Reservation request processing method, system and device, storage medium and program product
By using off-chain server-side identity authentication and smart contract cluster anti-fraud checks, the abnormal behavior and data security issues in the reservation system were resolved, ensuring the legality and security of reservation requests, and guaranteeing fair user participation and system stability.
Patent Information
- Application Number
- CN202510953363.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-10
- Publication Date
- 2025-12-05
AI Technical Summary
The existing reservation system has issues such as users using automated scripts to snatch up items, one person having multiple reservations, and bulk reservations being resold. Furthermore, the centralized deployment poses a risk of data tampering or leakage, making it impossible to ensure reservation security.
User accounts are authenticated through off-chain servers, verifiable credentials and time windows are generated, and anti-fraud checks are performed using smart contract clusters to ensure the legality and security of reservation requests.
To curb the practice of one person using multiple phone numbers, prevent abnormal users from snapping up items, reduce network congestion, improve the security and efficiency of the reservation system, and ensure that the target users are allocated to normal users.
Smart Images

Figure CN121077673A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of blockchains, and in particular to a reservation request processing method and system, a device, a storage medium and a program product. BACKGROUND
[0002] When issuing a specific object, it is usually limited in quantity, and the reservation and redemption are realized through a systematic process combining online and offline. Among them, the reservation system is mostly centrally deployed, and the reservation process is not publicly announced.
[0003] In the reservation process, there may be abnormal behaviors such as users using automated scripts to purchase, one person using multiple numbers, and batch reservations for resale. The existing reservation system is difficult to prevent users with abnormal operations from making reservations, thereby preventing the purchase behavior of users with abnormal operations, and because the existing reservation system is mostly centrally deployed, there is a risk of data tampering or leakage, resulting in a loss of security for the reservation process.
[0004] Therefore, in order to ensure the security of the reservation, it is necessary to provide a reservation request processing method. SUMMARY
[0005] The present application provides a reservation request processing method, system, device, storage medium and program product to solve the technical problem of being unable to ensure the security of the reservation.
[0006] In a first aspect, the present application provides a reservation request processing method applied to an off-chain server, the method comprising:
[0007] In response to an authentication request corresponding to a user account, performing identity authentication on the user account, and after the user account passes the identity authentication, generating a verifiable credential of the user account and determining a time window corresponding to the user account;
[0008] sending the time window and the verifiable credential to a smart contract cluster, and sending the time window to a user terminal, so that the user terminal initiates a reservation request for a target object in the time window;
[0009] obtaining the reservation request initiated by the user account and sending it to the smart contract cluster, so that the smart contract cluster obtains real-time behavior data of the user account, and when it is determined that the reservation request meets the corresponding time window, performs anti-cheating inspection on the user account based on the verifiable credential and the real-time behavior data, and after the user account passes the anti-cheating inspection, allocates the target object corresponding to the reservation request to the user account.
[0010] In a second aspect, the present application provides a reservation request processing method applied to a smart contract cluster, the method comprising:
[0011] In response to a reservation request initiated by a user account, determine verifiable credentials and a time window of the user account, the verifiable credentials and the time window being used for identity authentication of the user account by an off-chain server, and being generated after the user account passes the identity authentication;
[0012] Obtain real-time behavior data of the user account, and perform anti-cheating inspection on the user account based on the verifiable credentials and the real-time behavior data when it is determined that the reservation request meets the corresponding time window;
[0013] After the user account passes the anti-cheating inspection, assign a target object corresponding to the reservation request to the user account.
[0014] In a third aspect, the present application provides a reservation request processing system, which comprises an off-chain server and a smart contract cluster; wherein the off-chain server is configured to perform identity authentication on a user account in response to an authentication request corresponding to the user account, generate verifiable credentials of the user account after the user account passes the identity authentication, and determine a time window corresponding to the user account; send the time window and the verifiable credentials to the smart contract cluster, and send the time window to a user terminal, so that the user terminal initiates a reservation request for a target object within the time window; and obtain the reservation request initiated by the user account and send it to the smart contract cluster.
[0015] The smart contract cluster is configured to, in response to the reservation request initiated by the user account, determine the verifiable credentials and the time window of the user account; obtain real-time behavior data of the user account, and perform anti-cheating inspection on the user account based on the verifiable credentials and the real-time behavior data when it is determined that the reservation request meets the corresponding time window; and after the user account passes the anti-cheating inspection, assign a target object corresponding to the reservation request to the user account.
[0016] In a fourth aspect, the present application provides an electronic device, which comprises a processor and a memory connected to the processor in communication;
[0017] The memory stores computer execution instructions;
[0018] The processor executes the computer execution instructions stored in the memory to implement the method of any one of the first aspect or implement the method of any one of the second aspect.
[0019] In a fifth aspect, the present application provides a computer readable storage medium, which stores computer execution instructions, and the computer execution instructions are used to implement the method of any one of the first aspect or implement the method of any one of the second aspect when executed by a processor.
[0020] In a sixth aspect, the present application provides a computer program product, which comprises a computer program, and the computer program is used to implement the method of any one of the first aspect or implement the method of any one of the second aspect when executed by a processor.
[0021] The pre-order request processing method provided in the application can authenticate the authentication request of the user account on the off-chain server, perform identity authentication on the user account, inhibit one-person multi-number behavior, and ensure that real users participate fairly. By determining the time window of the user account, network congestion caused by centralized purchase is avoided, and the security of the pre-order is further improved. After the user is qualified on the off-chain server, the pre-order request is checked by the anti-cheating inspection of the smart contract cluster, the target object is allocated to the normal user, abnormal users are prevented from attacking the pre-order system, abnormal situations in the pre-order processing process are reduced, the overall efficiency of the system is improved, and the security of the system is further ensured. BRIEF DESCRIPTION OF DRAWINGS
[0022] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the application and serve to explain the principles of the application together with the specification.
