining module is configured to obtain the digital identity certificate of the subscribing node from the blockchain; the information verification module is configured to verify the target verifiable expression and the first signature information by using the digital identity certificate of the subscribing node to obtain a first verification result; the verification result sending module is configured to send the first verification result to the distribution node, so that after the first verification result indicates that the verification passes, the distribution node adds the identification information of the subscribing node to the subscribing list of the target topic, so as to distribute the content under the target topic to the subscribing node through the subscribing channel after the content corresponding to the target topic is published by the publishing node.

[0012] In an implementable manner, the second request receiving module is further configured to receive a second verification request sent by the distribution node, where the second verification request is generated by the distribution node in response to a publishing request sent by the publishing node according to second signature information in the publishing request; after verifying that the operating environment in the distribution node is a trusted execution environment and establishing a publishing channel with the distribution node, the publishing node sends the publishing request to the distribution node based on the publishing channel; the publishing request further includes the target topic and the subscription condition; the certificate acquisition module is configured to acquire the digital identity certificate of the publishing node from the blockchain; the information verification module is further configured to verify the second signature information according to the digital identity certificate of the publishing node to obtain a second verification result; the verification result sending module is further configured to send the second verification result to the distribution node, so that after determining that the second verification result indicates verification passed, the distribution node publishes the publishing information of the target topic, where the publishing information includes the target topic and the subscription condition of the target topic.

[0013] In an implementable manner, the blockchain node is the target management node in the institution to which the subscription node belongs; the apparatus further includes a registration request receiving module, a document signature module, a certificate generation module, and a consensus processing module, where the registration request receiving module is configured to receive a registration request sent by the subscription node, and the registration request includes the digital identity document of the subscription node, and the digital identity document includes the attributes of the subscription node and the signature public key of the subscription node; the document signature module is configured to, in response to the registration request, sign the digital identity document of the subscription node with the private key of the target management node to obtain document signature information; the certificate generation module is configured to generate the digital identity certificate of the subscription node based on the digital identity document of the subscription node and the document signature information; the consensus processing module is configured to perform consensus processing on the digital identity certificate of the subscription node, and write the digital identity certificate of the subscription node into the blockchain after the consensus passes.

[0014] In one implementable manner, the device further includes: an endorsement request receiving module, a certificate obtaining module, a signature verification module, a claim generating module, and a claim sending module. The endorsement request receiving module is configured to receive an attribute endorsement request sent by a subscribing node, where the attribute endorsement request includes the attribute to be endorsed by the subscribing node and fourth signature information obtained by signing with the private key of the subscribing node; the certificate obtaining module is configured to, in response to the attribute endorsement request, obtain the digital identity certificate of the subscribing node from the blockchain; the signature verification module is configured to verify the document signature information in the digital identity certificate of the subscribing node through the public key of the target management node; the signature verification module is further configured to verify the fourth signature information through the signature public key of the subscribing node in the digital identity certificate; the claim generating module is configured to, if the document signature information in the digital identity certificate passes the verification, the fourth signature information passes the verification, and it is determined that the digital identity certificate of the subscribing node includes the attribute to be endorsed, generate a verifiable claim for the attribute to be endorsed; the verifiable claim includes the node identifier of the target management node, the attribute to be endorsed, and third signature information obtained by signing the claim with the private key of the target management node; the claim sending module is configured to send the verifiable claim for the attribute to be endorsed to the subscribing node.

[0015] In one implementable manner, the information verification module is further configured to verify the first signature information through the public key of the subscribing node in the digital identity certificate of the subscribing node; verify the third signature information included in the target verifiable expression through the public key of the target management node in the institution to which the subscribing node belongs; and perform a matching verification on the attribute in the target verifiable expression through the attribute in the digital identity certificate of the subscribing node.

[0016] In a fifth aspect, an embodiment of the present application provides an electronic device, including a processor and a memory; one or more programs are stored in the memory and configured to be executed by the processor to implement the above method.

[0017] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, in which program code is stored, and when the program code is run by a processor, the above method is executed.

[0018] In a seventh aspect, an embodiment of the present application provides a computer program product or a computer program, the computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the electronic device obtains the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the above method.

[0019] A content distribution method, apparatus, device, and storage medium based on a blockchain system provided by an embodiment of the present application. The method includes: after a subscription node verifies that the running environment in a distribution node is a trusted execution environment and establishes a subscription channel with the distribution node, receiving a subscription request sent by the subscription node based on the subscription channel; the subscription request includes a target topic, a first signature information of the subscription node, and a target verifiable expression, and the target verifiable expression is determined according to a verifiable claim corresponding to a target attribute of the subscription node; the target attribute refers to an attribute that meets the subscription condition of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; based on the target verifiable expression and the first signature information, sending a first verification request to a blockchain node in the blockchain system, so that the blockchain node uses the digital identity certificate of the subscription node in the blockchain to verify the target verifiable expression and the first signature information to obtain a first verification result; receiving the first verification result returned by the blockchain node; if the first verification result indicates that the verification is passed, adding the identification information of the subscription node to the subscription list of the target topic, so that after the content is published by the publishing node of the target topic, the content under the target topic is distributed to the subscription node through the subscription channel. By adopting the above method, since the running environment of the distribution node is a trusted execution environment, there is usually no problem of data leakage during the process of receiving and forwarding content. In addition, since the verification process of the subscription node is that the subscription node sends a subscription request to the distribution node, so that the distribution node sends a first verification request to the blockchain node in response to the subscription request, so as to realize direct verification by the blockchain node based on the stored information (such as digital identity certificate), without relying on the target management node, thus greatly simplifying the verification process and improving the efficiency of information subscription and publication. In addition, before the content is published, the subscription node can only know the target topic to be published and the subscription conditions of the target topic, and needs to be verified on the blockchain before completing the subscription. After the subscription is completed, after the distribution node confirms that the publishing node of the target topic publishes the content, the content under the target topic is distributed to the subscription node through the subscription channel, so that only the subscription nodes that meet the subscription conditions can obtain the content corresponding to the target topic after passing the verification, while the un-verified or non-compliant subscription nodes cannot perceive the published content, improving the privacy and security during the data publishing process. Description of the Drawings

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative efforts.

[0021] Figure 1The figure shows an application scenario diagram of a content distribution method provided by an embodiment of the present application based on a blockchain system;

[0022] Figure 2 The figure shows a schematic flowchart of a content distribution method proposed by an embodiment of the present application for a content distribution system;

[0023] Figure 3 The figure shows a storage process of an identity certificate of a publishing node proposed by an embodiment of the present application;

[0024] Figure 4 The figure shows a process of processing a publishing request of a publishing node proposed by an embodiment of the present application;

[0025] Figure 5 The figure shows a storage process of an identity certificate of a subscribing node proposed by an embodiment of the present application;

[0026] Figure 6 The figure shows a process of verifying attribute endorsement of a subscribing node proposed by an embodiment of the present application;

[0027] Figure 7 The figure shows a process of processing a subscription request of a subscribing node provided by an embodiment of the present application;

[0028] Figure 8 The figure shows another schematic flowchart of a content distribution method proposed by an embodiment of the present application for a content distribution system;

[0029] Figure 9 The figure shows an interaction diagram of revoking a subscription permission of a subscribing node provided by an embodiment of the present application;

[0030] Figure 10 The figure shows a schematic flowchart of a content distribution method provided by an embodiment of the present application for a distribution node;

[0031] Figure 11 The figure shows another schematic flowchart of a content distribution method provided by an embodiment of the present application for a distribution node;

[0032] Figure 12 The figure shows another schematic flowchart of a content distribution method provided by an embodiment of the present application for a blockchain node;

[0033] Figure 13 The figure shows another schematic flowchart of a content distribution method provided by an embodiment of the present application for a blockchain node;

[0034] Figure 14 The figure shows another schematic flowchart of a content distribution method provided by an embodiment of the present application for a blockchain node;

[0035] Figure 15 It shows another schematic flowchart of a content distribution method applied to a blockchain node provided by an embodiment of the present application;

[0036] Figure 16 It shows a connection block diagram of a content distribution device applied to a distribution node proposed by an embodiment of the present application;

[0037] Figure 17 It shows a connection block diagram of a content distribution device applied to a blockchain node proposed by an embodiment of the present application;

[0038] Figure 18 It shows a structural block diagram of an electronic device for executing the method of an embodiment of the present application. Detailed implementation manners

[0039] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.

[0040] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.

[0041] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0042] The flowcharts shown in the drawings are only illustrative and do not necessarily include all the content and operations / steps, nor do they necessarily have to be executed in the described order. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.

[0043] It should be noted that: "multiple" mentioned in this article refers to two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0044] In addition, it should be noted that in the embodiments of this application, obtaining the attributes of the subscription node and the distribution node requires the permission or consent of the affiliated user, and the collection, use, processing, and storage of the above attributes need to comply with the regulations of the region where they are located.

[0045] The following explains the terms involved in this application.

[0046] Blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. Essentially, a blockchain is a decentralized database, a string of blocks generated by using cryptographic methods. Each block contains information about a batch of network transactions, which is used to verify the validity of the information (anti-counterfeiting) and generate the next block.

[0047] A blockchain consists of multiple blocks. The genesis block includes a block header and a block body. The block header stores the input information feature value, version number, timestamp, and difficulty value. The block body stores the input information. The next block after the genesis block uses the genesis block as the parent block. The next block also includes a block header and a block body. The block header stores the input information feature value of the current block, the block header feature value of the parent block, version number, timestamp, and difficulty value, and so on. This ensures that the block data stored in each block in the blockchain is associated with the block data stored in the parent block, guaranteeing the security of the input information in the block. The input information feature value of the current block is specifically the hash value of the data record stored in the current block (the hash value of this block), and the block header feature value of the parent block is specifically the hash value of the parent block.

