Block chain transaction processing method and device of anti-collision library, electronic equipment and storage medium
By employing zero-knowledge proof technology to anonymize user identities in a blockchain network, generating and storing anonymous transaction data, the problem of user identity information leakage in blockchain networks is solved, thereby improving user identity security and privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-22
- Publication Date
- 2026-04-03
AI Technical Summary
In blockchain networks, how to avoid the leakage of user identity information and prevent operational risks caused by the leakage of customer identity information, especially how to protect the privacy and security of user identity information in consortium blockchain networks.
Zero-knowledge proof technology is used to anonymize the original digital identity in the original transaction data, generating anonymous transaction data, which is then stored in the business blockchain of the business blockchain network. This anonymization process blocks cross-institutional identity association analysis paths, increasing the difficulty for malicious parties to crack the user's real identity.
It significantly improves the security of user identities, increases the difficulty for malicious parties to crack users' real identities through credential stuffing attacks, and protects users' privacy information.
Smart Images

Figure CN121786874A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and more particularly to the field of blockchain, specifically to a blockchain transaction processing method, apparatus, electronic device, and storage medium with anti-collision credentialing. Background Technology
[0002] Blockchain networks are an innovative solution that leverages peer-to-peer communication technology to achieve peer-to-peer communication, relies on consensus mechanisms to ensure the legitimacy of ledger entries, and utilizes a chain structure to store data, thereby enabling collaborative ledger recording. Blockchain technology can facilitate business and data collaboration among consortium organizations. However, because the ledger in a consortium blockchain network is publicly transparent, all participants can query the on-chain data.
[0003] When organizations have specific data privacy protection needs, they typically perform cryptographic processing on the data before uploading it to the blockchain. For example, for customer personal identification information such as ID card numbers and mobile phone numbers, cryptographic methods such as hashing, symmetric encryption, and asymmetric encryption are used to hide customer identity information or make it visible only to specific organizations (such as regulatory agencies). This prevents operational risks such as customer churn due to the leakage of customer identity information. How to avoid the leakage of user identity information and eliminate the risk of customer churn is an important technical problem that urgently needs to be solved in the industry. Summary of the Invention
[0004] This application provides a blockchain transaction processing method, apparatus, electronic device, and storage medium with anti-credential collision prevention to enhance the security of user identity information.
[0005] In a first aspect, embodiments of this application also provide a blockchain transaction processing method for preventing credential stuffing, executed by a first business system within a blockchain transaction system for preventing credential stuffing, wherein the blockchain transaction system further includes a digital identity system and a business blockchain network, and the method includes:
[0006] In response to an anonymization request, the system obtains the original transaction data of the user in the first business entity associated with the first business system, the original transaction data including the user's original digital identity in the first business entity;
[0007] The original digital identity in the original transaction data is anonymized using zero-knowledge proof technology to obtain anonymous transaction data.
[0008] The anonymous transaction data is stored in the business blockchain of the business blockchain network.
[0009] Secondly, embodiments of this application also provide a blockchain transaction processing device for preventing credential stuffing, configured in a first business system of a blockchain transaction system for preventing credential stuffing. The blockchain transaction system further includes a digital identity system and a business blockchain network. The device includes:
[0010] The raw data acquisition module is used to acquire raw transaction data of the user in the first business institution associated with the first business system in response to an anonymization processing request. The raw transaction data includes the user's original digital identity in the first business institution.
[0011] An anonymization module is used to anonymize the original digital identity in the original transaction data using zero-knowledge proof technology to obtain anonymous transaction data.
[0012] An anonymous storage module is used to store the anonymous transaction data in the business blockchain of the business blockchain network.
[0013] Thirdly, embodiments of this application also provide an electronic device, which includes:
[0014] One or more processors;
[0015] Storage device for storing one or more programs;
[0016] When one or more programs are executed by one or more processors, the one or more processors implement any of the anti-collision blockchain transaction processing methods provided in the embodiments of this application.
[0017] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the anti-collision blockchain transaction processing methods provided in embodiments of this application.
[0018] Fifthly, embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements any of the anti-collision brute-force blockchain transaction processing methods provided in embodiments of this application.