[0023] Figure 1 A scene schematic diagram for pre-ordering commemorative coins;
[0024] Figure 2 A flowchart of a pre-order request processing method provided by an embodiment of the application;
[0025] Figure 3 A flowchart of a commemorative coin pre-order method based on a smart contract provided by an embodiment of the application;
[0026] Figure 4 A flowchart of another pre-order request processing method provided by an embodiment of the application;
[0027] Figure 5 A flowchart of an anti-cheating inspection provided by an embodiment of the application;
[0028] Figure 6 An interaction schematic diagram of a pre-order request processing system provided by an embodiment of the application;
[0029] Figure 7 An architecture schematic diagram of a commemorative coin pre-order system based on a smart contract provided by an embodiment of the application;
[0030] Figure 8 A structural schematic diagram of an electronic device provided by an embodiment of the application.
[0031] The specific embodiments of the application have been shown by the above drawings, and will be described in more detail hereinafter. These drawings and the written description are not intended to restrict the scope of the inventive concept in any way, but to explain the inventive concept to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0032] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The description of the exemplary embodiments is intended to apply to any embodiment of the application, unless specified otherwise. Accordingly, when the description of the exemplary embodiments contains language that can imply limitations on the scope of the application, such limitations are not intended to apply to any specific embodiment provided herein that can not specifically recite such limitations. For a better understanding, the exemplary embodiments will now be described, by way of example, with reference to the following drawings, in which:
[0033] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of related data comply with relevant laws, regulations and standards of relevant countries and regions, necessary security measures are taken, do not violate public order and good customs, and provide corresponding operation portal for user to choose authorization or refusal.
[0034] And the present application involves big data analysis of user information (including but not limited to personal biological characteristics, identity data, consumption data, asset data, electronic terminal operation data, etc.), and uses artificial intelligence technology for automatic decision making, and makes technical solutions based on automatic decision making results that have a significant impact on personal rights and interests, provides corresponding operation portal for users to choose to agree or refuse automatic decision making results; if the user chooses to refuse, enter the expert decision making process.
[0035] It should be noted that the reservation request processing method, system, device, storage medium and program product provided by the present application can be used in the field of block chain, and can also be used in any field other than block chain. The application field of the reservation request processing method, system, device, storage medium and program product in the present application is not limited.
[0036] First, the terms involved in the present application are explained:
[0037] NFT: Non-Fungible Token, a non-fungible token, is a digital asset based on blockchain technology, with uniqueness, indivisibility and verifiability. It is a data unit on the blockchain, recording ownership and transaction history through smart contract. Each NFT is unique and cannot be exchanged 1:1.
[0038] When issuing a specific object, for example, a commemorative coin, it is usually limited in quantity. The reservation of commemorative coins is usually realized through a systematic process combining online and offline reservation and exchange. Figure 1 A schematic diagram of the reservation scene of the commemorative coin is shown in FIG. 1. As shown in FIG. 1, the commemorative coin reservation system receives a commemorative coin reservation request of a user, determines whether the user has the reservation qualification, and issues a commemorative coin reservation success voucher to the user when the user meets the commemorative coin reservation qualification. The commemorative coin reservation system is usually centrally deployed, and the process of the commemorative coin reservation is not disclosed to the outside. Figure 1
[0039] The existing commemorative coin reservation system has the following problems: 1. The centralized commemorative coin reservation system is vulnerable to attacks, leading to data tampering or leakage; 2. Abnormal accounts can send a large number of reservation requests to the reservation system through automated scripts, occupying the reservation request processing of the reservation system, and ordinary users have difficulty in successfully realizing the reservation of commemorative coins; 3. The identity verification mechanism of the user account is not perfect, and it is difficult to effectively prevent the same user from using multiple accounts.
[0040] The blockchain realizes the reservation system by obtaining the reservation information of the user's commemorative coin and the identity information of the user; records the reservation information of the user's commemorative coin; and performs on-chain storage of the user's commemorative coin reservation information on the alliance chain after confirming the validity. The existing blockchain solution can solve part of the data tampering problem, but it still cannot identify and prevent abnormal operations such as automated script purchase, one person with multiple accounts, and batch reservation resale, and it is difficult to conduct anti-cheating checks on user behavior.
[0041] Therefore, the reservation request processing method, system, device, storage medium and program product provided by the present application can be applied in the scene of reserving specific objects such as commemorative coins, precious metals and tickets, which are limited in quantity. The present application authenticates the user account through the off-chain service end, conducts anti-cheating checks on the reservation request through the smart contract cluster, sends the specific target object corresponding to the user reservation request that passes the anti-cheating check to the user, and ensures the security of the reservation process, aiming to solve the above technical problems of the prior art.
[0042] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.
[0043] Figure 2 A flowchart of a reservation request processing method provided by an embodiment of the present application is shown in FIG. 1. As shown in FIG. 1, the method is applied to an off-chain service end and includes the following steps. Figure 2
[0044] S201, in response to the authentication request corresponding to the user account, identity authentication is performed on the user account, and after the user account passes the identity authentication, a verifiable credential of the user account is generated, and a time window corresponding to the user account is determined.
[0045] In an example, the user submits an authentication request and identity information of the user account through the user terminal. The identity information of the user is chained through the alliance chain, and the blockchain address of the user is bound with the biometric information, including: generating a de-identified ID corresponding to the identity information according to the identity information of the user account through the real name information acquisition unit; collecting the hash value of the user's fingerprint or facial features through the biometric feature acquisition unit; providing a verification code or behavior verification for distinguishing between a person and a computer for the user account through the behavior verification unit, and determining that the user account verification is passed after the user completes the specific action verification; generating a verifiable credential of the user account as a reservation qualification of the user account through the credential issuing unit, and recording the verifiable credential of the user account to the blockchain.
