Data processing method and device based on block chain, equipment, medium and product

By calling the data signature service program in the blockchain business to hide the signature key and recovering the signature key reconstruction service program in the event of failure, the problem that the signature key management method cannot ensure both security and functionality is solved, and the security and recovery of the signature key are achieved.

CN120337237APending Publication Date: 2025-07-18TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410068813.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-17
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the prior art, the management method of signature key cannot be effectively used to sign while ensuring the security of storage, the front-end management method cannot guarantee security, and the back-end management method cannot be combined with the signature function.

Method used

By calling the data signature service program to sign the uploaded business data, hiding the signature key, and calling the key recovery service program to restore the signature key when it fails, rebuilding the data signature service program to complete the signature.

Benefits of technology

It realizes that while ensuring the security of the signature key storage, it can effectively use the signature key to sign, and supports the restorability of the signature key to ensure the normal operation of the signature function.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337237A_ABST
    Figure CN120337237A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data processing method and device based on a block chain, equipment, a medium and a product. The data processing method based on the block chain comprises the following steps: calling a data signature service program to sign business data to be uploaded to the block chain; the data signature service program is created based on the signature key, and the signature key is hidden when the data signature service program performs signature based on the signature key; if the calling of the data signature service program fails, calling a key recovery service program to recover the signature key; reconstructing a data signature service program according to the recovered signature key; and calling the reconstructed data signature service program to sign the business data, and uploading the signed business data to the block chain. By adopting the embodiment of the invention, the signature key can be used for signature on the premise of ensuring the storage security of the signature key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, especially the field of blockchain technology, and particularly relates to a data processing method, apparatus, device, medium and product based on blockchain. Background Art

[0002] When blockchain services interact with a blockchain, signature keys are usually required. The specific usage method is to use the signature key to sign the service data to be uploaded to the blockchain in the blockchain service. Currently, the management methods of signature keys can be divided into two categories. The first category is the front-end management method of blockchain services, and the second category is the back-end management method of blockchain services.

[0003] In the front-end management method of blockchain services, the signature key is in the environment of the business object. The signature process requires mutual operations with the business object, and the security protection factor needs to be combined with the characteristics or information of the business object. That is to say, in the front-end management method of blockchain services, the security of the environment where the signature key is stored is not trusted, and the security of storing the signature key cannot be guaranteed. In the back-end management method of blockchain services, the signature key is in the server environment and is usually paired with the security measures of the server itself (the security measures can be, for example, firewalls, network security policies, and file system permission management, etc.). However, the back-end management method of blockchain services usually cannot be combined with the signature function of the signature key. That is to say, in the back-end management method of blockchain services, the security of storing the signature key can be guaranteed, but the signature key cannot perform the signature function. It can be seen that the current management methods of signature keys cannot use the signature key to sign while ensuring the security of storing the signature key. Summary of the Invention

[0004] Embodiments of this application provide a data processing method, apparatus, device, medium and product based on blockchain, which can use the signature key to sign while ensuring the security of storing the signature key.

[0005] On the one hand, embodiments of this application provide a data processing method based on blockchain. The data processing method based on blockchain includes:

[0006] Invoking a data signature service program to sign the service data to be uploaded to the blockchain; the data signature service program is created based on the signature key, and when the data signature service program signs based on the signature key, the signature key is hidden;

[0007] If the invocation of the data signature service program fails, then invoking a key recovery service program to recover the signature key;

[0008] Reconstructing the data signature service program according to the recovered signature key;

[0009] Call the reconstructed data signature service program to sign the business data, and upload the signed business data to the blockchain.

[0010] Correspondingly, an embodiment of the present application provides a blockchain-based data processing device, which includes:

[0011] A processing unit, configured to call a data signature service program to sign business data to be uploaded to the blockchain; the data signature service program is created based on a signature key, and when the data signature service program signs based on the signature key, the signature key is hidden;

[0012] The processing unit is further configured to, if the call to the data signature service program fails, call a key recovery service program to recover the signature key;

[0013] The processing unit is further configured to reconstruct the data signature service program according to the recovered signature key;

[0014] The processing unit is further configured to call the reconstructed data signature service program to sign the business data;

[0015] A communication unit, configured to upload the signed business data to the blockchain.

[0016] In one implementation, when the processing unit is configured to call the key recovery service program to recover the signature key, it is specifically configured to perform the following steps:

[0017] Call the key recovery service program to recover the encrypted mnemonic information of the signature key;

[0018] Decrypt the encrypted mnemonic information to obtain the mnemonic information of the signature key;

[0019] Recover the signature key according to the mnemonic information.

[0020] In one implementation, the encrypted mnemonic information is backed up to a hardware encryption machine and cloud storage space; when the processing unit is configured to call the key recovery service program to recover the encrypted mnemonic information of the signature key, it is specifically configured to perform the following steps:

[0021] Call the key recovery service program to recover the encrypted mnemonic information of the signature key from the hardware encryption machine;

[0022] If the recovery of the encrypted mnemonic information of the signature key from the hardware encryption machine fails, call the key recovery service program to recover the encrypted mnemonic information from the cloud storage space.

[0023] In one implementation, the business data belongs to the target blockchain service; the encrypted mnemonic information is stored in the cloud storage space allocated for the target blockchain service by the cloud; the cloud allocates independent cloud storage spaces for different blockchain services;

[0024] The processing unit is used to call the key recovery service program to recover the encrypted mnemonic information from the cloud storage space, and specifically used to perform the following steps:

[0025] Obtain the cloud account information of the target blockchain service;

[0026] Call the key recovery service program, and based on the cloud account information of the target blockchain service, recover the encrypted mnemonic information from the cloud storage space of the target blockchain service.

[0027] In one implementation, when the processing unit is used to reconstruct the data signature service program according to the recovered signature key, it is specifically used to perform the following steps:

[0028] Perform a first key hiding process on the signature key according to the first cryptographic algorithm to obtain a data signature library;

[0029] Reconstruct the data signature service program based on the data signature library.

[0030] In one implementation, the data signature library refers to a data signature table, and the data signature library includes multiple data signatures; when the processing unit is used to call the reconstructed data signature service program to sign the business data, it is specifically used to perform the following steps:

[0031] Query the data signature corresponding to the business data in the data signature library based on the business data to obtain the signed business data.

[0032] In one implementation, when the processing unit is used to reconstruct the data signature service program according to the recovered signature key, it is specifically used to perform the following steps:

[0033] Perform a second key hiding process on the signature key according to the second cryptographic algorithm to obtain a security key;

[0034] Pass the security key into the basic signature library, and reconstruct the data signature service program according to the basic signature library after the security key is passed in.

[0035] In one implementation, the basic signature library refers to a basic signature table, and the basic signature library includes multiple basic signatures; when the processing unit is used to call the reconstructed data signature service program to sign the business data, it is specifically used to perform the following steps:

[0036] Query the basic signature corresponding to the business data in the basic signature library based on the business data;

[0037] Sign the basic signature corresponding to the service data based on the security key to obtain the signed service data.

[0038] In one implementation, the failure of the data signature service program includes any of the following:

[0039] The data signature service program does not exist;

[0040] The data signature service program exists but has an exception;

[0041] The data signature service program fails to decrypt;

[0042] The data signature service program is constructed by the basic signature library of the incoming security key, and the security key is lost; the security key is generated based on the signature key.

[0043] In one implementation, the service data belongs to the target blockchain service; the processing unit is further configured to perform the following steps:

[0044] In response to the creation request of the target blockchain service, allocate a signature key for the target blockchain service;

[0045] Create a data signature service program based on the signature key;

[0046] Encrypt and back up the signature key.

[0047] In one implementation, when the processing unit is used to encrypt and back up the signature key, it is specifically configured to perform the following steps:

[0048] Obtain the mnemonic information of the signature key;

[0049] Create a hardware encryption service program, and call the hardware encryption service program to encrypt the mnemonic information to obtain the encrypted mnemonic information, and then store the encrypted mnemonic information in the hardware encryption machine;

[0050] Create a cloud encryption service program, and call the cloud encryption service program to encrypt the mnemonic information to obtain the encrypted mnemonic information, and then request the cloud to allocate cloud storage space for the target blockchain service, and request the cloud to store the encrypted mnemonic information in the cloud storage space allocated for the target blockchain service.

[0051] Correspondingly, an embodiment of the present application provides a computer device, which includes:

[0052] A processor, adapted to implement a computer program;

[0053] A computer-readable storage medium, storing a computer program, which is adapted to be loaded and executed by the processor to perform the above-mentioned blockchain-based data processing method.

[0054] Accordingly, an embodiment of the present application provides a computer-readable storage medium storing a computer program. When the computer program is read and executed by a processor of a computer device, the computer device is caused to execute the above-mentioned blockchain-based data processing method.

[0055] Accordingly, an embodiment of the present application provides a computer program product including a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, causing the computer device to execute the above-mentioned blockchain-based data processing method.