[0019] The technical solution of this application involves a first business system employing zero-knowledge proof technology to anonymize the original digital identity in the original transaction data, resulting in anonymous transaction data. This anonymous transaction data is then stored in the business blockchain, ensuring that the business blockchain does not leak the user's original digital identity. This mechanism significantly increases the difficulty for malicious parties to crack the user's real identity through credential stuffing attacks, effectively improving the security of the user's identity. Attached Figure Description
[0020] Figure 1a This is a flowchart of a blockchain transaction processing method for preventing credential stuffing, provided in Embodiment 1 of this application;
[0021] Figure 1b This is a schematic diagram of a blockchain transaction processing system with anti-collision credentialing provided according to Embodiment 1 of this application;
[0022] Figure 1c This is a schematic diagram of the structure of a digital identity system according to Embodiment 1 of this application;
[0023] Figure 1d This is a schematic diagram of a blockchain node structure provided in Embodiment 1 of this application;
[0024] Figure 2a This is a flowchart of another anti-collision blockchain transaction processing method according to Embodiment 2 of this application;
[0025] Figure 2b This is a schematic diagram of the structure of a business system according to Embodiment 2 of this application;
[0026] Figure 3 This is a schematic diagram of a blockchain transaction processing device for preventing credential stuffing, provided in Embodiment 3 of this application.
[0027] Figure 4 This is a schematic diagram of the structure of an electronic device that implements the anti-collision brute-force blockchain transaction processing method according to the embodiments of this application. Detailed Implementation
[0028] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0029] It should be noted that the terms "first" and "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0030] Example 1
[0031] Figure 1a This is a flowchart of a blockchain transaction processing method for brute-force protection according to Embodiment 1 of this application. This embodiment is applicable to situations where user digital identities are anonymized and uploaded to the blockchain. It can be executed by a brute-force protection blockchain transaction processing device, which can be implemented in hardware and / or software. This device can be configured in the first business system of the brute-force protection blockchain transaction system. The blockchain transaction system also includes a digital identity system and a business blockchain network for brute-force protection blockchain transaction processing. The first business system can be any business system. Figure 1a As shown, the method includes:
[0032] S101. In response to the anonymization processing request, obtain the original transaction data of the user in the first business institution associated with the first business system, wherein the original transaction data includes the user's original digital identity in the first business institution.
[0033] S102. The original digital identity in the original transaction data is anonymized using zero-knowledge proof technology to obtain anonymous transaction data.
[0034] S103. Store the anonymous transaction data in the business blockchain of the business blockchain network.
[0035] refer to Figure 1b The anti-collision credentialing blockchain transaction system comprises a digital identity system (4), multiple business systems (3), and a business blockchain network (1). Each business entity forms a business blockchain network based on its business cooperation needs, creating a business chain. The digital identity system, as the authoritative identity issuing institution, can be selected to participate in the business blockchain network, along with regulatory agencies. Business entities, as participants, must pass an institutional identity verification process for access. After access, they deploy blockchain nodes (2) and connect their own business systems to the corresponding blockchain nodes of their local business entities.
[0036] When the business blockchain network is initialized and launched, each blockchain node exchanges certificates and reads the organizational information configured by each business unit. The business system can initialize according to the alliance agreement, putting information such as the organization's identity certificate, service role information, business system communication address, and digital identity system address on the chain and disclosing it to each business unit in the alliance.
[0037] The business blockchain network is built according to the consortium's business needs and includes multiple blockchain nodes, all of which are member nodes of the business chain. Member nodes deploy data-sharing business smart contracts and store business request information and execution results initiated by the business system on the chain. The total number of blockchain nodes in the business chain is 3f+1 (f is the number of supportable fault-tolerant nodes, with a minimum value of 1). Both requests and business requests use PBFT (Practical Byzantine Fault Tolerance) for consensus. A consensus request requires each validator node in the business chain to receive at least 2f+1 consistent confirmation messages from other validators before the current stage of consensus can be completed. The Byzantine fault-tolerant algorithm requires three stages of consensus before the business request is executed, and the execution result is used as valid data to generate a new block and is persisted.
[0038] Blockchain nodes are used to process on-chain requests initiated by business systems, including endorsing the initiating institution and transaction request information on the chain, and disclosing the processing results of on-chain smart contracts. Blockchain nodes can be deployed distributed across participating institutions. Update-type transaction requests require consensus from the business chain consensus nodes. During the consensus process, each blockchain node must receive consistent confirmation messages from 2f+1 other blockchain nodes to complete consensus. The data processed according to the logic in the contract generates new block data and triggers the relevant processing result accounting process after contract execution. Query-type transaction requests directly retrieve the corresponding world state or block data from the corresponding blockchain node without requiring consensus.
[0039] Business systems serve as user-facing touchpoints for different business entities. Through integrated on-chain interactive components, they interact with the business chain and digital identity service system to complete processes such as customer identity verification, distributed digital identity (DID) issuance, user transaction request processing, identity information anonymization, and transaction information uploading to the blockchain. The digital identity service system, provided by an authoritative institution, supports real-name verification and DID issuance, serving as an endorsement of the association between the DID and the real-name identity of customers served by the business system.
