Data processing method and device based on block chain

By receiving and processing structured data in Internet services, creating verifiable statements and uploading them to the alliance blockchain system, the problems of user data processing and privacy protection are solved, the secure storage and privacy protection of data are realized, and the interpretability of operation behavior is improved.

CN120408723APending Publication Date: 2025-08-01ANT SHENGXIN (SHANGHAI) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510481908.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2021-01-28
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

In the process of Internet business processing, the rational processing of user data and privacy protection have become urgent issues that need to be resolved, especially in the service quality disputes that may arise after the business is completed, the importance of operational behavior data and page change data is highlighted.

Method used

By receiving structured data and user information from the business server, obtaining digital identity information, creating verified statements, and uploading them to the alliance blockchain system, using Merkel tree storage, realizing data security and authenticity, and defining access rights of data acquisition institutions to protect user privacy.

Benefits of technology

It ensures the security and authenticity of the data, supports the positioning of abnormal data and the construction of Merkel trees, realizes permission control over different data acquisition institutions, protects the privacy of user behavior data, and improves the interpretability of operation behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408723A_ABST
    Figure CN120408723A_ABST
Patent Text Reader

Abstract

Embodiments of the invention provide a block chain-based data processing method and apparatus. The method comprises the steps of receiving structured data of a target service and user information of a target user sent by a service server; acquiring digital identity information of a target user based on the user information; creating a verifiable statement of the structured data corresponding to the digital identity information according to the obtained digital identity information and the structured data; and uploading the statement content data of the created verifiable statement to an alliance block chain system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This divisional application of a Chinese invention patent application has an application date of January 28, 2021, an application number of 202110121511.9, and a title of "A Data Processing Method and Device Based on Blockchain". Technical Field

[0002] This document relates to the field of blockchain technology, and particularly to a data processing method and device based on blockchain. Background Art

[0003] With the rapid development of Internet technology, more and more services can be carried out online through the Internet, such as commercial insurance application services, financial management services, etc. When users handle services, they need to perform operations related to the services, such as clicking certain buttons or entering service-related information, etc. However, after the service is completed, there may be disputes such as the quality of service or the user not being able to enjoy the corresponding service. In this case, the relevant data during the user's service handling, such as operation behavior data, page change data, etc., becomes particularly important. Therefore, how to reasonably process the data during the user's service execution has become an urgent technical problem to be solved. Summary of the Invention

[0004] Embodiments of this specification provide a data processing method based on blockchain. Among them, the method includes: receiving the structured data of the target service and the user information of the target user sent by the service server. Obtaining the digital identity information of the target user based on the user information. Creating a verifiable claim for the structured data corresponding to the digital identity information according to the digital identity information and the structured data. Uploading the claim content data of the verifiable claim to the consortium blockchain system.

[0005] Embodiments of this specification also provide a data processing method based on blockchain. Among them, the method includes: obtaining the structured data of the target service. Generating access permission information for the structured data by each data acquisition institution. Sending the structured data and the access permission information to the authorization management server, so that the authorization management server uploads the structured data and the access permission information to the consortium blockchain system.

[0006] An embodiment of this specification also provides a blockchain-based data processing apparatus. The apparatus includes: a first receiving module, configured to receive the structured data of a target service and the user information of a target user sent by a service server; an obtaining module, configured to obtain the digital identity information of the target user based on the user information; a creating module, configured to create a verifiable claim of the structured data corresponding to the digital identity information according to the digital identity information and the structured data; and a first uploading module, configured to upload the claim content data of the verifiable claim to a consortium blockchain system.

[0007] An embodiment of this specification also provides a blockchain-based data processing apparatus. The apparatus includes: an obtaining module, configured to obtain the structured data of a target service; a generating module, configured to generate access permission information of each data obtaining institution for the structured data; and a sending module, configured to send the structured data and the access permission information to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system.

[0008] An embodiment of this specification also provides a blockchain-based data processing device, including: a processor; and a memory arranged to store computer-executable instructions, where the executable instructions, when executed, cause the processor to: receive the structured data of a target service and the user information of a target user sent by a service server; obtain the digital identity information of the target user based on the user information; create a verifiable claim of the structured data corresponding to the digital identity information according to the digital identity information and the structured data; and upload the claim content data of the verifiable claim to a consortium blockchain system.

[0009] An embodiment of this specification also provides a blockchain-based data processing device, including: a processor; and a memory arranged to store computer-executable instructions, where the executable instructions, when executed, cause the processor to: obtain the structured data of a target service; generate access permission information of each data obtaining institution for the structured data; and send the structured data and the access permission information to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system.

[0010] An embodiment of this specification also provides a storage medium for storing computer-executable instructions, where the executable instructions, when executed, implement the following process: receive the structured data of a target service and the user information of a target user sent by a service server; obtain the digital identity information of the target user based on the user information; create a verifiable claim of the structured data corresponding to the digital identity information according to the digital identity information and the structured data; and upload the claim content data of the verifiable claim to a consortium blockchain system.

[0011] The embodiment of this specification also provides a storage medium for storing computer-executable instructions, and when the executable instructions are executed, the following processes are implemented: obtaining structured data of a target service. Generating access right information of each data acquisition institution for the structured data. Sending the structured data and the access right information to an authorization management server, so that the authorization management server uploads the structured data and the access right information to a consortium blockchain system. Description of the Drawings

[0012] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in this application. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0013] Figure 1 It is a schematic diagram of the first application scenario of the blockchain-based data processing method provided by the embodiment of this specification; Figure 2 It is a schematic diagram of the second application scenario of the blockchain-based data processing method provided by the embodiment of this specification; Figure 3 It is a schematic diagram of the first process of the blockchain-based data processing method provided by the embodiment of this specification; Figure 4 It is a schematic diagram of the Merkle tree constructed in the blockchain-based data processing method provided by the embodiment of this specification; Figure 5 It is a schematic diagram of the second process of the blockchain-based data processing method provided by the embodiment of this specification; Figure 6 It is a schematic diagram of the structured data obtained in the blockchain-based data processing method provided by the embodiment of this specification; Figure 7 It is a schematic diagram of the third process of the blockchain-based data processing method provided by the embodiment of this specification; Figure 8 It is a schematic diagram of the interaction process of the blockchain-based data processing method provided by the embodiment of this specification; Figure 9 It is a schematic diagram of the first module composition of the blockchain-based data processing device provided by the embodiment of this specification; Figure 10 It is a schematic diagram of the second module composition of the blockchain-based data processing device provided by the embodiment of this specification; Figure 11Schematic structural diagram of a blockchain-based data processing device provided by an embodiment of this specification. Detailed implementation manners

[0014] In order to enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0015] Figure 1 Schematic diagram of the first application scenario of the blockchain-based data processing method provided by an embodiment of this specification, as Figure 1 shown, this application scenario includes a terminal device, a business server, an authorization management server, and a consortium blockchain system. Among them, the above terminal device can be a device such as a mobile phone, a tablet computer, or a computer. A business client is installed on the terminal device. Among them, the business client can be an independent application (APP) installed on the terminal device, can also be a small program embedded in some independent applications, or can also be a web page, etc.

