Blockchain-based resource processing method and device, and computer device
By encrypting blockchain addresses with attributes and using CP-ABE technology, only nodes that meet specific conditions are allowed to decrypt and store resource data, thus solving the problem of business data privacy protection in blockchain systems and achieving privacy protection for resource transfer and data storage.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2024-12-26
- Publication Date
- 2026-06-26
AI Technical Summary
How can we achieve privacy protection for business data in a blockchain system, especially during resource transfer and data storage, to ensure that only nodes that meet specific conditions can access and store relevant data?
By encrypting blockchain addresses with attributes, only nodes that meet specific attribute conditions are allowed to decrypt and store resource data. Combined with CP-ABE encryption technology, privacy protection is achieved for resource transfer and data storage.
During the resource transfer and data storage phases, it is ensured that only nodes that meet the attribute conditions can access and store data, thereby achieving privacy protection for business data and preventing unauthorized nodes from obtaining or storing sensitive information.
Smart Images

Figure CN122293353A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of blockchain technology, and in particular to blockchain-based resource processing methods, blockchain-based resource processing devices, and computer equipment. Background Technology
[0002] With the development of blockchain technology, more and more business systems are beginning to use it. A blockchain system is a distributed system composed of multiple nodes forming a peer-to-peer (P2P) network. In practical business systems, one or more types of business operations often use a specific blockchain. With the widespread application of blockchain, business users have a need to protect the privacy of their business data. How to protect the privacy of business data remains a problem to be solved. Summary of the Invention
[0003] This application provides a blockchain-based resource processing method, apparatus, and computer equipment, which can achieve privacy protection for business data related to resource transfer in both the execution of resource transfer and data storage.
[0004] On one hand, embodiments of this application provide a blockchain-based resource processing method, which includes:
[0005] Obtain resource transfer information, which includes a first encrypted blockchain address and characteristic information of the transferred resource data; the first encrypted blockchain address is obtained by encrypting the first blockchain address with attributes, and a blockchain node that meets the attribute conditions can successfully decrypt the first encrypted blockchain address; the first blockchain address is the blockchain address where the resource data is transferred.
[0006] Decrypt the first encrypted blockchain address;
[0007] If the first encrypted blockchain address is successfully decrypted, the decrypted first blockchain address is then encrypted to obtain the second encrypted blockchain address;
[0008] The second encrypted resource data is determined based on the first encrypted resource data recorded under the second encrypted blockchain address and the transfer resource data indicated by the feature information;
[0009] The second encrypted resource data and the second encrypted blockchain address are stored together.
[0010] On one hand, embodiments of this application provide a blockchain-based resource processing apparatus, which includes:
[0011] The acquisition unit is used to acquire resource transfer information, which includes a first encrypted blockchain address and characteristic information of the transferred resource data. The first encrypted blockchain address is obtained by encrypting the first blockchain address with attributes. Blockchain nodes that meet the attribute conditions can successfully decrypt the first encrypted blockchain address. The first blockchain address is the blockchain address where the resource data is transferred.
[0012] A processing unit is used to decrypt the first encrypted blockchain address;
[0013] The processing unit is further configured to, if the first encrypted blockchain address is successfully decrypted, encrypt the decrypted first blockchain address to obtain a second encrypted blockchain address;
[0014] The processing unit is further configured to determine the second encrypted resource data based on the first encrypted resource data recorded under the second encrypted blockchain address and the transfer resource data indicated by the feature information;
[0015] A storage unit is used to associate and store the second encrypted resource data and the second encrypted blockchain address.
[0016] Accordingly, embodiments of this application provide a computer device, the computer device comprising:
[0017] A processor is a tool for implementing computer programs.
[0018] A computer-readable storage medium storing a computer program adapted to be loaded by the processor and implement the blockchain-based resource processing method provided in the embodiments of this application.
[0019] Accordingly, embodiments of this application provide a computer-readable storage medium storing a computer program adapted to be loaded by a processor and to implement the blockchain-based resource processing method provided in embodiments of this application.
[0020] Accordingly, this application provides a computer program product, which includes a computer program that, when executed by a processor, implements the blockchain-based resource processing method provided in this application.
[0021] In this embodiment, the resource transfer information does not directly carry the resource transfer address (i.e., the blockchain address where the resource data is transferred) itself. Instead, it carries an encrypted blockchain address obtained by encrypting the resource transfer address with attributes. Only blockchain nodes that meet the attribute conditions can successfully decrypt the encrypted blockchain address and execute the resource transfer indicated by the resource transfer information based on the decrypted resource transfer address. Blockchain nodes that do not meet the attribute conditions cannot obtain the resource transfer address and cannot execute the resource transfer. This achieves privacy protection for resource transfer-related business data during the resource transfer execution phase. Furthermore, instead of directly associating and storing the resource transfer address and the resource data under the resource transfer address after the resource transfer is executed, the resource transfer address and the resource data under the resource transfer address after the resource transfer is executed are encrypted before being associating and stored. This achieves privacy storage of the resource data under the blockchain address, i.e., privacy protection for resource transfer-related business data during the data storage phase. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a schematic diagram of the architecture of a resource processing system provided by an exemplary embodiment of this application;
[0024] Figure 2 This is a schematic flowchart of a resource processing method provided by an exemplary embodiment of this application;
[0025] Figure 3 This is a schematic diagram illustrating an exemplary transaction construction method and transaction structure provided in the embodiments of this application;
[0026] Figure 4 This is a schematic diagram of a block proposal provided by an exemplary embodiment of this application;
[0027] Figure 5 This is an exemplary schematic diagram of data changes stored in a database, provided by an embodiment of this application.
[0028] Figure 6 This is a schematic flowchart of another resource processing method provided by an exemplary embodiment of this application;
[0029] Figure 7A This is a schematic diagram illustrating voting content as exemplarily provided in an embodiment of this application;
[0030] Figure 7B This is a schematic diagram illustrating another voting content provided by an exemplary embodiment of this application;
[0031] Figure 8 This is a schematic flowchart illustrating yet another resource processing method exemplarily provided in an embodiment of this application;
[0032] Figure 9 This is a schematic flowchart illustrating yet another resource processing method exemplarily provided in an embodiment of this application;
[0033] Figure 10 This is a schematic flowchart illustrating yet another resource processing method exemplarily provided in an embodiment of this application;
[0034] Figure 11 This is a schematic flowchart of a consensus processing method provided by an exemplary embodiment of this application;
[0035] Figure 12 This is a schematic diagram illustrating an exemplary method for processing voting content involved in consensus processing, provided by an embodiment of this application.
[0036] Figure 13 This is a schematic diagram of the structure of a resource processing device provided in an embodiment of this application;
[0037] Figure 14 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0038] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0039] To better understand the technical solutions provided in the embodiments of this application, some technical terms involved in the technical solutions will be introduced first:
[0040] Blockchain address: A blockchain account identifier formed by converting a key generated using an asymmetric encryption algorithm according to certain rules. It can be used to receive blockchain resources, which are a type of virtual resource.
[0041] Digital collectibles: Using blockchain technology, a unique digital certificate is generated for a specific object (such as a work of art). Digital collectibles are a type of blockchain resource.
[0042] Smart contracts are digitally defined protocols that must run in a trusted environment, such as a blockchain platform. They are contracts that operate in cyberspace using computers, and are disseminated, verified, or executed in an informational manner. They are read and executed by computers and possess self-service characteristics. The contracts discussed below refer to smart contracts.
[0043] Blockchain network: It is a peer-to-peer network. Based on a specific network protocol, the blockchain network does not require a central node to maintain the network state. Instead, each blockchain node maintains the state of the entire network and the connection state with its neighbors through broadcast interactions.
[0044] Blockchain is a distributed ledger technology in the field of information technology. It generally consists of consensus, transaction blocks and state data storage, cryptographic identity security and other components. Because the ledger is stored in a distributed manner and the blocks are agreed upon, it has the characteristics of being immutable, traceable and jointly maintained.
[0045] Consensus nodes are special nodes in a blockchain network that reach consensus through specific protocols to maintain the consistency and security of data state. Consensus nodes play a crucial role in blockchain networks, responsible for verifying transactions, packaging blocks, and maintaining the security and integrity of the entire network and its data. The effective operation of consensus nodes is key to decentralized networks, preventing tampering and other problems, and enhancing trust mechanisms.
[0046] Merkle Tree: A Merkle tree is a typical binary tree structure consisting of a root node (the Merkle root), a set of intermediate nodes, and a set of leaf nodes. The leaf nodes at the bottom level store data or its hash value, while the other nodes store the hash values of the contents of their two child nodes.
[0047] CP-ABE (Ciphertext Policy Attribute Based Encryption) is an attribute-based encryption technique that allows data owners to define complex access policies to control access to their data. In CP-ABE, the ciphertext corresponds to an access structure, and the key corresponds to a set of attributes. Decryption occurs if and only if the attributes in the set satisfy the access structure.
[0048] The CP-ABE attribute encryption and decryption process includes four steps: Setup, Key Generation, Encryption, and Decryption. The following is a detailed description of these four steps:
[0049] Setup
[0050] Generate public parameter PK: Based on a random algorithm, take hidden security parameters as input and output public parameter PK and a master key MK.
[0051] Determine the access structure: During the Setup phase, it is also necessary to determine an access structure, which defines which sets of attributes can decrypt the ciphertext.
[0052] Key Generation
[0053] Generate private key SK: Based on a random algorithm, take a set of attributes Y, master key MK, and public parameters PK as input, and output a decryption key D.
[0054] Assignment Attributes: A user's private key is generated based on their set of attributes, which are used in the subsequent decryption process.
[0055] Encryption
[0056] Generate ciphertext E: Based on a random algorithm, take a message m, an access structure A, and public parameters PK as input, and output ciphertext E.
[0057] Embedded access policy: The encryptor selects a random number as the key according to the access policy and encrypts the data using a symmetric encryption algorithm such as AES. Then, the random number is encrypted using the CP-ABE algorithm, and the encrypted random number and the encrypted data are sent to the user together.
[0058] Decryption
[0059] Decrypt the ciphertext: Ciphertext E encrypted based on access structure A, the decryption key D corresponding to attribute group Y, and public parameter PK. If Y∈A, output message m of X, where ∈ indicates belonging to.
[0060] Attribute verification: Users first need to obtain their private key from the certification authority. The private key contains the user's attributes and access policies. If the user's attributes meet the access policies, then the data can be decrypted.
[0061] In summary, CP-ABE attribute encryption achieves fine-grained access control and high security for data through the four steps described above. This encryption method not only ensures data security but also allows for flexible control over data access, making it suitable for various application scenarios.
[0062] This application provides a blockchain-based resource processing method to achieve privacy protection for business data related to resource transfer in both the execution of resource transfer and data storage.
[0063] The resource processing system provided in the embodiments of this application will be described below with reference to the accompanying drawings. This resource processing system is suitable for implementing the blockchain-based resource processing method provided in the embodiments of this application. For example... Figure 1 As shown, the resource processing system may include a client and a blockchain network, and the blockchain network includes multiple blockchain nodes.
[0064] The client can construct resource transfer information (also known as transaction information) based on attribute encryption. This can be achieved by the client receiving user input related to the resource transfer, including a first blockchain address (i.e., the blockchain address where the resource data is transferred, also known as the resource transfer address) and characteristic information of the transferred resource data; the first blockchain address is then encrypted based on node attributes to obtain a first encrypted blockchain address, so that only blockchain nodes meeting the attribute conditions can successfully decrypt the first encrypted blockchain address; based on the first encrypted blockchain address and the characteristic information of the transferred resource data, resource transfer information is generated, for example... Figure 1 As shown, the resource transfer information includes a transfer quantity of 200 and a resource transfer address ABE(Add2), where Add2 is the first blockchain address and ABE represents attribute decryption. Thus, only blockchain nodes that meet the attribute conditions can execute the resource transfer indicated by the resource transfer information based on the decrypted first blockchain address. The client sends the generated resource transfer information to the blockchain nodes in the blockchain network.