[0040] When a user engages in a business transaction at a primary business institution, the primary business system extracts the original transaction data from local business records. This data includes the user's original digital identity, institution identifier, transaction serial number, and specific transaction details (such as a merchant's facial recognition payment record). Zero-knowledge proof technology is used to anonymize the original digital identity in the original transaction data, generating anonymous transaction data. This anonymous transaction data is then written into the business chain of the business blockchain network, achieving data persistence. By independently anonymizing the user's digital identity across different business institutions, the digital identity of the same user is independent across different institutions, blocking cross-institutional identity association analysis paths. Anonymous data is stored after verification through the blockchain consensus mechanism, ensuring that transactions are traceable and tamper-proof, significantly increasing the difficulty for malicious parties to crack the user's true identity through credential stuffing attacks. The information collected in this embodiment of the invention is information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant national and regional laws, regulations, and standards, and necessary confidentiality measures are taken. This does not violate public order and good morals, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0041] In one optional implementation, the method further includes: responding to a user's data sharing request by invoking the digital identity system to perform real-name authentication on the user; and if the real-name authentication is successful, obtaining the original digital identity generated by the digital identity system for the first business entity based on the user's root identity certificate.
[0042] Users can authorize anonymous sharing of their data using the First Business System. The First Business System then calls the digital identity system to perform real-name authentication on the user. (Reference) Figure 1c The digital identity system's real-name authentication device supports business system access, collecting and verifying users' real-name identity information. If real-name authentication is successful, the system generates the user's original digital identity for the first business entity based on the user's root identity certificate. In other words, each user has a unique root identity certificate, and the same user's digital identity differs across multiple business entities, ensuring the uniqueness of a user's digital identity within a business scenario. By issuing independent digital identities to the same user across different business entities, the system enhances the flexibility of digital identities and increases the difficulty for malicious parties to perform credential stuffing attacks based on digital identities, thereby improving the security of user identity data. The digital identity system can record the relationship between a user's real-name identity information, root identity certificate, and original digital identity, enabling the tracing of real-name identity information for anonymous information in the business chain under necessary circumstances such as regulatory requirements.
[0043] Combination Figure 1b and Figure 1cThe digital identity service system 4 includes a real-name authentication device 31, a DID identity issuance device 32, and a DID mapping relationship storage device 33. The real-name authentication device 31 is a system that supports different alliance institutions in the business blockchain network 1 to conduct user real-name authentication. It allows the business system 3 to access and collect and verify user real-name identity information. If the verification is successful, the device supports the DID identity issuance device 32 in issuing a digital identity DID for the user. The DID identity issuance device 32 is responsible for issuing root certificates and scenario DIDs for users who have passed real-name authentication. For different institutions, the same user only has one root certificate, and the device supports users deriving different DIDs according to different scenarios. After issuance, it returns the user's root certificate, the user's registered DID, and the corresponding private key information to the business system 3. The DID mapping relationship storage device 33 mainly undertakes the task of maintaining the relationship between user real-name identity information, user root identity certificate, and user registered DID, so as to realize the traceability of real-name identity information of anonymous information on the chain when necessary, such as under regulatory requirements.
[0044] In this embodiment, the first business system employs zero-knowledge proof technology to anonymize the original digital identity in the original transaction data, obtaining anonymous transaction data. This anonymous transaction data is then stored in the business blockchain, ensuring that the business blockchain does not leak the user's original digital identity. This mechanism significantly increases the difficulty for malicious parties to crack the user's real identity through credential stuffing attacks, effectively improving the security of the user's identity.
[0045] In one optional implementation, the step of anonymizing the original digital identity in the original transaction data using zero-knowledge proof technology to obtain anonymous transaction data includes: generating an anonymous random number; calculating a first intermediate value based on the anonymous random number and a first private key in the original digital identity; generating an anonymous digital identity for the user in this transaction based on the first intermediate value and elliptic curve parameters; replacing the original digital identity in the original transaction data with the anonymous digital identity to form the anonymous transaction data; the anonymous transaction data further includes at least one of a first business entity identifier, a transaction serial number, or user transaction data; and storing the association between the anonymous random number, the anonymous digital identity, and the transaction serial number in the off-chain log data of the first business system.
[0046] The original digital identity may include a digital identity identifier and a cryptographic pair constructed from a first public key and a first private key. The first public key x and the first private key y satisfy the following relationship: , where p is the prime modulus in the elliptic curve parameters.
[0047] The first business system responds to the user's anonymous processing request by generating a unique anonymous random number, denoted as r. It then calculates a first intermediate value k based on the anonymous random number r and the first private key x. For example, it can use the formula k = h(x, r) for calculation, where h(x, r) is a processing function for the first private key x and the anonymous random number r. This processing function can be a hash operation, linear superposition, etc. This processing function must satisfy two conditions: 1. One-wayness, meaning it is impossible to deduce the original first private key or anonymous random number from the first intermediate value; 2. Determinism, meaning that for the same input (x, r), it will always output a unique and definite first intermediate value.