[0016] Specifically, when a user executes a target business through a terminal device, the terminal device collects the operation behavior data and page change data of the user when executing the target business, and sends the collected operation behavior data and page change data to the business server. The business server generates structured data of the user executing the target business based on the operation behavior data and page change data; the business server sends the user information of the user and the structured data to the authorization management server, and the authorization management server obtains the digital identity information of the user based on the user information of the user. Among them, in a specific implementation manner, the digital identity information can be a Decentralized Identity (DID). The authorization management server creates a verifiable claim for the structured data corresponding to the digital identity information; and uploads the claim content data of the verifiable claim to the consortium blockchain, so that the consortium blockchain constructs a Merkle tree corresponding to the claim content data, thereby realizing the storage of the structured data in the consortium blockchain system.

[0017] Optionally, in a specific implementation manner, the verifiable claim for the structured data corresponding to the digital identity information of the target user is created through a digital identity blockchain system, and a specific manifestation form of the digital identity blockchain system can be a DID blockchain system. Therefore, Figure 2This is the second application scenario schematic diagram of the blockchain-based data processing method provided by the embodiments of this specification. As Figure 2 shown, this application scenario includes a terminal device, a business server, an authorization management server, a consortium blockchain system, and a DID blockchain system. Among them, Figure 2 For the relevant introductions of the terminal device and the business server in the shown system, reference can be made to Figure 1 the relevant introductions therein, which will not be elaborated here.

[0018] Figure 2 The difference between the shown application scenario and Figure 1 is that after the authorization management server obtains the digital identity information of the user based on the user information of the user, the authorization management server publishes the digital identity information and the structured data to the DID blockchain system, and the DID blockchain system constructs a verifiable claim for the structured data corresponding to the digital identity information. After the DID blockchain creates a verifiable claim for the structured data corresponding to the digital identity information, it returns the claim content data of the created verifiable claim and the identification information of the verifiable claim to the authorization management server; then, the authorization management server uploads the claim content data of the verifiable claim to the consortium blockchain so that the consortium blockchain constructs a Merkle tree corresponding to the claim content data, thereby realizing the storage of the structured data in the consortium blockchain.

[0019] Among them, it should be noted that the above Figure 1 and Figure 2 only exemplarily list two possible application scenarios of the blockchain-based data processing method provided by the embodiments of this specification, and do not constitute a limitation on the application scenarios of the blockchain-based data processing method provided by the embodiments of this specification.

[0020] In addition, it should be noted that the target service mentioned in the embodiments of this specification can be any service, such as commercial insurance application service, commodity trading service, and so on.

[0021] Figure 3 This is the first process schematic diagram of the blockchain-based data processing method provided by the embodiments of this specification. This method is applied to the authorization management server. As Figure 3 shown, this method at least includes the following steps: Step 102, receive the structured data of the target service and the user information of the target user sent by the business server.

[0022] Among them, the above user information can be the identification information of the target user on the business server, the account information of the target user on the business server, or the identity document information of the target user, etc. Of course, the above user information can also be other information, as long as it can identify the target user, and the embodiments of this specification will not elaborate one by one.

[0023] The above structured data is the structured data of the relevant data generated when the target user executes the target business. The above relevant data can be the user's operation behavior data, page change data, etc. The above structured data is generated based on the above relevant data. Among them, the above operation behavior data can be collected by pre-burying points in the business client.

[0024] Optionally, in specific implementation, when the business server receives the operation behavior data of the target user executing the target business and the page change data of the business client when the target user executes the target business reported by the business client, it associates the operation behavior data and the page change data, and generates the structured data corresponding to the associated operation behavior data. Specifically, the above association of the operation behavior data and the page change data can be to determine the page changes caused by each operation behavior according to the operation time corresponding to each operation behavior data and the change time corresponding to each page change data, so as to associate each operation behavior data with the page change data.

[0025] For example, in a specific implementation manner, the time when the target user executes the click operation of clicking the "Buy Now" control is 13:12:06 on December 18, 2019, and the time when the business client jumps from the "Insurance Details" page to the "Important Notice" page is also 13:12:06 on December 18, 2019. Since the time when the user executes the above operation behavior is the same as the time of this page change, it can be considered that this page change is caused by the target user executing the click operation of the "Buy Now" control, so this operation behavior is associated with the above page change.

[0026] Of course, it should be noted that when associating the operation behavior data and the page change data based on the operation time corresponding to the operation behavior data and the change time corresponding to the page change, the association condition can be that the operation time is the same as the change time, or the change time is later than the operation time, and the time difference is less than or equal to a preset value.

[0027] After the business server determines the structured data of the target user executing the target business and the user information of the target user, it sends the structured data of the target user and the user information of the target user to the authorization management server.

[0028] Step 104: Obtain the digital identity information of the target user based on the above user information.

[0029] Among them, the above digital identity information can have multiple forms of expression. One possible form of expression is, for example, DID.

[0030] Step 106: Create a verifiable claim for the structured data corresponding to the digital identity information according to the above digital identity information and structured data.

[0031] Among them, the claim content data of the above verifiable claim is actually the above structured data, and the above verifiable claim is used to claim the structured data corresponding to the target user.

[0032] Step 108: Upload the claim content data of the verifiable claim to the consortium blockchain system.

[0033] Among them, in the embodiments of this specification, the claim content data of the verifiable claim is stored in the consortium blockchain system in the form of a Merkle tree. Optionally, for the convenience of understanding the storage form of the claim content data mentioned in the embodiments of this specification, the following will be described with reference to the drawings. For example, in a specific implementation manner, a schematic diagram of the Merkle tree corresponding to the claim content constructed by the consortium blockchain is as Figure 4 shown.

[0034] In the embodiments of this specification, in the consortium blockchain system, the claim content data of the verifiable claim is stored in the form of a Merkle tree. In this way, different levels of signature verification are granted to data with different privacy levels, realizing the protection of user privacy data.

[0035] Optionally, in a specific implementation manner, before uploading the claim content data of the verifiable claim to the consortium blockchain, in order to protect the security of the claim content data, the claim content data can also be encrypted, and the encrypted ciphertext data is uploaded to the consortium blockchain system.

[0036] Among them, in specific implementation, the above claim content data can be encrypted using the Advanced Encryption Standard (AES).

[0037] The data processing method based on blockchain provided by the embodiments of this specification. After the authorization management server obtains the structured data of the target user when performing the target service, based on the digital identity information of the target user and this structured data, it creates a verifiable claim for the structured data corresponding to this digital identity information; then it uploads the claim content data of this verifiable claim to the consortium blockchain system, thereby realizing the storage of the claim content data in the consortium blockchain, ensuring that the claim content data will not be tampered with, that is, ensuring the security and authenticity of the claim content data; in addition, in the embodiments of this specification, storing the data of the target user when performing the target service in the form of structured data can not only facilitate the subsequent positioning of abnormal data, but also facilitate the construction of the Merkle tree corresponding to this structured data.

[0038] To facilitate the understanding of the method provided by the embodiments of this specification, the following will introduce in detail the specific implementation processes of the above-mentioned various steps.

[0039] Optionally, in a specific implementation manner, in the above step 104, obtaining the digital identity information of the target user based on the user information may include at least the following two implementation manners: Manner 1 Search for the digital identity information corresponding to the target user from the pre-generated digital identity information corresponding to each user.

[0040] Optionally, in a specific implementation manner, when the target user is not performing a service on the authorization management server for the first time, since the digital identity information corresponding to the target user has been created when the target user first performed a service through the authorization management server, and the mapping relationship between the user information and the digital identity information of each user is stored in the authorization management server, therefore, when the target user is not performing a service on the authorization management server for the first time, the digital identity information corresponding to the target user can be matched from the above mapping relationship based on the identity information of the target user.