[0065] When a resource transfer as indicated by the resource transfer information needs to be executed, a blockchain node can decrypt the first encrypted blockchain address carried in the resource transfer information. If the blockchain node meets the attribute conditions, decryption will be successful, and the first blockchain address can be obtained. The node can then encrypt the decrypted first blockchain address using its own configured encryption method to obtain a second encrypted blockchain address. The node then queries the recorded first encrypted resource data under the second encrypted blockchain address. Based on the recorded first encrypted resource data under the second encrypted blockchain address and the transferred resource data indicated by the feature information, the second encrypted resource data is determined. Finally, the second encrypted resource data and the second encrypted blockchain address are associated and stored. This completes the resource transfer for the first blockchain address (resource transfer address). For example, as shown... Figure 1 As shown, the data originally recorded by blockchain node A is "E(Add2):E(200)", where E represents the encryption method configured by the node itself and 200 is the original amount of resources. After the resource transfer is performed, the data recorded by blockchain node A is updated to "E(Add2):E(400)", where 200 is the amount of resources after the transfer.
[0066] In this embodiment, the resource transfer information does not directly carry the resource transfer address (i.e., the first blockchain address) itself, but rather carries an encrypted blockchain address obtained by encrypting the resource transfer address with attributes. This ensures that only blockchain nodes meeting the attribute conditions can successfully decrypt the encrypted blockchain address and execute the resource transfer indicated by the resource transfer information based on the decrypted resource transfer address. Blockchain nodes not meeting the attribute conditions cannot obtain the resource transfer address and therefore cannot execute the resource transfer. This achieves privacy protection for resource transfer-related business data during the resource transfer execution phase. Furthermore, instead of directly associating and storing the resource transfer address and the resource data under the resource transfer address after the resource transfer is executed, the resource transfer address and the resource data under the resource transfer address after the resource transfer is executed are encrypted before being associating and stored. This achieves privacy storage of the resource data under the blockchain address, thus protecting the privacy of resource transfer-related business data during the data storage phase.
[0067] The resource processing method based on blockchain provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0068] This application provides a blockchain-based resource processing method, which can be executed by consensus nodes in a blockchain network. For example... Figure 2 As shown, this blockchain-based resource processing method may include, but is not limited to, the following steps:
[0069] 201. Obtain resource transfer information, which includes the first encrypted blockchain address and the characteristic information of the transferred resource data.
[0070] In this embodiment, resource transfer information can be used to instruct the transfer or storage of resource data; resource transfer information can also be referred to as transaction information. Resource transfer information may include a first encrypted blockchain address and characteristic information of the transferred resource data.
[0071] The characteristic information of transferred resource data may include one or more of the following: the type and quantity of the resource data to be transferred, digital credentials (or identifiers), etc. For example, when resource transfer information instructs for an electronic resource transfer, the characteristic information of the transferred resource data may include the type and quantity of the electronic resources to be transferred. As another example, when resource transfer information instructs for a digital collectible transaction, the characteristic information of the transferred resource data may include the digital credentials of the digital collectible to be traded. In other feasible implementations, the characteristic information of transferred resource data may also refer to the transferred resource data itself. For example, in a notarization application scenario, resource transfer information can be used to instruct the storage of resource data (e.g., electronic tickets) under a blockchain address, and the characteristic information of the transferred resource data may refer to the resource data itself to be stored.
[0072] The first encrypted blockchain address can be obtained by encrypting the first blockchain address with attributes. This first blockchain address is the address where resource data is transferred (also known as the resource transfer address). Blockchain nodes that meet the attribute conditions can successfully decrypt the first encrypted blockchain address, while those that do not meet the attribute conditions cannot. Attribute encryption can be implemented based on a defined access structure, which defines a set of attributes that can decrypt the first encrypted blockchain address. This set of attributes can consist of node attributes. Node attributes can include, for example, the node's geographical location, Internet Protocol address (IP address), device type (e.g., desktop computer, server), node type (e.g., consensus node, business node), and so on. A blockchain node's key (e.g., private key) can be associated with the node's attributes. For example, a blockchain node's key can be generated based on its node attributes. Meeting the attribute conditions means that the node attributes corresponding to the blockchain node's key are included in the attribute set defined by the access structure. By encrypting the attributes of the first blockchain address, it can be made public only to a portion of the blockchain nodes. In other words, only a portion of the blockchain nodes can execute the resource transfer (also known as a transaction) indicated by the resource transfer information.
[0073] In some embodiments, the first encrypted blockchain address can be obtained by encrypting the first blockchain address using attribute-based encryption technology CP-ABE. For example, combining the specific process of CP-ABE attribute encryption and decryption described above, it can involve generating public parameters PK and access structure A, where access structure A defines the set of node attributes that can decrypt the ciphertext. Based on the first blockchain address, access structure A, and public parameters PK, ciphertext is generated, which is the first encrypted blockchain address obtained by attribute encryption of the first blockchain address.
[0074] In some embodiments, such as in applications like electronic resource transfer, the resource transfer information may further include a second blockchain address, which can be the blockchain address from which the resource data is transferred (also known as the resource transfer-out address). The resource transfer information can be used to indicate that the resource data indicated by the feature information (i.e., the feature information of the transferred resource data) is transferred from the second blockchain address to the first blockchain address indicated by the first encrypted blockchain address.
[0075] In some embodiments, the resource transfer information may further include the number of public nodes, which refers to the number of blockchain nodes that can successfully (or have the authority to) decrypt the first encrypted blockchain address. In one possible implementation, when performing attribute encryption on the first blockchain address, the number of public nodes can be determined. The number of public nodes can be randomly determined or input by the user. Based on the number of public nodes, a corresponding number of blockchain nodes (which may refer to consensus nodes) are selected from the blockchain network. Based on the node attributes of the selected blockchain nodes, an access structure for performing attribute encryption on the first blockchain address is generated, and the first blockchain address is then encrypted based on this access structure.
[0076] In some embodiments, resource transfer information may be obtained from block proposals. Alternatively, the client may receive user-inputted information related to resource transfer, which may include a first blockchain address (resource receiving address), a second blockchain address (resource sending address, selectable based on application scenario), and characteristic information of the transferred resource data. The client performs attribute encryption on the first blockchain address to obtain a first encrypted blockchain address, and generates resource transfer information based on the first encrypted blockchain address, the second blockchain address, and the characteristic information of the transferred resource data.
[0077] In one possible implementation, the resource transfer information can be transaction information constructed according to the requirements of a smart contract. For example, such as... Figure 3 As shown, the client obtains contract input parameter information, which may include the first blockchain address, the second blockchain address, and the characteristic information of the transferred resource data. The first blockchain address is encrypted using attribute-based encryption technology CP-ABE to obtain the first encrypted blockchain address. The first encrypted blockchain address, the second blockchain address, and the characteristic information of the transferred resource data are used as contract parameters, and transaction information is constructed based on the contract parameters. The constructed transaction information may include transaction identifier (TxID), contract name, contract method, contract parameters, number of public nodes (NodeSize), etc.
[0078] like Figure 3As shown, the client can send the generated resource transfer information to blockchain nodes in the blockchain network. The blockchain nodes can then save this resource transfer information to a database, such as a transaction pool. When it is necessary to process the resource transfer indicated by the information, the master node can retrieve the information from the database and generate a block proposal based on it. The master node can refer to the consensus node currently responsible for producing blocks (or generating block proposals).
[0079] For example, the structure of a block proposal could be as follows: Figure 4 As shown, Figure 4 The block proposal shown includes a block header and a block body. The block header includes: the block hash value, the block height, the transaction hash root, and, if empty, the read / write information hash root and the result hash root. The block body may include one or more transaction information, which may include the aforementioned resource transfer information, such as... Figure 4 The transaction information is 2 (Tx2). Other transaction information can be generated in the same way as the resource transfer information, or it can be generated directly based on the resource transfer address itself without encrypting the resource transfer address. Among them, the block hash value (GenBlockHash) in the block header can be a hash value determined based on the block height and the transaction hash root, and the transaction hash root can be a Merkle root determined based on the transaction information in the block body.
[0080] The master node broadcasts the block proposal to the consensus nodes in the blockchain network. After receiving the block proposal, the consensus nodes obtain the resource transfer information from the block proposal and execute the resource processing method provided in this application embodiment based on the resource transfer information.
[0081] 202. Decrypt the first encrypted blockchain address.
[0082] When a blockchain node's key (e.g., a private key) is associated with the node's attributes—for example, the key might be generated based on the node's attributes—the consensus node can use its key to decrypt the first encrypted blockchain address. If the node attributes corresponding to the consensus node's key are included in the set of attributes defined in the access structure that can successfully decrypt the first encrypted blockchain address, then the consensus node is a blockchain node that meets the attribute conditions, and its key can successfully decrypt the first encrypted blockchain address, thus obtaining the first blockchain address. Conversely, if not all of the node attributes corresponding to the consensus node's key are included in the attribute set, then the consensus node is a blockchain node that does not meet the attribute conditions, and its key cannot successfully decrypt the first encrypted blockchain address, thus failing to obtain the first blockchain address.
[0083] For example, the attribute set defined in the access structure that can successfully decrypt the first encrypted blockchain address includes the following node attributes: node type is consensus node, geographical location is city A or city B, and device type is server. The key for blockchain node 1 is generated based on the master key MK, public parameter P, and the node attributes of blockchain node 1 (node type is consensus node, geographical location is city A, device type is server). The key for blockchain node 2 is generated based on the master key MK, public parameter P, and the node attributes of blockchain node 2 (node type is consensus node, geographical location is city C, device type is server). Since the node attributes corresponding to the key of blockchain node 1 (node type is consensus node, geographical location is city A, device type is server) are all included in the above attribute set, blockchain node 1 can successfully decrypt the first encrypted blockchain address using its key. Since the node attribute corresponding to the key of blockchain node 2 includes the geographical location of city C, which does not meet the requirement of geographical location being city A or city B in the attribute set, blockchain node 2 cannot successfully decrypt the first encrypted blockchain address using its key.
[0084] It should be noted that if the first encrypted blockchain address is obtained by encrypting the first blockchain address using attribute-based encryption technology CP-ABE, the method of decrypting the first encrypted blockchain address using the key of the blockchain node can be found in the relevant content of the specific process of CP-ABE attribute encryption and decryption introduced above, and will not be repeated here.
[0085] If the first encrypted blockchain address is successfully decrypted, the first blockchain address can be obtained, and the resource transfer indicated by the resource transfer information can then be executed based on the first blockchain address, i.e., steps 203-205 are executed. If the first encrypted blockchain address fails to be decrypted, the first blockchain address cannot be obtained, and the resource transfer indicated by the resource transfer information cannot be executed. In this case, step 206 can be executed.
[0086] 203. If the first encrypted blockchain address is successfully decrypted, the decrypted first blockchain address is then encrypted to obtain the second encrypted blockchain address.
[0087] In this embodiment, upon successful decryption of the first encrypted blockchain address, the first blockchain address can be obtained. The decrypted first blockchain address can then be encrypted to obtain a second encrypted blockchain address, which may be different from the first encrypted blockchain address. The consensus node may encrypt the first blockchain address using its own configured encryption method. The resulting second encrypted blockchain address can typically only be decrypted by the consensus node itself to obtain the first blockchain address.