[0046] Through multi-factor identity verification, the biometric features of the user account and the on-chain address of the blockchain are bidirectionally bound, solving the problem of false identity or node attack, avoiding the problem of abnormal user account impersonating multiple identities, and preventing abnormal operation from damaging the security and tamper resistance of the reservation request processing system.
[0047] Optionally, the time window corresponding to the user account is determined, including: determining a credit evaluation result of the user account; obtaining a credit offset based on the credit evaluation result and a preset time step; obtaining a starting time of the time window based on the issuance time of the target object corresponding to the reservation request, the credit offset, and a random factor, and determining the issuance deadline of the target object as the termination time of the time window.
[0048] In an example, through a dynamic reservation time window mechanism, a reservation time window is randomly allocated to each user account that passes the identity verification according to the credit evaluation result of the user account, and the user can submit a reservation request within the time window. The starting time of the time window can be determined in the following way: the starting time of the time window = the base time - the credit offset ± the random factor, wherein the base time is the issuance time of the target object; the credit offset = (the maximum credit score - the credit evaluation result of the user account) × the preset time step; the random factor is a time disturbance calculated based on a random number provided by an oracle.
[0049] By combining the credit rating result and the random factor, different time periods are allocated to different user accounts for reservation, preventing all users from initiating reservations at the same time, thereby reducing the pressure on the reservation request processing system and further improving the security of the reservation.
[0050] Optionally, the credit evaluation result of the user account is determined, including: obtaining historical behavior data of the user account, the historical behavior data including: valid performance times, total performance times and abnormal operation times; determining performance quality of the user account according to a proportion of the valid performance times to the total performance times, the valid performance times being used to represent a number of appointments completed by the user account in a non-peak period; calculating a product of the abnormal operation times of the user account and a preset weight to obtain a real-time penalty factor of the user account; and determining the credit evaluation result of the user account based on the performance quality and the real-time penalty factor.
[0051] In an example, the credit evaluation result of the user account is calculated based on historical behavior data of the user account. The credit evaluation result affects the appointment priority of the user account, and abnormal operation behavior of the user account causes the credit evaluation of the user account to decrease. The credit evaluation result of the user account can be determined by the following reputation scoring model:
[0052] Credit evaluation result = account age term + performance quality - real-time penalty factor - scarcity penalty term + adjustment term
[0053] Account age term = min(account age, 3) x 10
[0054]
[0055] Real-time penalty factor = abnormal operation times x 2
[0056]
[0057] Adjustment term = additional points
[0058] The account age term is used to prevent the credit evaluation of a user account that has not performed an appointment operation for a long time from being too high. The valid performance times are the number of appointments completed by the user account in a non-peak period and without cancellation or transfer. The total performance times are the number of appointments completed by the user account. The performance quality term is calculated by power attenuation to suppress high-frequency appointment operations of abnormal accounts. The abnormal operation times are the number of times that the user account is detected to perform abnormal operations in real time. The abnormal operations include: the frequency of initiating an appointment request is greater than a preset frequency threshold, the number of operations such as changing an IP (Internet Protocol) or a device is greater than a preset number of changes threshold, interaction with a known blacklist address, and increasing a penalty point each time the IP or the device is changed. The real-time penalty factor is used to dynamically respond to the risk caused by abnormal operations of the user account. The scarcity penalty is used to suppress the hoarding risk of the user account. The adjustment term is used to balance fairness and ecological health. The parameter settings of the reputation scoring model are changed according to the application situation of the appointment request processing system, and are not limited in the present application.
[0059] In an implementation scenario, the user account is processed by the credit scoring model, and four types of user accounts are distinguished, i.e., a first type of user account, a second type of user account, a third type of user account, and a fourth type of user account. For example, the output of the credit scoring model can be a score, and the user account is classified according to the interval in which the score is located. Specific examples are as follows:
[0060] The registration time of the user account A is greater than or equal to 3 years, the number of valid performance is 18 times, the total number of performance is 20 times, and the number of abnormal operations is 0 times. The specific parameters are as follows:
[0061]
[0062] According to the credit scoring model, the credit evaluation result of the user account A is as follows: 212.75 points, and the current user account is determined to be a first type of user account.
[0063]
[0064] The registration time of the user account B is less than or equal to 1 month, the number of valid performance is 1 time, the total number of performance is 1 time, and the number of abnormal operations is 0 times. The specific parameters are as follows:
[0065]
[0066] According to the credit scoring model, the credit evaluation result of the user account B is as follows: 43.08 points, and the current user account is determined to be a second type of user account.
[0067]
[0068] The registration time of the user account C is less than 3 years, the number of valid performance is 2 times, the total number of performance is 8 times, the number of abnormal operations is 4 times, and the number of resources held by the current user account is greater than the number of resources held by the target object per capita. The specific parameters are as follows:
[0069]
[0070] According to the credit scoring model, the credit evaluation result of the user account C is -1.8 points. The credit evaluation result of the user account C is lower than 0 and higher than the ban threshold, and the user account C is determined to be a third type of user account. The transaction behavior of the user account C is prevented, and the reservation request of the user account C is sent to an audit system for audit. The audit system is used for expert audit on the reservation request of the user account.
[0071]
[0072] The registration time of the user account D is less than 3 years, the effective performance times is 0, the total performance times is 50, the abnormal operation times is 15, and the specific parameters are as follows:
[0073]
[0074] According to the credit evaluation result of the user account D obtained according to the credit score model, the credit evaluation result of the user account D is-225 points, the credit evaluation result of the user account D is lower than the ban threshold, and the user account D is determined as the fourth type of user account, and the user account D is banned; determine the associated account of the user account D, and mark the associated account of the user account D as a suspicious account, and when the pre-reservation request corresponding to the suspicious account is obtained, the pre-reservation request is abnormally processed.