[0048] Furthermore, the user's anonymous digital identity in this transaction can be calculated using the following formula: Where R is the anonymous digital identity, (g,p) are elliptic curve parameters, and k1 is the first intermediate value. This anonymous digital identity replaces the original digital identity in the original transaction data, thus forming anonymous transaction data. In addition to the anonymous digital identity, the anonymous transaction data may also include at least one of the following: the first business entity identifier, the transaction serial number, or the user's transaction data. That is, only the anonymous digital identity is uploaded to the business chain for storage, ensuring that the business chain does not disclose the user's original digital identity. Furthermore, the first business system can also store the association between anonymous random numbers, the anonymous digital identity, and the transaction serial number in its local off-chain log data. Moreover, this association may also include the corresponding original digital identity. This association will provide necessary information for subsequent identity verification, working in conjunction with the anonymous digital identity on the chain to jointly ensure the accuracy and security of identity verification.
[0049] Combination Figure 1b and Figure 1dBlockchain node 2 includes a transaction request access device 11 and a transaction consensus and execution device 12. The transaction request access device 11 is responsible for establishing and authenticating connections with other participating blockchain nodes 2 on the business chain 1 and the organization's own business system 3, and for processing corresponding transaction request access. This device specifically includes an initialization module 111 and a transaction access module 112. The initialization module 111 is mainly responsible for storing and verifying the identity certificate of blockchain node 2, as well as initiating and receiving connection requests between nodes. The certificate mentioned here is a trusted node identity certificate issued during system initialization between business chain 1 and business system 4, which ensures secure verification of connections between chain nodes. This certificate uses an elliptic curve cryptography algorithm to generate a public-key and private-key cryptographic pair, and then broadcasts the certificate with the public key to all blockchain nodes on the chain and the organization's own business system for node authentication. The transaction access module 112 is responsible for receiving blockchain business transaction requests initiated by business system 3, and using the certificate to verify transaction signatures, confirm identities, and verify permissions. Once the verification is successful, the transaction request is routed to the corresponding transaction consensus and execution device, thereby completing the transaction consensus and the persistence of ledger data.
[0050] The transaction consensus and execution device 12 is responsible for verifying the legality of smart contract transaction request parameters, executing smart contract transaction consensus, and writing the transaction execution result into the world state and the blockchain ledger. Different businesses will deploy different business smart contracts, and different program instances will be launched during runtime. Each smart contract program instance includes a transaction consensus module 121 and a transaction execution module 122. The transaction consensus module 121 is the core module that interacts with all blockchain nodes 2 in the business chain 1 to achieve peer-to-peer consensus information and completes transaction consensus. It achieves consensus on transaction results, specifically using a three-stage consensus process based on the Byzantine consensus algorithm. Only when all three stages of consensus are completed is the requested transaction considered legal and can proceed to the transaction execution module 122. The transaction execution module 122 is responsible for executing smart contract requests and persisting the ledger. It saves the successful transaction information, transaction result information, and blockchain consensus result completed by the transaction consensus module 121 into the block, records the transaction log and sends a block execution success event, performs strong consistency checks on blockchain nodes 2 (including block height, predecessor, and current hash), and finally updates the world state information. The evidence-based regulatory information includes transaction information submitted by business entities and signature information on the transaction information.
[0051] Example 2
[0052] Figure 2a This is a flowchart of another blockchain transaction processing method for preventing credential stuffing, provided in Embodiment 2 of this application. The technical solution of this embodiment is further refined based on the above technical solution. See also Figure 2aThe illustrated blockchain transaction processing method for preventing credential stuffing includes:
[0053] S201. In response to the anonymization processing request, obtain the original transaction data of the user in the first business institution associated with the first business system, wherein the original transaction data includes the user's original digital identity in the first business institution.
[0054] S202. The original digital identity in the original transaction data is anonymized using zero-knowledge proof technology to obtain anonymous transaction data;
[0055] S203. Store the anonymous transaction data in the business blockchain of the business blockchain network;
[0056] S204. Receive a challenge request for the anonymous transaction data initiated by the second business system pushed by the business blockchain network; the challenge request includes a challenge random number and the anonymous transaction data.
[0057] S205. Verify the authenticity of the anonymous digital identity and transaction serial number in the anonymous transaction data;
[0058] S206. If the verification result is true, then extract the corresponding anonymous random number from the off-chain log data of the first business system.
[0059] S207. Generate a response message based on the first private key in the original digital identity, the extracted anonymous random number, and the challenge random number, and send the response message back to the second business system through the business blockchain network, so that the second business system can verify the validity of the anonymous digital identity.