[0048] Trusted Execution Environment: A hardware-based secure computing environment with an inherent endorsement key for protecting data privacy and authenticating data integrity, source reliability, etc.; there is a memory barrier with the outside, that is, the outside, including the operating system, does not have access to the storage space within the Trusted Execution Environment domain; it has a remote authentication mechanism for proving to the remote end that the logic running within a Trusted Execution Environment has not been tampered with. The effect achieved by using the Trusted Execution Environment is that the data and program logic within the Trusted Execution Environment domain cannot be snooped by the external environment without active output. TEE: Full name Trusted Execution Environment, Trusted Execution Environment.

[0049] A blockchain system is a distributed system, which can be formed by connecting multiple nodes (any form of computing device accessing the network, such as servers and user terminals) through network communication. A blockchain system is formed by multiple blockchain nodes, and a peer-to-peer network is formed among the blockchain nodes.

[0050] A blockchain node can be any form of computing device in the network, which can be a server or a terminal device. The server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. Terminal devices can be smartphones, tablets, laptops, desktop computers, smart speakers, smart watches, etc., but are not limited thereto. Each node can be directly or indirectly connected through wired or wireless communication methods, and this application does not make any restrictions here. Each node can receive input information during normal operation and maintain the shared data within the blockchain system based on the received input information. To ensure information intercommunication within the blockchain system, there can be information connections between each node in the blockchain system, and information can be transmitted between nodes through the above information connections.

[0051] Digital Identity Certificate (DID): (Decentralized Identity). Compared with the traditional identity system based on PKI (Public Key Infrastructure), the distributed digital identity system established based on the blockchain has characteristics such as ensuring the authenticity and credibility of data, protecting user privacy and security, and strong portability. In DID, the identity of each user is not controlled by a trusted third party, but by its owner, and individuals can independently manage their own identities. Identity-related data is anchored on the blockchain, and the authentication process does not need to rely on the application party providing the identity.

[0052] Verifiable Credential (VC) provides a specification to describe certain attributes possessed by an entity, realizing trust based on evidence. The DID holder can prove to other entities (individuals, organizations, specific things, etc.) that certain of their attributes are credible through verifiable credentials. At the same time, combined with cryptographic technologies such as digital signatures and zero-knowledge proofs, the claim can be made more secure and credible, and further protect user privacy from being violated.

[0053] Verifiable presentation (VP): A verifiable presentation is data by which a VC holder proves their identity to a verifier. Generally, the full text of the VC can be directly presented. However, in some cases, due to privacy protection requirements, it is not necessary to present the complete VC content. Instead, it is only desired to selectively disclose certain attributes, or not disclose any attributes at all, and only prove a certain assertion.

[0054] Figure 1 FIG. is a schematic diagram of an application scenario of a content distribution method based on a blockchain system according to an embodiment of the present application. As Figure 1 shown, this method is applied in a content distribution system 10, which includes a subscription node 11, a publishing node 12, a distribution node 13, a target management node 14, and a blockchain system 15.

[0055] Among them, the subscription node 11 and the publishing node 12 can be user-side computing devices. Among them, the user-side computing devices can include, for example, PC computing devices, mobile computing devices, Internet of Things devices, and other forms of electronic devices with certain computing capabilities, and so on.

[0056] It should be noted that the user-side computing devices do not mean that all of the user-side computing devices are in the same communication network, but only a general term for these user-side computing devices.

[0057] The publishing node 12 is mainly responsible for publishing content. Before publishing the content, it is necessary to determine the access rights of the published content, that is, it is necessary to limit which subscription nodes with certain attributes can access the content it publishes.

[0058] The subscription node 11 is mainly used to subscribe to the content published by the publishing node 12. The subscription node itself can have various attributes, such as gender, age, work unit, work department, and work rank, and so on. The attributes owned by the subscription node can be verified, and only the subscription node 11 that has the subscription attribute requirements defined by the publishing node 12 can obtain the content published by the publishing node.

[0059] The distribution node 13 can be a trusted hardware device. The distribution node 13 can be any electronic device such as a server or a terminal device that runs a trusted execution environment and is capable of data processing and forwarding. In the embodiment of the present application, it is mainly used to receive the content published by the publishing node 12 and distribute the content to the subscription node 11.

[0060] The blockchain system 15 includes multiple blockchain nodes. In the blockchain network, the blockchain nodes are logical communication entities and also electronic devices capable of data processing. In this embodiment, the blockchain system is mainly used to store digital identity certificates and perform data processing or verification, etc.

[0061] The target management node 14 refers to a management node used to manage nodes in the organizations to which the subscription node 11 and / or the publishing node 12 belong. When the attributes in the registration request submitted by the publishing node 12 or the subscription node 11 correspond to the actual attributes of the nodes, it signs the digital identity document included in the registration request to generate the digital identity certificate of the publishing node 12 and / or the subscription node 11. Among them, the target management node 14 can be a blockchain node in the blockchain system 15 or not, which can be set according to actual needs.

[0062] Figure 1 The content distribution system 10 when the target management node 14 does not belong to the blockchain system 15 is shown.

[0063] When using the above content distribution system 10 for content distribution, the publishing node 12 is used to publish the target topic and the subscription policy of the target topic. The subscription node 11 is used to send a subscription request to the distribution node after verifying that the running environment in the distribution node 13 is a trusted execution environment and establishing a subscription channel with the distribution node 13. The subscription request includes the target topic, the first signature information of the subscription node, and the target verifiable expression, where the target verifiable expression is determined according to the verifiable claim corresponding to the target attribute of the subscription node; the target attribute refers to the attribute that meets the subscription conditions of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; the distribution node 13 is used to send a first verification request to the blockchain node in the blockchain system 15 based on the target verifiable expression and the first signature information; the blockchain node is used to verify the target verifiable expression and the first signature information using the digital identity certificate of the subscription node in the blockchain, obtain the first verification result and return it to the distribution node 13; the distribution node 13 is also used to add the identification information of the subscription node to the subscription list of the target topic after confirming that the first verification result indicates that the verification is passed, so that after the distribution node 13 receives the content corresponding to the target topic published by the publishing node 12, it distributes the content under the target topic to the subscription node 11 through the subscription channel.

[0064] When the content distribution system 10 based on the blockchain system described above is used for content distribution, it realizes the use of trusted hardware as a distribution node to execute the content distribution service. When a subscription node receives subscribed content, it needs to establish a trusted subscription channel with the distribution node and verify the legitimacy of the distribution node. When the distribution node distributes content, no external user can peek at the specific content being distributed, thus ensuring the privacy and security of the distributed content. Specifically, since the verification process of the subscription node is to send a subscription request from the subscription node to the distribution node, so that the distribution node sends a first verification request to the blockchain node in response to the subscription request, to realize direct verification by the blockchain node based on the stored information (such as digital identity certificates), without relying on the target management node, thus greatly simplifying the verification process and improving the efficiency of information subscription and publication. In addition, before content is published, the subscription node can only know the target topic to be published and the subscription conditions for the target topic, and needs to be verified on the blockchain before it can complete the subscription. After the subscription is completed, after the distribution node confirms that the publishing node of the target topic publishes the content, it distributes the content under the target topic to the subscription node through the subscription channel, so that only the subscription nodes that meet the subscription conditions can obtain the content corresponding to the target topic after passing the verification, while the subscription nodes that are not verified or do not meet the subscription conditions cannot perceive the published content, improving the privacy and security in the data publishing process.

[0065] The following will specifically describe the embodiments of the present application with reference to the accompanying drawings.

[0066] Please refer to Figure 2 , Figure 2 The present application also provides a content distribution method based on a blockchain system, which can be applied to the above content distribution system. When using the content distribution system to execute content distribution, it specifically includes the following steps:

[0067] Step S110: After the publishing node verifies that the running environment in the distribution node is a trusted execution environment and establishes a publishing channel with the distribution node, it sends a publishing request to the distribution node based on the publishing channel.

[0068] The publishing request includes a target topic, subscription conditions, and second signature information of the publishing node.

[0069] The target topic refers to a summary description of the content that the publishing node needs to publish, which facilitates users to quickly understand the summary of the content to be subscribed before knowing the detailed content. The target topic can be any topic such as "Employee Care of XX Company", "Rest Arrangement of XX Hospital", "Weekend Cultural and Entertainment Activities of XX Organization", etc.

[0070] The subscription conditions refer to the attribute conditions that the subscribing node needs to meet. For example, if the target topic can only be subscribed by employees in department B of company A, the subscription conditions are company A and department B. Another example is that if the target topic can only be subscribed by doctors with rank E in department D of hospital C, the subscription conditions corresponding to the target topic include hospital C, department D, and rank E.

[0071] It should be understood that in addition to the target topic, subscription conditions, and second signature information, the subscription request may also include other information, such as at least one of the identity identifier of the publishing node and the publishing time, etc.

[0072] The second signature information of the publishing node refers to the signature information obtained by signing at least one of the target topic, subscription conditions, etc. using the private key of the publishing node.

[0073] Among them, the distribution node runs a trusted execution environment, and this trusted execution environment can be a verified trusted execution environment such as Intel SGX, AMD SEV, and Haiguang CSV.