[0041] Manner 2 Create the digital identity information corresponding to the target user based on the user information of the target user.

[0042] Optionally, in a specific implementation manner, when the target user first performs a service through the authorization management platform, the digital identity information corresponding to the target user needs to be created. Specifically, the digital identity information of the target user is created based on one or more items of information in the user information of the target user.

[0043] Optionally, in a specific implementation manner, in the above step 106, creating a verifiable claim for the structured data corresponding to this digital identity information according to the above digital identity information and structured data specifically includes the following Step 1 and Step 2: Step 1: Upload the digital identity information and structured data of the target user to the digital identity blockchain system, and create a verifiable claim through the digital identity blockchain system based on the digital identity information and structured data of the target user. Step 2: Receive the identification information of the verifiable claim and the content data of the verifiable claim returned by the digital identity blockchain system.

[0044] Among them, in a specific implementation manner, a specific manifestation form of the above digital identity blockchain system may be a DID blockchain system. That is, in the embodiments of this specification, the specific creation process of the above verifiable claim is executed in the DID blockchain system. After the DID blockchain system completes the creation of the above verifiable claim, it returns the identification information of the created verifiable claim and the claim content data of the verifiable claim to the authorization management server.

[0045] Specifically, in the embodiments of this specification, the above verifiable claim is actually used to declare the structured data of the target user when performing the target business.

[0046] Optionally, the claim content data of the generated verifiable claim actually includes multiple operation behavior data, and each operation behavior data is represented in a structured form. For example, a specific content of the above claim content data is as follows: Operation behavior data 1: Operation time, operation page identifier, page area identifier of the operation; Operation behavior data 2: Operation time, operation page identifier, edited information; Operation behavior data 3: Operation time, operation page identifier, page change data.

[0047] That is, each operation behavior data has multiple data contents. However, some data contents may involve the privacy information of the target user. For example, for the operation behavior data of "editing the policyholder", it will involve the user's personal information. Therefore, this data content cannot be open to some data acquisition institutions. Therefore, in the embodiments of this specification, in order to open different data to different data acquisition institutions, different access permission information needs to be generated for different data acquisition institutions. Therefore, the method provided in the embodiments of this specification further includes the following steps: Receive the access permission information of the data acquisition institution for the above claim content data sent by the business server; upload the access permission information to the consortium blockchain system.

[0048] Among them, it should be noted that different data acquisition institutions correspond to different access permission information. The above access permission information includes the access permission values corresponding to each data content in the statement content data. The above access permission values include a first value and a second value. The first value indicates that the data acquisition institution has the permission to access the data content, and the second value indicates that the data acquisition institution does not have the permission to access the data content.

[0049] Generally, when the access permission value corresponding to a certain data content is the first value, the content value of the data content is returned to the data acquisition institution. When the access permission value corresponding to a certain data content is the second value, the hash value corresponding to the data content is returned to the data acquisition institution.

[0050] Optionally, in a specific implementation manner, the access permission information corresponding to each of the above data acquisition institutions can be generated on the business server. Specifically, when the business server generates the access permission information corresponding to each data acquisition institution by defining an index. Specifically, the index contains multiple pairs of key-value values. The key represents the data content in the statement content data, and the value represents the access permission value of the data acquisition institution for the content data.

[0051] For the convenience of understanding, the following will give examples for illustration.

[0052] For example, in a specific implementation manner, assume that the statement content of the verifiable statement includes data content 1, data content 2, data content 3, data content 4, and data content 5. A specific form of the index corresponding to a certain data acquisition institution generated is as follows: {data content 1 - 0; data content 2 - 1; data content 3 - 0; data content 4 - 0; data content 5 - 0} Among them, when the value value corresponding to a certain data content is 0, it indicates that the data acquisition institution can obtain the data value of this data content. When the value value corresponding to a certain data content is 1, it indicates that the data acquisition institution cannot obtain this data content and can only obtain the hash value corresponding to this data content.

[0053] Therefore, when the data acquisition institution obtains the statement content data of the above verifiable statement, if the permission value corresponding to a certain data content is 0, the data value of this data content is carried in the statement content data. If the permission value corresponding to a certain data content is 1, the hash value of this data content is carried in the statement content data.

[0054] For example, in a specific implementation manner, a specific form of the defined index is as follows: { "Item1": "1", "Educational information": { "Education level": "0", "Graduated from institution": "0", "Major": "0" Based on the above index, the claim content data of the verifiable claim shared with the data acquisition institution is as follows: "claim": { "Item1": "hash value", "Educational information": { "Education level": "Master", "Graduated from institution": "Shanghai Jiao Tong University", "Major": "Civil Engineering" Of course, this is only an illustrative example here and does not constitute a limitation to the embodiments of this specification.

[0055] Optionally, after the business server generates the access permission information corresponding to the data acquisition institution, it can directly upload the access permission information to the consortium blockchain system for storage, or send the access permission information to the authorization management server, and upload the access permission information to the consortium blockchain system for storage through the authorization management server.

[0056] The method provided by the embodiments of this specification can determine which data content in the claim content data to share with the data acquisition institution by defining the access permission information corresponding to each data acquisition institution, so as to realize sharing different data content for different data acquisition institutions, thereby ensuring the privacy of user behavior data.

[0057] Optionally, in a specific implementation manner, after performing the above step 108, that is, after uploading the claim content data of the verifiable claim to the consortium blockchain system, the method provided by the embodiments of this specification further includes the following process: Receive an authorization request from the business server to authorize the target data acquisition institution to access the claim content data of the verifiable claim; execute the permission to grant the target data acquisition institution to access the claim content data of the verifiable claim according to the authorization request.

[0058] Among them, the above authorization request carries the digital identity information of the target data acquisition institution, the identification information of the verifiable claim, and the access permission information corresponding to the target data acquisition institution.

[0059] Optionally, each data acquisition institution can obtain its corresponding digital identity information through the authorization management server in advance. In specific implementation, it can be that each data acquisition institution sends its relevant information to the authorization management server, and the authorization management server creates its corresponding digital identity information.

[0060] Specifically, after the on-chain operation of the structured data corresponding to the target business is completed, an operation of granting the permission information for the target data acquisition institution to access the claim content data of the verifiable claim is performed. In a specific implementation manner, it can be that after the on-chain operation of the structured data is completed, a prompt message for whether to authorize the data acquisition institution to access the claim content data of the verifiable claim is popped up on the current page of the business client, and operation buttons such as "Yes", "No", "Go to Authorize", and "Temporarily Not Authorize" are displayed on this interface. If the user clicks the operation button of "Yes" or "Go to Authorize", the operation of granting the data acquisition institution the permission to access the claim content data of the verifiable claim is triggered.

[0061] Actually, in specific implementation, when the user clicks the operation button of "Yes" or "Go to Authorize", it is equivalent to sending an instruction message to the business server to execute the authorization for the data acquisition institution to access the claim content data of the verifiable claim. Of course, if the user clicks the operation button of "Yes" or "Go to Authorize", a list of data acquisition institutions that can be authorized will be popped up on the current page, and the user can select the data acquisition institution that needs to be authorized from the popped-up list of data acquisition institutions, and use the data acquisition institution selected by the user as the above-mentioned target data acquisition institution.