[0056] In an embodiment of the present application, a data signature service program can be called to sign business data to be uploaded to a blockchain. Among them, the data signature service program can be created based on a signature key. When the data signature service program signs based on the signature key, the signature key can be hidden. It can be seen that on the one hand, the data signature service program can hide the signature key to ensure the security of the signature key storage, and on the other hand, it can play the signature function of the signature key. That is to say, the signature key can be used for signature on the premise of ensuring the security of the signature key storage. In addition, when the call of the data signature service program fails, an embodiment of the present application can support calling a key recovery service program to recover the signature key, reconstruct the data signature service program based on the recovered signature key, and call the reconstructed data signature service program to sign the business data. That is to say, an embodiment of the present application can support the recovery of the signature key to ensure the recoverability of the signature key. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0058] Figure 1 is a schematic diagram of the architecture of a single-layer blockchain network provided by an embodiment of the present application;

[0059] Figure 2 is a schematic diagram of the architecture of a two-layer blockchain network provided by an embodiment of the present application;

[0060] Figure 3 is a schematic diagram of the operation mode of a main chain and a local chain provided by an embodiment of the present application;

[0061] Figure 4It is a schematic diagram of an interaction method between a blockchain service and a blockchain provided by an embodiment of the present application;

[0062] Figure 5 It is a schematic diagram of the architecture of a data processing system provided by an embodiment of the present application;

[0063] Figure 6 It is a schematic diagram of a data signature process provided by an embodiment of the present application;

[0064] Figure 7 It is a schematic diagram of another data signature process provided by an embodiment of the present application;

[0065] Figure 8 It is a schematic diagram of a process of a data processing method based on a blockchain provided by an embodiment of the present application;

[0066] Figure 9 It is a schematic diagram of the signature logic of a data signature service program provided by an embodiment of the present application;

[0067] Figure 10 It is a schematic diagram of the signature logic of a static data signature service program provided by an embodiment of the present application;

[0068] Figure 11 It is a schematic diagram of the signature logic of a dynamic data signature service program provided by an embodiment of the present application;

[0069] Figure 12 It is a schematic diagram of another process of a data processing method based on a blockchain provided by an embodiment of the present application;

[0070] Figure 13 It is a schematic diagram of an application scenario provided by an embodiment of the present application;

[0071] Figure 14 It is a schematic diagram of the structure of a data processing device based on a blockchain provided by an embodiment of the present application;

[0072] Figure 15 It is a schematic diagram of the structure of a computer device provided by an embodiment of the present application. Detailed implementation manners

[0073] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without making creative efforts shall fall within the protection scope of the present application.

[0074] To better understand the technical solutions provided in the embodiments of the present application, some technical terms related to the technical solutions are introduced herein:

[0075] (1) Blockchain network:

[0076] A blockchain network is a peer-to-peer connected network. The blockchain network is based on a specific type of network protocol, such that there is no need for a central node to maintain the network state among the blockchain nodes in the blockchain network. Instead, each blockchain node maintains the node state of the entire network and the connection state with its adjacent nodes through broadcast interactions with adjacent nodes. The blockchain network can include a single-layer blockchain network and a two-layer blockchain network (the two-layer blockchain network can also be referred to as a hierarchical blockchain network).

[0077] The single-layer blockchain network can be understood as Figure 1 the data sharing system 10 shown. The data sharing system 10 refers to a system used for data sharing between nodes. The data sharing system may include multiple (multiple can include two or more) blockchain nodes 101. The multiple blockchain nodes 101 can refer to each client, terminal device, or server in the data sharing system. Each blockchain node 101 can receive input information (for example, the service data involved in the embodiments of the present application) during normal operation and maintain the shared data within the data sharing system based on the received input information. To ensure information interconnection within the data sharing system, there may be information connections between each blockchain node in the data sharing system, and the blockchain nodes can transmit information through the above information connections. For example, when any blockchain node in the data sharing system receives input information, other nodes in the data sharing system obtain the input information according to the consensus algorithm and store the input information as data in the shared data, so that the data stored on all blockchain nodes in the data sharing system is consistent.

[0078] For each blockchain node in the data sharing system, there is a corresponding node identifier, and each blockchain node in the data sharing system can store the node identifiers of other blockchain nodes in the data sharing system, so as to broadcast the generated block to other blockchain nodes in the data sharing system according to the node identifiers of other blockchain nodes in the future. Each blockchain node can maintain a node identifier list as shown in Table 1 below, and store the node name and node identifier in the node identifier list correspondingly. Among them, the node identifier can be an IP (Internet Protocol) address and any other information that can be used to identify the blockchain node. Table 1 only takes the IP address as an example for illustration:

[0079] Table 1

[0080] Node Name Node Identifier Node 1 111.111.111.111 Node 2 222.222.222.222 … … Node N NNN.NNN.NNN.NNN

[0081] The above single-layer blockchain network has some problems in actual application scenarios. For example, in the scenario of issuing electronic vouchers (electronic vouchers can be, for example, electronic bills, electronic invoices, etc.), not all nodes in the blockchain network need to be deployed as nodes for executing the task of issuing electronic vouchers. Another example is that in the data storage scenario, not all nodes in the blockchain network have sufficient resources and necessity to participate in the blockchain consensus. To solve the problems existing in the single-layer blockchain network, the embodiments of the present application also propose a two-layer blockchain network, and the architecture of the two-layer blockchain network will be introduced below.

[0082] A two-layer blockchain network refers to dividing the blockchain network into a core consensus network and a business network (the business network can also be called a witness network). The core consensus network can be used to execute the core consensus algorithm, and the business network can be used for data clearing and synchronization and complete relevant specific services based on the business nodes in the business network. The two-layer blockchain network is as Figure 2 shown. In the two-layer blockchain network 20, it can include a core consensus network 201, a business network 202 (the business network 202 can also be called a witness network 202), and a routing proxy network 203. Among them:

[0083] The core consensus network 201 can include one or more blockchain management nodes (the blockchain management nodes can also be called consensus nodes). The blockchain management nodes can run the blockchain consensus protocol and are used for consensus accounting of the blockchain. The business network 202 can include one or more business nodes. The business nodes can be, for example, SPV (Simplified Payment Verification) nodes. The business nodes are mainly used for business execution and do not participate in the accounting consensus. The business nodes achieve data synchronization through data clearing. Data clearing (data clearing can also be called transaction clearing) means that after the consensus nodes in the core consensus network receive the request from the business nodes to synchronize transaction data, they synchronize the transaction data that the business nodes have the right to read to the business nodes. Specifically, it means that the business nodes obtain the block header data and part of the block data with authorized visibility from the core consensus network. The routing proxy network 203 can include one or more proxy nodes. The proxy nodes can be used to isolate the network between the core consensus network 201 and the business network 202. The communication data between the core consensus network 201 and the business network 202 needs to be forwarded by the proxy nodes in the routing proxy network 203.

[0084] Generally speaking, the core consensus network 201 and the business network 202 are in different network environments. The business network 202 can be in a public network, while the core consensus network 201 can be in a private network. Since the core consensus network 201 is in a relatively secure private network, the mutual access between its blockchain management nodes is already guaranteed secure by the consensus mechanism and does not require additional identity management and network control. However, the business network 202 is in a public network and may be accessed by other uncertain network terminals. Therefore, the behavior of the business network 202 and other possible nodes accessing the core consensus network 201 needs to be strictly controlled.

[0085] In the single-layer blockchain network and the double-layer blockchain network introduced above, the blockchain node, the blockchain management node, the business node, and the proxy node can be any one of a client, a terminal, and a server. The client can include, but is not limited to, any one of the following: application programs, applets, software, and web pages. The terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, a vehicle-mounted terminal, a smart home appliance, an aircraft, etc., but is not limited thereto. The server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.

[0086] (2) Blockchain:

[0087] Blockchain is a distributed ledger technology in the field of information technology, generally composed of consensus, transaction block and state data storage, cryptographic identity security, etc. Since the ledger is stored distributively and the blocks are consensus-based, it has characteristics such as immutability, traceability, and co-maintenance.

[0088] In the embodiments of the present application, the blockchain maintained in the blockchain network may specifically refer to a consortium blockchain. A consortium blockchain refers to a blockchain with an access mechanism, which has consensus nodes and other nodes (business nodes). Generally speaking, any smart contract on a blockchain needs to be executed by all consensus nodes. If the execution results are consistent, the consensus nodes can reach a consensus. Business nodes generally do not execute smart contracts, but will synchronize the execution results of smart contracts from the consensus nodes. Business nodes can also execute local smart contracts of business nodes; local smart contracts refer to smart contracts running on business nodes. This type of smart contract has independent local storage. Local smart contracts are only executed on a single business node, and consensus nodes will not execute local smart contracts again. The execution results of local smart contracts can be submitted to the blockchain by business nodes in transactions.

[0089] The blockchain can be a single blockchain composed of blocks, or the blockchain can include a parent chain and a sub-chain. Among them, the parent chain can also be called the main chain, which is the general underlying blockchain in the blockchain network. The sub-chain can also be called the local chain, which refers to the blockchain built on the basis of the underlying parent chain; when the sub-chain is created, the relevant information of the sub-chain will be recorded in the parent chain, that is, data uploading to the chain must rely on the parent chain for storage, verification, and traceability, etc. The sub-chain is the representative of each industry or vertical field of the blockchain, and it is also a general term for various blockchain projects in each subdivided field. One sub-chain can correspond to one industry or one vertical field; in the embodiments of the present application, the industry or vertical field can be collectively referred to as blockchain services. That is to say, one sub-chain can correspond to one blockchain service, and different sub-chains correspond to different blockchain services; for example, in the tax scenario, issuing electronic invoices and handling tax refunds can be different blockchain services, corresponding to different sub-chains respectively.