[0088] For example, a consensus node can use its public key to encrypt a first blockchain address, obtaining a second encrypted blockchain address. Only the consensus node's private key can then be used to decrypt the second encrypted blockchain address, revealing the first blockchain address. Alternatively, a consensus node can generate an access policy based on its node attributes, and then encrypt the attributes of the first blockchain address using this policy, generating a second encrypted blockchain address. Only the consensus node matches the set of attributes indicated by this access policy that can successfully decrypt the second encrypted blockchain address. Therefore, only the consensus node can successfully decrypt the second encrypted blockchain address, obtaining the first blockchain address.
[0089] 204. Determine the second encrypted resource data based on the first encrypted resource data and the transfer resource data indicated by the feature information under the recorded second encrypted blockchain address.
[0090] In this embodiment, when recording the first blockchain address and the resource data under the first blockchain address, the first blockchain address and the resource data under the first blockchain address are not directly associated and stored in the database. Instead, a second encrypted blockchain address obtained by encrypting the first blockchain address and encrypted data obtained by encrypting the resource data under the first blockchain address are associated and stored in the database. This enables privacy storage of the first blockchain address and the resource data under the first blockchain address, that is, privacy protection of business data related to resource transfer is achieved during the data storage stage.
[0091] When resource data needs to be transferred to the first blockchain address, the decrypted first blockchain address can be encrypted to obtain a second encrypted blockchain address. Based on the second encrypted blockchain address, the first encrypted resource data recorded under the second encrypted blockchain address is obtained. The resource data indicated by the first encrypted resource data is the original resource data recorded under the first blockchain address. Based on the first encrypted resource data and the transferred resource data indicated by the feature information (i.e., the feature information of the transferred resource data), the second encrypted resource data is determined. The resource data indicated by the second encrypted resource data is the latest resource data under the first blockchain address that needs to be recorded.
[0092] In some embodiments, determining the second encrypted resource data based on the first encrypted resource data and the transferred resource data indicated by the feature information can be achieved by: decrypting the first encrypted resource data to obtain the first resource data, which is the original resource data recorded under the first blockchain address; determining the second resource data based on the first resource data and the transferred resource data indicated by the feature information, which is the latest resource data to be recorded under the first blockchain address; and encrypting the second resource data to obtain the second encrypted resource data.
[0093] It should be noted that consensus nodes can use their own configured encryption and decryption methods to encrypt resource data. The encryption methods used to encrypt the first blockchain address and resource data can be the same or different.
[0094] 205. The second encrypted resource data and the second encrypted blockchain address are associated and stored together.
[0095] The second encrypted resource data and the second encrypted blockchain address can be associated and stored in a database, which can refer to the local database of the consensus node.
[0096] In some embodiments, storing the second encrypted resource data and the second encrypted blockchain address together may refer to updating the first encrypted resource data in the first encrypted resource data and the second encrypted blockchain address that were originally stored together with the second encrypted blockchain address to the second encrypted resource data.
[0097] For resource transfers such as evidence storage, which only require writing resource data to a blockchain address, the resource transfer is complete. However, for resource transfers such as electronic resource transfers, the process of transferring resource data from other blockchain addresses is also involved. In some embodiments, the resource transfer information also includes a second blockchain address (resource transfer address). If the first encrypted blockchain address is successfully decrypted, meaning the resource transfer can be executed, the third resource data recorded under the second blockchain address can be obtained. This third resource data is the original resource data recorded under the second blockchain address. Based on the third resource data and the transferred resource data indicated by the feature information, fourth resource data is determined. This fourth resource data is the latest resource data under the second blockchain address that needs to be recorded. The fourth resource data and the second blockchain address are then associated and stored. In one possible implementation, the fourth resource data and the second blockchain address can be associated and stored in a database, which may be the local database of the consensus node. Associating the fourth encrypted resource data and the second blockchain address can mean updating the third resource data in the originally associated second blockchain address and third resource data to the fourth resource data.
[0098] For example, resource transfer information indicates the need for electronic resource transfers, such as... Figure 5 As shown, the resource transfer information includes the resource transfer-out address Add1, the number of resources transferred (200), and the encrypted resource transfer-in address ABE(Add2). Add is short for Address. Add2 is the resource transfer-in address, and ABE(Add2) is the result of encrypting Add2's attributes. Figure 5The data originally recorded in the database of node A includes: "Add1, 1000", indicating that the original electronic resource quantity under address Add1 is 1000; "E(Add2), E(200)", indicating that the original electronic resource quantity under address Add2 is 200, and the address Add2 and the electronic resource quantity 200 are stored after encryption. After node A obtains the resource transfer information, it decrypts the encrypted resource transfer address ABE(Add2). If the decryption is successful, it obtains address Add2 and can execute the electronic resource transfer indicated by the resource transfer information. It transfers 200 electronic resources from address Add1, that is, subtracts 200 from the original 1000, leaving 800, and transfers 200 electronic resources to address Add2, that is, adds 200 to the original 200, becoming 400. After the electronic resource transfer, the data recorded in the database of node A is updated to: "Add1, 800", which means that the new electronic resource quantity under address Add1 is 800; "E(Add2), E(400)", which means that the new electronic resource quantity under address Add2 is 400, and the address Add2 and the electronic resource quantity 400 are stored after encryption.
[0099] 206. If decryption of the first encrypted blockchain address fails, a decryption error message will be returned.
[0100] Decryption error messages can be used to indicate failure to decrypt the first encrypted blockchain address, and / or to indicate that the resource transfer indicated by the resource transfer information could not be performed. Decryption error messages can be specific information such as "-1", "error", etc.
[0101] The above describes the method of resource transfer indicated by the resource transfer information. In some embodiments, where the resource transfer can be executed upon successful decryption of the first encrypted blockchain address, the resource processing method provided in this application may also include, but is not limited to, methods such as... Figure 6 The following steps are shown:
[0102] 601. Determine the first hash value of the first resource data, and generate first data reading information based on the first encrypted blockchain address and the first hash value.
[0103] As mentioned earlier, the first resource data can be the original resource data recorded under the first blockchain address, or it can be obtained by reading the first encrypted resource data under the second encrypted blockchain address (obtained by encrypting the first blockchain address) of the original record and then decrypting the first encrypted resource data. The first encrypted blockchain address is included in the resource transfer information. The first encrypted blockchain address is obtained by encrypting the attributes of the first blockchain address, and the first blockchain address is the blockchain address to which the resource data is transferred.
[0104] This can be achieved by performing a hash calculation on the first resource data to obtain the first hash value of the first resource data. For example, if the first resource data is 200 electronic resources, the first hash value would be Hash(200).
[0105] This can be achieved by combining a first encrypted blockchain address and a first hash value into a key-value pair. This key-value pair serves as the data retrieval information for the first blockchain address (the resource transfer address), i.e., the first data retrieval information. This data retrieval information can be used to indicate the resource data under the first blockchain address in the original record (or the record before the resource data transfer). A key-value pair is a data structure consisting of a key and a value. In this structure, the key is a unique identifier used to distinguish different values, while the value is the specific data associated with the key.
[0106] For example: If the first encrypted blockchain address is ABE(Add2) and the first hash value is Hash(200), we can use ABE(Add2) as the key and Hash(200) as the value to generate the key-value pair "ABE(Add2):Hash(200)". The key-value pair "ABE(Add2):Hash(200)" is the data reading information for the first blockchain address.
[0107] 602. Determine the second hash value based on the first blockchain address and the second resource data, and generate the first data writing information based on the first encrypted blockchain address and the second hash value.
[0108] As mentioned earlier, the second resource data can be the latest resource data under the first blockchain address that needs to be recorded. The second resource data can be determined based on the first resource data and the transferred resource data indicated by the feature information (feature information of the transferred resource data). The first blockchain address can be obtained after successfully decrypting the first encrypted blockchain address.
[0109] The second hash value can be obtained by hashing the first blockchain address and the second resource data. For example, if the first blockchain address is Add2 and the second resource data is 400 electronic resources, the second hash value would be Hash(Add2, 400). In other feasible implementations, the second hash value can also be obtained by hashing the second resource data. Similarly, the first hash value can be obtained by hashing the first blockchain address and the first resource data.
[0110] It can be that the first encrypted blockchain address and the second hash value are combined into a key-value pair, and this key-value pair is used as data writing information for the first blockchain address (i.e., the blockchain address where the resource data is transferred), that is, the first data writing information. This data writing information can be used to indicate the resource data under the first blockchain address of the latest record (or the record after the resource data is transferred).
[0111] For example, if the first encrypted blockchain address is ABE(Add2) and the second hash value is Hash(Add2, 400), we can use ABE(Add2) as the key and Hash(Add2, 400) as the value to generate the key-value pair "ABE(Add2): Hash(Add2, 400)". The key-value pair "ABE(Add2): Hash(Add2, 400)" is the data writing information for the first blockchain address.
[0112] 603. Determine the hash value of the first read / write information based on the first data read information and the first data write information.
[0113] The first read / write information hash value can be used to indicate the original resource data before the resource data was transferred to the first blockchain address, and the latest resource data after the resource data was transferred to the first blockchain address.
[0114] In some embodiments, the hash values of the first data read information and the first data write information can be directly calculated to obtain the hash value of the first read / write information. Alternatively, the hash value of the first read information and the first data write information can be calculated by summarizing the summarization results. For example, if the first data read information is "ABE(Add2):Hash(200)" and the first data write information is "ABE(Add2):Hash(Add2,400)", the two can be summarized as "ABE(Add2):(Hash(200),Hash(Add2,400))" and then the hash value can be calculated.
[0115] In other embodiments, the hash value of the first read / write information may be determined based on the first data read information, the first data write information, the second data read information, and the second data write information. The second data read information is generated based on the second blockchain address and the third resource data, and the second data write information is generated based on the second blockchain address and the fourth resource data.
[0116] As mentioned earlier, in application scenarios such as electronic resource transfer, resource transfer information may also include a second blockchain address, which is the blockchain address from which the resource data is transferred. The third resource data may be the original resource data recorded under the second blockchain address, and the fourth resource data may be the latest resource data under the second blockchain address that needs to be recorded. The fourth resource data may be determined based on the transferred resource data indicated by the third resource data and feature information.
[0117] In feasible implementations, the second blockchain address and the third resource data can be directly combined into a key-value pair, for example, "Add1: 1000"; or the hash value of the third resource data can be calculated, and the hash value of the second blockchain address and the third resource data can be combined into a key-value pair, for example, "Add1: Hash(1000)"; this key-value pair is used as data reading information for the second blockchain address (resource transfer address), i.e., second data reading information, which can be used to indicate the resource data under the second blockchain address of the original record (or the record before the resource data transfer). Similarly, the second blockchain address and the fourth resource data can be directly combined into a key-value pair, for example, "Add1: 800"; or the hash value of the fourth resource data can be calculated, and the hash value of the second blockchain address and the fourth resource data can be combined into a key-value pair, for example, "Add1: Hash(800)"; this key-value pair is used as data writing information for the second blockchain address, i.e., second data writing information, which can be used to indicate the resource data under the second blockchain address of the latest record (or the record after the resource data transfer). In this way, the hash value of the first read / write information can also be used to indicate the original resource data before the resource data was transferred to the second blockchain address, as well as the latest resource data after the resource data was transferred to the second blockchain address.
[0118] 604. Obtain the return result after the resource transfer indicated by the execution resource transfer information, and determine the first result hash value based on the return result.