[0074] The way for the publishing node to verify that the running environment in the distribution node is a trusted execution environment can be: the publishing node verifies that the running environment in the distribution node is a trusted execution environment based on the trusted measurement value sent by the distribution node. The trusted measurement value is obtained by performing trusted measurement on the code loaded by each program process in the distribution node using a hash algorithm. It can also be: the publishing node receives at least part of the security feature information sent by the distribution node indicating whether it is normal, and at least part of the information includes the device status information of the distribution node; in response to at least part of the security feature information being detected as normal, the running environment of the distribution node is determined to be secure. It should be understood that the above ways for the publishing node to determine the security of the distribution node are only illustrative, and there can be other confirmation ways, which are not specifically limited in the embodiments of the present application.

[0075] The way for the publishing node to establish a channel with the distribution node can be that the publishing node establishes an Ethernet communication channel, an RS485 / RS422 communication channel, or a serial communication channel, etc. with the distribution node, as long as it can ensure that the publishing node can transmit data with the distribution node through the established communication channel and is not disturbed by external devices.

[0076] Step S120: In response to the publishing request, the distribution node sends a second verification request to the blockchain node based on the second signature information.

[0077] Among them, the second verification request may include the second signature information and may also include the identity identifier of the publishing node.

[0078] Step S130: In response to the second verification request, the blockchain node verifies the second signature information using the digital identity certificate of the publishing node in the blockchain, obtains the second verification result, and sends the second verification result to the distribution node.

[0079] Specifically, in response to the second verification request, the blockchain node can obtain the digital identity certificate corresponding to the identity identifier of the publishing node from the blockchain. The digital identity certificate may include the public key of the publishing node, and the second verification result is obtained by verifying the second signature information using the public key of the publishing node.

[0080] Among them, the digital identity certificate of the publishing node is pre-stored in the blockchain. It can be submitted by the publishing node or any data sending terminal to the blockchain node and stored in the blockchain after being consensus-verified by the blockchain node.

[0081] In an implementable manner, if the blockchain node is the target management node in the organization to which the publishing node belongs, during the storage process of the digital identity certificate of the publishing node: the blockchain node receives the registration request sent by the publishing node. The registration request includes the digital identity document of the publishing node, and the digital identity document includes the attributes of the publishing node and the signature public key of the publishing node; in response to the registration request, the digital identity document of the subscription node is signed using the private key of the target management node to obtain the document signature information; based on the digital identity document of the publishing node and the document signature information, the digital identity certificate of the publishing node is generated; the digital identity certificate of the publishing node is subjected to consensus processing, and after the consensus is passed, the digital identity certificate of the publishing node is written into the blockchain.

[0082] In an implementable manner, the digital identity certificate of the publishing node can be generated by the target management node in the organization to which the publishing node belongs and then submitted to the blockchain system. The blockchain system performs consensus verification on the digital identity certificate of the publishing node and then writes it into the blockchain. When the target management node generates the digital identity certificate, the generation process is similar to the foregoing process, that is, the target management node receives the registration request sent by the publishing node. The registration request includes the digital identity document of the publishing node, and the digital identity document includes the attributes of the publishing node and the signature public key of the publishing node; in response to the registration request, the digital identity document of the subscription node is signed using the private key of the target management node to obtain the document signature information; based on the digital identity document of the publishing node and the document signature information, the digital identity certificate of the publishing node is generated and submitted to the blockchain system for consensus verification and storage.

[0083] In the above two implementation manners, when a blockchain node stores a digital identity document, it shall also associatively store the identity identifier of the publishing node corresponding to the digital identity document. Among them, the identity identifier of the publishing node can be generated by the publishing node or generated when the blockchain node generates the digital identity certificate of the publishing node.

[0084] In this manner, as Figure 3 shown, the figure shows a schematic diagram in which the publishing node is not a node in the blockchain system. The publishing node can receive the user's filled registration information and generate the digital identity document of the publishing node. The digital identity document of the publishing node includes the attribute information that the user needs to disclose and the public key of the publishing node. The publishing node sends a registration request to the target management node in the institution to which the publishing node belongs. The registration request includes the digital identity document of the publishing node. The target management node registers an identity identifier for the publishing node after verifying the publishing node based on the user registration information. The identity identifier of the publishing node is bound to the digital identity document of the publishing node. Then, a proof field is added to the digital identity document of the publishing node. The content of this field is the document signature information obtained by signing the digital identity document of the publishing node with the private key of the target management node. Thus, based on the digital identity document of the publishing node and the document signature information, the digital identity certificate of the publishing node is generated. Then, the target management node submits the digital identity certificate to the blockchain network so that the blockchain network performs a consensus process on the digital identity certificate of the publishing node to obtain a consensus verification result. After the blockchain network passes the consensus verification of the digital identity certificate, it writes the digital identity certificate of the publishing node into the blockchain and at the same time feeds back the consensus verification result to the target management node. After the target management node confirms that the consensus verification is passed based on the consensus verification result, it generates a registration success result and returns it to the publishing node.

[0085] Step S140: The distribution node receives the second verification result, and when the second verification result indicates that the verification is passed, it publishes the publishing information of the target topic. The publishing information includes the target topic and the subscription conditions of the target topic.

[0086] The manner in which the distribution node publishes the publishing information of the target topic can be to broadcast the publishing information of the target topic, or publish the publishing information of the target topic to the target platform. The target platform can be a public platform accessible to any node (such as a terminal), or a public platform accessible to some nodes. By publishing the publishing information of the target topic, it is convenient for other nodes, such as subscription nodes, to know the target topic and the subscription conditions of the target topic.

[0087] As Figure 4As shown, the publishing verification process of the publishing node is shown. Before publishing content, the publishing node first needs to specify the subscription conditions that the subscription nodes of the content need to meet. The subscription conditions are used to describe a set of attributes (the set of attributes can be described by a boolean algebra access control policy, for example: A and B, A or B, etc.). After determining the target topic and subscription conditions for publishing, the publishing node can make the target topic and subscription conditions public so that the subscription nodes can determine whether they can subscribe to the target topic based on the public information.

[0088] After determining the target topic and subscription conditions, the publishing node requests to establish a TLS connection with the distribution node. During the TLS handshake process, the distribution node generates TEE code measurement information and embeds it in the extension field of the TLS certificate. The subscription node performs remote attestation when receiving the TLS certificate to verify the legitimacy of the running environment of the distribution node, and conducts publishing verification after the verification is successful.

[0089] Specifically, the publishing node requests to establish a first inquiry data packet for the data connection and sends it to the distribution node. Based on the first inquiry data packet, the distribution node sends a first response data packet including the measurement information of the execution environment to the publishing node. When receiving the first response data packet, the publishing node verifies the legitimacy of the execution environment based on the measurement information. When confirming that the execution environment is legitimate, the publishing node generates a second inquiry data packet and sends the second inquiry data packet to the distribution node. When receiving the second inquiry data packet sent by the terminal, the distribution node creates a publishing channel for data transmission with the publishing node.

[0090] After establishing the TLS connection, the publishing node sends a publishing request to the distribution node, including the target topic, subscription conditions, and the identity identifier of the publishing node. In response to the publishing request, the distribution node sends a second verification request to the blockchain nodes in the blockchain system based on the identity identifier of the publishing node and the second signature information. After receiving the second verification request, the blockchain calls the smart contract to perform the following verification steps: First, obtain the digital identity certificate of the publishing node according to the identity identifier of the publishing node; use the public key of the publishing node in the digital identity certificate of the publishing node to verify the second signature information to obtain the second verification result and return it to the distribution node. The distribution node confirms that the second verification result is verified successfully, associates and stores the target topic and subscription conditions, returns the result of successful publishing authentication to the publishing node, and maintains the connection of the publishing channel between the publishing node and the distribution node.

[0091] It should also be noted that if the second verification result indicates that the verification fails, the distribution node sends a publishing failure prompt message to the publishing node and closes the publishing channel between the distribution node and the publishing node.

[0092] Step S150: After the subscribing node verifies that the running environment in the distributing node is a trusted execution environment and establishes a subscription channel with the distributing node, the subscribing node sends a subscription request to the distributing node through the subscription channel.

[0093] The subscription request includes a target topic, a first signature information of the subscribing node, and a target verifiable expression, where the target verifiable expression is determined according to a verifiable claim corresponding to a target attribute of the subscribing node; the target attribute refers to an attribute that satisfies the subscription condition of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscribing node in the blockchain.

[0094] The target attribute of the subscribing node may be an attribute of the user to which the subscribing node belongs, such as one or more of the gender attribute of the user to which the subscribing node belongs, the work unit, the work section or department attribute, and the rank attribute, etc.

[0095] It should be understood that the subscription request may also include an identity identifier of the subscribing node or any identifier information that can identify the subscribing node.

[0096] The first signature information of the subscribing node may be obtained by signing at least one of the foregoing target topic, target verifiable expression, and identity identifier of the subscribing node based on the private key of the subscribing node.

[0097] The manner in which the subscribing node verifies that the running environment in the distributing node is a trusted execution environment may be: the subscribing node verifies that the running environment in the distributing node is a trusted execution environment based on the trusted measurement value included in the message sent by the distributing node, where the trusted measurement value is the code loaded by each program process in the distributing node and is obtained by performing trusted measurement using a hash algorithm. It may also be to receive at least part of the security feature information sent by the distributing node indicating whether the information is normal, where at least part of the information includes the device status information of the distributing node; in response to at least part of the security feature information being detected as normal, the running environment of the distributing node is determined to be secure. It should be understood that the above manners of determining the security of the distributing node are only illustrative, and there may be other confirmation manners, which are not specifically limited in the embodiments of the present application.