[0060] Secondary business entities, or other business entities, can query anonymous transaction data from the business blockchain network using blockchain nodes. When a secondary business entity needs to verify the authenticity of anonymous transaction data, it can initiate a challenge request to the business blockchain network. The challenge request may include a challenge random number and the anonymous transaction data to be challenged. This anonymous transaction data may include the identifier of the primary business entity (i.e., the business entity to be challenged), an anonymous digital identity, and may also include transaction serial numbers, user transaction data, etc. For example, the secondary business system queries the anonymous transaction data to be challenged from the business blockchain, generates a unique challenge random number, and initiates a challenge transaction request to the business blockchain network based on the challenge random number and the anonymous transaction data to be challenged. The blockchain node forwards the challenge request to the primary business system based on the primary business entity identifier in the anonymous transaction data.
[0061] In response to the challenge request, the first business system uses local off-chain log data to verify the authenticity of the anonymous digital identity and transaction serial number in the anonymous transaction data, to confirm whether the anonymous digital identity and transaction serial number belong to its own business system. If the verification result indicates that it belongs to its own system, i.e., the verification result is authentic, the first business system extracts an anonymous random number associated with the anonymous digital identity to be challenged from its local off-chain log data; it then combines the first private key in the original digital identity, the extracted anonymous random number, and the challenge random number to generate a response message, and sends the response message back to the second business system, enabling the second business system to verify the validity of the anonymous digital identity to be challenged. Through the challenge and verification processing of anonymous transaction data, the reliability of the user's anonymous digital identity is further improved.
[0062] In one optional implementation, the step of generating a response message based on the first private key in the original digital identity, the extracted anonymous random number, and the challenge random number, and feeding the response message back to the second business system through the business blockchain network, so that the second business system verifies the validity of the anonymous digital identity, includes: calculating a second intermediate value based on the extracted anonymous random number and the first private key in the original digital identity; performing a modulo operation on the prime modulus in the elliptic curve parameters by multiplying the verification random number by the first private key, and adding the modulo operation result to the second intermediate value to obtain the response message; feeding the response message, the first public key in the original digital identity, and the elliptic curve parameters back to the second business system through the business blockchain network, so that the second business system performs the following: performing an exponential calculation on the response message using the base point in the elliptic curve parameters as the base to obtain a first verification value; multiplying the anonymous digital identity by the power of the verification random number of the first public key, and performing a modulo operation on the prime modulus in the elliptic curve parameters by the multiplication result to obtain a second verification value; if the first verification value is equal to the second verification value, then the anonymous digital identity is determined to be valid.
[0063] In response to the challenge request, the first business system calculates a second intermediate value h2 based on the extracted anonymous random number r and the first private key x from the original digital identity. The calculation method for the second intermediate value is the same as that for the first intermediate value, and will not be repeated here. The first business system generates a response message using the following formula: Where S is the response message, c is the challenge random number, p is the prime modulus in the elliptic curve parameters, and mod is the modulo operator. This calculation method cleverly combines anonymous random numbers, private keys, and challenge random numbers, making the response message highly unique and secure, difficult to forge or tamper with, and providing a reliable foundation for the subsequent verification process.
[0064] The first business system feeds back the response message S, the first public key from the original digital identity, and the elliptic curve parameters to the second business system. This information is interconnected and mutually corroborating, providing comprehensive and accurate data support for the second business system's verification process.
[0065] The second business system uses the base point g in the elliptic curve parameters as the base to perform exponential calculation on the response message S, thus obtaining the first verification value. This process utilizes the properties of elliptic curve cryptography to ensure the accuracy and uniqueness of the calculation results. Furthermore, the second business system obtains the second verification value using the following formula. Where R is the anonymous digital identity to be challenged, and y is the first public key. The first verification value and the second verification value are compared. If they are the same, the second business system determines that the anonymous digital identity R reported by the first business system is valid, meaning that the first private key of the original digital identity corresponding to the anonymous digital identity R does indeed belong to the first business organization. This verification method is based on strict mathematical principles, has extremely high credibility, and can effectively prevent identity impersonation and fraud. Conversely, if the first verification value and the second verification value are different, the second business system determines that the anonymous digital identity R is invalid. In this case, it can mark the message as a false message on the business chain and submit it to the regulatory agency for arbitration. The regulatory agency can conduct further investigations and processing based on more detailed information and rules to ensure the fairness and impartiality of the entire business system.
[0066] The technical solution in this embodiment, through a rigorous verification method based on mathematical principles, can ensure the authenticity and legitimacy of the identity at a mathematical level. The complex mathematical operations and unique cryptographic properties of elliptic curve cryptography make the identity verification process highly secure and reliable, greatly enhancing the credibility of anonymous digital identities in business systems and providing a solid guarantee for the stable operation of business and data security.