[0119] After executing the resource transfer indicated by the resource transfer information, that is, after associating and storing the second encrypted resource data and the second encrypted blockchain address, and / or associating and storing the fourth resource data and the second blockchain address, data indicating the completion of the resource transfer can be returned; this data is the return result. For example, the return result can be the numerical value "1", the character "Accomplish", etc. The return result can also be generated based on the second resource data and / or the fourth resource data. For example, if the number of resources transferred to the resource receiving address is 400 and the number of resources transferred out of the resource sending address is 800, then the average of the two, 600, can be used as the return result.
[0120] You can perform a hash calculation on the returned result to obtain the first result hash value. For example, if the returned result is the average of 600 in the example above, you can determine Hash(600) as the first result hash value.
[0121] 605. Generate the first vote content corresponding to the resource transfer based on the hash value of the first read / write information and the hash value of the first result.
[0122] In some embodiments, the first voting content corresponding to the resource transfer can be generated directly based on the hash value of the first read / write information and the hash value of the first result. For example, the identifier of the resource transfer information can be used as the key, and the hash value of the first read / write information and the hash value of the first result can be used as the value to generate a key-value pair, which can then be used as the first voting content corresponding to the resource transfer indicated by the resource transfer information.
[0123] In other embodiments, the first voting content corresponding to the resource transfer may be generated based on the hash value of the first read / write information, the hash value of the first result, the data read / write information, and the return result. The data read / write information may include one or more of the aforementioned first data read information, first data write information, second data read information, and second data write information. For example, a first key-value pair may be generated by using the identifier of the resource transfer information as the key and the hash value of the first read / write information and the hash value of the first result as the value; a second key-value pair may be generated by using the identifier of the resource transfer information as the key and the first data read information, first data write information, second data read information, second data write information, and the return result as the value; and the first key-value pair and the second key-value pair may be used as the first voting content corresponding to the resource transfer indicated by the resource transfer information.
[0124] For example, such as Figure 7A As shown, Figure 7A The content contained within the dashed boxes shown in 701 and 702 is the first voting content. In the dashed box shown in 701, TxID2 is the identifier of the resource transfer information (or transaction identifier), TxRWSetHash2 is the hash value of the first read / write information, and TxResultHash2 is the hash value of the first result. In the dashed box shown in 702, TxID2 is the identifier of the resource transfer information, "ABE(Add2):Hash(200)" is the data read information for the first blockchain address (i.e., the first data read information), "ABE(Add2):Hash(Add2,400)" is the data write information for the first blockchain address (i.e., the first data write information), "Add1:1000" is the data read information for the second blockchain address (i.e., the second data read information), and "Add1:800" is the data write information for the second blockchain address (i.e., the second data write information).
[0125] 606. Broadcast the first vote to the consensus nodes in the blockchain network. The first vote is used by the consensus nodes to make voting decisions.
[0126] The first vote can be used by consensus nodes to make voting decisions. That is, consensus nodes can determine whether to approve the resource transfer executed for the resource transfer information based on the first vote.
[0127] In some embodiments, the first vote corresponding to the resource transfer information can be packaged together with the votes corresponding to other transaction information (or other resource transfer information) and broadcast to the consensus nodes in the blockchain network. For example... Figure 7A As shown, the broadcast content can include not only the voting content corresponding to TxID2, but also the voting content corresponding to TxID1, etc.
[0128] In some embodiments, when decryption of the first encrypted blockchain address fails, i.e., resource transfer cannot be performed, the resource processing method provided in this application embodiment may also include, but is not limited to, the following: Figure 8 The following steps are shown:
[0129] 801. Determine the hash value of the decryption error message and use it as the hash value of the second result.
[0130] As mentioned earlier, the decryption error message is the result returned when decryption of the first encrypted blockchain address fails. The hash value of the decryption error message can be calculated and used as the second result hash value. For example, if the decryption error message is "-1", then Hash(-1) can be determined as the second result hash value. The second result hash value can be used to indicate that decryption of the first encrypted blockchain address failed, and / or that the resource transfer indicated by the resource transfer message cannot be performed (or there is no permission).
[0131] 802. Determine the hash value of the setting information and use it as the hash value of the second read / write information.
[0132] Since decryption of the first encrypted blockchain address failed, the resource transfer indicated by the resource transfer information could not be executed. Therefore, there are no read / write operations for resource data on the first blockchain address (resource receiving address) and the second blockchain address (resource sending address). In this case, the hash value of the setting information can be used as the hash value of the second read / write information. The setting information can be an empty value or a character such as "0" or "nil". For example, if the decryption error message is "nil", Hash(nil) can be used as the second result hash value. The setting information and the hash value of the second read / write information can be used to indicate that data read / write information associated with the resource transfer could not be obtained.
[0133] 803. Based on the hash value of the second result and the hash value of the second read / write information, generate the second voting content corresponding to the resource transfer.
[0134] One approach is to use the identifier of the resource transfer information as the key, the hash value of the second read / write information and the hash value of the second result as the value, generate a key-value pair, and use this key-value pair as the second voting content corresponding to the resource transfer indicated by the resource transfer information.
[0135] For example, such as Figure 7B As shown, Figure 7B The content contained in the dashed box shown in Figure 703 is the second voting content. TxID2 in the dashed box shown in Figure 703 is the identifier of resource transfer information (or transaction identifier), Hash(nil) is the hash value of the second read / write information, and Hash(-1) is the hash value of the second result.
[0136] 804. Broadcast the second voting content to the consensus nodes in the blockchain network. The second voting content is used by the consensus nodes to make voting decisions.
[0137] The second voting content can be used by consensus nodes to make voting decisions. That is, consensus nodes can determine whether to approve the resource transfer executed for the resource transfer information based on the second voting content.
[0138] In some embodiments, the second vote corresponding to the resource transfer information can be packaged together with the votes corresponding to other transaction information (or other resource transfer information) and broadcast to the consensus nodes in the blockchain network. For example... Figure 7B As shown, the broadcast content can include not only the voting content corresponding to TxID2, but also the voting content corresponding to TxID1, etc.
[0139] In blockchain technology, resource transfer (or transaction) is typically implemented based on smart contracts. The resource processing method provided in this application, including resource transfer and other processing, can also be implemented based on smart contracts. To implement the resource processing method provided in this application, the capabilities of existing smart contracts have been extended, including adding (or modifying) some encryption-related capabilities on top of the capabilities provided by the existing contract SDK (Software Development Kit), as shown in Tables 1 and 2 below:
[0140] Table 1:
[0141]
[0142] Table 2:
[0143]
[0144] In some embodiments, the relevant steps of the resource processing method provided in this application embodiment can be implemented based on a capability-extended smart contract, which may include one or more of the following methods:
[0145] The GetOriginData function under the smart contract can be called to decrypt the first encrypted blockchain address. If decryption is successful, the first blockchain address will be returned; if decryption fails, a specific error message will be returned.
[0146] The GetLocalState function under the smart contract can be called to encrypt the decrypted first blockchain address to obtain a second encrypted blockchain address, retrieve the first encrypted resource data recorded under the second encrypted blockchain address from the database, decrypt the first encrypted resource data to obtain the first resource data, calculate the first hash value of the first resource data, and return the first resource data and the first hash value. After calling the GetLocalState function, first data reading information can be generated. The first data reading information can be a key-value pair with the first encrypted blockchain address as the key and the first hash value as the value.
[0147] Based on the first resource data and the transfer resource data indicated by the feature information (feature information of the transfer resource data), after determining the second resource data, the SetLocalState function under the smart contract can be called to encrypt the second resource data, obtaining the second encrypted resource data. The second encrypted resource data and the second encrypted blockchain address are then associated and stored in the database. After calling the GetLocalState function, first data write information can be generated. This first data write information can be a key-value pair with the first encrypted blockchain address as the key and the second hash value determined based on the first blockchain address and the second resource data as the value.
[0148] The GetState function under the smart contract can be called to retrieve the third resource data under the second blockchain address recorded in the database. After calling the GetState function, second data retrieval information can be generated. The first data retrieval information can be a key-value pair with the second blockchain address as the key and the third resource data or the hash value of the third resource data as the value.
[0149] Based on the transfer resource data indicated by the third resource data and the characteristic information (i.e., the characteristic information of the transfer resource data), after determining the fourth resource data, the SetState function under the smart contract can be called to associate and store the fourth resource data and the second blockchain address in the database. After calling the SetState function, second data write information can be generated. The second data write information can be a key-value pair with the second blockchain address as the key and the fourth resource data or the hash value of the fourth resource data as the value.
[0150] Based on capability-extended smart contracts, the above-mentioned steps of the resource processing method provided in this application embodiment are implemented. This allows for privacy protection of resource transfer-related business data (i.e., blockchain business data) at the smart contract level (or on-chain). For off-chain privacy processing of business data, the smart contracts of the blockchain system involve relatively few businesses, and most of the development work is done by the blockchain business system, increasing the development workload. Since the process information of the business data is not on-chain, a clear trust relationship exists, meaning off-chain behavior must be trusted, which contradicts the blockchain's support for trustless scenarios. Different businesses may involve different processing solutions, leading to a large number of solutions and high development workload and complexity if a blockchain system involves many businesses. These are important reasons why blockchain businesses are difficult to promote. However, this application embodiment completes the privacy processing of business data at the smart contract level (or on-chain), eliminating the need for complex business data privacy processing by the blockchain business system. This saves resources and reduces the development difficulty of the blockchain business system, significantly promoting its application and adoption.
[0151] To better understand how the capability-extended smart contract implements the embodiments of this application, the following explanation uses electronic resource transfer as an example. Assume the application scenario is: transferring electronic resources from a public account (or public blockchain address) to a specific account (or blockchain address). This public account and the electronic resources under it are public, but the account to which the electronic resources are transferred and the electronic resources under that account need to be kept confidential. The quantity of the transferred electronic resources is also public. Assume the public account is "from", the account to which the electronic resources are transferred is "to", ABE(to) is the result of encrypting the "to" attribute, and the quantity of the transferred electronic resources is "asset". The processing flow can be found in [reference needed]. Figure 9 ,like Figure 9 As shown, it may include the following steps:
[0152] The parameters obtained from the resource transfer information include: from, asset, and ABE(to). The GetOriginData function under the smart contract is called to decrypt ABE(to). If decryption fails, a specific error message is returned, which can be used by other nodes to determine if the error occurred during decryption. If decryption succeeds, the account "to" is obtained. The GetState function under the smart contract is called to obtain the electronic resource quantity afrom1 under the account "from". If afrom1 is less than asset, an error message indicating insufficient electronic resources in from is returned. If afrom1 is greater than or equal to asset, the GetLocalState function under the smart contract is called to encrypt "to" to obtain E(to). The data E(ato1) corresponding to the recorded E(to) is obtained, and E(ato1) is decrypted to obtain the electronic resource quantity atto1 under the account "to". A data read record "ABE(to): Hash(ato1)" can be generated, which can be used by other nodes to verify the intermediate data involved in the resource transfer process. Calculate afrom2 = afrom1 - asset, atto2 = atto1 + asset. The `SetState` function within the smart contract is called to save `afrom2` to the account "from". The `SetLocalState` function within the smart contract is then called to encrypt "ato2", obtaining `E(ato2)`. `E(ato2)` is saved to `E(to)`, and a data write record "ABE(to): Hash(to, ato2)" is generated. This data write record can be used by other nodes to verify the result. Thus, the electronic resource transfer is completed based on the smart contract. It should be noted that the steps in the above process, such as calculating `afrom2` and `ato2`, can also be completed by calling the smart contract.