[0075]
[0076] The behavior of the user account is quantified through the credit evaluation, the effective performance times and the total performance times are used to avoid the high frequency operation score of the abnormal account being too high, and the abnormal operation times are used to reduce the score value of the account with abnormal operation, so as to realize dynamic response to risks and further improve the security of the pre-reservation.
[0077] Optionally, it is judged whether the credit evaluation result of the user account is lower than the ban threshold; when the credit evaluation result of the user account is lower than the ban threshold, the user account is banned; the associated account of the user account is determined, and the associated account is marked as a suspicious account, so that when the pre-reservation request corresponding to the suspicious account is obtained, the pre-reservation request is abnormally processed.
[0078] In an example, it is judged whether the credit evaluation result of the user account is lower than the ban threshold; when the credit evaluation result of the user account is lower than the ban threshold, the user account is banned, and the user account is subjected to social association analysis, the associated account of the user account on the block chain is determined, the associated account is marked as a suspicious account, and the credit evaluation result of the associated account is set to be lower than the credit evaluation threshold. When the associated account submits a pre-reservation request, the pre-reservation request of the associated account is submitted to an audit system for expert audit, or the pre-reservation request of the associated account is put into a waiting queue, or the pre-reservation request of the associated account is prohibited, so as to abnormally process.
[0079] By judging whether the credit evaluation result of the user account is lower than the ban threshold, it is determined that the user account with the credit evaluation result lower than the ban threshold is an abnormal account, the abnormal account is banned, and the associated account is traced back, so as to further improve the security of the pre-reservation.
[0080] S202, send the time window and the verifiable credential to the smart contract cluster, and send the time window to the user terminal, so that the user terminal initiates a pre-reservation request for the target object in the time window.
[0081] The time window and the verifiable credential of the user account that passes the verification are chained to make the smart contract cluster located in the blockchain obtain the time window and the verifiable credential. The time window is sent to the user terminal of the user, and the user initiates a reservation request in the time window through the user terminal.
[0082] S203, obtaining the reservation request initiated by the user account and sending it to the smart contract cluster.
[0083] The smart contract cluster obtains the real-time behavior data of the user account, and when it is determined that the reservation request meets the corresponding time window, it performs anti-cheating checking on the user account based on the verifiable credential and the real-time behavior data. After the user account passes the anti-cheating checking, the target object corresponding to the reservation request is allocated to the user account.
[0084] In an example, taking a commemorative coin as an example, the commemorative coin reservation includes the following stages:
[0085] 1. Qualification acquisition stage: including user registration and reservation submission, obtaining the identity information submitted by the user, identity authentication of the user account, binding the biometric information of the user account with the blockchain address. After the user completes the behavior verification, it is determined that the user account passes the verification, the verifiable credential of the user account is generated as the reservation qualification of the user account, and the verifiable credential of the user account is recorded to the blockchain. After the user selects the type and quantity of the commemorative coin, the credit evaluation result of the user account is determined based on the historical behavior data of the user account, and the corresponding time window is allocated, the time window and the verifiable credential are chained, and the time window is sent to the user terminal.
[0086] 2. Reservation stage: the user initiates a reservation request in the time window through the user terminal, the smart contract obtains the real-time behavior data of the user account through the oracle, verifies the validity of the verifiable credential of the user account and the time window, performs anti-cheating checking on the user account, and checks the cheating behavior in real time during the reservation process. The smart contract executes the reservation logic, and the failed reservation can be appealed, and if the appeal is successful, the qualification acquisition can be performed again. The oracle is used to obtain the real-time behavior data of the user account and perform real-time risk monitoring on the real-time behavior data of the user account.
[0087] 3. Confirmation stage: after the user account reservation is successful, the credit evaluation result of the user account is updated. The commemorative coin ownership credential is sent to the user account, and the allocation record of the commemorative coin is written to the blockchain to support public verification. At the same time, a transfer restriction timer is started, and a transfer constraint is set for the successfully reserved commemorative coin.
[0088] Figure 3 A flowchart of a commemorative coin reservation method based on a smart contract provided by an embodiment of the present application is shown inFigure 3 As shown, the reservation process includes:
[0089] Step 1: User submits authentication request: The user submits an authentication request, and after the user account is authenticated, a verifiable credential of the user account is generated, which contains the identity information of the user account, the biometric information, and the digital signature of the blockchain address of the user account, to ensure the authenticity and uniqueness of the user's identity.
[0090] Step 2: Smart contract cluster verifies the validity of the NFT corresponding to the verifiable credential of the user account, including: checking whether the NFT already exists, whether it matches the blockchain address of the user account, and whether the biometric information stored in the NFT is consistent with the biometric information of the user account.
[0091] Step 3: Dynamic time window allocation: After the user account is successfully authenticated, the smart contract cluster allocates a dynamic time window for the user account based on the user's credit evaluation results and other factors (such as random factors). The time window refers to a specific time period during which the user can initiate a reservation, to prevent all users from initiating reservations at the same time, thereby reducing the pressure on the system.
[0092] Step 4: User initiates reservation within specified time period: The user initiates a reservation request through the user terminal within the dynamic time window allocated to the user account, requiring the user to operate within a specific time range to prevent abnormal accounts from initiating a large number of reservations within a short period of time through automated tools.
[0093] Step 5: Smart contract cluster performs anti-cheating checks: After the user account initiates a reservation request, the smart contract cluster performs anti-cheating checks, including but not limited to dragging a slider, clicking on a specific picture, a CAPTCHA, etc., to ensure that the reservation request is manually initiated by a real user, rather than an automated script. For user accounts that fail the anti-cheating checks, the user account can file a complaint and resubmit an authentication request to obtain reservation eligibility.