[0067] In one optional implementation, the method further includes: synchronizing the response message with a regulatory agency, enabling the regulatory agency to verify the original digital identity stored in the first business system based on the first public key in the response message, and calling the digital identity system to verify the authenticity of the original digital identity.
[0068] The primary business system can also synchronize response messages with regulatory agencies, enabling them to authenticate users using the primary public key within the response message. The regulatory agency can compare the primary public key in the response message with the original digital identity stored in the primary business entity's off-chain log data to initially confirm whether the primary public key is associated with the original digital identity, effectively preventing public key tampering or impersonation and ensuring the accuracy and consistency of information from the data source. After completing the comparison with the off-chain log data, the regulatory agency can further verify the authenticity of the original digital identity by calling the digital identity service system. By verifying identity authenticity through multiple methods, the regulatory agency further enhances the accuracy and reliability of identity verification.
[0069] refer to Figure 2b The business system includes a user interaction device 21 and an information anonymization processing device 22. The user interaction device 21 is the business interaction portal provided by the alliance organization for different data sharing customers. Customers can use this device to connect with the digital identity system and carry out a series of operations, including real-name authentication, registering DID identity information in different data sharing scenarios, and completing the confirmation and authorization of shared data.
[0070] The information anonymization processing device 22 is a device for anonymizing customer identity information before customer shared data is uploaded to the blockchain. It includes an anonymization processing module 221, an off-chain storage module 222, and an on-chain interaction module 223. The anonymization processing module 221 uses zero-knowledge proof technology to anonymize customer information in the shared data. Specifically, it selects a random number r for each piece of shared data, generates identity verification information R based on the random number r and the private key x corresponding to the DID, and uploads R as the anonymized information of the customer's identity DID along with the customer shared data to the blockchain. At the same time, the random number is recorded off-chain as transaction backup data.
[0071] The off-chain storage module 222 is responsible for storing the private and public key information corresponding to the user's DID. To ensure the security of private key storage, the private key can be split into N fragments and distributed across IPFS nodes using a secret sharing encryption method. Furthermore, this module stores the user's shared data identity identifier (DID), random number (R), and unique transaction sequence number as key data in the institution's local secure storage for use in challenging on-chain data identity verification. The on-chain interaction module 223 is primarily responsible for interacting with blockchain nodes to enable anonymous sharing of customer data on-chain. It also supports challenges from different institutions regarding the identity identifier of shared on-chain data and provides responses to these challenges.
[0072] Example 3
[0073] Figure 3This is a schematic diagram of a blockchain transaction processing device for brute-force prevention according to Embodiment 3 of this application. This embodiment is applicable to situations where user digital identities are anonymized and uploaded to the blockchain. The brute-force prevention blockchain transaction processing device can be implemented in hardware and / or software. This device can be configured in the first business system of the brute-force prevention blockchain transaction system. The blockchain transaction system also includes a digital identity system and a business blockchain network. (Reference) Figure 3 The specific structure of the anti-collision brute-force blockchain transaction processing device 300 is as follows:
[0074] The raw data acquisition module 310 is used to acquire raw transaction data of the user in the first business institution associated with the first business system in response to an anonymization processing request. The raw transaction data includes the user's original digital identity in the first business institution.
[0075] Anonymization module 320 is used to anonymize the original digital identity in the original transaction data using zero-knowledge proof technology to obtain anonymous transaction data.
[0076] Anonymous storage module 330 is used to store the anonymous transaction data in the business blockchain of the business blockchain network.
[0077] In one optional implementation, the anonymization processing module 320 includes:
[0078] An anonymous random number unit is used to generate anonymous random numbers and calculate a first intermediate value based on the anonymous random numbers and the first private key in the original digital identity.
[0079] An anonymous identity unit is used to generate an anonymous digital identity for the user in this transaction based on the first intermediate value and the elliptic curve parameters.
[0080] An anonymous transaction unit is used to replace the original digital identity in the original transaction data with the anonymous digital identity to form the anonymous transaction data; the anonymous transaction data also includes at least one of a first business entity identifier, a transaction serial number, or user transaction data.
[0081] An anonymous storage unit is used to store the association between the anonymous random number, the anonymous digital identity, and the transaction serial number in the off-chain log data of the first business system.
[0082] In one alternative embodiment, the device 300 further includes an anonymous challenge module, the anonymous challenge module comprising:
[0083] The challenge request unit is used to receive a challenge request for the anonymous transaction data initiated by the second business system pushed by the business blockchain network; the challenge request includes a challenge random number and the anonymous transaction data;
[0084] An authenticity verification unit is used to verify the authenticity of the anonymous digital identity and transaction serial number in the anonymous transaction data.
[0085] The random number extraction unit is used to extract the corresponding anonymous random number from the off-chain log data of the first business system if the verification result is true.