[0098] The manner in which the subscribing node establishes a channel with the distributing node may be to establish an Ethernet communication channel, an RS485 / RS422 communication channel, or a serial communication channel, etc. between the subscribing node and the distributing node, as long as it can ensure that the subscribing node can transmit data with the distributing node through the established communication channel between the two and is not disturbed by external devices.

[0099] In an implementable manner of the present application, the process of establishing a subscription channel between a subscription node and a distribution node can be similar to the process of establishing a publishing channel between a publishing node and a distribution node, that is, the types of the subscription channel and the publishing channel can be the same.

[0100] Among them, the digital identity certificate is stored in the blockchain node, and the specific storage process can be: receiving the digital identity certificate sent by the target node (such as, the subscription node), and storing it in the blockchain node together with the identity identifier of the corresponding node after consensus verification of the digital identity certificate.

[0101] The process of obtaining the digital identity certificate of the subscription node and storing it after consensus verification of the digital identity certificate of the subscription node should be similar to the process of obtaining the digital identity certificate of the publishing node and storing it after consensus verification of the digital identity certificate of the publishing node.

[0102] In an implementable manner, the blockchain node is the target management node in the institution to which the subscription node belongs. In the storage process of the digital identity certificate: the blockchain node receives a registration request sent by the subscription node, and the registration request includes the digital identity document of the subscription node, and the digital identity document includes the attributes of the subscription node and the signature public key of the subscription node; in response to the registration request, using the private key of the target management node to sign the digital identity document of the subscription node to obtain document signature information; based on the digital identity document of the subscription node and the document signature information, generating the digital identity certificate of the subscription node; performing consensus processing on the digital identity certificate of the subscription node, and writing the digital identity certificate of the subscription node into the blockchain after the consensus passes.

[0103] In this way, as Figure 5 shown, the subscription node can receive the user to fill in the registration information and generate the digital identity document of the subscription node. The digital identity document of the subscription node includes the attribute information that the user needs to disclose and the public key of the subscription node, and sends a registration request to the target management node in the institution to which the subscription node belongs. The registration request includes the digital identity document of the subscription node. The target management node registers an identity identifier for the subscription node by verifying the subscription node based on the user registration information. The identity identifier of the subscription node is bound to the digital identity document of the subscription node. Then, a proof field is added to the digital identity document of the subscription node, and the content of this field is the document signature information obtained by signing the digital identity document of the subscription node with the private key of the target management node. Thus, based on the digital identity document of the subscription node and the document signature information, the digital identity certificate of the subscription node is generated. Then, the target management node performs consensus processing on the digital identity certificate of the subscription node, and writes the digital identity certificate of the subscription node into the blockchain after the consensus passes. Then, a registration success result is generated and returned to the subscription node.

[0104] When obtaining a verifiable claim through attribute endorsement based on the digital identity certificate of a subscribing node in a blockchain, the blockchain node is the target management node in the organization to which the subscribing node belongs. The blockchain node can receive an attribute endorsement request sent by the subscribing node, where the attribute endorsement request includes the attributes to be endorsed by the subscribing node and the fourth signature information obtained by signing with the private key of the subscribing node; in response to the attribute endorsement request, obtain the digital identity certificate of the subscribing node from the blockchain; verify the document signature information in the digital identity certificate of the subscribing node through the public key of the target management node; verify the fourth signature information through the signature public key of the subscribing node in the digital identity certificate; if the document signature information in the digital identity certificate passes the verification, the fourth signature information passes the verification, and it is determined that the digital identity certificate of the subscribing node includes the attributes to be endorsed, generate a verifiable claim for the attributes to be endorsed; the verifiable claim includes the node identifier of the target management node, the attributes to be endorsed, and the third signature information obtained by signing the claim with the private key of the target management node; send the verifiable claim for the attributes to be endorsed to the subscribing node.

[0105] Specifically, as Figure 6 shown, the main purpose of subscriber attribute endorsement is to verify the authenticity of the attributes of the subscribing node. Exemplarily, in a certain medical data publishing system, if the publishing node restricts that only doctors in Department B of Hospital A can subscribe to the published content, then the subscribing node needs to have two attributes, namely Hospital A and doctors in Department B, and needs to obtain verifiable claims (VCs) for these two attributes. The following steps will describe the process by which the subscriber obtains the two attributes. The subscribing node sends an attribute endorsement request to the target management node in its affiliated organization, applying for verifiable credentials containing Attribute A and Attribute B. The attribute endorsement request includes the identity identifier of the subscribing node and the fourth signature information obtained by using the signature private key of the subscribing node.

[0106] After receiving the attribute endorsement request from the subscribing node, the target management node sends a query request to the blockchain system according to the identity identifier of the subscribing node, so that the blockchain system queries the digital identity certificate corresponding to the identity identifier of the subscribing node on the blockchain, and the blockchain returns the query result; afterwards, first verify the validity of the proof (document signature information) in the digital identity certificate (verify using the public key of the target management node of the institution to which the subscribing node corresponding to the digital identity certificate belongs), after verification, use the public key in the digital identity certificate of the subscribing node to verify the fourth signature information in the request, after verification, the target management node verifies whether the attributes to be endorsed of the subscribing node meet Attribute A and Attribute B through the attributes in the digital identity certificate of the subscribing node; if the verification passes, issue a verifiable claim VC to the subscribing node, and the VC includes information of the target management node (identifier of the target management node, claim issuance time and validity period), identity identifier of the subscribing node, attribute information of the subscribing node, and the third signature information obtained by signing the verifiable claim with the private key of the target management node. Afterwards, the above verifiable claim can also be returned to the subscribing node.

[0107] Step S160: In response to the subscription request, the distribution node sends a first verification request to the blockchain nodes in the blockchain system based on the target verifiable expression and the first signature information.

[0108] Among them, the first verification request includes the target verifiable expression and the first signature information. In an implementable manner, the first verification request may further include an identifier corresponding to the subscribing node.

[0109] Step S170: In response to the first verification request, the blockchain node verifies the target verifiable expression and the first signature information using the digital identity certificate of the subscribing node in the blockchain, obtains a first verification result, and sends the first verification result to the distribution node.

[0110] Among them, the above step S170 may specifically be to obtain the digital identity certificate corresponding to the identifier of the subscribing node from the blockchain. Invoke the first smart contract in the blockchain node to verify the target verifiable expression and the first signature information using the digital identity certificate of the subscribing node in the blockchain, and obtain a first verification result.

[0111] In an implementable manner, the digital identity certificate stores the attributes of the subscribing node and the public key of the subscribing node. The above step S170 may be to verify the signature of the first signature information using the public key of the subscribing node in the digital identity certificate of the subscribing node, and perform a matching verification on the attributes in the target verifiable expression using the attributes in the digital identity certificate of the subscribing node. Among them, if the signature verification of the first signature information passes and the subscription policy matches the attributes in the target verifiable expression, the first verification result is verification passed.

[0112] In another implementable manner, the public key of the target management node in the institution to which the subscription node belongs is also stored in the blockchain, the attributes of the subscription node and the public key of the subscription node are stored in the digital identity certificate, and the third signature information obtained by signing the statement with the private key of the target management node in the institution to which the subscription node belongs is further included in the target verifiable expression; when verifying the target verifiable expression and the first signature information by using the digital identity certificate of the subscription node, the specific verification process may be: verifying the first signature information by using the public key of the subscription node in the digital identity certificate of the subscription node; verifying the third signature information included in the target verifiable expression by using the public key of the target management node in the institution to which the subscription node belongs; and performing a matching verification on the attributes in the target verifiable expression by using the attributes in the digital identity certificate of the subscription node.

[0113] Wherein, if the verification of the first signature information passes, the verification of the third signature information passes, and the subscription policy matches the attributes in the target verifiable expression, the first verification result is verification passed.

[0114] In yet another implementable manner, in addition to verifying the first signature information and the second signature information and passing the verification and the subscription policy matching the attributes in the target verifiable expression, the valid subscription time period in the digital identity certificate can also be verified. Specifically, a timeliness verification is performed based on the request time when the first verification request is received and the valid subscription time period in the digital identity certificate of the subscription node. If the request time is within the valid subscription time period, and the verification of the first signature information passes, the verification of the third signature information passes, and the subscription policy matches the attributes in the target verifiable expression, the first verification result is verification passed.

[0115] Step S180: If the distribution node confirms that the first verification result indicates verification passed, add the identification information of the subscription node to the subscription list of the target topic, so as to distribute the content under the target topic to the subscription node through the subscription channel after the publishing node of the target topic publishes the content.

[0116] Wherein, if the first verification result indicates verification passed, it means that the subscription node meets the subscription conditions of the target topic and can subscribe to the content corresponding to the target topic. It should be understood that there can be subscription lists for multiple topics in the distribution node. By adding the identification information of the subscription node to the subscription list of the target topic, when the distribution node receives the content corresponding to the target topic, the subscription nodes corresponding to the target topic can be obtained by reading the list corresponding to the target topic, and the content corresponding to the target topic can be sent to the subscription node through the subscription channel between the subscription node and the distribution node.

[0117] Such as Figure 7As shown, the establishment process of the subscription channel between the subscription node and the distribution node is shown. The subscription node can obtain the target topic publicly announced by the publishing node and the subscription conditions of the target topic. When the subscription node determines that its own attributes meet the subscription conditions of the target topic, it can generate a target verifiable expression. Subsequently, the subscription node requests to establish a TLS connection with the distribution node. During the TLS handshake process, the distribution node generates TEE code measurement information and embeds it in the extension field of the TLS certificate. The subscription node performs remote attestation when receiving the TLS certificate to verify the legality of the operating environment of the distribution node.