[0090] In a two-layer blockchain network, the operating modes of the main chain and the local chain are as Figure 3 shown. Taking the tax scenario as an example, the State Taxation Administration corresponds to the core consensus network, and the core consensus network can operate the main chain and provide main chain services. Each level of tax agency (for example, the first-level tax agency is a subordinate agency of the State Taxation Administration, the second-level tax agency is a subordinate agency of the first-level tax agency, and the third-level tax agency is a subordinate agency of the second-level tax agency) corresponds to the business network. Each first-level tax agency synchronizes the relevant business data visible to its own level in the form of first-level main chain business nodes, and the corresponding main chain business data is also forwarded to the entrance of the core consensus network through the first-level main chain business nodes and finally sent to the core consensus network for consensus execution. Figure 3 There are 2 first-level main chain business nodes in

[0091] In the secondary tax agencies, a local consensus network runs independently. Each secondary tax agency, through its secondary local consensus business nodes, not only synchronizes the main chain data from the primary main chain business nodes but also forms a local consensus network to receive business data and conduct local block packaging and consensus. All transactions sent to the local consensus are not forwarded to the main chain but are processed in the local chains of each secondary tax agency. If necessary, the summary information in the local consensus can be uploaded to the main chain.

[0092] Outside the local consensus network are the tertiary business nodes corresponding to the tertiary tax agencies. These nodes no longer obtain the ledger of the main chain but can obtain the main chain business data related to the business from the local consensus network. At the same time, the ledger data they obtain is that of the local consensus. They also obtain their own relevant ledger and status data through data clearing. Their own business transactions are also sent to the local consensus network.

[0093] (3) Blockchain business:

[0094] Blockchain business refers to the business that interacts with the blockchain. Blockchain business can store business data in the blockchain and utilize the decentralized characteristics of the blockchain to ensure the immutability and security of business data. For example, blockchain business can be the e-invoice issuing business in the tax scenario, and the business data can be the issued e-invoices. Blockchain business can store the issued e-invoices in the blockchain. Another example is that blockchain business can be the digital collectible minting business, and the business data can be the minted digital collectibles. Blockchain business can store the minted digital collectibles in the blockchain.

[0095] The interaction method between blockchain business and the blockchain is as Figure 4 shown. Blockchain business provides a client corresponding to the blockchain business and a server corresponding to the blockchain business. The client corresponding to the blockchain business can also be called the business client, and the business client can run on the terminal. The business client faces the business object (the business object refers to the object served by the blockchain business), and the business object can initiate a business request regarding the blockchain business through the business client. The server corresponding to the blockchain business can also be called the business server. The business server can process the business request of the business object and, after signing the business data generated when processing the business request, upload the signed business data to the blockchain.

[0096] The embodiments of the present application do not limit the type of business client. The business client may include, but is not limited to, any one of the following: business application (a business application can be referred to as a Dapp (Decentralized Application)), business applet, and business web page. The embodiments of the present application do not limit the type of business server. The business server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. When the business client is a Dapp, the business server can be referred to as the Dapp backend or Dapp background.

[0097] Based on the above introduction of technical terms such as blockchain network, blockchain, and blockchain business, before uploading business data to the blockchain, the business server needs to sign the business data using a signature key. The embodiments of the present application provide a blockchain-based data processing method. This blockchain-based data processing method can provide a key security guarantee system for the business server, and the key security guarantee system can provide triple guarantees for the signature key. Specifically, the first guarantee in the triple guarantees is to create a data signature service program. The data signature service program can be used to provide a data signature service while hiding the signature key. The data signature service can be understood as a data signature function for performing data signing. The second guarantee in the triple guarantees is to create a hardware encryption service program. The hardware encryption service program can be used to encrypt and save the mnemonic information of the signature key to a hardware encryption machine. The mnemonic information of the signature key can be used to recover the signature key. The third guarantee in the triple guarantees is to create a cloud encryption service program. The cloud encryption service program can be used to request the cloud to encrypt and save the mnemonic information of the signature key.

[0098] Based on the triple protection of the signature key, the first protection (i.e., the data signature service program) can hide the signature key during the data signature process. The signature key cannot be exported, and the signature key can be used for signature while ensuring the security of the signature key storage. The second protection (i.e., the hardware encryption service program) and the third protection (i.e., the cloud encryption service program) can encrypt and back up the signature key. When there is a need to recover the signature key, the signature key can be recovered from the hardware encryption machine and the cloud. Even in the case of damage to the hardware encryption machine, the signature key can still be recovered from the cloud, which can ensure the recoverability of the signature key. The service program mentioned in the embodiments of the present application refers to the process in the business server. The service programs included in the service program can be understood as sub-processes in the process. This is hereby explained.

[0099] The data processing system provided by the embodiments of the present application will be introduced below with reference to the accompanying drawings. The data processing system is suitable for implementing the blockchain-based data processing method provided by the embodiments of the present application.

[0100] As Figure 5 shown, the data processing system may include a business server 501 and a blockchain node 502 in the blockchain network. The embodiments of the present application do not limit the connection method between the business server 501 and the blockchain node 502. A direct communication connection can be established between the business server 501 and the blockchain node 502 through a wired communication method, or an indirect communication connection can be established between the business server 501 and the blockchain node 502 through a wireless communication method.

[0101] In the data processing system composed of the business server 501 and the blockchain node 502, the business server 501 is the server corresponding to the target blockchain service. The target blockchain service refers to any blockchain service that supports interaction with the blockchain. The business server 501 can respond to a business request sent by a business object through a business client, sign the business data generated by executing the business request, and send the signed business data to the blockchain node 502, so that the blockchain node 502 uploads the signed business data to the blockchain. It should be noted that when the blockchain network is a single-layer blockchain network, the blockchain node 502 can be any blockchain node in the single-layer blockchain network; when the blockchain network is a two-layer blockchain network, the blockchain node 502 can be any business node in the business network of the two-layer blockchain network.

[0102] Based on the data processing system composed of the business server 501 and the blockchain node 502, the data signature process of the business server 501 will be introduced in detail below. After creating the target blockchain service, the target blockchain service is assigned a signature key; as Figure 5As shown, the business server 501 can create a key protection service program and a key recovery service program; the key protection service program can include a data signature service program, a hardware encryption service program, and a cloud encryption service program. The data signature service program can be created based on a signature key. The hardware encryption service program can be used to encrypt and back up the mnemonic information of the signature key to a hardware encryption machine, which is a hardware device used to provide encryption security for the mnemonic information of the signature key; for example, the hardware encryption machine can be an HSM (Hardware Security Module), and the HSM is an encrypted hardware device certified by an independent specification and can act as a reliable source of encryption and key generation, so as to maintain appropriate encryption functions for other applications and systems. The cloud encryption service program can be used to request the cloud to encrypt and back up the mnemonic information of the signature key to the cloud storage space of the target blockchain service. The cloud can allocate independent cloud storage spaces for different blockchain services. For example, Figure 5 the cloud storage space of the target blockchain service, the cloud storage space of blockchain service 1, and the cloud storage space of blockchain service 2 in Figure 5 are independent of each other; and when the cloud extracts information from the cloud storage space, it needs the cloud account information of the corresponding blockchain service as an extraction voucher. For example, when the cloud extracts the encrypted information of the signature key from the cloud storage space of the target blockchain service, it needs the cloud account information of the target blockchain service as an extraction voucher, and the cloud account information of the target blockchain service can be used to uniquely identify the target blockchain service in the cloud.

[0103] Based on Figure 5 the service program architecture in the business server 501 shown, the data signature process of the business server 501 can include two cases: successful call of the data signature service program and failed call of the data signature service program. The following combines Figure 6 to introduce the data signature process of the business server 501 when the call of the data signature service program is successful, and combines Figure 7 to introduce the data signature process of the business server 501 when the call of the data signature service program fails.

[0104] As Figure 6 shown, when the call of the data signature service program is successful, the data signature process of the business server 501 can be specifically described as follows: The business server 501 can call the data signature service program to sign the business data, and the data signature service program can sign the business data while hiding the signature key; if the call of the data signature service program successfully signs the business data, the business server 501 can send the signed business data to the blockchain node 502.

[0105] As Figure 7As shown in the figure, when the data signature service program is successfully called, the data signature process of the business server 501 can be specifically described as follows: The business server 501 can call the data signature service program to sign the business data, and the data signature service program can sign the business data while hiding the signature key; if the call to the data signature service program fails, the business server 501 can call the key recovery service program to recover the signature key. After the signature key is recovered, the business server 501 can reconstruct the data signature service program based on the recovered signature key and call the reconstructed data signature service program to sign the business data.

[0106] Specifically, during the process of the business server 501 calling the key recovery service program to recover the signature key, the key recovery service program can call the hardware encryption service program to recover the signature key from the hardware encryption machine; if the call to the hardware encryption service program to recover the signature key fails, the key recovery service program can call the cloud encryption service program to recover the signature key from the cloud storage space of the target blockchain service in the cloud.

[0107] It should be noted that the mnemonic information of the signature key is encrypted and stored in the hardware encryption machine and the cloud storage space of the target blockchain service, and the mnemonic information of the encrypted storage signature key needs to be decrypted. In this case, as Figure 5 shown, the key guarantee service program can also include a decryption program (the decryption program can be a decryption SDK (Software Development Kit)), and the decryption program can be used to decrypt the mnemonic information of the encrypted storage signature key to obtain the mnemonic information of the signature key, and the mnemonic information of the signature key can be used to recover the signature key. By encrypting and storing the mnemonic information of the signature key and the cooperation of the decryption program, it is possible to prevent the plaintext of the signature key from being exposed in the source code of the business server 501, thereby preventing the signature key from being maliciously exploited.