[0153] The above describes the processing methods involved in resource transfer executed by consensus nodes. The consensus method for resource transfer will now be introduced. This consensus method can be executed by consensus nodes in the blockchain network. For example... Figure 10 As shown, consensus methods for resource transfer may include, but are not limited to, the following steps:
[0154] 1001. Obtain the voting content broadcast by consensus nodes in the blockchain network.
[0155] In this embodiment, the broadcast voting content is the voting content of the consensus nodes regarding the resource transfer information. The voting content can be generated using the method described above, which will not be repeated here. Specifically, the voting content broadcast by the first consensus node is the aforementioned first voting content, and the voting content broadcast by the second consensus node is the aforementioned second voting content. The first consensus node is a consensus node that can successfully (i.e., has the authority) decrypt the first encrypted blockchain address, meaning it can execute the resource transfer. The second consensus node is a consensus node that cannot successfully (i.e., does not have the authority) decrypt the first encrypted blockchain address, meaning it cannot execute the resource transfer.
[0156] As mentioned earlier, the first vote is generated based on the hash value of the first read / write information and the hash value of the first result, assuming successful decryption of the first encrypted blockchain address. The second vote is generated based on the hash value of the second read / write information and the hash value of the second result, assuming unsuccessful decryption of the first encrypted blockchain address.
[0157] 1002. When the first quantity of obtained voting content satisfies the first quantity condition, if there is a second voting content among the first quantity of obtained voting content, the voting result shall be determined according to the first voting content among the obtained voting content.
[0158] In some embodiments, the first quantity condition may be determined based on the total number of consensus nodes in the blockchain network. For example, the first quantity condition may be greater than or equal to half of the total number. In other embodiments, the first quantity condition may be determined based on the number of malicious nodes allowed by the Pbft consensus algorithm (i.e., a consensus algorithm based on Practical Byzantine Fault Tolerance). For example, if the number of malicious nodes is f, the first quantity condition may be greater than or equal to n*f+1, where n can be a value such as 2 or 3.
[0159] If the first quantity of obtained votes meets the first quantity condition, it is checked whether there is a second vote among the first quantity of obtained votes. If there is a second vote, it means that some consensus nodes cannot execute the resource transfer indicated by the resource transfer information, and only some consensus nodes have executed the resource transfer. At this time, the voting judgment result can be determined based on the first vote among the obtained votes, that is, whether to recognize the resource transfer executed by the consensus nodes in the blockchain network in response to the resource transfer information.
[0160] In some embodiments, determining the voting result based on the first voting content in the obtained voting content can be achieved by determining a second number of first consensus nodes with identical voting content based on the first voting content in the obtained voting content. For example, the first voting content includes a first read / write information hash value and a first result hash value. The maximum number of first voting contents containing the same first read / write information hash value and / or first result hash value can be determined, and this maximum number is the second number of first consensus nodes with identical voting content.
[0161] The second quantity condition is checked to see if it is satisfied. This second quantity condition can be determined based on the third quantity in the resource transfer information. The third quantity is the number of blockchain nodes that can successfully decrypt the first encrypted blockchain address, which is also the number of public nodes (NodeSize) mentioned earlier. For example, if the third quantity is M, the second quantity condition can be greater than M / 2. If the second quantity condition is satisfied, it indicates that among the first consensus nodes that can execute the resource transfer, a majority of consensus nodes agree on the execution of the resource transfer, and a voting approval result can be generated.
[0162] In some embodiments, a voting approval result may be generated based on the hash value of the first read / write information included in the first voting content and the hash value of the first result. The voting approval result may be used to instruct consensus nodes in the blockchain network to perform resource transfers.
[0163] In one possible implementation, the read / write information hash root can be determined based on the first read / write information hash value included in the first vote content, and the result hash root can be determined based on the first result hash value included in the first vote content; the block proposal hash value can be determined based on the read / write information hash root, the result hash root, and relevant information in the block proposal; and the voting approval result can be generated based on the block proposal hash value.
[0164] For example, resource transfer information is from Figure 4 The block proposal shown contains transaction information 2 (Tx2), and also includes transaction information 1 (Tx1). Among the consensus nodes that can execute transaction Tx2, after a majority of consensus nodes execute the transaction, the broadcast voting content for that transaction is... Figure 7A The dashed box shown in Figure 701 contains "TxID2 (transaction identifier), TxRWSetHash2 (first read / write information hash value), and TxResultHash2 (first result hash value)". After a consensus node in the blockchain network executes transaction Tx1, the majority of consensus nodes broadcast their votes for that transaction. Figure 7AThe symbols "TxID1, TxRWSetHash1, TxResultHash1" are shown in the diagram. After determining the voting content of transactions Tx1 and Tx2, the hash roots (which can be Merkle roots) of the hash values TxRWSetHash1 and TxRWSetHash2 can be calculated. These hash roots are the read / write information hash roots (TxRWSetRoot). Similarly, the hash roots (which can be Merkle roots) of the hash values TxResultHash1 and TxResultHash2 can be calculated. These hash roots are the result hash roots (TxResultRoot). The block proposal hash value BlockHash can be obtained by hashing the read / write information hash root TxRWSetRoot, the result hash root TxResultRoot, the block height (BlockHeight) in the block proposal, and the transaction hash root TxRoot. That is, BlockHash = Hash(BlockHeight, TxRoot, TxRWSetRoot, TxResultRoot). BlockHash can be directly used as the voting result, which can be used to instruct the consensus nodes in the blockchain network to execute transactions Tx1 and Tx2.
[0165] In some embodiments, the first vote may also include data read / write information and the return result after performing resource transfer. For example, such as... Figure 7A As shown, the first voting content also includes data read / write information and return results within the dashed box shown in Figure 702. If the consensus node fails to decrypt the first encrypted blockchain address, i.e., cannot execute the resource transfer, then when the second quantity meets the second quantity condition, it can obtain the data read / write information and return results included in the first voting content, and store (or update) the data read / write information and return results to the local database to ensure the consistency of the data read / write information and return results for the resource transfer record of the consensus node. It can also obtain the first encrypted blockchain address and the second hash value from the first data write information included in the data read / write information, and store the first encrypted blockchain address and the second hash value together. This allows for privacy storage of resource data under the first blockchain address (resource transfer address) even for consensus nodes that cannot execute resource transfers. Furthermore, it can obtain the second blockchain address and the fourth resource data from the second data write information included in the data read / write information. This allows for synchronized storage of resource data under the second blockchain address (resource transfer-out address) even for consensus nodes that do not have permission to execute resource transfers.
[0166] For example, such as Figure 3As shown, if node A can perform resource transfer while node B cannot, the final recorded data in node A's database will be "Add1: 800; E(Add2): E(400)", while the final recorded data in node B's database will be "Add1: 800; ABE(Add2): Hash(Add2, 400)".
[0167] In some embodiments, where the first voting content includes a first read / write information hash value, a first result hash value, data read / write information, and the return result after performing resource transfer, the first read / write information hash value and the first result hash value can be verified based on the data read / write information and the return result. If the verification passes, the voting result can be determined using the first voting content, including determining the second number of first consensus nodes with the same voting content, etc.; conversely, if the verification fails, the first voting content can be discarded. This ensures the authenticity of the voting content and the accuracy of the voting result.
[0168] In some embodiments, if the second quantity condition is not met, a vote of disapproval can be generated if the disapproval condition is determined to be met. For example, the disapproval condition could mean that the number of first consensus nodes with different voting content meets the second quantity condition. Meeting the disapproval condition indicates that among the first consensus nodes that can execute resource transfers, most consensus nodes are inconsistent in their execution of the resource transfer, and a vote of disapproval can be generated in this case. The vote of disapproval can be used to indicate disapproval of resource transfers executed by consensus nodes in the blockchain network. In feasible implementations, this could involve calculating the hash value of a specific character and using that hash value as the vote of disapproval result. For example, Hash(nil) could be used as the vote of disapproval result.
[0169] 1003. Broadcast the voting results to the consensus nodes in the blockchain network.
[0170] When a resource transfer executed by a consensus node in the blockchain network is approved, the voting result is broadcast in approval order; this result may be, for example, the block proposal hash value (BlockHash). When a resource transfer executed by a consensus node in the blockchain network is not approved, the voting result is broadcast in disapproval order; this result may be, for example, Hash(nil). The voting results broadcast by the consensus nodes can be used to determine the consensus outcome of the resource transfer.
[0171] 1004. Obtain the voting results of resource transfer broadcast by consensus nodes in the blockchain network.
[0172] Other consensus nodes in the blockchain network can also use the above method to determine the voting result based on the received voting content for resource transfer broadcast, and broadcast the voting result.
[0173] Consensus nodes can receive voting results on resource transfers broadcast by other consensus nodes in the blockchain network.
[0174] 1005. If the number of votes in the obtained voting results meets the third quantity condition, then the consensus result of the resource transfer is determined to be consensus passed.
[0175] In some embodiments, the third quantity condition may be determined based on the total number of consensus nodes in the blockchain network. For example, the third quantity condition may refer to two-thirds or more of the total number of nodes.
[0176] If the number of votes in the obtained voting results meets the third quantity condition, it indicates that most consensus nodes in the blockchain network approve the execution of the resource transfer, and the consensus result of the resource transfer can be considered as consensus passed.
[0177] 1006. Update the data of the block proposal to obtain the block to be added to the chain, and then add the block to the chain.
[0178] If the consensus result of the resource transfer is that the consensus is passed, the block proposal can be updated with data to obtain the block to be added to the chain, and the block to be added to the chain can be processed.
[0179] In some embodiments, the determined read / write information hash root (TxRWSetRoot) and result hash root (TxResultRoot) can be added to the corresponding positions in the block header of the block proposal, and the original block hash value (GenBlockHash) in the block proposal can be updated to the determined block proposal hash value BlockHash, thereby obtaining the block to be added to the blockchain, and saving the block to be added to the blockchain. This enables the notarization of relevant data involved in the execution of resource transfer.
[0180] In general, to ensure data privacy, nodes unable to execute resource transfers (or transactions) require two pieces of information: one is the data read / write information generated during the resource transfer process and the returned result after the transfer; the other is the hash value of the data read / write information and the hash value of the returned result. This data can be used by the node to determine the block proposal hash value, facilitating consensus voting on resource transfers.
[0181] The consensus mechanism provided in this application is an improvement on the Byzantine Fault Tolerance (BFT) approach, comprising three core phases: a proposal phase, a two-phase voting phase, and a three-phase voting phase. The transfer of resources will be referred to as a transaction below, illustrated with accompanying drawings. Figure 11 As shown, during the proposal phase, the master node retrieves sufficient transactions from the transaction pool, executes the transactions according to the transaction scheduling algorithm, generates a block proposal, and broadcasts the block proposal to the slave nodes. For example, a block proposal could be like this: Figure 4 The data structure shown.
[0182] For the proposal phase, the following two scenarios may occur due to differences in scheduling algorithms:
[0183] Nondeterministic scheduling algorithm: In this algorithm, the master node executes transactions, generating a transaction DAG (Directed Acyclic Graph, a widely used data structure in blockchain). Transactions that cannot be executed (returning specific error messages) can be placed at the end of the transaction DAG to prevent conflicts with other transactions.
[0184] Deterministic scheduling algorithm: In this algorithm, the master node does not need to execute transactions; it simply packages them. Slave nodes (i.e., consensus nodes other than the master node) will execute the transactions according to the same processing logic. For a specific transaction, regardless of whether it can be executed, it can be placed at the end of the entire transaction execution process to ensure consistency.