[0086] The response message unit is used to generate a response message based on the first private key in the original digital identity, the extracted anonymous random number, and the challenge random number, and to feed the response message back to the second business system through the business blockchain network, so that the second business system can verify the validity of the anonymous digital identity.
[0087] In one optional implementation, the response message unit is specifically used for:
[0088] Calculate the second intermediate value based on the extracted anonymous random number and the first private key from the original digital identity;
[0089] The product of the verification random number and the first private key is used to perform a modulo operation on the prime modulus in the elliptic curve parameters, and the result of the modulo operation is added to the second intermediate value to obtain the response message;
[0090] Through the business blockchain network, the response message, the first public key in the original digital identity, and the elliptic curve parameters are fed back to the second business system, causing the second business system to perform the following: using the base point in the elliptic curve parameters as the base, the response message is exponentially calculated to obtain a first verification value; the anonymous digital identity is multiplied by the result of the verification random number power operation of the first public key, and the result of the multiplication is modulo the prime number modulo in the elliptic curve parameters to obtain a second verification value; if the first verification value is equal to the second verification value, the anonymous digital identity is determined to be valid.
[0091] In one alternative implementation, the anonymous challenge module further includes:
[0092] The response monitoring unit is used to synchronize the response message with the regulatory agency, so that the regulatory agency can verify the original digital identity stored in the first business system based on the first public key in the response message, and call the digital identity system to verify the authenticity of the original digital identity.
[0093] In one alternative embodiment, the device 300 further includes an original digital identity module, the original digital identity module comprising:
[0094] The real-name authentication unit is used to respond to a user's data sharing request by calling the digital identity system to perform real-name authentication on the user;
[0095] The original digital identity unit is used to obtain the original digital identity generated by the digital identity system for the first business entity based on the user's root identity certificate, provided that the real-name identity authentication is successful.
[0096] The technical solution provided in this application embodiment authenticates users' real-name identity information through an authoritative identity verification agency. Based on scenario requirements and business needs, it applies for and issues different digital identity (DID) information for the same user. When data is uploaded to the blockchain, the user identity that needs to be protected is anonymized for each transaction. This approach can help business organizations protect the commercial secrets of their own user information and meet the regulatory requirements of regulatory agencies to restore users' real-name identity information. On the one hand, to meet the privacy protection requirements of data, real-name identity information is issued as different DIDs according to different scenarios. When data is shared in the scenario, the public and private key information based on the DID is combined with zero-knowledge proof technology to process into anonymous information that is different for each transaction, realizing double anonymization of the user's real identity information, effectively protecting the real identity of the user to whom the data belongs, and preventing the theft of customer information of the sharing institution through credential stuffing. On the other hand, to ensure the authenticity and verifiability of identity, the user's distributed digital identity DID information is issued and its validity is maintained by an authoritative institution based on real-name identity authentication information. Through the 1:N mapping relationship between the real-name identity root certificate and the distributed digital identity DID, it is ensured that the user's real-name identity information is traceable, and at the same time, it is ensured that transactions initiated by the user based on the DID identity identifier have the same validity as the real-name identity.
[0097] According to embodiments of the present invention, the present invention also provides an electronic device, a readable storage medium, and a computer program product.
[0098] Example 4
[0099] Figure 4 This is a schematic diagram of the structure of an electronic device 410 implementing the anti-collision brute-force blockchain transaction processing method according to embodiments of this application. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workbenches, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present application described and / or claimed herein.
[0100] like Figure 4As shown, the electronic device 410 includes at least one processor 411 and a memory, such as a read-only memory (ROM) 412 or a random access memory (RAM) 413, communicatively connected to the at least one processor 411. The memory stores computer programs executable by the at least one processor. The processor 411 can perform various appropriate actions and processes based on the computer program stored in the ROM 412 or loaded from storage unit 418 into the RAM 413. The RAM 413 may also store various programs and data required for the operation of the electronic device 410. The processor 411, ROM 412, and RAM 413 are interconnected via a bus 414. An input / output (I / O) interface 415 is also connected to the bus 414.
[0101] Multiple components in electronic device 410 are connected to I / O interface 415, including: input unit 416, such as keyboard, mouse, etc.; output unit 417, such as various types of displays, speakers, etc.; storage unit 418, such as disk, optical disk, etc.; and communication unit 419, such as network card, modem, wireless transceiver, etc. Communication unit 419 allows electronic device 410 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0102] Processor 411 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 411 include, but are not limited to, central processing unit (CPU), graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. Processor 411 performs the various methods and processes described above, such as the brute-force blockchain transaction processing method.