[0094] Step 6: Smart contract cluster processes reservations based on challenge results: After the user account passes the anti-cheating checks, the smart contract cluster will mint a commemorative coin NFT or provide an entity commemorative coin number, and assign the corresponding commemorative coin to the user account, while setting a cooling-off period to prevent immediate transfer. The smart contract cluster can effectively prevent cheating behavior and ensure the fairness and security of the commemorative coin reservation process.
[0095] In an implementation scenario, taking a commemorative coin reservation as an example, 1. The issuer configures the smart contract cluster parameters: total issuance: 10,000; individual purchase limit: 1; reservation opening time: 2025-12-01 00:00 UTC (Universal Time Coordinated, UTC); identity verification requirement: KYC Level 2 (Know Your Customer Level).
[0096] 2. User A completes identity verification: submits an ID card ID and a selfie verification, completes 3 behavior verification challenges, and obtains a reputation score of 44.7 points (account history of 1 year, 3 times of perfect fulfillment).
[0097] 3. The system allocates a reservation time window: base time: 0 minutes after opening; reputation bonus: -15 minutes (high-score users are given priority); random factor: +7 minutes; actual window: -8 minutes after opening (i.e., 8 minutes in advance).
[0098] 4. User A completes the reservation at the specified time and passes all anti-cheating checks, successfully reserving 1 commemorative coin.
[0099] The reservation request processing method provided by the embodiment suppresses the behavior of one person using multiple accounts by authenticating authentication requests of user accounts on an off-chain server and authenticating user accounts, ensuring that real users can participate fairly; by determining the time window of the user account, it avoids network congestion caused by concentrated purchases, further improves the security of the reservation, and facilitates anti-cheating checks on reservation requests by the smart contract cluster after the user completes authentication, thereby ensuring that the target object is allocated to normal users.
[0100] Figure 4 Another flowchart of a reservation request processing method provided by an embodiment of the present application is applied to a smart contract cluster. As shown in Figure 4 , the method comprises:
[0101] S401, in response to a reservation request initiated by a user account, determining verifiable credentials and a time window of the user account.
[0102] The verifiable credentials and the time window are generated after the user account passes the identity authentication by the off-chain server.
[0103] S402, obtaining real-time behavior data of the user account, and when it is determined that the reservation request meets the corresponding time window, performing anti-cheating checks on the user account based on the verifiable credentials and the real-time behavior data.
[0104] Optionally, the anti-cheating checking process includes: judging whether the user account completes a signature challenge, the signature challenge representing a behavior that a machine cannot simulate; after the user account completes the signature challenge, judging whether the verifiable credential of the user account is valid; when the verifiable credential of the user account is valid, judging whether the reservation request triggers a fuse mechanism based on real-time behavior data; when the reservation request does not trigger the fuse mechanism, determining that the user account passes the anti-cheating check.
[0105] In an example, judging whether the user account completes the signature challenge can be executed by a smart contract cluster arranged in the blockchain, the smart contract cluster simulating human operation intervals by arranging a variable delay response mechanism; the user account needs to complete multi-step interactive verification, and randomness factors are introduced for each interactive verification to prevent pattern recognition.
[0106] Specifically, the smart contract cluster can include: an interaction interval limiting unit for limiting the minimum time interval between two operations of the user account. A pattern verification unit for checking whether the real-time behavior of the user account conforms to the characteristics of human behavior: requiring the user account to complete a signature challenge that is human-solvable and machine-difficult to simulate. For example, drawing a straight line connecting (3, 4) and (7, 2) and the intersection of the circle x²+y²=25, and for example, dragging the left triangle into the right circle and then rotating the triangle so that one of its corners points to the center of the circle. A random challenge unit for inserting unpredictable verification requirements: for example, during the signature challenge process, requiring the user to hold the progress bar and pull it to a random place such as 75% of the progress bar at a random time node.
[0107] Specifically, during the behavior verification / signature challenge process, mouse movement trajectory and keyboard input interval behavior are extracted. Based on the characteristics that human mouse movement contains random acceleration / deceleration, and scripts are usually uniform, human and script attacks are distinguished. For example, when the acceleration variance of the movement trajectory is >0.5, it is determined to be human, and the script trajectory variance is close to 0. When the trajectory tortuosity is large, the drawing path is not a smooth straight line or a standard circle, it is determined to be human; when the trajectory tortuosity is small, the drawing path is a smooth straight line or a standard circle, it is determined to be a script. Calculate the deviation of the trajectory from the ideal straight line, greater than 20% is determined to be human behavior, otherwise it is a script attack. Since the human thinking time is random, the human keyboard input interval is between 100ms and 2s; while the script input interval is fixed, such as about 50ms. The mouse movement trajectory and keyboard input interval during the behavior verification process are combined to distinguish between humans and scripts.
[0108] By performing signature challenge verification, verifiable credential verification and fuse mechanism triggering verification on the user account, it is determined that the user account sending the reservation request is a normal human. By performing signature challenge verification, verifiable credential verification and fuse mechanism triggering verification on the user account, it is determined that the user is a normal human only when the user passes all verifications, abnormal reservation requests initiated by scripts and the like are excluded, cheating and automated attacks are prevented, and the security of the reservation system is further improved.
[0109] Optionally, when the user account does not complete the signature challenge, the user account is determined to be a suspicious account, and the reservation request of the user account is rejected; when the verifiable credential of the user account is invalid, the reservation request of the user account is rejected; when the reservation request triggers the fuse mechanism, the reservation request is put into the waiting queue until the termination time corresponding to the fuse mechanism, the reservation request is taken out from the waiting queue, and the step of judging whether the user account completes the signature challenge is returned.
[0110] In an example, Figure 5 A flowchart of an anti-cheating check provided by an embodiment of the present application is shown as Figure 5 The flowchart of the anti-cheating check can include:
[0111] Step 1: Start verification: the smart contract cluster initiates an anti-cheating check on the reservation request initiated by the user account.