[0108] Based on Figure 5 the data processing system shown in the figure, it is possible to use the signature key for signing while ensuring the security of the signature key storage, and it is also possible to ensure the recoverability of the signature key. It can be understood that the data processing system described in the embodiments of the present application is for more clearly explaining the technical solutions of the embodiments of the present application, and does not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art know that with the evolution of the blockchain network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0109] The following will introduce in detail the blockchain-based data processing method provided by the embodiments of the present application with reference to the accompanying drawings.

[0110] An embodiment of the present application provides a data processing method based on a blockchain. The content introduced by this data processing method based on a blockchain includes: the process of the data signature service program signing business data, the process of restoring the signature key, and the process of reconstructing the data signature service program. This data processing method based on a blockchain can be executed by a computer device, and the computer device can be, for example, Figure 5 the business server 501 in the data processing system shown (the business server 501 refers to the server corresponding to the target blockchain service). As Figure 8 shown, this data processing method based on a blockchain may include, but is not limited to, the following steps S801 - step S804:

[0111] S801, call the data signature service program to sign the business data to be uploaded to the blockchain; the data signature service program is created based on the signature key, and when the data signature service program signs based on the signature key, the signature key is hidden.

[0112] The data signature service program is a process in the business server that signs the business data to be uploaded to the blockchain based on the signature key, and the data signature service program can be created based on the signature key.

[0113] After the target blockchain service is created, the target blockchain service can be assigned a pair of asymmetric keys by PKI (Public Key Infrastructure, public key certificate system). The asymmetric keys can include a public key and a private key. The public key can be made public, and the blockchain nodes in the blockchain network can obtain the public key of the target blockchain service; the target blockchain service can also send the public key to the CA (Certificate Authority) certificate signing center to generate a digital certificate of the public key (for example, the digital certificate can be an x509 digital certificate), and the digital certificate can be used to identify the target blockchain service. The private key cannot be made public and needs to be privately stored by the business server. The signature key in the embodiment of the present application refers to the private key assigned to the target blockchain service.

[0114] The data signature service program can hide the signature key when signing the business data to be uploaded to the blockchain based on the signature key. The way the data signature service program hides the signature key and the way the data signature service program signs the business data are related to the creation method of the data signature service program. The data signature service program specifically refers to a white-box service program. First, the white-box service program will be introduced below, and then the creation method of the data signature service program will be introduced.

[0115] The white-box service program is implemented based on white-box cryptography technology. White-box cryptography technology is a cryptographic technology that can resist white-box attacks, that is, when an attacker has complete control over the encrypted device terminal, can observe and change the internal data during program operation, and perform reverse analysis on the password operation process, it can effectively protect the security of encrypted data and keys. Compared with traditional encryption technology, white-box cryptography technology makes it difficult to extract keys in the white-box environment. At the same time, white-box key management also supports device-bound authentication capabilities to ensure the security protection of sensitive key information and encrypted data.

[0116] White-box security, different from traditional black-box security, aims to ensure system security when illegal objects break into the system and understand all system contents. The core ideas of white-box encryption include obfuscation technology, key hiding, key attack tolerance, etc. White-box cryptography technology can be divided into two categories from the implementation method: static white-box and dynamic white-box.

[0117] A static white-box refers to a specific cryptographic algorithm library formed after a cryptographic algorithm is processed by white-box cryptography technology in combination with a specific key, called a white-box library. The white-box library has specific cryptographic functions (cryptographic functions can include encryption, decryption, and encryption and decryption), and can effectively protect the security of the original key in a white-box attack environment. To update the key in a static white-box, a new white-box library needs to be generated.

[0118] A dynamic white-box means that once the white-box library is generated, it does not need to be updated anymore. The original key is transformed into a white-box key through the same white-box cryptography technology. The white-box key can be passed into a matching white-box library to perform normal encryption or decryption functions. The white-box key is secure, and an attacker cannot obtain any information about the original key by analyzing the white-box key.

[0119] Due to its convenience of use, general white-box services usually provide dynamic white-box services. White-box keys can be used to protect sensitive root key information on the device (sensitive root key information can be, for example, API SecretKey), authentication keys used in internal systems, tokens, and other local sensitive root key information, etc., to implement an end-to-end full-link data security solution. The white-box key management solution integrates keys and algorithms, and effectively hides the keys by introducing a randomization factor, greatly increasing the difficulty of key sniffing and cracking, thereby protecting this extremely sensitive information of the keys.

[0120] Based on the above introduction to the white-box service program, it can be further understood that the signature logic of the data signature service program for business data is as Figure 9 shown. The data signature service program can combine a signature key and a standard cryptographic algorithm to sign business data and obtain the signed business data.

[0121] White box cryptography technology can include static white box and dynamic white box. Correspondingly, data signature service program can include static data signature service program and dynamic data signature service program. The following introduces the creation method and signature method of static data signature service program and the creation method and signature method of dynamic data signature service program.

[0122] For a static data signature service program, the creation method of the static data signature service program may include: performing a first key hiding process on the signature key according to a first cryptographic algorithm to obtain a data signature library; creating a data signature service program based on the data signature library, and the data signature service program here specifically refers to a static data signature service program. Among them, the data signature library refers to a data signature table, and the data signature table may include multiple data signatures; that is, the static data signature service program hides the signature key by converting the signature key into a data signature library. The first cryptographic algorithm is the white box cryptography technology used by the static white box.

[0123] Based on the creation method of static data signature service program, such as Figure 10 As shown, the signing method of the static data signature service program, that is, the method of calling the static data signature service program to sign the business data, may include: based on the business data, querying the data signature corresponding to the business data in the data signature library to obtain the signed business data; it can be understood that the signing process of the static data signature service program is the query process of the data signature table to query the data signature that matches the business data.

[0124] For a dynamic data signature service program, the creation method of the dynamic data signature service program may include: performing a second key hiding process on the signature key according to a second cryptographic algorithm to obtain a security key; transferring the security key into the basic signature library, and creating a data signature service program according to the basic signature library after the security key is transferred. The data signature service program here specifically refers to the dynamic data signature service program. In other words, the dynamic data signature service program hides the signature key by converting the signature key into a security key. Among them, the basic signature library is the basic signature service program that comes with the basic signature service program, and the basic signature library refers to the basic signature table. The basic signature table may include multiple basic signatures. It can be understood that the dynamic data signature service program is a modification of the basic signature service program based on the signature key. The second cryptographic algorithm is the white box cryptographic technology used by the dynamic white box.

[0125] Based on the creation method of dynamic data signature service program, such as Figure 11As shown, the signature method of the dynamic data signature service program, that is, the method of calling the dynamic data signature service program to sign business data, may include: querying the basic signature corresponding to the business data in the basic signature library based on the business data; signing the basic signature corresponding to the business data with a security key to obtain the signed business data. It can be understood that the signature process of the dynamic data signature service program is the process of signing the query result of the basic signature table with a security key.

[0126] The applicable scenarios of the static data signature service program and the dynamic data signature service program are different. The applicable data signature service for signing business data can be selected from the static data signature service program and the dynamic data signature service program as needed. Specifically, for the static data signature service program, the signature key is bound to the static data signature service program. Once the signature key changes, the static data signature service program also needs to change. Therefore, the static data signature service program is suitable for data signature scenarios where the signature key is relatively stable and does not change frequently; for the dynamic data signature service program, the signature key is not bound to the dynamic data signature service program. When the signature key changes, the dynamic data signature service program only needs to change the security key passed into it. Therefore, the dynamic data signature service program is suitable for both data signature scenarios where the signature key changes frequently and data signature scenarios where the signature key is relatively stable and does not change frequently.

[0127] The content of step S801 above introduces the creation method of the data signature service program and the signature method of the data signature service program for business data. In addition, the data signature service program can be encrypted. Before calling the data signature service program to sign the business data to be uploaded to the blockchain, the decryption program can be called to decrypt the data signature service program first; if the decryption of the data signature service program is successful, the decryption program can be called to decrypt the data signature service program. If the decryption of the data signature service program fails, it can be determined that the call to the data signature service program fails.

[0128] The decryption process of the data signature service program can be understood as the usage permission verification process of the data signature service program; if the decryption is successful, it can indicate that the usage permission of the data signature service program is available, and if the decryption fails, it can indicate that the usage permission of the data signature service program is not available; this can ensure the call security of the data signature service program, and the data signature service program can only be called when the usage permission of the data signature service program is available. It should be noted that the data signature service program can support symmetric keys. A symmetric key refers to a key that is used for both encryption and decryption. The symmetric key can be, for example, SM4 (a symmetric key). The data signature service program can be encrypted with a symmetric key, and the same symmetric key needs to be used for decryption during decryption.

[0129] S802, if the data signature service program call fails, then call the key recovery service program to recover the signature key.

[0130] The failure of the data signature service program call can include any of the following situations: the data signature service program does not exist, that is, the data signature service program is lost; the data signature service program exists but an exception occurs. For example, the data signature service program decrypts successfully but the call is abnormal; the data signature service program decryption fails; for the dynamic data signature service program in the data signature service program, the data signature service program is constructed by the basic signature library with the incoming security key, and the security key is lost. The security key is generated based on the signature key. If the data signature service program call fails, then the key recovery service program can be called to recover the signature key. The key recovery service program is a process in the business server used to recover the signature key. If the data signature service program successfully signs the business data to be uploaded to the blockchain, then the signed business data can be uploaded to the blockchain.