[0062] After the business server receives the instruction sent by the client to execute the authorization for the target data acquisition institution to access the claim content data of the verifiable claim, it determines the access permission information corresponding to the target data acquisition institution, generates an authorization request based on the access permission information corresponding to the target data acquisition institution, the digital identity information of the target data acquisition institution, and the identification information of the verifiable claim to be accessed, and sends this authorization request to the authorization management server; after receiving the above authorization request sent by the business server, the authorization management server executes the operation of granting the target data acquisition institution the permission to access the claim content data of the verifiable claim based on this authorization request.

[0063] In addition, it should be noted that in some other specific embodiments, when the user performs an operation to authorize the target data acquisition institution to access the claim content data of the verifiable claim, the user can directly send the corresponding authorization instruction information to the authorization management server through the business client; that is, in a specific embodiment, the authorization management server receives the instruction information sent by the user to grant the target data acquisition institution the right to access the claim content data of the verifiable claim, where the instruction information carries the digital identity information of the target data acquisition institution and the identification information of the verifiable claim; the authorization management server determines the access right information corresponding to the target data acquisition institution based on the digital identity information of the target data acquisition institution, and then grants the target data acquisition institution the right to access the claim content data of the verifiable claim based on the digital identity information of the target data acquisition structure, the identification information of the verifiable claim, and the access right information.

[0064] Optionally, in a specific embodiment, the above-mentioned granting the target data acquisition institution the right to access the claim content data of the verifiable claim according to the authorization request specifically includes the following process: Send the above authorization request to the consortium blockchain system so that the consortium blockchain system determines the transaction hash value corresponding to the authorization request; obtain the above transaction hash value from the consortium blockchain system, and return the transaction hash value and the digital identity information of the target data acquisition institution to the business server.

[0065] Wherein, the above transaction hash value can be used to obtain the claim content data of the verifiable claim from the consortium blockchain.

[0066] Optionally, in a specific embodiment, after obtaining the above transaction hash value from the consortium blockchain system and returning the transaction hash value and the digital identity information of the target data acquisition institution to the business server, the method provided by the embodiments of this specification further includes the following steps: Receive a data query request sent by the target data acquisition institution for querying the claim content data of the verifiable claim; where the data query request carries the identification information of the verifiable claim; determine the claim content data of the verifiable claim shared with the target data acquisition institution according to the access right information corresponding to the target data acquisition institution and the identification information of the verifiable claim, and send the claim content data to the target data acquisition institution so that the target data acquisition institution verifies the signature of the obtained claim content data based on the transaction hash value.

[0067] Optionally, in a specific embodiment, after authorizing the target data acquisition institution, the above transaction hash value and the digital identity information of the target data acquisition institution are returned to the business server, thereby completing the authorization operation for the target data acquisition institution.

[0068] Specifically, after completing the authorization operation for the target data acquisition institution, the business server sends the identification information and transaction hash value of the above verifiable claim to the target data acquisition institution.

[0069] When the target data acquisition institution needs to query the content data of the verifiable claim, it sends a data query request to the authorization management server. The data query request carries the identification information of the verifiable claim and the digital identity information of the target data acquisition institution. The authorization management server determines the claim content data to be returned to the target data acquisition institution based on the data query request and returns it to the target data acquisition institution. The target data acquisition institution verifies the acquired claim content data based on the pre-acquired transaction hash value.

[0070] The data processing method based on blockchain provided by the embodiments of this specification has at least the following beneficial effects: After obtaining the structured data of the target business, the authorization management server creates a verifiable claim for the structured data corresponding to the digital identity information based on the digital identity information of the target user and the structured data. Then, it uploads the claim content data of the verifiable claim to the consortium blockchain system, thereby realizing the storage of the claim content data in the consortium blockchain, ensuring that the claim content data will not be tampered with, that is, ensuring the security and authenticity of the claim content data. In addition, in the embodiments of this specification, the data when the target user executes the target business is stored in the form of structured data, which can not only facilitate the subsequent positioning of abnormal data but also facilitate the construction of the Merkle tree corresponding to the structured data. By defining the access permission information corresponding to each data acquisition institution, it is possible to determine which data contents in the claim content data are shared with the data acquisition institution, thereby realizing the sharing of different data contents for different data acquisition institutions, and thus ensuring the privacy of user behavior data. Associating the operation behavior data with the page change data through time can realize the interpretability of each operation behavior.

[0071] Corresponding to the method provided in the above embodiments of this specification, based on the same idea, the embodiments of this specification also provide a data processing method based on blockchain. This method is applied to the business server. Figure 5 This is the second process schematic diagram of the data processing method based on blockchain provided by the embodiments of this specification. As Figure 5 described, this method at least includes the following steps: Step 202, obtain the structured data of the target business.

[0072] Step 204, generate the access permission information for each data acquisition institution for the above structured data.

[0073] Step 206: Send the above-mentioned structured data and access right information to the authorization management server, so that the authorization management server uploads the structured data and access right information to the alliance blockchain system.

[0074] Wherein, in the embodiments of this specification, the above-mentioned structured data is stored in the alliance blockchain system using a Merkle tree.

[0075] Optionally, in a specific implementation manner, in the above step 202, obtaining the structured data of the target user executing the target service specifically includes the following process: Obtain the operation behavior data of the target user when executing the target service on the client, and obtain the page change data of the client when the target user executes the target service on the client; associate the operation behavior data with the page change data, and construct the above-mentioned structured data according to the operation behavior granularity.

[0076] Specifically, the above-mentioned operation behavior data includes the operation time corresponding to each operation behavior, and the above-mentioned page change data includes the change time corresponding to each page change; Correspondingly, the above-mentioned association of the operation behavior data with the page change data specifically includes the following process: For each operation behavior in the operation behavior data, determine the change time that is consistent with the operation time corresponding to the operation behavior; determine the page change corresponding to the change time that is consistent with the operation time as the page change associated with the operation behavior, and establish an association relationship between the operation behavior and its associated page change.

[0077] Wherein, the specific process of obtaining the structured data of the target user executing the target service can refer to the foregoing method embodiments, and will not be elaborated here.

[0078] Optionally, in a specific implementation manner, a specific form of the structured data of the target user executing the target service obtained is as Figure 6 shown. Of course, Figure 6 this is only an exemplary illustration and does not constitute a limitation on the embodiments of this specification.

[0079] In addition, it should be noted that in the embodiments of this specification, by associating the user operation behavior data with the page change data, the interpretability of some user operation behaviors can be realized through the page change situation. Compared with realizing the interpretability of user operation behaviors in the form of an admission video, it has lower management costs and retrieval costs.

[0080] Wherein, the specific implementation process of each step in the above Figure 5 shown embodiment can refer to the foregoing method embodiments, and will not be elaborated here.

[0081] Optionally, in a specific embodiment, the federated blockchain system stores the statement content data of the verifiable statement corresponding to the above structured data, and the verifiable statement is created by the authorization management server; correspondingly, after performing the above step 206, that is, sending the structured data and access permission information to the authorization management server, the method provided by the embodiments of this specification further includes the following steps: Receiving an indication message sent by the target user to authorize the target data acquisition institution to access the statement content data of the verifiable statement corresponding to the structured data; wherein, the indication message carries the digital identity information of the target data acquisition institution and the identification information of the verifiable statement; determining the access permission information of the target data acquisition institution for the verifiable statement according to the digital identity information of the target data acquisition institution and the identification information of the verifiable statement; generating an authorization request for requesting the target data acquisition institution to access the statement content data of the verifiable statement based on the digital identity information of the target data acquisition institution, the identification information of the verifiable statement, and the access permission information, and sending the authorization request to the authorization management server, so that the authorization management server performs an operation of granting the target data acquisition institution the permission to access the content data of the verifiable statement.