[0112] Step 2: Check time window validity: the smart contract cluster checks whether the reservation request initiated by the user account is within a valid time window; if the time window is valid, the next step of verification is continued; if the time window is invalid, the reservation request of the user account is directly rejected.
[0113] Step 3: Verify interaction mode: the smart contract cluster performs interaction mode verification on the user account to determine whether the reservation request is initiated by a human user or a script automated operation; if human features are detected, the next step of verification is continued. If script features are detected, the user is marked as suspicious, it is determined that the user account does not pass the anti-cheating check, and the reservation request is rejected.
[0114] Step 4: Check frequency limit: the smart contract cluster determines whether the frequency of the reservation request initiated by the user account is greater than a preset frequency threshold; when the frequency of the reservation request initiated by the user account is not greater than the preset frequency threshold, the next step of verification is continued; when the frequency of the reservation request initiated by the user account is greater than the preset frequency threshold, the reservation request initiated by the user account is subjected to flow limiting processing, and the user account is limited to perform the reservation request operation.
[0115] Step 5: Verify credential signature: The smart contract cluster verifies whether the verifiable credential of the user account is valid, which includes a digital signature and identity verification information; if the verifiable credential is valid, proceed to the next step of verification; if the verifiable credential is invalid, reject the reservation request of the user account.
[0116] Step 6: Check the fuse state: The smart contract cluster checks whether the reservation request triggers the fuse mechanism to prevent system overload or attack. If the reservation request does not trigger the fuse mechanism, proceed to execute the reservation process.
[0117] Step 7: Execute reservation: After the user account passes the anti-cheating check, the smart contract cluster executes the reservation operation.
[0118] Step 8: Reservation success: The reservation request of the user account is successful, and the smart contract cluster completes the reservation process.
[0119] Step 9: Enter the waiting queue: If the smart contract cluster is in the fuse state, put the reservation request of the user account into the waiting queue until the termination time corresponding to the fuse mechanism of the smart contract cluster, take the reservation request from the waiting queue, and return to the step of judging whether the user account completes the signature challenge. When the fuse mechanism is triggered, the smart contract cluster cools down the reservation request of the user account, for example, prohibits the user account from initiating a reservation request until the termination time corresponding to the fuse mechanism, or performs additional verification on the reservation request of the user account, which helps to prevent cheaters from attacking the system through continuous automated attempts.
[0120] By verifying the user account that does not pass the signature challenge verification, verifiable credential verification, and fuse mechanism trigger verification, it is determined that the user account that sends the reservation request is a normal human. The interactive mode verification, request frequency verification, and fuse mechanism trigger verification of the user account are performed, and when the user does not pass any verification, it is determined that the user is not a normal human, excluding abnormal reservation requests initiated by scripts, preventing cheating and automated attacks, and further improving the security of the reservation system. Through the fuse mechanism, system overload or attack is prevented, which helps to prevent non-normal accounts from attacking the system through continuous automated attempts.
[0121] Optionally, based on real-time behavior data, it is determined whether the reservation request triggers the fuse mechanism, including: judging whether the frequency of the reservation request is greater than a preset frequency threshold; when the frequency of the reservation request is not greater than the preset frequency threshold, judging whether the real-time transaction behavior data meets the abnormal transaction condition; when the real-time transaction behavior data does not meet the abnormal transaction condition, determining that the reservation request does not trigger the fuse mechanism.
[0122] The real-time behavior data includes the frequency of the reservation request and the real-time transaction behavior data.
[0123] In an example, the smart contract cluster obtains real-time behavior data through an oracle, monitors the real-time behavior data in real time, triggers a fuse mechanism when determining that the real-time behavior data is suspicious behavior, and reserves a reservation channel for normal user accounts during triggering of the fuse mechanism. The transaction frequency and pattern are analyzed in real time by an anomaly detection unit; the hierarchical response unit takes different restriction measures according to the risk level; and the bypass channel unit maintains access of verified user accounts during the fuse period.
[0124] Specifically, determining whether the reservation request triggers the fuse mechanism can include: determining whether the frequency of the reservation request is greater than a preset frequency threshold, determining whether the number of operations such as IP or device replacement of the user account is greater than a preset replacement number threshold, and determining whether the user account interacts with a known blacklist address. When any of the following conditions is met: the frequency of the reservation request is greater than the preset frequency threshold, or the number of operations such as IP or device replacement of the user account is greater than the preset replacement number threshold, or the user account interacts with a known blacklist address, it is determined that the reservation request triggers the fuse mechanism.
[0125] By setting the fuse mechanism, the frequency of the reservation request and the real-time transaction behavior data are judged to prevent abnormal operation of the user account. Through the fuse mechanism, system overload or attack is prevented, which helps to prevent cheaters from attacking the system through continuous automated attempts.
[0126] S403, after the user account passes the anti-cheating check, the target object corresponding to the reservation request is allocated to the user account.
[0127] In an implementation scenario, after the target object corresponding to the reservation request is allocated to the user account, a cooling-off period can be set before transfer, the transfer price is set with an upper limit to prevent speculation, the price upper limit of secondary sales is limited, a destruction mechanism is introduced, that is, an official repurchase channel is provided, speculation is suppressed, and an increasing tax fee is collected for frequent transfer behavior.
[0128] For example, the following transfer restrictions are set: 1. Cooling-off period: no transfer within 30 days after reservation success; 2. Price upper limit: transfer price is not more than 150% of the original price; 3. Destruction option: allow to sell back to the issuer at a fixed price; 4. Transfer tax: collect 10% fee for each transfer to reward compliant users.