[0131] The mnemonic information of the signature key is encrypted and backed up to the hardware encryption machine and the cloud storage space. The mnemonic information of the signature key can be recovered from the hardware encryption machine and the cloud storage space. The mnemonic information of the signature key is the description information of the signature key, and the signature key can be recovered based on the mnemonic information of the signature key. Specifically, the process of calling the key recovery service program to recover the signature key can include: calling the key recovery service program to recover the encrypted mnemonic information of the signature key; decrypting the encrypted mnemonic information to obtain the mnemonic information of the signature key; recovering the signature key according to the mnemonic information. Among them, the encrypted mnemonic information of the signature key can be obtained by encrypting the mnemonic information of the signature key with a symmetric key. The decryption program can be called to decrypt the encrypted mnemonic information of the signature key with the same symmetric key to obtain the mnemonic information of the signature key; through the cooperation of encrypting and storing the mnemonic information of the signature key and the decryption program, it is possible to prevent the plaintext of the signature key from being exposed in the source code of the business server, thereby preventing the signature key from being maliciously exploited.

[0132] Furthermore, after the mnemonic information of the signature key is encrypted, the obtained encrypted mnemonic information can be backed up to the hardware encryption machine and the cloud storage space. The process of calling the key recovery service program to recover the encrypted mnemonic information of the signature key can include: calling the key recovery service program to recover the encrypted mnemonic information of the signature key from the hardware encryption machine; specifically, the key recovery service program calls the hardware encryption service program to recover the encrypted mnemonic information of the signature key from the hardware encryption machine. If the recovery of the encrypted mnemonic information of the signature key from the hardware encryption machine fails, then the key recovery service program can be called to recover the encrypted mnemonic information from the cloud storage space; specifically, the key recovery service program calls the cloud encryption service program to recover the encrypted mnemonic information from the cloud storage space.

[0133] Furthermore, the encrypted mnemonic information can be saved in the cloud storage space allocated for the target blockchain service. The cloud can allocate independent cloud storage spaces for different blockchain services; the cloud storage space for each blockchain service is associated with the cloud account information of that blockchain service. That is to say, the cloud account information of any blockchain service can uniquely identify the cloud storage space corresponding to that blockchain service. Through the cloud account information of the blockchain service, the cloud storage space of that blockchain service can be uniquely determined in the cloud. Based on this, the process of calling the key recovery service program to recover the encrypted mnemonic information from the cloud storage space may include: obtaining the cloud account information of the target blockchain service; calling the key recovery service program, and based on the cloud account information of the target blockchain service, recovering the encrypted mnemonic information from the cloud storage space of the target blockchain service; specifically, the key recovery service program calls the cloud encryption service program, and based on the cloud account information of the target blockchain service, recovers the encrypted mnemonic information from the cloud storage space of the target blockchain service.

[0134] It should be noted that the cloud account information of the target blockchain service needs to be obtained from the management object of the target blockchain service (the management object specifically refers to the operator of the target blockchain service). Specifically, before calling the cloud encryption service program, a cloud account input interface can be output to the management object. The management object can input the cloud account information of the target blockchain service in the cloud account input interface and submit it to the service server; the service server can call the cloud encryption service program based on the cloud account information of the target blockchain service submitted by the management object, and recover the encrypted mnemonic information from the cloud storage space of the target blockchain service.

[0135] It can be seen that based on the encryption backup of the mnemonic information of the signature key by the hardware encryption machine and the cloud storage space, the mnemonic information of the signature key can be recovered from the hardware encryption machine and the cloud storage space. Moreover, when the data signature service program running on the service server fails to be called by the management object of the target blockchain service, and when the hardware encryption service program cannot operate, and in the case of failure to call the hardware encryption service program to recover, the key recovery service program can still be used to call the cloud encryption service program, log in to the cloud account information of the target blockchain service, complete the retrieval of the mnemonic information of the signature key, and recover the signature key. Thus, the embodiments of the present application can effectively ensure the recoverability of the signature key.

[0136] S803, reconstruct the data signature service program according to the recovered signature key.

[0137] After the signature key is recovered, the data signature service program can be reconstructed according to the recovered signature key. The process of reconstructing the data signature service program according to the recovered signature key is similar to the process of creating the data signature service program according to the signature key. For details, please refer to the process of creating the data signature service program according to the signature key in step S801 above.

[0138] Briefly speaking, for the static data signature service program, the process of reconstructing the data signature service program according to the recovered signature key may include: performing a first key hiding process on the signature key according to the first cryptographic algorithm to obtain a data signature library; reconstructing the data signature service program based on the data signature library. For the dynamic data signature service program, the process of reconstructing the data signature service program according to the recovered signature key may include: performing a second key hiding process on the signature key according to the second cryptographic algorithm to obtain a security key; passing the security key into the basic signature library, and reconstructing the data signature service program according to the basic signature library after the security key is passed in.

[0139] S804. Invoke the reconstructed data signature service program to sign the service data, and upload the signed service data to the blockchain.

[0140] After the data signature service program is reconstructed, the reconstructed data signature service program can be invoked to sign the service data. The process of invoking the reconstructed data signature service program to sign the service data is similar to the process of invoking the created data signature service program to sign the service data. For details, please refer to the process of invoking the created data signature service program to sign the service data in step S801 above.

[0141] Briefly speaking, for the static data signature service program, the process of invoking the reconstructed data signature service program to sign the service data may include: the data signature library refers to the data signature table, and the data signature library may include multiple data signatures; based on the service data, the data signature corresponding to the service data can be queried in the data signature library to obtain the signed service data. For the dynamic data signature service program, the process of invoking the reconstructed data signature service program to sign the service data may include: the basic signature library refers to the basic signature table, and the data signature library may include multiple basic signatures; based on the service data, the basic signature corresponding to the service data can be queried in the basic signature library; sign the basic signature corresponding to the service data based on the security key to obtain the signed service data.

[0142] After obtaining the signed service data (the signed service data can be obtained by invoking the created data signature service program to sign the service data, or the signed service data can be obtained by invoking the reconstructed data signature service program to sign the service data), the signed service data can be uploaded to the blockchain. Specifically, the service server can upload the signed service data to a blockchain node in the blockchain network, and the blockchain node uploads the signed service data to the blockchain.

[0143] Further, in the embodiments of the present application, the target blockchain service can interact with the blockchain in a single-layer blockchain network. In this case, the blockchain node in the blockchain network specifically refers to any blockchain node in the single-layer blockchain network; that is, the service server can upload the signed service data to any blockchain node in the single-layer blockchain network. Or, the target blockchain service can interact with the blockchain in a two-layer blockchain network. In this case, the blockchain node in the blockchain network specifically refers to any service node in the service network of the two-layer blockchain network; that is, the service server can upload the signed service data to any service node in the service network of the two-layer blockchain network.

[0144] In addition, in the embodiments of the present application, the target blockchain service can interact with a single blockchain composed of blocks. In this case, the service server can upload the signed service data to a blockchain node in the blockchain network, and the blockchain node uploads the signed service data to the single blockchain composed of blocks. Or, the target blockchain service can interact with a blockchain composed of a parent chain and a child chain, and the blockchain can include a child chain corresponding to the target blockchain service. In this case, the service server can upload the signed service data to a blockchain node in the blockchain network, and the blockchain node uploads the signed service data to the child chain corresponding to the target service.

[0145] In the embodiments of the present application, a data signature service program can be called to sign the business data to be uploaded to the blockchain. Among them, the data signature service program can be created based on a signature key. When the data signature service program signs based on the signature key, the signature key can be hidden. It can be seen that on the one hand, the data signature service program can hide the signature key to ensure the security of the signature key storage, and on the other hand, it can play the signature function of the signature key. That is to say, the signature key can be used for signing on the premise of ensuring the security of the signature key storage. In addition, when the call of the data signature service program fails, the embodiments of the present application support restoring the signature key by calling the key recovery service program, reconstructing the data signature service program based on the restored signature key, and calling the reconstructed data signature service program to sign the business data. That is to say, the embodiments of the present application can support the recovery of the signature key to ensure the recoverability of the signature key.

[0146] The embodiments of the present application provide a data processing method based on a blockchain. The content introduced by this data processing method based on a blockchain includes: the creation process of the target blockchain service. This data processing method based on a blockchain can be executed by a computer device, and the computer device can be, for example, Figure 5 the business server 501 in the data processing system shown (the business server 501 refers to the server corresponding to the target blockchain service). As Figure 12 shown, this data processing method based on a blockchain can include but is not limited to the following steps S1201 - step S1207:

[0147] S1201, in response to a creation request for a target blockchain service, allocate a signature key for the target blockchain service.

[0148] S1202, create a data signature service program based on the signature key.

[0149] The process of the data signature service program based on the signature key is recorded in step S801 of the above Figure 8 shown embodiment. Specifically, reference can be made to the process of the data signature service program based on the signature key in the above Figure 8 shown embodiment, which will not be elaborated here.

[0150] S1203, encrypt and back up the signature key.

[0151] The process of encrypting and backing up the signature key may include: obtaining the mnemonic information of the signature key; creating a hardware encryption service program, calling the hardware encryption service program to encrypt the mnemonic information, and after obtaining the encrypted mnemonic information, storing the encrypted mnemonic information in the hardware encryption machine; creating a cloud encryption service program, calling the cloud encryption service program to encrypt the mnemonic information, and after obtaining the encrypted mnemonic information, requesting the cloud to allocate cloud storage space for the target blockchain service, and requesting the cloud to store the encrypted mnemonic information in the cloud storage space allocated for the target blockchain service.

[0152] Among them, the mnemonic information of the signature key can be obtained from the management object of the target blockchain service (the management object specifically refers to the operator of the target blockchain service). Specifically, the business server can output a mnemonic information import interface to the management object of the target blockchain service, and the management object of the target blockchain service can input the mnemonic information of the signature key in the mnemonic information import interface and submit it to the business server.