[0082] Among them, the specific implementation processes of the above steps can refer to the foregoing method embodiments and will not be elaborated here.

[0083] To facilitate understanding of the method provided by the embodiments of this specification, the method provided by the embodiments of this specification will be introduced below in the form of interaction between the business server and the authorization management server. Figure 7 This is the third process schematic diagram of the blockchain-based data processing method provided by the embodiments of this specification. As Figure 7 shown, the method at least includes the following steps: Step 302, the business server obtains the operation behavior data of the target user when performing the target business, and obtains the page change data of the client when the target user performs the target business.

[0084] Step 304, associating the above operation behavior data with the page change data, and constructing structured data according to the operation behavior granularity.

[0085] Step 306, generating access permission information for each data acquisition institution for the structured data.

[0086] Step 308, sending the above structured data, access permission information, and user information of the target user to the authorization management server.

[0087] Step 310, the authorization management server obtains the digital identity information of the target user based on the user information of the target user.

[0088] Step 312: The authorization management server uploads the above digital identity information and structured data to the digital identity blockchain system so that the digital identity blockchain system creates a verifiable claim for the structured data corresponding to the digital identity information.

[0089] Step 314: The authorization management server obtains the identification information and claim content data of the verifiable claim returned by the digital identity blockchain system.

[0090] Step 316: The authorization management server uploads the claim content data of the verifiable claim and the access permission information to the consortium blockchain system so that the consortium blockchain system stores the access permission information and constructs a Merkle tree corresponding to the claim content data.

[0091] Optionally, in a specific implementation, when the blockchain-based data processing method provided in the embodiments of this specification is executed, it may involve a business server, an authorization management server, a DID blockchain system, a consortium blockchain system, and a data acquisition institution; therefore, the interaction flowchart of the blockchain-based data processing method provided in the embodiments of this specification is as Figure 8 shown, and at least includes a data on-chain stage, an authorization stage, and a data verification stage, specifically including the following steps: Data on-chain stage: Step 402: The business server obtains the operation behavior data of the target user performing the target business and the page change data of the business client.

[0092] Step 404: The business server correlates the operation behavior data and the page change data, and constructs structured data based on the correlated data.

[0093] Step 406: The business server generates access permission information for each data acquisition institution for the above structured data.

[0094] Step 408: The business server sends the above structured data, access permission information, and user information of the target user to the authorization management server.

[0095] Step 410: The authorization management server obtains the digital identity information of the target user based on the user information.

[0096] Step 412: The authorization management server sends the digital identity information of the target user and the structured data to the DID blockchain system.

[0097] Step 414: The DID blockchain system creates a verifiable claim for the structured data corresponding to the digital identity information of the target user.

[0098] Step 416, the DID blockchain returns the identification information and claim content data of the created verifiable claim to the authorization management server.

[0099] Step 418, the authorization management server uploads the claim content data of the verifiable claim and the access permission information to the consortium blockchain system.

[0100] Step 420, the consortium blockchain system stores the access permission information and constructs a Merkle tree corresponding to the claim content data.

[0101] Authorization phase: Step 422, the business server receives an indication message triggered by the target user to authorize the target data acquisition institution to access the claim content data of the above verifiable claim.

[0102] Among them, the above indication message carries the digital identity information of the target data acquisition institution and the identification information of the verifiable claim.

[0103] Step 424, the business server determines the access permission information of the target data acquisition institution for the claim content data of the verifiable claim based on the digital identity information of the target data acquisition institution and the identification information of the verifiable claim.

[0104] Step 426, the business server generates an authorization request for requesting the target data acquisition institution to access the claim content data of the verifiable claim based on the digital identity information of the target data acquisition institution, the identification information of the verifiable claim, and the access permission information.

[0105] Step 428, the business server sends the authorization request to the authorization management server.

[0106] Step 430, the authorization management server sends the authorization request to the consortium blockchain system.

[0107] Step 432, the consortium blockchain system determines the transaction hash value corresponding to the target data acquisition institution based on the authorization request.

[0108] Step 434, the authorization management server obtains the transaction hash value and the digital identity information of the target data acquisition institution from the consortium blockchain system.

[0109] Step 436, the authorization management server sends the above transaction hash value and the identification information of the verifiable claim to the business server.

[0110] Data verification phase: Step 438, the authorization management server receives a data query request sent by the target data institution for querying the claim content data of the verifiable claim.

[0111] Among them, the above data query request carries the identification information of the verifiable claim and the digital identity information of the target data acquisition institution.

[0112] Step 440, the authorization management server determines the claim content data to be shared with the target data acquisition institution.

[0113] Step 442, the authorization management server sends the claim content data to the target data acquisition institution.

[0114] Step 444, the target data acquisition institution verifies the acquired claim content data through the consortium blockchain system based on the transaction hash value.

[0115] The data processing method based on blockchain provided by the embodiments of this specification has at least the following beneficial effects: acquiring the structured data of the target user when performing the target service and uploading the structured data to the consortium blockchain system for storage, thereby realizing the storage of the structured data in the consortium blockchain, ensuring that the structured data will not be tampered with, that is, ensuring the security and authenticity of the structured data; in addition, in the embodiments of this specification, storing the data of the target user when performing the target service in the form of structured data can not only facilitate the subsequent positioning of abnormal data, but also facilitate the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition institution, it is possible to determine which data content in the claim content data is shared with the data acquisition institution, so as to realize sharing different data content for different data acquisition institutions, thereby ensuring the privacy of user behavior data; associating the operation behavior data with the page change data through time can realize the interpretability of each operation behavior.

[0116] Corresponding to the method provided in this specification Figure 3 Based on the same idea, the embodiments of this specification also provide a data processing device based on blockchain, which is used to execute the method provided in the embodiments shown in this specification Figure 3 shown in this specification Figure 9 The first schematic diagram of the module composition of the data processing device based on blockchain provided by the embodiments of this specification is as shown in Figure 9 shown, and the device at least includes: The first receiving module 502 is used to receive the structured data of the target service and the user information of the target user sent by the service server. The obtaining module 504 is used to obtain the digital identity information of the target user based on the user information. The creating module 506 is used to create a verifiable claim of the structured data corresponding to the digital identity information according to the digital identity information and the structured data. The first upload module 508 is used to upload the statement content data of the verifiable statement to the consortium blockchain system.

[0117] Among them, the device provided in the embodiments of this specification can implement Figure 3 all the method steps of the method provided in the illustrated embodiments, which will not be elaborated here.

[0118] The blockchain-based data processing device provided in the embodiments of this specification has at least the following beneficial effects: after the authorization management server obtains the structured data of the target user when performing the target service, based on the digital identity information of the target user and the structured data, it creates a verifiable statement of the structured data corresponding to the digital identity information; then it uploads the statement content data of the verifiable statement to the consortium blockchain system, thereby realizing the storage of the statement content data in the consortium blockchain, ensuring that the statement content data will not be tampered with, that is, ensuring the security and authenticity of the statement content data; in addition, in the embodiments of this specification, the data of the target user when performing the target service is stored in the form of structured data, which can not only facilitate the subsequent positioning of abnormal data, but also facilitate the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition institution, it is possible to determine which data contents in the statement content data are shared with the data acquisition institution, so as to realize sharing different data contents for different data acquisition institutions, thereby ensuring the privacy of user behavior data; associating the operation behavior data with the page change data through time can realize the interpretability of each operation behavior.