[0185] like Figure 11 As shown, in the second-phase voting, nodes execute the transactions in the block proposal according to the transaction rules to generate the second-phase voting content. For those following the... Figure 3 The specific transaction constructed as shown, that is, the transaction carries the result of attribute encryption of the resource transfer address based on node attributes, can be executed and the voting content for this specific transaction can be generated as described above. For a node that can execute this specific transaction, the final generated two-phase voting content can be as follows: Figure 7A As shown, 701 and 702 represent the voting content for this specific transaction. For nodes unable to execute this specific transaction, the final generated second-phase voting content could be as follows: Figure 7B As shown in Figure 703, the content displayed is the voting content for this specific transaction. For the master node, the voting content for this specific transaction can also be generated in the manner described above, and combined with the voting content of other transactions to generate the final two-stage voting content. For other blocks in the proposal that do not follow this method... Figure 3For a specific transaction constructed in the manner shown, such as a transaction where the resource transfer address is not encrypted, all consensus nodes can execute the transaction and generate the voting content for that transaction. The processing method differs from the embodiments in this application only in the encryption of the data involved; other processing logic is similar. The master node and slave nodes broadcast the generated two-stage voting content to other consensus nodes in the blockchain network.
[0186] like Figure 11 As shown, in the three-phase voting, the master node and slave nodes collect the second-phase voting content broadcast by the consensus nodes in the blockchain network. They then verify and aggregate the collected second-phase voting content to generate the third-phase voting content. The processing methods for the collected second-phase voting content may include, but are not limited to, methods such as... Figure 12 The following steps are shown:
[0187] Once a sufficient number of Phase 2 voting entries have been collected (e.g., greater than or equal to 2f+1, where f can be the number of malicious nodes allowed by consensus), the Phase 2 voting entries are aggregated and grouped by transaction, forming a Txs data structure: TxID->[TxRWSetHash (read / write information hash value), TxResultHash (result hash value)]. Voting is then performed on the voting entries of each transaction sequentially according to TxID. When voting on any transaction, the transaction TxID and its corresponding TxRWSetHash and TxResultHash sets are retrieved from Txs. The TxResultHash set is checked to see if it contains a specific value, which could be the hash value of the decryption error message returned when the transaction cannot be executed, for example... Figure 7B The Hash(-1) in the voting information shown.
[0188] If the TxResultHash set does not contain a specific value, it indicates that the transaction is public to all nodes, and all nodes can execute the transaction. In this case, the node's TxRWSetHash and TxResultHash can be obtained from the TxRWSetHash and TxResultHash sets. The node's TxRWSetHash is generated based on the data read / write information during transaction execution, and the TxResultHash is generated based on the return result after the transaction is completed. The number of nodes with the same TxRWSetHash and / or TxResultHash is checked to see if it meets a quantity condition. This condition could be, for example, greater than or equal to 2 / 3 of the total number of nodes, or greater than or equal to 2f+1. If the quantity condition is not met, further checks can be performed to determine if the condition is not met. For example, if the number of nodes with different TxRWSetHash and / or TxResultHash is greater than or equal to 1 / 2 of the total number of nodes, it can be determined that the condition is not met; otherwise, it cannot be determined that the condition is not met. If the condition cannot be determined as unsatisfactory, the loop can be exited, a timeout timer can be created, and if the timeout is triggered, the transaction can be re-evaluated through voting. If the number of nodes with the same TxRWSetHash and / or TxResultHash still does not meet the quantity requirement, a disapproval vote can be generated and broadcast. If the condition can be determined as unsatisfactory, the loop can be exited, a disapproval vote can be generated, and broadcast. Conversely, if the number of nodes with the same TxRWSetHash and / or TxResultHash meets the quantity requirement, the transaction verification is successful.
[0189] If the TxResultHash set contains a specific value, it indicates that the transaction is not public to all nodes; only some nodes executed the transaction. In this case, the original transaction information can be retrieved from memory, and the number of public nodes (NodeSize, i.e., the number of nodes that can execute the transaction) can be obtained. The TxRWSetHash and TxResultHash of the specific node are retrieved from the TxRWSetHash and TxResultHash sets. The specific node can refer to a node that can execute the transaction. The TxRWSetHash of the specific node is generated based on the data read / write information during transaction execution, and the TxResultHash is generated based on the return result after the transaction is completed. The number of specific nodes with the same TxRWSetHash and / or TxResultHash is checked to see if it satisfies more than half of NodeSize.
[0190] If the number of nodes does not meet more than half of NodeSize, further checks can be performed to determine if the condition is not met. For example, if the number of specific nodes with different TxRWSetHash and / or TxResultHash meets more than half of NodeSize, it can be determined as not meeting the condition; otherwise, it cannot be determined as not meeting the condition. If it cannot be determined as not meeting the condition, the loop can be exited, a timeout timer can be created, and if the timeout is triggered, the transaction can be re-evaluated through voting. If the number of specific nodes with the same TxRWSetHash and / or TxResultHash still does not meet more than half of NodeSize, a disapproval vote can be generated and broadcast. If the disapproval condition is met, the loop can be exited, a disapproval vote can be generated, and the vote can be broadcast.
[0191] If more than half of the NodeSize is reached, the transaction verification is successful. If the node itself is unable to execute the transaction, it can retrieve the transaction's data read / write information TxRWSet and the transaction's return result TxResult from the voting content, and update the information to the local database.
[0192] After all transactions have been processed and verified, the hash roots of all transactions' TxRWSetHash can be calculated to obtain the read / write information hash root TxRWSetRoot. The hash roots of all transactions' TxResultHash can also be calculated to obtain the result hash root TxResultRoot. These TxRWSetRoot and TxResultRoot are then inserted into the corresponding positions in the block header of the block proposal. The hash values of BlockHeight (block height), TxRoot (transaction root), TxRWSetRoot, and TxResultRoot in the block header of the block proposal are calculated to obtain the block proposal hash value BlockHash. The original block hash value (GenBlockHas) in the block proposal is then updated to the block proposal hash value BlockHash. This completes the data update of the block proposal, resulting in the block to be added to the chain. At this point, a vote of approval can be generated, and the content of this vote can be the BlockHash. The vote is then broadcast.
[0193] In the subsequent stage, master nodes and slave nodes can collect the three-stage voting content broadcast by consensus nodes in the blockchain network. If the number of approval votes in the obtained three-stage voting content meets the third quantity condition, such as being greater than or equal to two-thirds of the total number of nodes, then the consensus result of the transaction can be determined as consensus passed. At this time, the generated block to be added to the chain can be added to the chain.
[0194] This application provides a detailed description of a scenario involving attribute encryption of the resource transfer-in address (first blockchain address). In feasible embodiments, based on the processing concept of this application, attribute encryption can also be applied to one or more of the following: the resource transfer-in address (first blockchain address), the resource transfer-out address (second blockchain address), and the characteristic information of the transferred resource data. However, to ensure feasibility, the same attribute encryption method (including the same access structure, the same public parameter PK, etc.) should be used to process multiple pieces of information. This ensures that nodes meeting the attribute conditions can successfully decrypt the attribute-encrypted information, thereby enabling resource transfer.
[0195] For example, the resource transfer information generated by the client may include an attribute-encrypted resource transfer-out address, attribute-encrypted transfer resource characteristic information, and attribute-encrypted resource transfer-in address. When a resource transfer needs to be performed, these three attributes can be decrypted individually. If decryption fails, a decryption error message is returned, and the voting content for the consensus phase is generated based on the error message to complete the consensus. This process is similar to the previous one and will not be repeated here. If decryption is successful, the resource transfer-out address, transfer resource characteristic information, and resource transfer-in address can be obtained.
[0196] The system encrypts the resource transfer-out address and the resource transfer-in address using its own configured encryption method, resulting in encrypted resource transfer-out addresses and encrypted resource transfer-in addresses. Based on the original encrypted resource data under the recorded encrypted resource transfer-out address and the transferred resource data indicated by the transferred resource feature information, the system determines the new encrypted resource data under the resource transfer-out address and stores the encrypted resource transfer-out address and the new encrypted resource data together. Based on the original encrypted resource data under the recorded encrypted resource transfer-in address and the transferred resource data indicated by the transferred resource feature information, the system determines the new encrypted resource data under the resource transfer-in address and stores the encrypted resource transfer-in address and the new encrypted resource data together.
[0197] Data read / write information can be generated for the resource transfer-out address. For example, the data read information is "ABE(Add1): Hash(1000)", and after transferring out 200 electronic resources, the data write information is "ABE(Add1): Hash(Add1, 800)". Data read / write information can also be generated for the resource transfer-in address. For example, the data read information is "ABE(Add2): Hash(200)", and after transferring in 200 electronic resources, the data write information is "ABE(Add2): Hash(Add2, 400)". Based on the above data read / write information, the voting content and voting results for the consensus phase can be generated to complete the consensus. This process is similar to the previous one and will not be repeated here. Finally, for nodes that successfully decrypt, the final recorded data is, for example, “E(Add1):E(800)” and “E(Add2):E(400)”; while for nodes that fail to decrypt, the final recorded data is, for example, “ABE(Add1):Hash(Add1,800)” and “ABE(Add2):Hash(Add2,400)”.
[0198] It should be noted that the execution entity used to implement each step in the above method embodiments can be hardware, software, or a combination of hardware and software.
[0199] The methods of the embodiments of this application have been described in detail above. In order to facilitate better implementation of the above solutions of the embodiments of this application, the apparatus of the embodiments of this application is provided below.
[0200] Please see Figure 13 , Figure 13 This is a schematic diagram of the structure of a blockchain-based resource processing device provided in an embodiment of this application. The blockchain-based resource processing device can be installed in the computer equipment provided in the embodiment of this application, and the computer equipment can be a consensus node in the blockchain network. Figure 13 The blockchain-based resource processing device shown can be a computer program running on a computer device, which can be used to execute... Figure 2 , Figure 6 , Figures 8-12 Some or all of the steps in the method embodiments shown. Please refer to [link / reference]. Figure 13 The blockchain-based resource processing device may include, but is not limited to, an acquisition unit 1301, a processing unit 1302, a storage unit 1303, and a transceiver unit 1304, wherein:
[0201] The acquisition unit 1301 is used to acquire resource transfer information, which includes a first encrypted blockchain address and characteristic information of the transferred resource data. The first encrypted blockchain address is obtained by encrypting the first blockchain address with attributes. Blockchain nodes that meet the attribute conditions can successfully decrypt the first encrypted blockchain address. The first blockchain address is the blockchain address where the resource data is transferred.
[0202] Processing unit 1302 is used to decrypt the first encrypted blockchain address;
[0203] The processing unit 1302 is further configured to, if the first encrypted blockchain address is successfully decrypted, encrypt the decrypted first blockchain address to obtain a second encrypted blockchain address;
[0204] Processing unit 1302 is further configured to determine the second encrypted resource data based on the first encrypted resource data recorded under the second encrypted blockchain address and the transfer resource data indicated by the feature information;
[0205] Storage unit 1303 is used to associate and store the second encrypted resource data and the second encrypted blockchain address.
[0206] In some embodiments, when the processing unit 1302 determines the second encrypted resource data based on the first encrypted resource data recorded under the second encrypted blockchain address and the transfer resource data indicated by the feature information, it may be configured to: obtain the first encrypted resource data recorded under the second encrypted blockchain address; decrypt the first encrypted resource data to obtain the first resource data; determine the second resource data based on the first resource data and the transfer resource data indicated by the feature information; and encrypt the second resource data to obtain the second encrypted resource data.