[0153] The hardware encryption service program is a process in the business server that encrypts the mnemonic information of the signature key and stores the encrypted mnemonic information obtained by encryption in the hardware encryption machine. Specifically, the hardware encryption service program can provide an API (Application Programming Interface), establish a secure connection, and after obtaining the mnemonic information imported by the management object, complete the encryption of the mnemonic information by calling the hardware encryption machine, and store the encrypted hardware encryption information obtained by encryption in the hardware encryption machine. Here, the hardware encryption service program can use a symmetric key to encrypt the mnemonic information of the signature key.

[0154] The cloud encryption service program (API Key custody service program) is a process in the business server that interacts with the cloud. Specifically, the cloud encryption service program can be docked with the cloud storage service and accept calls from the hardware encryption service program externally; the cloud encryption service program will pass through the cloud storage service, and the cloud storage service can create independent cloud storage spaces for each blockchain service in the cloud. The cloud storage space here can be understood as an IAM (Identity and Access Management, business access permission management) space; the encrypted mnemonic information imported by the management object can be independently stored and managed in the cloud storage space of the target blockchain service, isolated from the cloud storage spaces of other blockchain services, and providing the cloud account information of the target blockchain service can access the cloud storage space of the target blockchain service to obtain the encrypted mnemonic information stored therein. Here, the cloud encryption service program can use a symmetric key to encrypt the mnemonic information of the signature key.

[0155] Moreover, the cloud storage service on the cloud manages the encrypted mnemonic information based on the KMS (Key Management Service) system. Among them, the KMS is usually a server responsible for controlling the entire life cycle of the encryption key through a remote client and can securely process inbound and outbound key distribution requests. In addition, for compliance and security reasons, these systems can maintain audit logs for accessing these keys. However, in order for the key management team to manage the key lifestyle, the KMS must be backed up by its dedicated HSM to correctly generate and protect the keys. Whenever the KMS needs to generate or distribute key data, it directly interacts with its HSM for key generation, retrieval, and encryption, while sharing the key with the designated target, which can be another HSM or a secure application server.

[0156] S1204, call the data signature service program to sign the business data to be uploaded to the blockchain; the data signature service program is created based on the signature key, and when signing based on the signature key, the signature key is hidden.

[0157] In the embodiment of the present application, the execution process of step S1204 is the same as that of step S801 in the above Figure 8 shown embodiment, and the execution process of step S1204 can specifically refer to the execution process of step S801 in the above Figure 8 shown embodiment, which will not be elaborated here.

[0158] S1205, if the call to the data signature service program fails, then call the key recovery service program to recover the signature key.

[0159] In the embodiment of the present application, the execution process of step S1205 is the same as that of step S802 in the above Figure 8 shown embodiment, and the execution process of step S1205 can specifically refer to the execution process of step S802 in the above Figure 8 shown embodiment, which will not be elaborated here.

[0160] S1206, reconstruct the data signature service program according to the recovered signature key.

[0161] In the embodiment of the present application, the execution process of step S1206 is the same as that of step S803 in the above Figure 8 shown embodiment, and the execution process of step S1206 can specifically refer to the execution process of step S803 in the above Figure 8 shown embodiment, which will not be elaborated here.

[0162] S1207, call the reconstructed data signature service program to sign the service data, and upload the signed service data to the blockchain.

[0163] In the embodiment of the present application, the execution process of step S1207 is the same as that of step S804 in the above Figure 8 illustrated embodiment. The execution process of step S1207 can be specifically referred to the execution process of step S804 in the above Figure 8 illustrated embodiment, which will not be elaborated here.

[0164] In the embodiment of the present application, the data signature service program can be called to sign the service data to be uploaded to the blockchain; wherein, the data signature service program can be created based on the signature key. When the data signature service program signs based on the signature key, the signature key can be hidden; it can be seen that on the one hand, the data signature service program can hide the signature key to ensure the security of the signature key storage, and on the other hand, it can play the signature function of the signature key, that is, the signature key can be used for signature on the premise of ensuring the security of the signature key storage. In addition, when the call of the data signature service program fails, the embodiment of the present application supports restoring the signature key by calling the key recovery service program, reconstructing the data signature service program based on the restored signature key, and calling the reconstructed data signature service program to sign the service data, that is, the embodiment of the present application can support the recovery of the signature key to ensure the recoverability of the signature key.

[0165] Next, a specific example is used to introduce the application of the blockchain-based data processing method provided by the embodiment of the present application in the tax scenario based on the double-layer blockchain network. This application scenario can include two stages, the creation stage of the target blockchain service and the usage stage of the target blockchain service. The application scenario of the embodiment of the present application is introduced from these two stages.

[0166] (1) Creation stage of the target blockchain service:

[0167] As Figure 13 shown, when the business server receives the creation request of the target blockchain service submitted by the management object of the target blockchain service (the management object specifically refers to the operator of the target blockchain service), it can request the double-layer blockchain network to create a corresponding sub-chain for the target blockchain service. The sub-chain corresponding to the target blockchain service can be used to record accounts for the target blockchain service. Here, requesting the double-layer blockchain network to create a corresponding sub-chain for the target blockchain service is specifically to request the business network in the double-layer blockchain network (the business network corresponds to Figure 13The business layer shown creates a corresponding sub-chain for the target blockchain business; when creating the sub-chain, relevant information of the sub-chain will be recorded in the parent chain, and the business network can send the sub-chain information corresponding to the target blockchain business to the core consensus network (the core consensus network corresponds to the Figure 13 routing proxy layer shown) through the routing proxy network (the routing proxy network corresponds to the Figure 13 core consensus layer in), and the core consensus network uploads the sub-chain information corresponding to the target blockchain business to the main chain.

[0168] After the sub-chain corresponding to the target blockchain business is successfully created, the business server can allocate an asymmetric key for the target blockchain business, and the asymmetric key allocated for the target blockchain business can include a public key and a private key (the private key is the signature key).

[0169] For the signature key, on the one hand, the business server can create a data signature service program based on the signature key. On the other hand, the business server can receive the mnemonic information of the signature key submitted by the management object of the target blockchain business and encrypt and back up the mnemonic information of the signature key. The encryption backup can specifically include: creating a hardware encryption service program, calling the hardware encryption service program to encrypt the mnemonic information, obtaining the encrypted mnemonic information, and storing the encrypted mnemonic information in the hardware encryption machine; and creating a cloud encryption service program, calling the cloud encryption service program to encrypt the mnemonic information, obtaining the encrypted mnemonic information, requesting the cloud to allocate cloud storage space for the target blockchain business, and requesting the cloud to store the encrypted mnemonic information in the cloud storage space allocated for the target blockchain business.

[0170] For the public key, the business server can send the public key to the blockchain nodes in the double-layer blockchain network, and the blockchain nodes in the double-layer blockchain network broadcast the public key of the target blockchain business in the blockchain network. Here, the blockchain nodes in the double-layer blockchain network can specifically refer to any business node in the business network.

[0171] (2) Usage stage of the target blockchain business:

[0172] Figure 13 Taking the target blockchain business as a tax business as an example, the business server can respond to the tax handling request of the tax handling object (for example, the tax handling object can be Figure 13 the e-tax bureau, enterprises, consumers, etc. in), execute the tax business of the tax handling object, and the business data involved in the process of executing the tax business is tax data.

[0173] The business server can call the data signature service program to sign the tax data. If the tax data is successfully signed by calling the data signature service program, the signed tax data can be sent to the blockchain node in the double-layer blockchain network. If the call to the data signature service program fails, the key recovery service program can be called to recover the signature key, and the data signature service program can be reconstructed based on the recovered signature key. Then, the reconstructed data signature service program is called to sign the tax data, and the signed tax data is sent to the blockchain node in the double-layer blockchain network. Here, the blockchain node in the double-layer blockchain network can specifically refer to any business node in the business network.

[0174] After the business node in the business network that receives the signed tax data successfully verifies the signature of the signed tax data using the public key of the target blockchain service, the tax data can be uploaded to the sub-chain corresponding to the target blockchain service.

[0175] It can be seen that the blockchain-based data processing method provided by the embodiments of the present application, which is applied to the tax scenario based on the double-layer blockchain network, can ensure the security and recoverability of the storage of the signature key used to sign the business data (i.e., tax data) of the tax business, which is beneficial to the normal operation of the tax business.

[0176] The method of the embodiments of the present application is described in detail above. To facilitate the better implementation of the above solutions of the embodiments of the present application, correspondingly, the devices of the embodiments of the present application are provided below.

[0177] Please refer to Figure 14 , Figure 14 which is a schematic structural diagram of a blockchain-based data processing device provided by the embodiments of the present application. The blockchain-based data processing device can be set in the computer device provided by the embodiments of the present application. The computer device can be the business server 501 in the data processing system shown above Figure 5 shown. Figure 14 The blockchain-based data processing device shown above can be a computer program running in a computer device. The data processing device can be used to execute Figure 8 or Figure 12 some or all of the steps in the method embodiments shown. Please refer to Figure 14 which shows that the blockchain-based data processing device can include the following units:

[0178] The processing unit 1401 is configured to call the data signature service program to sign the business data to be uploaded to the blockchain; the data signature service program is created based on the signature key, and when the data signature service program signs based on the signature key, the signature key is hidden;

[0179] The processing unit 1401 is further configured to, if the data signature service program call fails, call the key recovery service program to recover the signature key;

[0180] The processing unit 1401 is further configured to reconstruct the data signature service program according to the recovered signature key;

[0181] The processing unit 1401 is further configured to call the reconstructed data signature service program to sign the service data;

[0182] The communication unit 1402 is configured to upload the signed service data to the blockchain.