[0119] Corresponding to the method provided in this specification Figure 5 Based on the same idea, the embodiments of this specification also provide a blockchain-based data processing device for executing the method provided in the illustrated embodiments of this specification Figure 5 shown in Figure 10 FIG. is the second schematic diagram of the module composition of the blockchain-based data processing device provided in the embodiments of this specification. As Figure 10 shown, the device at least includes: An acquisition module 602, configured to acquire structured data of a target service; A generation module 604, configured to generate access permission information for each data acquisition institution for the structured data; A sending module 606, configured to send the structured data and the access permission information to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to the consortium blockchain system.

[0120] Among them, the device provided in the embodiments of this specification can implement Figure 5All the method steps of the method provided by the illustrated embodiment are not elaborated herein.

[0121] The data processing device based on blockchain provided by the embodiments of this specification has at least the following beneficial effects: obtaining the structured data of the target user when executing the target service and uploading the structured data to the consortium blockchain system for storage, thereby realizing the storage of the structured data in the consortium blockchain, ensuring that the structured data will not be tampered with, that is, ensuring the security and authenticity of the structured data; in addition, in the embodiments of this specification, storing the data of the target user when executing the target service in the form of structured data can not only facilitate the subsequent positioning of abnormal data, but also facilitate the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition institution, it is possible to determine which data contents in the statement content data are shared with the data acquisition institution, thereby realizing the sharing of different data contents for different data acquisition institutions, and thus ensuring the privacy of user behavior data; associating the operation behavior data with the page change data through time can realize the interpretability of each operation behavior.

[0122] Furthermore, based on the above Figure 3 illustrated method, the embodiments of this specification also provide a data processing device based on blockchain, as Figure 11 illustrated.

[0123] The data processing device based on blockchain may vary greatly due to configuration or performance, and may include one or more processors 701 and a memory 702. One or more application programs or data may be stored in the memory 702. Among them, the memory 702 may be short-term storage or persistent storage. The application programs stored in the memory 702 may include one or more modules (not shown in the figure), and each module may include a series of computer-executable instruction information in the data processing device based on blockchain. Further, the processor 701 may be set to communicate with the memory 702 and execute a series of computer-executable instruction information in the memory 702 on the data processing device based on blockchain. The data processing device based on blockchain may also include one or more power supplies 703, one or more wired or wireless network interfaces 704, one or more input / output interfaces 705, one or more keyboards 706, etc.

[0124] In a specific embodiment, the blockchain-based data processing device includes a memory and one or more programs. One or more of the programs are stored in the memory, and one or more of the programs may include one or more modules. Each module may include a series of computer-executable instruction information in the blockchain-based data processing device and is configured to be executed by one or more processors. The one or more programs include the following computer-executable instruction information for: Receiving the structured data of the target service and the user information of the target user sent by the service server; Obtaining the digital identity information of the target user based on the user information; Creating a verifiable claim for the structured data corresponding to the digital identity information according to the digital identity information and the structured data; Uploading the claim content data of the verifiable claim to the consortium blockchain system.

[0125] Optionally, the blockchain-based data processing device provided in the embodiments of this specification can implement Figure 3 All the method steps of the method provided in the illustrated embodiment, which will not be elaborated here.

[0126] The blockchain-based data processing device provided in the embodiments of this specification has at least the following beneficial effects: After the authorization management server obtains the structured data of the target user when performing the target service, based on the digital identity information of the target user and the structured data, it creates a verifiable claim for the structured data corresponding to the digital identity information; then uploads the claim content data of the verifiable claim to the consortium blockchain system, thereby realizing the storage of the claim content data in the consortium blockchain, ensuring that the claim content data will not be tampered with, that is, ensuring the security and authenticity of the claim content data; in addition, in the embodiments of this specification, the data when the target user performs the target service is stored in the form of structured data, which can not only facilitate the subsequent positioning of abnormal data, but also facilitate the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition institution, it is possible to decide which data content in the claim content data to share with the data acquisition institution, thereby realizing the sharing of different data content for different data acquisition institutions, thus ensuring the privacy of user behavior data; associating the operation behavior data with the page change data through time can realize the interpretability of each operation behavior.

[0127] Further, based on the above Figure 5 illustrated method, the embodiments of this specification also provide a blockchain-based data processing device, as Figure 11 illustrated.

[0128] In a specific embodiment, the blockchain-based data processing device includes a memory and one or more programs. One or more of the programs are stored in the memory, and one or more of the programs may include one or more modules. Each module may include a series of computer-executable instruction information in the blockchain-based data processing device and is configured to be executed by one or more processors. The one or more programs include the following computer-executable instruction information for performing: Obtain the structured data of the target service; Generate access permission information for each data acquisition institution for the structured data; Send the structured data and the access permission information to the authorization management server so that the authorization management server uploads the structured data and the access permission information to the consortium blockchain system.

[0129] Optionally, the blockchain-based data processing device provided in the embodiments of the present specification can implement Figure 5 All the method steps of the method provided in the illustrated embodiment are not described herein again.

[0130] The blockchain-based data processing device provided in the embodiments of the present specification has at least the following technical effects: Obtain the structured data of the target user when performing the target service and upload the structured data to the consortium blockchain system for storage, so as to realize the storage of the structured data in the consortium blockchain, ensuring that the structured data will not be tampered with, that is, ensuring the security and authenticity of the structured data; In addition, in the embodiments of the present specification, the data of the target user when performing the target service is stored in the form of structured data, which can not only facilitate the subsequent positioning of abnormal data, but also facilitate the construction of the Merkle tree corresponding to the structured data; By defining the access permission information corresponding to each data acquisition institution, it is possible to determine which data contents in the statement content data are shared with the data acquisition institution, so as to realize sharing different data contents for different data acquisition institutions, thereby ensuring the privacy of user behavior data; Associating the operation behavior data with the page change data through time can realize the interpretability of each operation behavior.

[0131] Further, based on the above Figure 3 Illustrated method, the embodiments of the present specification also provide a storage medium for storing computer-executable instruction information. In a specific embodiment, the storage medium may be a USB flash drive, an optical disc, a hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, the following process can be realized: Receive the structured data of the target service and the user information of the target user sent by the service server; Obtain the digital identity information of the target user based on the user information; Create a verifiable claim for the structured data corresponding to the digital identity information according to the digital identity information and the structured data; Upload the claim content data of the verifiable claim to the consortium blockchain system.

[0132] Optionally, the computer-executable instruction information stored in the storage medium provided in the embodiments of this specification can be implemented when executed by a processor Figure 3 All the method steps of the method provided in the shown embodiments, which will not be elaborated here.

[0133] When the computer-executable instruction information stored in the storage medium provided in the embodiments of this specification is executed by a processor, it has at least the following beneficial effects: After the authorization management server obtains the structured data of the target user when executing the target service, based on the digital identity information of the target user and the structured data, create a verifiable claim for the structured data corresponding to the digital identity information; then upload the claim content data of the verifiable claim to the consortium blockchain system, so as to realize the storage of the claim content data in the consortium blockchain, ensuring that the claim content data will not be tampered with, that is, ensuring the security and authenticity of the claim content data; in addition, in the embodiments of this specification, the data of the target user when executing the target service is stored in the form of structured data, which can not only facilitate the subsequent positioning of abnormal data, but also facilitate the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition institution, it is possible to determine which data content in the claim content data is shared with the data acquisition institution, so as to realize sharing different data content for different data acquisition institutions, thus ensuring the privacy of user behavior data; associating the operation behavior data with the page change data through time can realize the interpretability of each operation behavior.