[0129] In another implementation scenario, the anti-cheating check to determine the abnormal account can include:
[0130] 1. Abnormal account attempts to use scripts to register accounts in batches: the system detects that multiple user accounts use the same device fingerprint, triggers social association analysis of each user account, marks each user account as a suspicious account, there is a potential risk of false identity or node attack, and sets the credit evaluation result of each suspicious account to be lower than 0 points.
[0131] 2. Script attempts at reservation time: due to the suspicious account credit rating result is lower than 0 points, the system assigns the time window for the suspicious account is the last time period, the interaction mode of suspicious account is identified by anomaly detection system, trigger fuse mechanism, prevent suspicious account reservation request.
[0132] 3. Normal users are not affected: the fuse mechanism only limits the reservation request of suspicious account, and the normal user access is maintained through the side channel.
[0133] The reservation request processing method provided by the embodiment can ensure that the target object is allocated to normal users, prevent abnormal users from attacking the reservation system, reduce abnormal situations in the reservation processing situation process, improve the overall efficiency of the system, and further ensure the security of the system.
[0134] Figure 6 An interaction schematic diagram of a reservation request processing system provided by an embodiment of the present application is shown in FIG. 1. Figure 6 As shown in the figure, the system includes an off-chain server and a smart contract cluster; wherein the off-chain server is used to perform the following steps:
[0135] S201, in response to the authentication request corresponding to the user account, identity authentication is performed on the user account, and after the user account passes the identity authentication, a verifiable credential of the user account is generated, and a time window corresponding to the user account is determined;
[0136] S202, send the time window and the verifiable credential to the smart contract cluster, and send the time window to the user terminal, so that the user terminal initiates a reservation request for the target object in the time window;
[0137] S203, get the reservation request initiated by the user account and send it to the smart contract cluster;
[0138] The smart contract cluster is used to perform the following steps:
[0139] S401, in response to the reservation request initiated by the user account, determine the verifiable credential and the time window of the user account;
[0140] S402, get the real-time behavior data of the user account, and when it is determined that the reservation request meets the corresponding time window, perform anti-cheating check on the user account based on the verifiable credential and the real-time behavior data;
[0141] S403, after the user account passes the anti-cheating check, allocate the target object corresponding to the reservation request to the user account.
[0142] In an implementation scenario, Figure 7An architecture schematic diagram of a commemorative coin reservation system based on a smart contract is provided in the embodiments of the present application. As shown in Figure 7 The reservation system can include a user terminal, a smart contract cluster, and an off-chain server including an identity verification service module, an oracle, and a data storage module.
[0143] Specifically, the user terminal: the user interacts with the system through the user terminal, and the user terminal is used to provide a reservation entry to receive a reservation application of a user account and obtain identity information of the user account.
[0144] The smart contract cluster is located in a blockchain and includes a reservation main contract, a reputation contract, an anti-cheating contract, a deployed evaluation model, and allocation logic, etc. In response to a reservation request initiated by a user account, the user account's verifiable credentials and time window are determined. Real-time behavior data of the user account is obtained through an oracle, and when it is determined that the reservation request meets the corresponding time window, the user account is checked for anti-cheating based on the verifiable credentials and real-time behavior data. After the user account passes the anti-cheating check, the target object corresponding to the reservation request is allocated to the user account.
[0145] The off-chain server includes an identity verification service module for identity verification of the user account to generate verifiable credentials. The oracle is used for real-time risk monitoring of real-time behavior data of the user account. The data storage module uses distributed storage to save the verifiable credentials, reservation records, behavior data, and allocation records of the user account after a successful reservation.
[0146] The reservation request processing system provided in the embodiments suppresses the behavior of one person with multiple accounts by authenticating the authentication request of the user account on the off-chain server and ensuring fair participation of real users by identity authentication of the user account. By determining the time window of the user account, network congestion caused by concentrated purchase is avoided, and the security of the reservation is further improved. It is convenient for the user to complete authentication and use the smart contract cluster to check the reservation request for anti-cheating, and then ensure that the target object is allocated to a normal user. After the user is qualified on the off-chain server, the smart contract cluster checks the reservation request for anti-cheating to ensure that the target object is allocated to a normal user, prevents abnormal users from attacking the reservation system, reduces abnormal situations in the reservation processing process, improves the overall efficiency of the system, and further ensures the security of the system.
[0147] Figure 8 A structure schematic diagram of an electronic device is provided in the embodiments of the present application. As shown in Figure 8As shown, the electronic device 800 can include a memory 801, a processor 802. Optionally, the electronic device can further include a transceiver 804, wherein the memory 801 and the processor 802 are in communication; for example, the memory 801, the processor 802 and the transceiver 804 can be in communication through a communication bus 804, the memory 801 is configured to store a computer program, and the processor 802 executes the computer program to implement the method of the above-mentioned embodiments.
[0148] Optionally, the processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor and the like. The steps of the method embodiments disclosed in the present application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor.
[0149] The embodiments of the present application also provide a computer readable storage medium, and the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method in any of the above method embodiments.
[0150] The embodiments of the present application also provide a computer program product, and the computer program product includes a computer program, and the computer program is executed by the processor to implement the method in any of the above method embodiments.
[0151] All or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware. The foregoing program can be stored in a readable memory. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the foregoing memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid state disk, magnetic tape, floppy disk, optical disc and any combination thereof.
[0152] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and a combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices generate a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 one or more flows and / or blocks
[0153] These computer program instructions can also be stored in a computer-readable memory that can direct the computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including instruction devices that implement the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 one or more flows and / or blocks
[0154] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are performed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 one or more flows and / or blocks
[0155] Obviously, those skilled in the art can make various modifications and variations to the embodiments of the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalents, the present application also intends to include these modifications and variations.