[0183] In one implementation, when the processing unit 1401 is configured to call the key recovery service program to recover the signature key, it is specifically configured to perform the following steps:

[0184] Call the key recovery service program to recover the encrypted mnemonic information of the signature key;

[0185] Decrypt the encrypted mnemonic information to obtain the mnemonic information of the signature key;

[0186] Recover the signature key according to the mnemonic information.

[0187] In one implementation, the encrypted mnemonic information is backed up to the hardware encryption machine and the cloud storage space; when the processing unit 1401 is configured to call the key recovery service program to recover the encrypted mnemonic information of the signature key, it is specifically configured to perform the following steps:

[0188] Call the key recovery service program to recover the encrypted mnemonic information of the signature key from the hardware encryption machine;

[0189] If the recovery of the encrypted mnemonic information of the signature key from the hardware encryption machine fails, call the key recovery service program to recover the encrypted mnemonic information from the cloud storage space.

[0190] In one implementation, the service data belongs to the target blockchain service; the encrypted mnemonic information is stored in the cloud storage space allocated for the target blockchain service by the cloud; the cloud allocates independent cloud storage spaces for different blockchain services;

[0191] When the processing unit 1401 is configured to call the key recovery service program to recover the encrypted mnemonic information from the cloud storage space, it is specifically configured to perform the following steps:

[0192] Obtain the cloud account information of the target blockchain service;

[0193] Call the key recovery service program to recover the encrypted mnemonic information from the cloud storage space of the target blockchain service based on the cloud account information of the target blockchain service.

[0194] In one implementation, when the processing unit 1401 is used to reconstruct the data signature service program according to the recovered signature key, it is specifically used to perform the following steps:

[0195] Perform first key hiding processing on the signature key according to the first cryptographic algorithm to obtain a data signature library;

[0196] Reconstruct the data signature service program based on the data signature library.

[0197] In one implementation, the data signature library refers to a data signature table, and the data signature library includes multiple data signatures; when the processing unit 1401 is used to call the reconstructed data signature service program to sign business data, it is specifically used to perform the following steps:

[0198] Query the data signature corresponding to the business data in the data signature library based on the business data to obtain the signed business data.

[0199] In one implementation, when the processing unit 1401 is used to reconstruct the data signature service program according to the recovered signature key, it is specifically used to perform the following steps:

[0200] Perform second key hiding processing on the signature key according to the second cryptographic algorithm to obtain a security key;

[0201] Pass the security key into the basic signature library, and reconstruct the data signature service program according to the basic signature library after the security key is passed in.

[0202] In one implementation, the basic signature library refers to a basic signature table, and the basic signature library includes multiple basic signatures; when the processing unit 1401 is used to call the reconstructed data signature service program to sign business data, it is specifically used to perform the following steps:

[0203] Query the basic signature corresponding to the business data in the basic signature library based on the business data;

[0204] Sign the basic signature corresponding to the business data based on the security key to obtain the signed business data.

[0205] In one implementation, the failure of the data signature service program to be called includes any of the following:

[0206] The data signature service program does not exist;

[0207] The data signature service program exists but an exception occurs;

[0208] The data signature service program fails to decrypt;

[0209] The data signature service program is constructed by the basic signature library that passes in the security key, and the security key is lost; the security key is generated based on the signature key.

[0210] In one implementation, the service data belongs to the target blockchain service; the processing unit 1401 is further configured to perform the following steps:

[0211] In response to a creation request for the target blockchain service, allocate a signature key for the target blockchain service;

[0212] Create a data signature service program based on the signature key;

[0213] Encrypt and back up the signature key.

[0214] In one implementation, when the processing unit 1401 is used to encrypt and back up the signature key, it is specifically configured to perform the following steps:

[0215] Obtain the mnemonic information of the signature key;

[0216] Create a hardware encryption service program, and call the hardware encryption service program to encrypt the mnemonic information to obtain encrypted mnemonic information, and then store the encrypted mnemonic information in the hardware encryption machine;

[0217] Create a cloud encryption service program, and call the cloud encryption service program to encrypt the mnemonic information to obtain encrypted mnemonic information, and then request the cloud to allocate cloud storage space for the target blockchain service, and request the cloud to store the encrypted mnemonic information in the cloud storage space allocated for the target blockchain service.

[0218] According to another embodiment of the present application, Figure 14 Each unit in the blockchain-based data processing device shown can be separately or all combined into one or several other units to form, or a certain one (or some) of the units can be further split into multiple smaller units with functional division to form, which can achieve the same operation without affecting the implementation of the technical effects of the embodiments of the present application. The above units are divided based on logical functions. In actual applications, the function of one unit can also be implemented by multiple units, or the functions of multiple units are implemented by one unit. In other embodiments of the present application, the blockchain-based data processing device may also include other units. In actual applications, these functions can also be assisted by other units and can be implemented by multiple units collaborating.

[0219] According to another embodiment of the present application, it is possible to run a computer program capable of executing the steps involved in part or all of the methods shown in Figure 8 or Figure 12 on a general computing device such as a computer including processing elements and storage elements such as a central processing unit (CPU), a random access storage medium (RAM), and a read-only storage medium (ROM), to construct a device such as Figure 14The blockchain-based data processing device shown in the figure, and the blockchain-based data processing method for implementing the embodiments of the present application. The computer program can be recorded on, for example, a computer-readable storage medium, loaded into the above-mentioned computing device through the computer-readable storage medium, and run therein.

[0220] In the embodiments of the present application, a data signature service program can be called to sign the service data to be uploaded to the blockchain; among them, the data signature service program can be created based on a signature key, and when the data signature service program signs based on the signature key, the signature key can be hidden; it can be seen that on the one hand, the data signature service program can hide the signature key to ensure the security of the signature key storage, and on the other hand, it can play the signature function of the signature key, that is, it can use the signature key to sign on the premise of ensuring the security of the signature key storage. In addition, when the call of the data signature service program fails, the embodiments of the present application can support calling a key recovery service program to recover the signature key, reconstruct the data signature service program based on the recovered signature key, and call the reconstructed data signature service program to sign the service data, that is, the embodiments of the present application can support the recovery of the signature key to ensure the recoverability of the signature key.

[0221] Based on the above methods and device embodiments, the embodiments of the present application provide a computer device. Please refer to Figure 15 , Figure 15 which is a schematic structural diagram of a computer device provided by the embodiments of the present application. Figure 15 The computer device shown at least includes a processor 1501, an input interface 1502, an output interface 1503, and a computer-readable storage medium 1504. Among them, the processor 1501, the input interface 1502, the output interface 1503, and the computer-readable storage medium 1504 can be connected through a bus or other means.

[0222] The computer-readable storage medium 1504 can be stored in the memory of the computer device. The computer-readable storage medium 1504 is used to store a computer program, and the computer program includes computer instructions. The processor 1501 is used to execute the computer program stored in the computer-readable storage medium 1504. The processor 1501 (or CPU (Central Processing Unit)) is the computing core and control core of the computer device, which is suitable for implementing the computer program, specifically suitable for loading and executing the computer program to implement the corresponding method flow or corresponding function.

[0223] The embodiments of the present application also provide a computer-readable storage medium (Memory). A computer-readable storage medium is a memory device in a computer device, used to store programs and data. It can be understood that the computer-readable storage medium here can include both the built-in storage medium in the computer device, and of course, the extended storage medium supported by the computer device. The computer-readable storage medium provides a storage space, and the operating system of the computer device is stored in this storage space. And, a computer program suitable for being loaded and executed by a processor is also stored in this storage space. It should be noted that the computer-readable storage medium here can be a high-speed RAM memory, or a non-volatile memory (Non-Volatile Memory), such as at least one disk memory; optionally, it can also be at least one computer-readable storage medium located far from the aforementioned processor.

[0224] The computer device can be the service server 501 in the data processing system shown above. Figure 5 In a specific implementation, the processor 1501 can load and execute the computer program stored in the computer-readable storage medium 1504 to implement the relevant Figure 8 or Figure 12 corresponding steps in the data processing method based on blockchain shown above. In a specific implementation, the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 to perform the following steps:

[0225] Call the data signature service program to sign the service data to be uploaded to the blockchain; the data signature service program is created based on a signature key, and when the data signature service program signs based on the signature key, the signature key is hidden;

[0226] If the call to the data signature service program fails, call the key recovery service program to recover the signature key;

[0227] Reconstruct the data signature service program according to the recovered signature key;

[0228] Call the reconstructed data signature service program to sign the service data, and upload the signed service data to the blockchain.

[0229] In one implementation, when the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 to call the key recovery service program to recover the signature key, it is specifically used to perform the following steps:

[0230] Call the key recovery service program to recover the encrypted mnemonic information of the signature key;

[0231] Decrypt the encrypted mnemonic information to obtain the mnemonic information of the signature key;

[0232] Restore the signature key according to the mnemonic information.

[0233] In one implementation, the encrypted mnemonic information is backed up to a hardware encryption machine and cloud storage space; when the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 to call the key recovery service program to restore the encrypted mnemonic information of the signature key, it is specifically used to perform the following steps:

[0234] Call the key recovery service program to restore the encrypted mnemonic information of the signature key from the hardware encryption machine;

[0235] If the restoration of the encrypted mnemonic information of the signature key from the hardware encryption machine fails, then call the key recovery service program to restore the encrypted mnemonic information from the cloud storage space.