[0118] Specifically, the subscription node requests the third inquiry data packet for establishing a data connection and sends it to the distribution node. Based on the third inquiry data packet, the distribution node sends the second response data packet including the measurement information of the execution environment to the terminal. When receiving the second response data packet, the subscription node verifies the legality of the execution environment based on the measurement information, and generates the fourth inquiry data packet when confirming the legality of the execution environment. When receiving the fourth inquiry data packet sent by the terminal, the distribution node creates a subscription channel for data transmission with the subscription node.

[0119] After establishing the TLS connection, the subscription node sends a subscription request to the distribution node, including the target topic, the first signature information of the subscription node, the identity identifier of the subscription node, and the target verifiable expression. In response to the subscription request, the distribution node sends a first verification request to the blockchain node in the blockchain system based on the target verifiable expression and the first signature information. After receiving the first verification request, the blockchain calls the smart contract to perform the following verification steps: First, obtain the digital identity certificate of the subscription node according to the identity identifier of the subscription node; verify the first signature information using the public key of the subscription node in the digital identity certificate of the subscription node; verify the third signature information included in the target verifiable expression using the public key of the target management node in the institution to which the subscription node belongs and perform a matching verification on the attributes in the target verifiable expression using the attributes in the digital identity certificate of the subscription node; and perform a timeliness verification according to the reception time of the first verification request and the valid subscription time period in the digital identity certificate, obtain the first verification result of the smart contract for the first signature information, the third signature information, the matching verification, and the timeliness verification, and feedback it to the distribution node. If the distribution node confirms that one of the verifications in the first signature information, the third signature information, the matching verification, and the invalidation verification in the first verification result fails, it returns a subscription failure to the subscription node and closes the subscription channel between the subscription node and the distribution node. If the first verification result indicates that the first signature information, the third signature information, the matching verification, and the invalidation verification all pass, record the identity identifier of the subscription node in the list corresponding to the subscription topic, return a subscription success result to the subscription node, and maintain the connection of the subscription channel between the subscription node and the distribution node at the same time.

[0120] By adopting the above method of the present application, since the verification process of the subscription node is to send a subscription request from the subscription node to the distribution node, so that the distribution node sends a first verification request to the blockchain node in response to the subscription request, so as to realize direct verification by the blockchain node based on the stored information (such as digital identity certificate), without relying on the target management node, thus greatly simplifying the verification process and improving the efficiency of information subscription and publication. In addition, before the content is published, the subscription node can only know the target topic to be published and the subscription conditions of the target topic, and needs to be verified on the blockchain before the subscription can be completed. After the subscription is completed, after the distribution node confirms that the content is published by the publishing node of the target topic, the content under the target topic is distributed to the subscription node through the subscription channel, so that only the subscription nodes that meet the subscription conditions can obtain the content corresponding to the target topic after passing the verification, while the subscription nodes that are not verified or do not meet the subscription conditions cannot perceive the published content, thus protecting the privacy of sensitive data publication and improving the privacy and security during the data publication process. In addition, during the publication and subscription process, by storing the digital identity certificates of the subscription node and the publishing node in the blockchain, the subscription node can obtain verifiable attributes and remove the dependence on the centralized institution.

[0121] In an implementable manner, in the content distribution system, if the subscription node cannot meet the subscription policy of the target topic because the institution revokes the verifiable credential of a certain attribute of the subscription node or the valid time of its verifiable credential has passed, the distribution node should also timely revoke the subscription permission of the subscription node and cancel the subscription channel of the subscriber. The content distribution method further includes:

[0122] Step S190: The target management node sends a statement revocation request for the first attribute sent by the subscription node to the blockchain node.

[0123] Among them, the target management node refers to the management node in the blockchain system used to manage the nodes in the institution to which the subscription node belongs; the statement revocation request can be generated by the target management node in response to the revocation operation of the verifiable credential of the first attribute of the subscription node, or can be generated by the target management node in response to the verifiable credential of the first attribute of the subscription node not being within the valid time limit. The verifiable statement of the first attribute is obtained by the target management node endorsing the first attribute of the subscription node based on the digital identity certificate of the subscription node. The first attribute can be any attribute that needs to be revoked, and the first attribute can be one or more. The statement revocation notice may include the identity identifier of the subscription node.

[0124] Step S200: The blockchain node responds to the statement revocation request, revokes the first attribute in the digital identity certificate of the subscription node in the blockchain, and generates a statement revocation notice.

[0125] Step S210: When the distribution node receives a statement revocation notice, if it confirms that the first attribute meets the subscription conditions of the target topic, in response to the statement revocation notice, it deletes the identification information of the subscription node from the subscriber list of the target topic.

[0126] By deleting the identification information of the subscription node from the subscriber list of the target topic, when the distribution node receives the content corresponding to the target topic sent by the publishing node through the publishing channel, it cannot read the identification information of the subscription node from the subscriber list of the target topic, thus canceling the publication of the content corresponding to the target topic to the subscription node.

[0127] As Figure 9 shown, it should be understood that the revocation of the subscription permission of the above subscription node depends on the revocation of the attributes of the subscription node in the blockchain node. The target management node can also maintain a public accumulator, which is stored on the blockchain, and the accumulator is used to record verifiable statements. In response to the statement revocation request sent by the target management node for the first attribute of the subscription node, after revoking the first attribute in the digital identity certificate of the subscription node in the blockchain, the blockchain system updates the accumulator and generates a statement revocation notice; and sends it to the distribution node, so that the distribution node deletes the identification information from the subscriber list of the target topic based on the identification information in the statement revocation notice, thereby realizing the revocation of the subscription permission of the subscription node.

[0128] Please refer to Figure 10 , Figure 10 shown. The present application also provides a content distribution method based on a blockchain system, which can be applied to the above-mentioned electronic device. The electronic device can be the distribution node in the above content distribution system. The method includes:

[0129] Step S310: After the subscription node verifies that the running environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node, it receives a subscription request sent by the subscription node based on the subscription channel.

[0130] Among them, the subscription request includes a target topic, the first signature information of the subscription node, and a target verifiable expression. The target verifiable expression is determined according to the verifiable statement corresponding to the target attribute of the subscription node; the target attribute refers to the attribute that meets the subscription conditions of the target topic; the verifiable statement is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain.

[0131] Step S320: Based on the target verifiable expression and the first signature information, send a first verification request to the blockchain node in the blockchain system, so that the blockchain node uses the digital identity certificate of the subscription node in the blockchain to verify the target verifiable expression and the first signature information, and obtains a first verification result.

[0132] Step S330: Receive the first verification result returned by the blockchain node.

[0133] Step S340: If the first verification result indicates that the verification is passed, add the identification information of the subscription node to the subscription list of the target topic, so that after the publishing node of the target topic publishes the content, the content under the target topic is distributed to the subscription node through the subscription channel.

[0134] In an implementable manner, after receiving the first verification result returned by the blockchain node, the method further includes: if the first verification result indicates that the verification fails, send a subscription failure prompt message to the subscription node, and close the subscription channel between the distribution node and the subscription node.

[0135] By closing the subscription channel between the distribution node and the subscription node when the first verification result indicates that the verification fails, the situation of occupying resources in the subscription channel can be effectively avoided.

[0136] For the specific descriptions of the above steps S310 - S340, reference can be made to the specific descriptions of steps S150 - S180 in the previous text, which will not be elaborated one by one in this embodiment.

[0137] As Figure 11 shown, in an implementable manner, before receiving the subscription request sent by the subscription node based on the subscription channel, the method further includes:

[0138] Step S350: After the publishing node verifies that the running environment in the distribution node is a trusted execution environment and establishes a publishing channel with the distribution node, receive the publishing request sent by the publishing node based on the publishing channel.

[0139] The publishing request includes the target topic, the subscription condition, and the second signature information of the publishing node.

[0140] Step S360: Send a second verification request to the blockchain node based on the second signature information, so that the blockchain node verifies the second signature information by using the digital identity certificate of the publishing node in the blockchain to obtain a second verification result.

[0141] Step S370: Receive the second verification result returned by the blockchain node.

[0142] Step S380: If the second verification result indicates that the verification is passed, publish the publishing information of the target topic, where the publishing information includes the target topic and the subscription condition of the target topic.

[0143] In an implementable manner, after receiving the second verification result returned by the blockchain node, the method further includes: if the second verification result indicates that the verification fails, sending a publishing failure prompt message to the publishing node and closing the publishing channel between the distribution node and the publishing node.

[0144] For the specific descriptions of steps S350 - S380, reference can be made to the specific descriptions of steps S110 - S140 in the foregoing, which will not be elaborated herein one by one in this embodiment.

[0145] In an implementable manner, the digital identity certificate includes the attributes publicly disclosed by the node; the method further includes:

[0146] Receiving a statement revocation notice sent by the blockchain system, where the statement revocation notice is generated after the blockchain system revokes the first attribute in the digital identity certificate of the subscription node in response to a statement revocation request sent by the target management node for the first attribute of the subscription node; the target management node refers to the management node in the blockchain system for managing the nodes in the institution to which the subscription node belongs, and the verifiable statement of the first attribute is obtained by the target management node endorsing the first attribute of the subscription node based on the digital identity certificate of the subscription node. If the first attribute meets the subscription conditions of the target topic, in response to the statement revocation notice, deleting the identification information of the subscription node from the subscriber list of the target topic.

[0147] For the above - mentioned association process of the identification information of the subscription node, reference can be made to the specific descriptions of steps S190 - S210 in the foregoing, which will not be elaborated herein one by one in this embodiment.

[0148] Please refer to Figure 12 , Figure 12 As shown in, the present application further provides a content distribution method based on a blockchain system, which can be applied to a blockchain node. The method includes:

[0149] Step S410: Receiving a first verification request sent by the distribution node.