[0134] Furthermore, based on the above Figure 5 Shown method, the embodiments of this specification also provide a storage medium for storing computer-executable instruction information. In a specific embodiment, the storage medium can be a USB flash drive, an optical disc, a hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, the following process can be realized: Obtain the structured data of the target service; Generate the access permission information of each data acquisition institution for the structured data; Send the structured data and the access permission information to the authorization management server, so that the authorization management server uploads the structured data and the access permission information to the consortium blockchain system.

[0135] Optionally, when the computer-executable instruction information stored in the storage medium provided in the embodiments of this specification is executed by a processor, it can implement Figure 5 all the method steps of the method provided in the illustrated embodiment, which will not be elaborated here.

[0136] When the computer-executable instruction information stored in the storage medium provided in the embodiments of this specification is executed by a processor, it has at least the following beneficial effects: obtaining the structured data of the target user when executing the target service and uploading the structured data to the consortium blockchain system for storage, so as to realize the storage of the structured data in the consortium blockchain, ensuring that the structured data will not be tampered with, that is, ensuring the security and authenticity of the structured data; in addition, in the embodiments of this specification, storing the data of the target user when executing the target service in the form of structured data can not only facilitate the subsequent positioning of abnormal data, but also facilitate the construction of the Merkle tree corresponding to the structured data; by defining the access permission information corresponding to each data acquisition institution, it is possible to determine which data contents in the statement content data are shared with the data acquisition institution, so as to realize sharing different data contents for different data acquisition institutions, thus ensuring the privacy of user behavior data; associating the operation behavior data with the page change data through time can realize the interpretability of each operation behavior.

[0137] In the 1990s, it was obvious to distinguish whether an improvement in a technology was an improvement in hardware (e.g., improvement in circuit structures such as diodes, transistors, switches, etc.) or an improvement in software (improvement in method flows). However, with the development of technology, many method flow improvements today can be regarded as direct improvements in hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structures by programming the improved method flows into the hardware circuits. Therefore, it cannot be said that an improvement in a method flow cannot be implemented with a hardware entity module. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is such an integrated circuit whose logic function is determined by the user's programming of the device. The designer can program by himself to "integrate" a digital system on a PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a hardware description language (HDL), and there is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow with the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.

[0138] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same functions. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or the structures within the hardware component.

[0139] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0140] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0141] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0142] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present specification. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instruction information. These computer program instruction information can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instruction information executed by the processor of the computer or other programmable data processing devices generates a means for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0143] These computer program instruction information can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instruction information stored in the computer-readable memory generates a manufactured article including an instruction information means, and the instruction information means implements the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0144] These computer program instruction information can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instruction information executed on the computer or other programmable device provides steps for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0145] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0146] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0147] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can be implemented using any method or technology for information storage. The information can be computer-readable instruction information, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0148] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0149] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0150] The present application may be described in the general context of computer-executable instruction information executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0151] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the key points of each embodiment are the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiment.

[0152] The above description is only for the embodiments of the present application and is not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A data processing method based on blockchain, the method comprising: Receiving the structured data of the target service and the user information of the target user sent by the business server; Obtaining the digital identity information of the target user based on the user information; Creating a verifiable claim of the structured data corresponding to the digital identity information according to the digital identity information and the structured data; Uploading the claim content data of the verifiable claim to the consortium blockchain system; the consortium blockchain system stores the claim content data of the verifiable claim in the form of a Merkle tree to grant different levels of signature verification for data with different privacy levels; the operation behavior data included in the claim content data is represented in a structured form; the access permission information for the claim content data by the data acquisition institution is used to be uploaded to the consortium blockchain system to open different claim content data corresponding to different data acquisition institutions.

2. The method according to claim 1, the method further comprising: Receiving the access permission information for the claim content data by the data acquisition institution sent by the business server; Uploading the access permission information to the consortium blockchain system.

3. The method according to claim 2, after uploading the claim content data of the verifiable claim to the consortium blockchain system, the method further comprising: Receiving an authorization request sent by the business server to authorize the target data acquisition institution to access the claim content data of the verifiable claim; wherein, the authorization request carries the digital identity information of the target data acquisition institution, the identification information of the verifiable claim, and the access permission information corresponding to the target data acquisition institution; Executing the permission to grant the target data acquisition institution to access the claim content data of the verifiable claim according to the authorization request.

4. The method according to claim 3, the executing the permission to grant the target data acquisition institution to access the claim content data of the verifiable claim according to the authorization request includes: Sending the authorization request to the consortium blockchain system so that the consortium blockchain system determines the transaction hash value corresponding to the authorization request; Obtaining the transaction hash value from the consortium blockchain system and returning the transaction hash value and the digital identity information of the target data acquisition institution to the business server correspondingly.

5. The method according to claim 4, after obtaining the transaction hash value from the consortium blockchain system and returning the transaction hash value and the digital identity information of the target data acquisition institution to the business server correspondingly, the method further comprising: Receiving a data query request sent by the target data acquisition institution for querying the claim content data of the verifiable claim; wherein, the data query request carries the identification information of the verifiable claim and the digital identity information of the target data acquisition institution; Determine the claim content data of the verifiable claim shared with the target data acquisition institution based on the access permission information corresponding to the target data acquisition institution and the identification information of the verifiable claim, and send the claim content data to the target data acquisition institution, so that the target data acquisition institution verifies the signature of the obtained claim content data based on the transaction hash value.

6. The method according to claim 1, wherein creating a verifiable claim for the structured data corresponding to the digital identity information based on the digital identity information and the structured data includes: Upload the digital identity information of the target user and the structured data to the digital identity blockchain system, and create the verifiable claim by the digital identity blockchain system according to the digital identity information of the target user and the structured data; Receive the identification information of the verifiable claim and the content data of the verifiable claim returned by the digital identity blockchain system.

7. A blockchain-based data processing method, the method comprising: Obtain structured data of a target service; Generate access permission information for each data acquisition institution; Different ones of the data acquisition institutions correspond to different claim content data being opened; Send the structured data and the access permission information to an authorization management server, so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system; the consortium blockchain system stores the claim content data of the verifiable claim corresponding to the structured data, and the verifiable claim is created by the authorization management server; the consortium blockchain system stores the claim content data of the verifiable claim in the form of a Merkle tree to grant different levels of signature verification for data with different privacy levels; the operation behavior data included in the claim content data is represented in a structured form.

8. The method according to claim 7, after sending the structured data and the access permission information to the authorization management server, the method further includes: Receive an indication information sent by a target user to authorize a target data acquisition institution to access the claim content data of the verifiable claim corresponding to the structured data; wherein, the indication information carries the digital identity information of the target data acquisition institution and the identification information of the verifiable claim; Determine the access permission information of the target data acquisition institution for the verifiable claim according to the digital identity information of the target data acquisition institution and the identification information of the verifiable claim; Generate an authorization request for requesting the target data acquisition institution to access the claim content data of the verifiable claim based on the digital identity information of the target data acquisition institution, the identification information of the verifiable claim, and the access permission information, and send the authorization request to the authorization management server, so that the authorization management server performs an operation of granting the target data acquisition institution the permission to access the content data of the verifiable claim.

9. The method according to claim 7, wherein obtaining the structured data of the target service includes: Obtain the operation behavior data of the target user when executing the target service on the client, and obtain the page change data of the client when the target user executes the target service on the client; Associate the operation behavior data with the page change data, and construct the structured data according to the operation behavior granularity.