[0207] In some embodiments, the processing unit 1302 may further be used to: determine a first hash value of the first resource data, generate first data read information based on the first encrypted blockchain address and the first hash value; determine a second hash value based on the first blockchain address and the second resource data, and generate first data write information based on the first encrypted blockchain address and the second hash value.
[0208] In some embodiments, the processing unit 1302 may further be configured to: determine a first read / write information hash value based on the first data read information and the first data write information; obtain a return result after executing the resource transfer indicated by the resource transfer information, and determine a first result hash value based on the return result; and generate a first vote content for the resource transfer based on the first read / write information hash value and the first result hash value.
[0209] The transceiver unit 1304 can be used to broadcast the first voting content to the consensus nodes in the blockchain network, and the first voting content is used by the consensus nodes to make voting decisions.
[0210] In some embodiments, the resource transfer information further includes a second blockchain address, which is the blockchain address from which the resource data was transferred.
[0211] Processing unit 1302 can also be used to: acquire the third resource data recorded under the second blockchain address; and determine the fourth resource data based on the third resource data and the transfer resource data indicated by the feature information.
[0212] Storage unit 1303 can also be used to associate and store the fourth resource data and the second blockchain address.
[0213] In some embodiments, when the processing unit 1302 determines the first read / write information hash value based on the first data read information and the first data write information, it may be used to: determine the first read / write information hash value based on the first data read information, the first data write information, the second data read information, and the second data write information; wherein the second data read information is generated based on the second blockchain address and the third resource data, and the second data write information is generated based on the second blockchain address and the fourth resource data.
[0214] In some embodiments, when the processing unit 1302 generates the first voting content corresponding to the resource transfer based on the first read / write information hash value and the first result hash value, it may be used to: generate the first voting content corresponding to the resource transfer based on the first read / write information hash value, the first result hash value, data read / write information, and the returned result; wherein, the data read / write information includes one or more of the first data read information, the first data write information, the second data read information, and the second data write information.
[0215] In some embodiments, the processing unit 1302 may further be used to: return decryption error information if decryption of the first encrypted blockchain address fails; determine the hash value of the decryption error information and determine the hash value of the decryption error information as a second result hash value; determine the hash value of the setting information and determine the hash value of the setting information as a second read / write information hash value; and generate the second voting content of the resource transfer based on the second result hash value and the second read / write information hash value.
[0216] The transceiver unit 1304 can also be used to broadcast the second voting content to the consensus nodes in the blockchain network, and the second voting content is used by the consensus nodes to make voting decisions.
[0217] In some embodiments, the transceiver unit 1304 can also be used to obtain voting content broadcast by consensus nodes in the blockchain network; wherein the broadcast voting content is the voting content for the resource transfer indicated by the resource transfer information; the voting content broadcast by the first consensus node is the first voting content, and the voting content broadcast by the second consensus node is the second voting content; the first consensus node is a consensus node that can successfully decrypt the first encrypted blockchain address, and the second consensus node is a consensus node that cannot successfully decrypt the first encrypted blockchain address;
[0218] The processing unit 1302 can also be used to determine the voting result based on the first voting content in the first number of voting contents when the first number of obtained voting contents meets the first number condition. If the second voting content exists in the first number of obtained voting contents, the processing unit 1302 can also be used to determine the voting result based on the first voting content in the obtained voting contents.
[0219] The transceiver unit 1304 can also be used to broadcast the voting determination result to the consensus nodes in the blockchain network, and the voting determination result is used to determine the consensus result of the resource transfer.
[0220] In some embodiments, when the processing unit 1302 determines the voting result based on the first voting content in the obtained voting content, it may be used to: determine a second number of first consensus nodes with the same voting content based on the first voting content in the obtained voting content; if the second number satisfies the second number condition, generate a voting approval result based on the first read / write information hash value and the first result hash value included in the first voting content; wherein, the second number condition is determined based on the third number in the resource transfer information, and the third number is the number of blockchain nodes that can successfully decrypt the first encrypted blockchain address.
[0221] In some embodiments, when the processing unit 1302 generates a voting approval result based on the first read / write information hash value and the first result hash value included in the first voting content, it may be configured to: determine a read / write information hash root based on the first read / write information hash value included in the first voting content; determine a result hash root based on the first result hash value included in the first voting content; determine a block proposal hash value based on the read / write information hash root, the result hash root, and relevant information in the block proposal; the resource transfer information is obtained from the block proposal; and generate a voting approval result based on the block proposal hash value.
[0222] In some embodiments, the processing unit 1302 may also be used to: when decryption of the first encrypted blockchain address fails and the second quantity meets the second quantity condition, obtain the data read / write information included in the first voting content and the return result after performing the resource transfer; and obtain the first encrypted blockchain address and the second hash value from the first data write information included in the data read / write information.
[0223] Storage unit 1303 can also be used to store the data read / write information and the return result, and to associate the first encrypted blockchain address and the second hash value.
[0224] In some embodiments, the transceiver unit 1304 can also be used to obtain the voting determination result of the resource transfer broadcast by the consensus node in the blockchain network;
[0225] The processing unit 1302 can also be used to determine the consensus result of the resource transfer as consensus passed if the number of votes in the obtained voting judgment results meets the third quantity condition.
[0226] According to another embodiment of this application, Figure 13 The units in the blockchain-based resource processing device shown can be individually or entirely merged into one or more other units, or some of the units can be further divided into multiple functionally smaller units. This achieves the same operation without affecting the technical effects of the embodiments of this application. The above units are based on logical function division. In practical applications, the function of one unit can be implemented by multiple units, or the function of multiple units can be implemented by one unit. In other embodiments of this application, the blockchain-based resource processing device may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented collaboratively by multiple units.
[0227] According to another embodiment of this application, the following can be achieved by running on a general-purpose computing device, such as a computer, which includes processing elements and storage elements such as a central processing unit (CPU), random access memory (RAM), and read-only memory (ROM), a device capable of performing operations such as... Figure 2 , Figure 6 , Figures 8-12 Computer programs for the steps involved in some or all of the methods shown, to construct, for example... Figure 13 The diagram illustrates a blockchain-based resource processing apparatus and a method for implementing the blockchain-based resource processing provided in the embodiments of this application. A computer program may be recorded on, for example, a computer-readable storage medium, loaded onto the aforementioned computing device via the computer-readable storage medium, and executed therein.
[0228] According to another embodiment of this application, the blockchain-based resource processing device provided in this application embodiment can be implemented in software. The blockchain-based data processing device can be stored in a memory, which can be software in the form of programs and plug-ins.
[0229] According to another embodiment of this application, the blockchain-based resource processing device provided in this application embodiment can also be implemented in a combination of hardware and software. As an example, the resource processing device provided in this application embodiment can be a processor in the form of a hardware decoding processor, which is programmed to execute the blockchain-based resource processing method provided in this application embodiment. For example, the processor in the form of a hardware decoding processor can adopt one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.
[0230] Based on the above methods and apparatus embodiments, this application provides a computer device. Please refer to... Figure 14 , Figure 14 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 14 The computer device shown may include a processor 1401, an input interface 1402, an output interface 1403, and a computer-readable storage medium 1404. The processor 1401, input interface 1402, output interface 1403, and computer-readable storage medium 1404 may be connected via a bus or other means.
[0231] The computer-readable storage medium 1404 can be stored in the memory of a computer device. The computer-readable storage medium 1404 is used to store computer programs, which include computer instructions. The processor 1401 is used to execute the computer program stored in the computer-readable storage medium 1404. The processor 1401 (or CPU (Central Processing Unit)) is the computing and control core of the computer device. It is suitable for implementing computer programs, specifically for loading and executing computer programs to achieve corresponding methods or functions.
[0232] This application also provides a computer-readable storage medium (Memory), which is a memory device in a computer device used to store programs and data. It is understood that the computer-readable storage medium here can include both built-in storage media in the computer device and extended storage media supported by the computer device. The computer-readable storage medium provides storage space for storing the operating system of the computer device. Furthermore, the storage space also stores computer programs suitable for loading and execution by a processor. It should be noted that the computer-readable storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device; optionally, it can also be at least one computer-readable storage medium located remotely from the aforementioned processor.
[0233] In one embodiment, the computer device may be a consensus node in a blockchain network. Specifically, the processor 1401 may load and execute the computer program stored in the computer-readable storage medium 1404 to implement the aforementioned... Figure 2 , Figure 6 , Figures 8-12 The corresponding steps in the blockchain-based resource processing method are shown. Specifically, the computer program in the computer-readable storage medium 1404 can be loaded and executed by the processor 1401 as follows:
[0234] Obtain resource transfer information, which includes a first encrypted blockchain address and characteristic information of the transferred resource data. The first encrypted blockchain address is obtained by encrypting a first blockchain address with attributes. A blockchain node that meets the attribute conditions can successfully decrypt the first encrypted blockchain address. The first blockchain address is the blockchain address to which the resource data is transferred. Decrypt the first encrypted blockchain address. If the first encrypted blockchain address is successfully decrypted, encrypt the decrypted first blockchain address to obtain a second encrypted blockchain address. Determine the second encrypted resource data based on the first encrypted resource data under the recorded second encrypted blockchain address and the transferred resource data indicated by the characteristic information. Store the second encrypted resource data and the second encrypted blockchain address together.
[0235] In some embodiments, when determining the second encrypted resource data based on the first encrypted resource data under the recorded second encrypted blockchain address and the transfer resource data indicated by the feature information, a computer program in the computer-readable storage medium 1404 can be loaded by the processor 1401 and execute the following steps: obtaining the first encrypted resource data under the recorded second encrypted blockchain address; decrypting the first encrypted resource data to obtain the first resource data; determining the second resource data based on the first resource data and the transfer resource data indicated by the feature information; and encrypting the second resource data to obtain the second encrypted resource data.
[0236] In some embodiments, a computer program in a computer-readable storage medium 1404 may be loaded by a processor 1401 and execute the following steps: determining a first hash value of the first resource data, generating first data read information based on the first encrypted blockchain address and the first hash value; determining a second hash value based on the first blockchain address and the second resource data, and generating first data write information based on the first encrypted blockchain address and the second hash value.
[0237] In some embodiments, the computer program in the computer-readable storage medium 1404 may be loaded by the processor 1401 and execute the following steps: determining a first read / write information hash value based on the first data read information and the first data write information; obtaining the return result after executing the resource transfer indicated by the resource transfer information, and determining a first result hash value based on the return result; generating a first vote content for the resource transfer based on the first read / write information hash value and the first result hash value; broadcasting the first vote content to consensus nodes in the blockchain network, wherein the first vote content is used by the consensus nodes to make voting decisions.
[0238] In some embodiments, the resource transfer information further includes a second blockchain address, which is the blockchain address from which the resource data is transferred. The computer program in the computer-readable storage medium 1404 can be loaded by the processor 1401 and execute the following steps: obtaining the third resource data recorded under the second blockchain address; determining the fourth resource data based on the third resource data and the transferred resource data indicated by the feature information; and storing the fourth resource data and the second blockchain address together.
[0239] In some embodiments, when determining the first read / write information hash value based on the first data read information and the first data write information, the computer program in the computer-readable storage medium 1404 can be loaded by the processor 1401 and execute the following steps: determining the first read / write information hash value based on the first data read information, the first data write information, the second data read information, and the second data write information; wherein the second data read information is generated based on the second blockchain address and the third resource data, and the second data write information is generated based on the second blockchain address and the fourth resource data.