[0156] In the present application, the term "comprising" and its variants can refer to non-limiting inclusion; the term "or" and its variants can refer to "and / or". In the present application, the terms "first", "second", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. In the present application, "multiple" refers to two or more. "And / or", which describes the relationship between the associated objects, means that there can be three relationships, for example, A and / or B, which can represent the three cases of A alone, A and B together, and B alone. The character " / " generally represents an "or" relationship between the associated objects.
Claims
1. A reservation request processing method characterized by comprising: The method is applied to an off-chain server, and the method comprises the following steps: In response to an authentication request corresponding to a user account, identity authentication is performed on the user account, and after the user account passes the identity authentication, a verifiable credential of the user account is generated, and a time window corresponding to the user account is determined; The time window and the verifiable credential are sent to a smart contract cluster, and the time window is sent to a user terminal, so that the user terminal initiates a reservation request for a target object within the time window; The reservation request initiated by the user account is obtained and sent to the smart contract cluster, so that the smart contract cluster obtains real-time behavior data of the user account, and when it is determined that the reservation request meets the corresponding time window, the user account is subjected to an anti-cheating check based on the verifiable credential and the real-time behavior data, and after the user account passes the anti-cheating check, a target object corresponding to the reservation request is allocated to the user account.
2. The method of claim 1, wherein, The determination of the time window corresponding to the user account comprises: A credit evaluation result of the user account is determined; A credit offset is obtained based on the credit evaluation result and a preset time step; A starting time of the time window is obtained based on an issuance time of a target object corresponding to the reservation request, the credit offset, and a random factor, and an issuance deadline of the target object is determined as a termination time of the time window.
3. The method of claim 2, wherein, The determination of the credit evaluation result of the user account comprises: Historical behavior data of the user account is obtained, and the historical behavior data comprises: a number of valid performances, a total number of performances, and a number of abnormal operations; The performance quality of the user account is determined according to the proportion of the number of valid performances to the total number of performances of the user account, and the number of valid performances represents the number of reservations completed by the user account in a non-peak period; A real-time penalty factor of the user account is obtained by multiplying the number of abnormal operations of the user account by a preset weight; The credit evaluation result of the user account is determined based on the performance quality and the real-time penalty factor.
4. The method of claim 2, wherein, The method further comprises: It is judged whether the credit evaluation result of the user account is lower than a ban threshold; When the credit evaluation result of the user account is lower than the ban threshold, the user account is banned; An associated account of the user account is determined, and the associated account is marked as a suspicious account, so that when a reservation request corresponding to the suspicious account is obtained, the reservation request is subjected to abnormal processing.
5. The method of claim 1, wherein, The process of the anti-cheating check comprises: It is judged whether the user account completes a signature challenge, and the signature challenge represents a behavior that cannot be simulated by a machine; After the user account completes the signature challenge, it is judged whether the verifiable credential of the user account is valid; When the verifiable credential of the user account is valid, it is judged whether the reservation request triggers a fuse mechanism based on the real-time behavior data; When the reservation request does not trigger the fuse mechanism, it is determined that the user account passes the anti-cheating check.
6. The method of claim 5, wherein, The process of the anti-cheating check further comprises: determining that the user account is a suspicious account when the user account fails to complete the signature challenge, and rejecting the reservation request of the user account; rejecting the reservation request of the user account when the verifiable credential of the user account is invalid; when the reservation request triggers a fuse mechanism, putting the reservation request into a waiting queue until a termination time corresponding to the fuse mechanism, taking the reservation request from the waiting queue, and returning to the step of determining whether the user account completes the signature challenge.
7. The method of claim 5, wherein, The real-time behavior data includes the frequency of the reservation request and real-time transaction behavior data. The method further includes: determining whether the frequency of the reservation request is greater than a preset frequency threshold; when the frequency of the reservation request is not greater than the preset frequency threshold, determining whether the real-time transaction behavior data meets an abnormal transaction condition; when the real-time transaction behavior data does not meet the abnormal transaction condition, determining that the reservation request does not trigger the fuse mechanism.
8. A reservation request processing method characterized by comprising: The method is applied to a smart contract cluster, and the method includes: in response to a reservation request initiated by a user account, determining a verifiable credential and a time window of the user account, the verifiable credential and the time window being generated by an off-chain server for identity authentication of the user account, and being generated after the user account passes the identity authentication; obtaining real-time behavior data of the user account, and performing anti-cheating inspection on the user account based on the verifiable credential and the real-time behavior data when it is determined that the reservation request meets a corresponding time window; after the user account passes the anti-cheating inspection, assigning a target object corresponding to the reservation request to the user account.
9. A reservation request processing system, the system comprising: an off-chain server and a smart contract cluster; wherein the off-chain server is configured to perform identity authentication on a user account in response to an authentication request of the user account, generate a verifiable credential of the user account after the user account passes the identity authentication, and determine a time window corresponding to the user account; send the time window and the verifiable credential to the smart contract cluster, and send the time window to a user terminal, so that the user terminal initiates a reservation request for a target object within the time window; and obtain the reservation request initiated by the user account and send the reservation request to the smart contract cluster; the smart contract cluster is configured to, in response to a reservation request initiated by a user account, determine a verifiable credential and a time window of the user account; obtain real-time behavior data of the user account, and perform anti-cheating inspection on the user account based on the verifiable credential and the real-time behavior data when it is determined that the reservation request meets a corresponding time window; and after the user account passes the anti-cheating inspection, assign a target object corresponding to the reservation request to the user account.
10. An electronic device, comprising: include: a processor, and a memory connected to the processor in communication; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the method of any one of claims 1 to 8.
11. A computer readable storage medium, characterized in that, The computer readable storage medium stores computer-executable instructions which, when executed by a processor, implement the method of any one of claims 1 to 8.
12. A computer program product, characterised in that, A computer program which, when executed by a processor, implements the method of any one of claims 1 to 8.