[0150] The first verification request is generated by the distribution node in response to a subscription request sent by the subscription node, based on the target verifiable expression and the first signature information in the subscription request; the subscription request further includes the target topic; after the subscription node verifies that the running environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node, it sends a subscription request to the distribution node based on the subscription channel; the target verifiable expression is determined according to the verifiable statement corresponding to the target attribute of the subscription node; the target attribute refers to the attribute that meets the subscription conditions of the target topic; the verifiable statement is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain;

[0151] Step S420: Obtaining the digital identity certificate of the subscription node from the blockchain;

[0152] Step S430: Verify the target verifiable expression and the first signature information by using the digital identity certificate of the subscription node to obtain a first verification result.

[0153] In an implementable manner, step S430 includes: verifying the first signature information by using the public key of the subscription node in the digital identity certificate of the subscription node; verifying the third signature information included in the target verifiable expression by using the public key of the target management node in the institution to which the subscription node belongs; and performing a matching verification on the attributes in the target verifiable expression by using the attributes in the digital identity certificate of the subscription node.

[0154] Step S440: Send the first verification result to the distribution node, so that after the first verification result indicates that the verification is passed, the distribution node adds the identification information of the subscription node to the subscription list of the target topic, so as to distribute the content under the target topic to the subscription node through the subscription channel after the content corresponding to the target topic is published by the publishing node.

[0155] For the specific descriptions of the above steps S410 - S440, reference can be made to the specific descriptions of steps S150 - S180 in the foregoing, and details will not be repeated in this embodiment.

[0156] As Figure 13 shown, in an implementable manner, before receiving the first verification request sent by the distribution node, the method further includes:

[0157] Step S450: Receive a second verification request sent by the distribution node.

[0158] The second verification request is generated by the distribution node in response to the publishing request sent by the publishing node; after verifying that the running environment in the distribution node is a trusted execution environment and establishing a publishing channel with the distribution node, the publishing node sends a publishing request to the distribution node based on the publishing channel; the publishing request further includes the target topic and the subscription condition;

[0159] Step S460: Obtain the digital identity certificate of the publishing node from the blockchain.

[0160] Step S470: Verify the second signature information according to the digital identity certificate of the publishing node to obtain a second verification result.

[0161] Step S480: Send the second verification result to the distribution node, so that after determining that the second verification result indicates that the verification is passed, the distribution node publishes the publishing information of the target topic, and the publishing information includes the target topic and the subscription condition of the target topic.

[0162] For the specific descriptions of the above steps S450 - S480, please refer to the specific descriptions of steps S110 - S140 in the previous text, which will not be elaborated one by one in this embodiment.

[0163] Please refer to Figure 14 , in an implementable manner, the blockchain node is the target management node in the institution to which the subscription node belongs; before receiving the first verification request sent by the distribution node, the method further includes:

[0164] Step S510: Receive a registration request sent by the subscription node.

[0165] The registration request includes the digital identity document of the subscription node, and the digital identity document includes the attributes of the subscription node and the signature public key of the subscription node.

[0166] Step S520: In response to the registration request, use the private key of the target management node to sign the digital identity document of the subscription node to obtain document signature information.

[0167] Step S530: Based on the digital identity document of the subscription node and the document signature information, generate a digital identity certificate for the subscription node.

[0168] Step S540: Perform a consensus process on the digital identity certificate of the subscription node, and write the digital identity certificate of the subscription node into the blockchain after the consensus is passed.

[0169] For the specific descriptions of the above steps S510 - S540, please refer to the specific descriptions of obtaining the digital identity certificate and storing it in the blockchain in step S150 in the previous text, which will not be elaborated one by one in this embodiment.

[0170] Please refer to Figure 15 , in an implementable manner, the above method further includes:

[0171] Step S550: Receive an attribute endorsement request sent by the subscription node.

[0172] The attribute endorsement request includes the attributes to be endorsed by the subscription node and the fourth signature information obtained by signing with the private key of the subscription node.

[0173] Step S560: In response to the attribute endorsement request, obtain the digital identity certificate of the subscription node from the blockchain.

[0174] Step S570: Verify the document signature information in the digital identity certificate of the subscription node through the public key of the target management node.

[0175] Step S580: Verify the fourth signature information through the signature public key of the subscription node in the digital identity certificate.

[0176] Step S590: If the document signature information in the digital identity certificate is verified successfully, the fourth signature information is verified successfully, and it is determined that the digital identity certificate of the subscription node includes the attribute to be endorsed, generate a verifiable claim for the attribute to be endorsed.

[0177] The verifiable claim includes the node identifier of the target management node, the attribute to be endorsed, and the third signature information obtained by signing the claim with the private key of the target management node.

[0178] Step S600: Send the verifiable claim of the attribute to be endorsed to the subscription node.

[0179] For the specific descriptions of the above steps S550 - S600, reference can be made to the descriptions of the part of endorsing the attribute to be endorsed in step S150 in the foregoing text, which will not be elaborated herein in this embodiment.

[0180] It should be understood that although the steps in the flowcharts involved in the above embodiments are shown in sequence according to the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless otherwise clearly stated in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0181] Please refer to Figure 16, Another embodiment of the present application provides a content distribution device 700 based on a blockchain system, which is applied to a distribution node. The device 700 includes: a first request receiving module 710, a first request sending module 720, a verification result receiving module 730, and an identification adding module 740. The first request receiving module 710 is configured to receive a subscription request sent by a subscription node based on a subscription channel after the subscription node verifies that the operating environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node; the subscription request includes a target topic, a first signature information of the subscription node, and a target verifiable expression, and the target verifiable expression is determined according to a verifiable claim corresponding to the target attribute of the subscription node; the target attribute refers to an attribute that satisfies the subscription condition of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; the first request sending module 720 is configured to send a first verification request to a blockchain node in the blockchain system based on the target verifiable expression and the first signature information, so that the blockchain node uses the digital identity certificate of the subscription node in the blockchain to verify the target verifiable expression and the first signature information and obtain a first verification result; the verification result receiving module 730 is configured to receive the first verification result returned by the blockchain node; the identification adding module 740 is configured to add the identification information of the subscription node to the subscription list of the target topic when the first verification result indicates that the verification is passed, so as to distribute the content under the target topic to the subscription node through the subscription channel after the publishing node publishes the content of the target topic.

[0182] In an implementable manner, the device 400 further includes a content distribution module. The first request receiving module 710 is further configured to receive a publishing request sent by a publishing node based on a publishing channel after the publishing node verifies that the operating environment in the distribution node is a trusted execution environment and establishes a publishing channel with the distribution node; the publishing request includes a target topic, a subscription condition, and a second signature information of the publishing node; the first request sending module 720 is further configured to send a second verification request to the blockchain node based on the second signature information, so that the blockchain node uses the digital identity certificate of the publishing node in the blockchain to verify the second signature information and obtain a second verification result; the verification result receiving module 730 is further configured to receive the second verification result returned by the blockchain node; the content distribution module is configured to publish the publishing information of the target topic when the second verification result indicates that the verification is passed, and the publishing information includes the target topic and the subscription condition of the target topic.

[0183] In an implementable manner, the device 700 further includes a publishing channel closing module, which is configured to send a publishing failure prompt message to the publishing node and close the publishing channel between the distribution node and the publishing node when the second verification result indicates that the verification fails.

[0184] In an implementable manner, the device 700 further includes a subscription channel closing module, configured to send a subscription failure prompt message to the subscription node when the first verification result indicates that the verification fails, and close the subscription channel between the distribution node and the subscription node.

[0185] Please refer to Figure 17 , an embodiment of the present application provides a content distribution device 800 based on a blockchain system, which is applied to a blockchain node in the blockchain system. The device 800 includes: a second request receiving module 810, a certificate obtaining module 820, an information verification module 830, and a verification result sending module 840; the second request receiving module 810 is configured to receive a first verification request sent by the distribution node; the first verification request is generated by the distribution node in response to a subscription request sent by the subscription node, according to the target verifiable expression and the first signature information in the subscription request; the subscription request further includes a target topic; after the subscription node verifies that the running environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node, it sends a subscription request to the distribution node based on the subscription channel; the target verifiable expression is determined according to the verifiable claim corresponding to the target attribute of the subscription node; the target attribute refers to the attribute that satisfies the subscription condition of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; the certificate obtaining module 820 is configured to obtain the digital identity certificate of the subscription node from the blockchain; the information verification module 830 uses the digital identity certificate of the subscription node to verify the target verifiable expression and the first signature information to obtain a first verification result; the verification result sending module 840 is configured to send the first verification result to the distribution node, so that after the first verification result indicates that the verification is passed, the distribution node adds the identification information of the subscription node to the subscription list of the target topic, so as to distribute the content under the target topic to the subscription node through the subscription channel after the content corresponding to the target topic is published by the publishing node.

[0186] In an implementable manner, the information verification module 830 is further configured to verify the signature of the first signature information using the public key of the subscription node in the digital identity certificate of the subscription node; verify the signature of the third signature information included in the target verifiable expression using the public key of the target management node in the institution to which the subscription node belongs; and perform a matching verification on the attributes in the target verifiable expression using the attributes in the digital identity certificate of the subscription node.