10. The method according to claim 9, wherein the operation behavior data includes the operation time corresponding to each operation behavior, and the page change data includes the change time corresponding to each page change; The associating the operation behavior data with the page change data includes: For each operation behavior in the operation behavior data, determine the change time that is consistent with the operation time corresponding to the operation behavior; Determine the page change corresponding to the change time that is consistent with the operation time as the page change associated with the operation behavior, and establish an association relationship between the operation behavior and its associated page change.

11. A data processing device based on a blockchain, the device includes: A first receiving module, which receives the structured data of the target service and the user information of the target user sent by the service server; An obtaining module, which obtains the digital identity information of the target user based on the user information; A creating module, which creates a verifiable claim of the structured data corresponding to the digital identity information according to the digital identity information and the structured data; A first uploading module, which uploads the claim content data of the verifiable claim to the consortium blockchain system; the consortium blockchain system stores the claim content data of the verifiable claim in the form of a Merkle tree to grant different levels of signature verification for data with different privacy levels; the operation behavior data included in the claim content data is represented in a structured form; the access permission information for the claim content data by the data acquisition institution is used to be uploaded to the consortium blockchain system to open different claim content data corresponding to different data acquisition institutions.

12. The device according to claim 11, the device further includes: A second receiving module, which receives the access permission information of the data acquisition institution for the claim content data sent by the service server; A second uploading module, which uploads the access permission information to the consortium blockchain system.

13. The device according to claim 12, the device further includes: A third receiving module, which receives the authorization request sent by the service server to authorize the target data acquisition institution to access the claim content data of the verifiable claim; wherein, the authorization request carries the digital identity information of the target data acquisition institution, the identification information of the verifiable claim, and the access permission information corresponding to the target data acquisition institution; An execution module, which executes the permission to grant the target data acquisition institution to access the claim content data of the verifiable claim according to the authorization request.

14. The execution module according to claim 13 includes: A first sending unit that sends the authorization request to the consortium blockchain system so that the consortium blockchain system determines the transaction hash value corresponding to the authorization request; An obtaining unit that obtains the transaction hash value from the consortium blockchain system; A second sending unit that correspondingly returns the transaction hash value and the digital identity information of the target data obtaining institution to the service server.

15. The device according to claim 14, wherein the device further comprises: A fourth receiving module that receives a data query request sent by the target data obtaining institution for querying the claim content data of the verifiable claim; wherein the data query request carries the identification information of the verifiable claim and the digital identity information of the target data obtaining institution; A determining module that determines the claim content data of the verifiable claim shared with the target data obtaining institution according to the access permission information corresponding to the target data obtaining institution and the identification information of the verifiable claim, and sends the claim content data to the target data obtaining institution so that the target data obtaining institution verifies the signature of the obtained claim content data based on the transaction hash value.

16. A blockchain-based data processing device, the device comprising: An obtaining module that obtains the structured data of the target service; A generating module that generates the access permission information of each data obtaining institution; Different ones of the data obtaining institutions are open to different claim content data; A sending module that sends the structured data and the access permission information to an authorization management server so that the authorization management server uploads the structured data and the access permission information to a consortium blockchain system; the consortium blockchain system stores the claim content data of the verifiable claim corresponding to the structured data, and the verifiable claim is created by the authorization management server; the consortium blockchain system stores the claim content data of the verifiable claim in the form of a Merkle tree to grant different levels of signature verification for data with different privacy levels; the claim content data includes operation behavior data represented in a structured form.

17. The device according to claim 16, wherein the device further comprises: A receiving module that receives an indication information sent by a target user for authorizing a target data obtaining institution to access the claim content data of the verifiable claim corresponding to the structured data; wherein the indication information carries the digital identity information of the target data obtaining institution and the identification information of the verifiable claim; A determining module that determines the access permission information of the target data obtaining institution for the verifiable claim according to the digital identity information of the target data obtaining institution and the identification information of the verifiable claim; A generating module that generates an authorization request for requesting to authorize the target data obtaining institution to access the claim content data of the verifiable claim based on the digital identity information of the target data obtaining institution, the identification information of the verifiable claim, and the access permission information; A sending module that sends the authorization request to the authorization management server, so that the authorization management server performs an operation of granting the target data acquisition institution the permission to access the content data of the verifiable claim.

18. The device according to claim 16, wherein the acquisition module comprises: An acquisition unit that acquires the operation behavior data of the target user when performing the target service on the client, and acquires the page change data of the client when the target user performs the target service on the client; A construction unit that associates the operation behavior data with the page change data and constructs the structured data according to the operation behavior granularity.

19. A blockchain-based data processing device, comprising: A processor; And A memory arranged to store computer-executable instructions, which when executed cause the processor to: Receive the structured data of the target service and the user information of the target user sent by the service server; Obtain the digital identity information of the target user based on the user information; Create a verifiable claim for the structured data corresponding to the digital identity information according to the digital identity information and the structured data; Upload the claim content data of the verifiable claim to the consortium blockchain system; the consortium blockchain system stores the claim content data of the verifiable claim in the form of a Merkle tree to grant different levels of signature verification for data with different privacy levels; the operation behavior data included in the claim content data is represented in a structured form; the access permission information for the claim content data by the data acquisition institution is used to be uploaded to the consortium blockchain system to open different claim content data corresponding to different data acquisition institutions.

20. A blockchain-based data processing device, comprising: A processor; And A memory arranged to store computer-executable instructions, which when executed cause the processor to: Obtain the structured data of the target service; Generate the access permission information for each data acquisition institution; different data acquisition institutions correspond to different claim content data to be opened; Send the structured data and the access permission information to the authorization management server, so that the authorization management server uploads the structured data and the access permission information to the consortium blockchain system; the consortium blockchain system stores the claim content data of the verifiable claim corresponding to the structured data, and the verifiable claim is created by the authorization management server; the consortium blockchain system stores the claim content data of the verifiable claim in the form of a Merkle tree to grant different levels of signature verification for data with different privacy levels; the operation behavior data included in the claim content data is represented in a structured form.

21. A storage medium for storing computer-executable instructions, which when executed implement the following process: Receive the structured data of the target service and the user information of the target user sent by the service server; Obtain the digital identity information of the target user based on the user information; Create a verifiable claim of the structured data corresponding to the digital identity information according to the digital identity information and the structured data; Upload the claim content data of the verifiable claim to the consortium blockchain system; the consortium blockchain system stores the claim content data of the verifiable claim in the form of a Merkle tree to grant different levels of signature verification for data with different privacy levels; the operation behavior data included in the claim content data is represented in a structured form; the access permission information for the claim content data by the data acquisition institution is used to be uploaded to the consortium blockchain system to open different claim content data corresponding to different data acquisition institutions.

22. A storage medium for storing computer-executable instructions, which when executed implement the following process: Obtain the structured data of the target business; Generate the access permission information for each data acquisition institution; different data acquisition institutions open different claim content data; Send the structured data and the access permission information to the authorization management server so that the authorization management server uploads the structured data and the access permission information to the consortium blockchain system; the consortium blockchain system stores the claim content data of the verifiable claim corresponding to the structured data, and the verifiable claim is created by the authorization management server; the consortium blockchain system stores the claim content data of the verifiable claim in the form of a Merkle tree to grant different levels of signature verification for data with different privacy levels; the operation behavior data included in the claim content data is represented in a structured form.