[0236] In one implementation, the business data belongs to the target blockchain service; the encrypted mnemonic information is stored in the cloud storage space allocated for the target blockchain service by the cloud; the cloud allocates independent cloud storage spaces for different blockchain services;

[0237] When the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 to call the key recovery service program to restore the encrypted mnemonic information from the cloud storage space, it is specifically used to perform the following steps:

[0238] Obtain the cloud account information of the target blockchain service;

[0239] Call the key recovery service program to restore the encrypted mnemonic information from the cloud storage space of the target blockchain service based on the cloud account information of the target blockchain service.

[0240] In one implementation, when the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 to execute the data signature service program reconstruction according to the restored signature key, it is specifically used to perform the following steps:

[0241] Perform a first key hiding process on the signature key according to the first cryptographic algorithm to obtain a data signature library;

[0242] Reconstruct the data signature service program based on the data signature library.

[0243] In one implementation, the data signature library refers to a data signature table, and the data signature library includes multiple data signatures; when the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 to call the reconstructed data signature service program to sign the business data, it is specifically used to perform the following steps:

[0244] Query the data signature corresponding to the service data in the data signature library based on the service data to obtain the signed service data.

[0245] In one implementation, when the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 to reconstruct the data signature service program according to the restored signature key, it is specifically used to perform the following steps:

[0246] Perform a second key hiding process on the signature key according to the second cryptographic algorithm to obtain a security key;

[0247] Pass the security key into the basic signature library, and reconstruct the data signature service program according to the basic signature library after the security key is passed in.

[0248] In one implementation, the basic signature library refers to a basic signature table, and the basic signature library includes multiple basic signatures; when the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 to call the reconstructed data signature service program to sign the service data, it is specifically used to perform the following steps:

[0249] Based on the service data, query the basic signature corresponding to the service data in the basic signature library;

[0250] Sign the basic signature corresponding to the service data based on the security key to obtain the signed service data.

[0251] In one implementation, the failure of the data signature service program call includes any one of the following:

[0252] The data signature service program does not exist;

[0253] The data signature service program exists but an exception occurs;

[0254] The decryption of the data signature service program fails;

[0255] The data signature service program is constructed by the basic signature library that passes in the security key, and the security key is lost; the security key is generated based on the signature key.

[0256] In one implementation, the service data belongs to the target blockchain service; the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 and is also used to perform the following steps:

[0257] In response to the creation request of the target blockchain service, allocate a signature key for the target blockchain service;

[0258] Create a data signature service program based on the signature key;

[0259] Encrypt and back up the signature key.

[0260] In one implementation, when the computer program in the computer-readable storage medium 1504 is loaded and executed by the processor 1501 to encrypt and back up the signature key, it is specifically used to perform the following steps:

[0261] Obtain the mnemonic information of the signature key;

[0262] Create a hardware encryption service program, and call the hardware encryption service program to encrypt the mnemonic information. After obtaining the encrypted mnemonic information, store the encrypted mnemonic information in the hardware encryption machine;

[0263] Create a cloud encryption service program, and call the cloud encryption service program to encrypt the mnemonic information. After obtaining the encrypted mnemonic information, request the cloud to allocate cloud storage space for the target blockchain service, and request the cloud to store the encrypted mnemonic information in the cloud storage space allocated for the target blockchain service.

[0264] In the embodiment of the present application, a data signature service program can be called to sign the service data to be uploaded to the blockchain; among them, the data signature service program can be created based on the signature key. When the data signature service program signs based on the signature key, the signature key can be hidden; it can be seen that on the one hand, the data signature service program can hide the signature key and ensure the security of the signature key storage, and on the other hand, it can play the signature function of the signature key, that is, the signature key can be used for signature on the premise of ensuring the security of the signature key storage. In addition, when the call of the data signature service program fails, the embodiment of the present application can support calling the key recovery service program to recover the signature key, reconstruct the data signature service program based on the recovered signature key, and call the reconstructed data signature service program to sign the service data, that is, the embodiment of the present application can support the recovery of the signature key and ensure the recoverability of the signature key.

[0265] The embodiment of the present application also provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above-mentioned blockchain-based data processing method.

[0266] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in this application can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0267] In the embodiments of this application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the functions of that module or unit.

[0268] In the above embodiments, they can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of this application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state disk (SSD)).

[0269] As described above, the above are only the specific embodiments of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A blockchain-based data processing method, characterized in that Including: Invoking a data signature service program to sign the business data to be uploaded to the blockchain; The data signature service program is created based on a signature key, and when the data signature service program signs based on the signature key, the signature key is hidden; If the invocation of the data signature service program fails, then invoke a key recovery service program to recover the signature key; Reconstruct the data signature service program according to the recovered signature key; Invoke the reconstructed data signature service program to sign the business data, and upload the signed business data to the blockchain.

2. The method according to claim 1, wherein The invoking the key recovery service program to recover the signature key includes: Invoking the key recovery service program to recover the encrypted mnemonic information of the signature key; Decrypt the encrypted mnemonic information to obtain the mnemonic information of the signature key; Recover the signature key according to the mnemonic information.

3. The method according to claim 2, characterized in that The encrypted mnemonic information is backed up to a hardware encryption machine and cloud storage space; the invoking the key recovery service program to recover the encrypted mnemonic information of the signature key includes: Invoking the key recovery service program to recover the encrypted mnemonic information of the signature key from the hardware encryption machine; If the recovery of the encrypted mnemonic information of the signature key from the hardware encryption machine fails, then invoke the key recovery service program to recover the encrypted mnemonic information from the cloud storage space.

4. The method according to claim 3, characterized in that, The business data belongs to a target blockchain service; the encrypted mnemonic information is stored in the cloud storage space allocated for the target blockchain service by the cloud; the cloud allocates mutually independent cloud storage spaces for different blockchain services; The invoking the key recovery service program to recover the encrypted mnemonic information from the cloud storage space includes: Obtaining the cloud account information of the target blockchain service; Invoking the key recovery service program to recover the encrypted mnemonic information from the cloud storage space of the target blockchain service based on the cloud account information of the target blockchain service.

5. The method according to claim 1, wherein The reconstructing the data signature service program according to the recovered signature key includes: Performing a first key hiding process on the signature key according to a first cryptographic algorithm to obtain a data signature library; Reconstructing the data signature service program based on the data signature library.

6. The method according to claim 5, wherein The data signature library refers to a data signature table, and the data signature library includes multiple data signatures; the invoking the reconstructed data signature service program to sign the business data includes: Querying the data signature corresponding to the business data in the data signature library based on the business data to obtain the signed business data.

7. The method according to claim 1, characterized in that The reconstructing the data signature service program according to the recovered signature key includes: Performing a second key hiding process on the signature key according to a second cryptographic algorithm to obtain a security key; Passing the security key into a basic signature library, and reconstructing the data signature service program according to the basic signature library after the security key is passed in.

8. The method according to claim 7, wherein The basic signature library refers to the basic signature table, and the basic signature library includes multiple basic signatures; the step of using the reconstructed data signature service program to sign the service data includes: Querying, based on the service data, the basic signature corresponding to the service data in the basic signature library; Signing the basic signature corresponding to the service data based on the security key to obtain the signed service data.

9. The method according to claim 1, characterized in that, The failure of the data signature service program to be called includes any of the following: The data signature service program does not exist; The data signature service program exists but an exception occurs; The data signature service program fails to decrypt; The data signature service program is constructed from the basic signature library with the incoming security key, and the security key is lost; the security key is generated based on the signature key.

10. The method according to claim 1, characterized in that, The service data belongs to the target blockchain service; the method further includes: In response to a creation request for the target blockchain service, allocating the signature key for the target blockchain service; Creating the data signature service program based on the signature key; Performing encrypted backup on the signature key.

11. The method according to claim 10, wherein The performing encrypted backup on the signature key includes: Obtaining the mnemonic information of the signature key; Creating a hardware encryption service program, and calling the hardware encryption service program to encrypt the mnemonic information to obtain encrypted mnemonic information, and then storing the encrypted mnemonic information in a hardware encryption machine; Creating a cloud encryption service program, and calling the cloud encryption service program to encrypt the mnemonic information to obtain encrypted mnemonic information, and then requesting the cloud to allocate cloud storage space for the target blockchain service, and requesting the cloud to store the encrypted mnemonic information in the cloud storage space allocated for the target blockchain service.

12. A data processing device based on blockchain, characterized in that, including: A processing unit, configured to call a data signature service program to sign service data to be uploaded to the blockchain; The data signature service program is created based on a signature key, and when signing based on the signature key, the data signature service program hides the signature key; The processing unit is further configured to, if the data signature service program fails to be called, call a key recovery service program to recover the signature key; The processing unit is further configured to reconstruct the data signature service program according to the recovered signature key; The processing unit is further configured to call the reconstructed data signature service program to sign the service data; A communication unit, configured to upload the signed service data to the blockchain.

13. A computer device, characterized in that, The computer device includes: A processor, adapted to implement a computer program; A computer-readable storage medium storing a computer program, the computer program being adapted to be loaded and executed by the processor to perform the blockchain-based data processing method according to any one of claims 1-11.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program being adapted to be loaded and executed by a processor to perform the blockchain-based data processing method according to any one of claims 1-11.

15. A computer program product, characterized in that, The computer program product includes a computer program which, when executed by a processor, implements the blockchain-based data processing method according to any one of claims 1-11.