[0187] In an implementable manner, the second request receiving module 810 is further configured to receive a second verification request sent by a distribution node, where the second verification request is generated by the distribution node in response to a publishing request sent by a publishing node according to second signature information in the publishing request; after verifying that the operating environment in the distribution node is a trusted execution environment and establishing a publishing channel with the distribution node, the publishing node sends a publishing request to the distribution node based on the publishing channel; the publishing request further includes a target topic and subscription conditions; the certificate acquisition module 820 is further configured to obtain a digital identity certificate of the publishing node from the blockchain; the information verification module 830 is further configured to verify the second signature information according to the digital identity certificate of the publishing node to obtain a second verification result; the verification result sending module 840 is further configured to send the second verification result to the distribution node, so that after determining that the second verification result indicates verification passed, the distribution node publishes the publishing information of the target topic, where the publishing information includes the target topic and the subscription conditions of the target topic.

[0188] In an implementable manner, the blockchain node is a target management node in the organization to which the subscription node belongs; the apparatus 800 further includes a registration request receiving module, a document signature module, a certificate generation module, and a consensus processing module. The registration request receiving module is configured to receive a registration request sent by the subscription node, where the registration request includes a digital identity document of the subscription node, and the digital identity document includes the attributes of the subscription node and the signature public key of the subscription node; the document signature module is configured to, in response to the registration request, sign the digital identity document of the subscription node with the private key of the target management node to obtain document signature information; the certificate generation module is configured to generate a digital identity certificate of the subscription node based on the digital identity document of the subscription node and the document signature information; the consensus processing module is configured to perform consensus processing on the digital identity certificate of the subscription node, and write the digital identity certificate of the subscription node into the blockchain after the consensus passes.

[0189] In an implementable manner, the apparatus 800 further includes: an endorsement request receiving module, a certificate acquisition module, a signature verification module, a claim generation module, and a claim sending module. The endorsement request receiving module is configured to receive an attribute endorsement request sent by a subscribing node, where the attribute endorsement request includes the attributes to be endorsed by the subscribing node and fourth signature information obtained by signing with the private key of the subscribing node; the certificate acquisition module is configured to, in response to the attribute endorsement request, acquire the digital identity certificate of the subscribing node from the blockchain; the signature verification module is configured to verify the document signature information in the digital identity certificate of the subscribing node through the public key of the target management node; the signature verification module is further configured to verify the fourth signature information through the signature public key of the subscribing node in the digital identity certificate; the claim generation module is configured to, if the document signature information in the digital identity certificate is verified successfully, the fourth signature information is verified successfully, and it is determined that the digital identity certificate of the subscribing node includes the attributes to be endorsed, generate a verifiable claim for the attributes to be endorsed; the verifiable claim includes the node identifier of the target management node, the attributes to be endorsed, and third signature information obtained by signing the claim with the private key of the target management node; the claim sending module is configured to send the verifiable claim for the attributes to be endorsed to the subscribing node.

[0190] Each module in the above apparatus can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the electronic device in hardware form or be independent of it, or can be stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to the above modules. It should be noted that the apparatus embodiments in this application correspond to the foregoing method embodiments. The specific principles in the apparatus embodiments can be referred to in the content of the foregoing method embodiments and will not be elaborated here.

[0191] Next, Figure 18 an electronic device provided in this application will be described.

[0192] Please refer to Figure 18 , based on the content distribution method of the molecular attribute-based blockchain system provided in the foregoing embodiments, another electronic device 100 provided in the embodiments of this application includes a processor 102 that can execute the foregoing method. The electronic device 100 can be a distribution node or a blockchain node. The electronic device can be a terminal device or a server. Among them, the terminal device can be a smart phone, a tablet computer, a computer, or a portable computer, etc.

[0193] The electronic device 100 further includes a memory 104. Among them, a program that can execute the content in the foregoing embodiments is stored in the memory 104, and the processor 102 can execute the program stored in the memory 104.

[0194] Among them, the processor 102 may include one or more cores for processing data and a message matrix unit. The processor 102 connects various parts within the entire electronic device 100 through various interfaces and lines, and executes various functions of the electronic device 100 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 104, and by calling the data stored in the memory 104. Optionally, the processor 102 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 102 may integrate a combination of one or several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the displayed content; the modem is used to process wireless communication. It can be understood that the above modem may not be integrated into the processor 102 and may be implemented separately through a communication chip.

[0195] The memory 104 may include random access memory (RAM) and may also include read-only memory. The memory 104 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 104 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for implementing at least one function, instructions for implementing the following various method embodiments, etc. The data storage area may also store data obtained during the use of the electronic device 100 (such as digital identity certificates), etc.

[0196] The electronic device 100 may further include a network module and a screen. The network module is used to receive and send electromagnetic waves, realize the mutual conversion between electromagnetic waves and electrical signals, so as to communicate with a communication network or other devices, such as communicating with an audio playback device. The network module may include various existing circuit elements for performing these functions, such as antennas, radio frequency transceivers, digital signal processors, encryption / decryption chips, subscriber identity module (SIM) cards, memories, and the like. The network module can communicate with various networks such as the Internet, enterprise intranets, wireless networks or communicate with other devices through a wireless network. The above-mentioned wireless network may include a cellular phone network, a wireless local area network or a metropolitan area network. The screen can display interface content and perform data interaction, such as displaying the predicted results of the molecular properties of the audio to be recognized, and inputting audio through the screen, etc.

[0197] In some embodiments, the electronic device 100 may further include: a peripheral interface 106 and at least one peripheral device. The processor 102, the memory 104 and the peripheral interface 106 may be connected by a bus or signal lines. Each peripheral device may be connected to the peripheral interface through a bus, signal lines or a circuit board. Specifically, the peripheral devices include at least one of a radio frequency component 108, a positioning component 112, a camera 114, an audio component 116, a display screen 118, and a power supply 122, etc.

[0198] The peripheral interface 106 can be used to connect at least one peripheral device related to I / O (Input / Output) to the processor 102 and the memory 104. In some embodiments, the processor 102, the memory 104 and the peripheral interface 106 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 102, the memory 104 and the peripheral interface 106 can be implemented on a separate chip or circuit board, and the embodiments of the present application do not limit this.

[0199] The radio frequency component 108 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency component 108 communicates with a communication network and other communication devices through electromagnetic signals. The radio frequency component 108 converts an electrical signal into an electromagnetic signal for transmission, or converts the received electromagnetic signal into an electrical signal. Optionally, the radio frequency component 108 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, and so on. The radio frequency component 108 can communicate with other terminals through at least one wireless communication protocol. The wireless communication protocol includes but is not limited to: the World Wide Web, a metropolitan area network, an intranet, various generations of mobile communication networks (2G, 3G, 4G, and 5G), a wireless local area network, and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency component 108 may further include a circuit related to NFC (Near Field Communication), which is not limited in this application.

[0200] The positioning component 112 is used to locate the current geographical location of the electronic device to implement navigation or LBS (Location-Based Service). The positioning component 112 can be a positioning component based on the US GPS (Global Positioning System), the Beidou system, or the Galileo system.

[0201] The camera 114 is used to capture images or videos. Optionally, the camera 114 includes a front camera and a rear camera. Generally, the front camera is disposed on the front panel of the electronic device 100, and the rear camera is disposed on the back of the electronic device 100. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth camera, a wide-angle camera, and a telephoto camera, to implement the function of background blurring by fusing the main camera and the depth camera, panoramic shooting by fusing the main camera and the wide-angle camera, and VR (Virtual Reality) shooting function or other fusion shooting functions. In some embodiments, the camera 114 may further include a flash. The flash can be a single-color temperature flash or a two-color temperature flash. The two-color temperature flash refers to the combination of a warm light flash and a cold light flash, which can be used for light compensation under different color temperatures.

[0202] The audio component 116 may include a microphone and a speaker. The microphone is used to collect sound waves of the user and the environment, and convert the sound waves into electrical signals for input to the processor 102 for processing, or input to the radio frequency component 108 to achieve voice communication. For the purpose of stereo collection or noise reduction, there may be multiple microphones, which are respectively arranged at different parts of the electronic device 100. The microphone may also be an array microphone or an omnidirectional collection microphone. The speaker is used to convert the electrical signal from the processor 102 or the radio frequency component 108 into sound waves. The speaker may be a traditional thin film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signal into sound waves audible to humans, but also convert the electrical signal into inaudible sound waves for uses such as ranging. In some embodiments, the audio component 114 may also include a headphone jack.

[0203] The display screen 118 is used to display the UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When the display screen 118 is a touch display screen, the display screen 118 also has the ability to collect touch signals on or above the surface of the display screen 118. The touch signal can be input to the processor 102 as a control signal for processing. At this time, the display screen 118 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there may be one display screen 118, which is arranged on the front panel of the electronic device 100; in other embodiments, there may be at least two display screens 118, which are respectively arranged on different surfaces of the electronic device 100 or in a foldable design; in still other embodiments, the display screen 118 may be a flexible display screen, which is arranged on the curved surface or the folding surface of the electronic device 100. Even, the display screen 118 can also be set as an irregular non-rectangular shape, that is, a special-shaped screen. The display screen 118 can be prepared using materials such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode).

[0204] The power supply 122 is used to supply power to each component in the electronic device 100. The power supply 122 may be alternating current, direct current, a disposable battery, or a rechargeable battery. When the power supply 122 includes a rechargeable battery, the rechargeable battery may be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery charged through a wired line, and a wireless rechargeable battery is a battery charged through a wireless coil. The rechargeable battery can also be used to support fast charging technology.

[0205] The embodiment of the present application further provides a structural block diagram of a computer-readable storage medium. Program code is stored in the computer-readable medium, and the program code can be called by a processor to execute the method described in the above method embodiment.

[0206] The computer-readable storage medium may be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk, or a ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium has a storage space for program code for performing any method step in the above method. These program codes can be read from or written into one or more computer program products. The program code can be compressed in a suitable form, for example.