[0103] In some embodiments, the anti-collision blockchain transaction processing method can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 418. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 410 via ROM 412 and / or communication unit 419. When the computer program is loaded into RAM 413 and executed by processor 411, one or more steps of the anti-collision blockchain transaction processing method described above can be performed. Alternatively, in other embodiments, processor 411 can be configured for the anti-collision blockchain transaction processing method by any other suitable means (e.g., by means of firmware).
[0104] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0105] Computer programs used to implement the methods of this application may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0106] In the context of this application, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0107] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0108] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0109] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0110] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this application can be achieved, and this is not limited herein.
[0111] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A blockchain transaction processing method for preventing credential stuffing, characterized in that, The method, executed by a first business system within a blockchain transaction system that has implemented anti-collision credentialing mechanisms, including a digital identity system and a business blockchain network, comprises: In response to an anonymization request, the system obtains the original transaction data of the user in the first business entity associated with the first business system, the original transaction data including the user's original digital identity in the first business entity; The original digital identity in the original transaction data is anonymized using zero-knowledge proof technology to obtain anonymous transaction data. The anonymous transaction data is stored in the business blockchain of the business blockchain network.
2. The method according to claim 1, characterized in that, The method employs zero-knowledge proof technology to anonymize the original digital identity in the original transaction data, resulting in anonymous transaction data, including: Generate an anonymous random number, and calculate a first intermediate value based on the anonymous random number and the first private key in the original digital identity; Based on the first intermediate value and the elliptic curve parameters, generate the user's anonymous digital identity in this transaction; The anonymous transaction data is formed by replacing the original digital identity in the original transaction data with the anonymous digital identity; the anonymous transaction data also includes at least one of the following: a first business entity identifier, a transaction serial number, or user transaction data. The association between the anonymous random number, the anonymous digital identity, and the transaction serial number is stored in the off-chain log data of the first business system.
3. The method according to claim 1, characterized in that, The method further includes: The system receives a challenge request for the anonymous transaction data initiated by a second business system pushed by the business blockchain network; the challenge request includes a challenge random number and the anonymous transaction data. The authenticity of the anonymous digital identity and transaction serial number in the anonymous transaction data is verified. If the verification result is true, then extract the corresponding anonymous random number from the off-chain log data of the first business system; A response message is generated based on the first private key in the original digital identity, the extracted anonymous random number, and the challenge random number. The response message is then fed back to the second business system through the business blockchain network, enabling the second business system to verify the validity of the anonymous digital identity.
4. The method according to claim 3, characterized in that, The step of generating a response message based on the first private key in the original digital identity, the extracted anonymous random number, and the challenge random number, and then feeding the response message back to the second business system through the business blockchain network, so that the second business system can verify the validity of the anonymous digital identity, includes: Calculate the second intermediate value based on the extracted anonymous random number and the first private key from the original digital identity; The product of the verification random number and the first private key is used to perform a modulo operation on the prime modulus in the elliptic curve parameters, and the result of the modulo operation is added to the second intermediate value to obtain the response message; Through the business blockchain network, the response message, the first public key in the original digital identity, and the elliptic curve parameters are fed back to the second business system, causing the second business system to perform the following: using the base point in the elliptic curve parameters as the base, the response message is exponentially calculated to obtain a first verification value; the anonymous digital identity is multiplied by the result of the verification random number power operation of the first public key, and the result of the multiplication is modulo the prime number modulo in the elliptic curve parameters to obtain a second verification value; if the first verification value is equal to the second verification value, the anonymous digital identity is determined to be valid.
5. The method according to claim 3, characterized in that, The method further includes: The response message is synchronized with the regulatory agency, enabling the regulatory agency to verify the original digital identity stored in the first business system based on the first public key in the response message, and to call the digital identity system to verify the authenticity of the original digital identity.
6. The method according to claim 1, characterized in that, The method further includes: In response to a user's data sharing request, the digital identity system is invoked to perform real-name authentication on the user; If real-name authentication is successful, the original digital identity generated by the digital identity system for the first business entity based on the user's root identity certificate is obtained.
7. A blockchain transaction processing device with anti-credential collision prevention, characterized in that, In a first business system configured within a blockchain transaction system with anti-collision credentialing, the blockchain transaction system further includes a digital identity system and a business blockchain network, and the device comprises: The raw data acquisition module is used to acquire raw transaction data of the user in the first business institution associated with the first business system in response to an anonymization processing request. The raw transaction data includes the user's original digital identity in the first business institution. An anonymization module is used to anonymize the original digital identity in the original transaction data using zero-knowledge proof technology to obtain anonymous transaction data. An anonymous storage module is used to store the anonymous transaction data in the business blockchain of the business blockchain network.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the blockchain transaction processing method with anti-collision library as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the anti-collision credentialing blockchain transaction processing method as described in any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the anti-collision credentialing blockchain transaction processing method according to any one of claims 1-6.