[0240] In some embodiments, when generating the first voting content corresponding to the resource transfer based on the first read / write information hash value and the first result hash value, the computer program in the computer-readable storage medium 1404 may be loaded by the processor 1401 and execute the following steps: generating the first voting content corresponding to the resource transfer based on the first read / write information hash value, the first result hash value, data read / write information, and the return result; wherein, the data read / write information includes one or more of the first data read information, the first data write information, the second data read information, and the second data write information.
[0241] In some embodiments, the computer program in the computer-readable storage medium 1404 may be loaded by the processor 1401 and execute the following steps: if decryption of the first encrypted blockchain address fails, return a decryption error message; determine the hash value of the decryption error message and determine the hash value of the decryption error message as a second result hash value; determine the hash value of the setting information and determine the hash value of the setting information as a second read / write information hash value; generate a second voting content for the resource transfer based on the second result hash value and the second read / write information hash value; broadcast the second voting content to the consensus nodes in the blockchain network, the second voting content being used by the consensus nodes for voting determination.
[0242] In some embodiments, a computer program in computer-readable storage medium 1404 may be loaded by processor 1401 and execute the following steps: obtaining voting content broadcast by consensus nodes in the blockchain network; wherein the broadcast voting content is voting content for the resource transfer indicated by the resource transfer information; the voting content broadcast by the first consensus node is first voting content, and the voting content broadcast by the second consensus node is second voting content; the first consensus node is a consensus node that can successfully decrypt the first encrypted blockchain address, and the second consensus node is a consensus node that cannot successfully decrypt the first encrypted blockchain address; when the first number of obtained voting content satisfies the first number condition, if the second voting content exists in the first number of obtained voting content, then a voting determination result is determined based on the first voting content in the obtained voting content; broadcasting the voting determination result to the consensus nodes in the blockchain network, the voting determination result being used to determine the consensus result of the resource transfer.
[0243] In some embodiments, when determining the voting result based on the first voting content in the obtained voting content, the computer program in the computer-readable storage medium 1404 can be loaded by the processor 1401 and execute the following steps: determining a second number of first consensus nodes with the same voting content based on the first voting content in the obtained voting content; if the second number satisfies the second number condition, generating a voting approval result based on the first read / write information hash value and the first result hash value included in the first voting content; wherein, the second number condition is determined based on a third number in the resource transfer information, the third number being the number of blockchain nodes that can successfully decrypt the first encrypted blockchain address.
[0244] In some embodiments, when generating a voting approval result based on the first read / write information hash value and the first result hash value included in the first voting content, the computer program in the computer-readable storage medium 1404 may be loaded by the processor 1401 and execute the following steps: determining a read / write information hash root based on the first read / write information hash value included in the first voting content; determining a result hash root based on the first result hash value included in the first voting content; determining a block proposal hash value based on the read / write information hash root, the result hash root, and relevant information in the block proposal; the resource transfer information is obtained from the block proposal; and generating a voting approval result based on the block proposal hash value.
[0245] In some embodiments, a computer program in computer-readable storage medium 1404 may be loaded by processor 1401 and execute the following steps: when decryption of the first encrypted blockchain address fails and the second quantity meets the second quantity condition, obtain data read / write information included in the first voting content and the return result after performing the resource transfer; obtain the first encrypted blockchain address and the second hash value from the first data write information included in the data read / write information; store the data read / write information and the return result, and associate the first encrypted blockchain address and the second hash value.
[0246] In some embodiments, the computer program in the computer-readable storage medium 1404 may be loaded by the processor 1401 and execute the following steps: obtaining the voting determination result of the resource transfer broadcast by the consensus node in the blockchain network; if the number of votes in the obtained voting determination result meets a third quantity condition, then the consensus result of the resource transfer is determined to be consensus passed.
[0247] According to another embodiment of this application, the input interface 1402 and output interface 1403 included in the computer device provided in this application embodiment are optional. The input interface 1402 and output interface 1403 can be user interfaces, and the user interface 502 is a medium for realizing interaction and information exchange between the user and the computer device. The computer device provided in this application embodiment may also include a communication interface, which may optionally include a standard wired interface or a wireless interface (such as Wi-Fi, mobile communication interface, etc.), and is controlled by the processor for sending and receiving data.
[0248] This application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the blockchain-based resource processing method provided in this application. Specific implementation details can be found in the preceding descriptions and will not be repeated here.
[0249] It should be noted that the collection and processing of relevant data in this application embodiment should strictly comply with the requirements of relevant laws and regulations, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the personal information subject.
[0250] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0251] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.
[0252] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0253] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A resource processing method based on blockchain, characterized in that, The method includes: Obtain resource transfer information, which includes a first encrypted blockchain address and characteristic information of the transferred resource data; the first encrypted blockchain address is obtained by encrypting the first blockchain address with attributes, and a blockchain node that meets the attribute conditions can successfully decrypt the first encrypted blockchain address; the first blockchain address is the blockchain address where the resource data is transferred. Decrypt the first encrypted blockchain address; If the first encrypted blockchain address is successfully decrypted, the decrypted first blockchain address is then encrypted to obtain the second encrypted blockchain address; The second encrypted resource data is determined based on the first encrypted resource data recorded under the second encrypted blockchain address and the transfer resource data indicated by the feature information; The second encrypted resource data and the second encrypted blockchain address are stored together.
2. The method as described in claim 1, characterized in that, The step of determining the second encrypted resource data based on the first encrypted resource data under the recorded second encrypted blockchain address and the transfer resource data indicated by the feature information includes: Obtain the first encrypted resource data under the recorded second encrypted blockchain address, decrypt the first encrypted resource data, and obtain the first resource data; Based on the first resource data and the transferred resource data indicated by the feature information, determine the second resource data; The second resource data is encrypted to obtain the second encrypted resource data.
3. The method as described in claim 2, characterized in that, The method further includes: Determine the first hash value of the first resource data, and generate first data reading information based on the first encrypted blockchain address and the first hash value; A second hash value is determined based on the first blockchain address and the second resource data, and a first data write information is generated based on the first encrypted blockchain address and the second hash value.
4. The method as described in claim 3, characterized in that, The method further includes: The hash value of the first read / write information is determined based on the first data read information and the first data write information; Obtain the return result after executing the resource transfer information indicated by the resource transfer, and determine the first result hash value based on the return result; The first voting content for the resource transfer is generated based on the hash value of the first read / write information and the hash value of the first result; The first vote content is broadcast to the consensus nodes in the blockchain network, and the first vote content is used by the consensus nodes to make voting decisions.
5. The method according to any one of claims 1-4, characterized in that, The resource transfer information also includes a second blockchain address, which is the blockchain address from which the resource data was transferred. The method further includes: Retrieve the third resource data under the recorded second blockchain address; Based on the third resource data and the transferred resource data indicated by the feature information, the fourth resource data is determined; The fourth resource data and the second blockchain address are associated and stored.
6. The method as described in claim 4, characterized in that, The step of determining the hash value of the first read / write information based on the first data read information and the first data write information includes: Based on the first data read information, the first data write information, the second data read information, and the second data write information, determine the hash value of the first read / write information; The second data reading information is generated based on the second blockchain address and the third resource data, and the second data writing information is generated based on the second blockchain address and the fourth resource data.
7. The method as described in claim 4 or 6, characterized in that, The step of generating the first vote content corresponding to the resource transfer based on the first read / write information hash value and the first result hash value includes: Based on the first read / write information hash value, the first result hash value, the data read / write information, and the returned result, generate the first vote content corresponding to the resource transfer; The data read / write information includes one or more of the first data read information, the first data write information, the second data read information, and the second data write information.
8. The method as described in claim 1, characterized in that, The method further includes: If decryption of the first encrypted blockchain address fails, a decryption error message will be returned; Determine the hash value of the decryption error message, and use the hash value of the decryption error message as the second result hash value; Determine the hash value of the setting information, and use the hash value of the setting information as the hash value of the second read / write information; Based on the hash value of the second result and the hash value of the second read / write information, the second voting content for the resource transfer is generated; The second voting content is broadcast to the consensus nodes in the blockchain network, and the second voting content is used by the consensus nodes to make voting decisions.
9. The method according to any one of claims 1-4 or 8, characterized in that, The method further includes: Obtain the voting content broadcast by consensus nodes in the blockchain network; wherein the broadcast voting content is the voting content for the resource transfer indicated by the resource transfer information; the voting content broadcast by the first consensus node is the first voting content, and the voting content broadcast by the second consensus node is the second voting content; the first consensus node is a consensus node that can successfully decrypt the first encrypted blockchain address, and the second consensus node is a consensus node that cannot successfully decrypt the first encrypted blockchain address; When the first quantity of obtained voting content meets the first quantity condition, if the second voting content exists in the first quantity of obtained voting content, the voting result is determined based on the first voting content in the obtained voting content. The voting result is broadcast to the consensus nodes in the blockchain network, and the voting result is used to determine the consensus result of the resource transfer.
10. The method as described in claim 9, characterized in that, The step of determining the voting result based on the first voting content in the obtained voting content includes: Based on the first voting content obtained from the voting content, determine the second number of first consensus nodes with the same voting content; If the second quantity satisfies the second quantity condition, a voting approval result is generated based on the first read / write information hash value and the first result hash value included in the first voting content; wherein, the second quantity condition is determined based on the third quantity in the resource transfer information, and the third quantity is the number of blockchain nodes that can successfully decrypt the first encrypted blockchain address.
11. The method as described in claim 10, characterized in that, The step of generating a voting approval result based on the hash value of the first read / write information and the hash value of the first result included in the first voting content includes: The read / write information hash root is determined based on the first read / write information hash value included in the first vote content, and the result hash root is determined based on the first result hash value included in the first vote content; The block proposal hash value is determined based on the read / write information hash root, the result hash root, and relevant information in the block proposal; the resource transfer information is obtained from the block proposal. A voting approval result is generated based on the block proposal hash value.
12. The method as described in claim 10, characterized in that, The method further includes: If decryption of the first encrypted blockchain address fails and the second quantity meets the second quantity condition, obtain the data read / write information included in the first vote content and the return result after executing the resource transfer; The first encrypted blockchain address and the second hash value are obtained from the first data write information included in the data read and write information; The data read / write information and the returned results are stored, and the first encrypted blockchain address and the second hash value are associated and stored.
13. The method as described in claim 9, characterized in that, The method further includes: Obtain the voting results of the resource transfer broadcast by the consensus nodes in the blockchain network; If the number of votes in the obtained voting results meets the third quantity condition, then the consensus result of the resource transfer is determined to be consensus passed.
14. A blockchain-based resource processing device, characterized in that, The device includes: The acquisition unit is used to acquire resource transfer information, which includes a first encrypted blockchain address and characteristic information of the transferred resource data. The first encrypted blockchain address is obtained by encrypting the first blockchain address with attributes. Blockchain nodes that meet the attribute conditions can successfully decrypt the first encrypted blockchain address. The first blockchain address is the blockchain address where the resource data is transferred. A processing unit is used to decrypt the first encrypted blockchain address; The processing unit is further configured to, if the first encrypted blockchain address is successfully decrypted, encrypt the decrypted first blockchain address to obtain a second encrypted blockchain address; The processing unit is further configured to determine the second encrypted resource data based on the first encrypted resource data recorded under the second encrypted blockchain address and the transfer resource data indicated by the feature information; A storage unit is used to associate and store the second encrypted resource data and the second encrypted blockchain address.
15. A computer device, characterized in that, The computer device includes: A processor is a tool for implementing computer programs. A computer-readable storage medium storing a computer program adapted to be loaded by the processor and to implement the blockchain-based resource processing method as described in any one of claims 1-13.