[0207] The embodiment of the present application further provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the method described in the above various optional implementation manners.

[0208] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A content distribution method based on a blockchain system, characterized in that Applied to a distribution node, the method includes: After verifying that the running environment in the distribution node is a trusted execution environment at the subscription node and establishing a subscription channel with the distribution node, receiving a subscription request sent by the subscription node based on the subscription channel; the subscription request includes a target topic, first signature information of the subscription node, and a target verifiable expression, where the target verifiable expression is determined according to a verifiable claim corresponding to the target attribute of the subscription node; the target attribute refers to an attribute that meets the subscription conditions of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; Sending a first verification request to a blockchain node in the blockchain system based on the target verifiable expression and the first signature information, so that the blockchain node uses the digital identity certificate of the subscription node in the blockchain to verify the target verifiable expression and the first signature information, and obtains a first verification result; Receiving the first verification result returned by the blockchain node; If the first verification result indicates that the verification is passed, adding the identification information of the subscription node to the subscription list of the target topic, so that after the content is published by the publishing node of the target topic, the content under the target topic is distributed to the subscription node through the subscription channel.

2. The method according to claim 1, wherein Before receiving the subscription request sent by the subscription node based on the subscription channel, the method further includes: After verifying that the running environment in the distribution node is a trusted execution environment at the publishing node and establishing a publishing channel with the distribution node, receiving a publishing request sent by the publishing node based on the publishing channel; the publishing request includes the target topic, the subscription conditions, and second signature information of the publishing node; Sending a second verification request to a blockchain node based on the second signature information, so that the blockchain node uses the digital identity certificate of the publishing node in the blockchain to verify the second signature information, and obtains a second verification result; Receiving the second verification result returned by the blockchain node; If the second verification result indicates that the verification is passed, publishing the publishing information of the target topic, where the publishing information includes the target topic and the subscription conditions of the target topic.

3. The method according to claim 1, characterized in that The digital identity certificate includes publicly disclosed attributes of the node; the method further includes: Receiving a claim revocation notice sent by the blockchain system, where the claim revocation notice is generated after the blockchain system revokes the first attribute in the digital identity certificate of the subscription node in the blockchain in response to a claim revocation request sent by a target management node for the first attribute of the subscription node; the target management node refers to a management node in the blockchain system for managing nodes in the organization to which the subscription node belongs, and the verifiable claim of the first attribute is obtained by the target management node endorsing the first attribute of the subscription node based on the digital identity certificate of the subscription node; If the first attribute meets the subscription conditions of the target topic, in response to the revocation notice of the statement, delete the identification information of the subscription node from the subscriber list of the target topic.

4. The method according to claim 2, wherein After receiving the second verification result returned by the blockchain node, the method further includes: If the second verification result indicates that the verification fails, send a publishing failure prompt message to the publishing node, and close the publishing channel between the distribution node and the publishing node.

5. The method according to claim 1, characterized in that After receiving the first verification result returned by the blockchain node, the method further includes: If the first verification result indicates that the verification fails, send a subscription failure prompt message to the subscription node, and close the subscription channel between the distribution node and the subscription node.

6. A content distribution method based on a blockchain system, characterized in that, Applied to a blockchain node in a blockchain system, the method includes: Receive a first verification request sent by a distribution node; the first verification request is generated by the distribution node in response to a subscription request sent by a subscription node, based on a target verifiable expression and first signature information in the subscription request; the subscription request further includes a target topic; after the subscription node verifies that the running environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node, the subscription request is sent to the distribution node based on the subscription channel; the target verifiable expression is determined according to a verifiable statement corresponding to the target attribute of the subscription node; the target attribute refers to an attribute that meets the subscription conditions of the target topic; the verifiable statement is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain. Obtain the digital identity certificate of the subscription node from the blockchain. Verify the target verifiable expression and the first signature information using the digital identity certificate of the subscription node to obtain a first verification result. Send the first verification result to the distribution node, so that after the first verification result indicates that the verification is passed, the distribution node adds the identification information of the subscription node to the subscription list of the target topic, so that after the content is published by the publishing node corresponding to the target topic, the content under the target topic is distributed to the subscription node through the subscription channel.

7. The method according to claim 6, characterized in that, Before receiving the first verification request sent by the distribution node, the method further includes: Receive a second verification request sent by the distribution node, the second verification request is generated by the distribution node in response to a publishing request sent by a publishing node, based on second signature information in the publishing request; after the publishing node verifies that the running environment in the distribution node is a trusted execution environment and establishes a publishing channel with the distribution node, the publishing request is sent to the distribution node based on the publishing channel; the publishing request further includes the target topic and the subscription conditions. Obtain the digital identity certificate of the publishing node from the blockchain. Verify the second signature information according to the digital identity certificate of the publishing node to obtain a second verification result. Send the second verification result to the distribution node, so that after the distribution node determines that the second verification result indicates successful verification, it publishes the release information of the target topic, where the release information includes the target topic and the subscription conditions of the target topic.

8. The method according to claim 6, wherein The blockchain node is the target management node in the institution to which the subscription node belongs; Before receiving the first verification request sent by the distribution node, the method further includes: Receive a registration request sent by the subscription node, where the registration request includes a digital identity document of the subscription node, and the digital identity document includes the attributes of the subscription node and the signature public key of the subscription node; In response to the registration request, use the private key of the target management node to sign the digital identity document of the subscription node to obtain document signature information; Generate a digital identity certificate for the subscription node based on the digital identity document of the subscription node and the document signature information; Perform a consensus process on the digital identity certificate of the subscription node, and after the consensus is passed, write the digital identity certificate of the subscription node into the blockchain.

9. The method according to claim 8, wherein The method further includes: Receive an attribute endorsement request sent by the subscription node, where the attribute endorsement request includes the attribute to be endorsed by the subscription node and the fourth signature information obtained by signing through the private key of the subscription node; In response to the attribute endorsement request, obtain the digital identity certificate of the subscription node from the blockchain; Verify the document signature information in the digital identity certificate of the subscription node through the public key of the target management node; Verify the fourth signature information through the signature public key of the subscription node in the digital identity certificate; If the document signature information in the digital identity certificate is verified successfully, the fourth signature information is verified successfully, and it is determined that the digital identity certificate of the subscription node includes the attribute to be endorsed, generate a verifiable claim for the attribute to be endorsed; the verifiable claim includes the node identifier of the target management node, the attribute to be endorsed, and the third signature information obtained by signing the claim based on the private key of the target management node; Send the verifiable claim for the attribute to be endorsed to the subscription node.

10. The method according to claim 9, characterized in that, The verification of the target verifiable expression and the first signature information by using the digital identity certificate of the subscription node includes: Verify the first signature information through the public key of the subscription node in the digital identity certificate of the subscription node; Verify the third signature information included in the target verifiable expression through the public key of the target management node in the institution to which the subscription node belongs; Perform a matching verification on the attributes in the target verifiable expression by using the attributes in the digital identity certificate of the subscription node.

11. A content distribution device based on a blockchain system, characterized in that, Applied to a distribution node, the device includes: A first request receiving module, configured to receive a subscription request sent by the subscription node based on the subscription channel after the subscription node verifies that the running environment in the distribution node is a trusted execution environment and establishes a subscription channel with the distribution node; the subscription request includes a target topic, a first signature information of the subscription node, and a target verifiable expression, where the target verifiable expression is determined according to a verifiable claim corresponding to a target attribute of the subscription node; the target attribute refers to an attribute that satisfies the subscription condition of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; A first request sending module, configured to send a first verification request to a blockchain node in the blockchain system based on the target verifiable expression and the first signature information, so that the blockchain node uses the digital identity certificate of the subscription node in the blockchain to verify the target verifiable expression and the first signature information, and obtains a first verification result; A verification result receiving module, configured to receive the first verification result returned by the blockchain node; An identification adding module, configured to add the identification information of the subscription node to the subscription list of the target topic when the first verification result indicates that the verification is passed, so as to distribute the content under the target topic to the subscription node through the subscription channel after the publishing node of the target topic publishes the content.

12. A content distribution device based on a blockchain system, characterized in that, Applied to a blockchain node in a blockchain system, the device includes: A second request receiving module, configured to receive a first verification request sent by a distribution node; the first verification request is generated by the distribution node in response to a subscription request sent by the subscription node, according to the target verifiable expression and the first signature information in the subscription request; the subscription request further includes a target topic; the subscription node sends the subscription request to the distribution node based on the subscription channel after verifying that the running environment in the distribution node is a trusted execution environment and establishing a subscription channel with the distribution node; the target verifiable expression is determined according to a verifiable claim corresponding to a target attribute of the subscription node; the target attribute refers to an attribute that satisfies the subscription condition of the target topic; the verifiable claim is obtained by endorsing the attribute based on the digital identity certificate of the subscription node in the blockchain; A certificate obtaining module, configured to obtain the digital identity certificate of the subscription node from the blockchain; An information verification module, configured to verify the target verifiable expression and the first signature information by using the digital identity certificate of the subscription node, and obtain a first verification result; A verification result sending module, configured to send the first verification result to the distribution node, so that after the first verification result indicates that the verification is passed, the distribution node adds the identification information of the subscription node to the subscription list of the target topic, so as to distribute the content under the target topic to the subscription node through the subscription channel after the publishing node corresponding to the target topic publishes the content.

13. An electronic device, characterized in that, Includes: One or more processors; A memory; One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1-5 or 6-10.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program code, and the program code can be called by a processor to execute the method according to any one of claims 1-5 or 6-10.

15. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1-5 or 6-10 are implemented.