Code property rights management system based on cloud smart contract compilation
Through cloud smart contracts and distributed storage technology, the problem of code property rights protection during the circulation and use of software products is solved, and the secure storage and efficient compilation of code property rights data is realized, ensuring the security and integrity of the code, and improving the transparency and traceability of transactions.
Patent Information
- Application Number
- PCT/CN2024/075146
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-27
- Filing Date
- 2024-02-01
- Publication Date
- 2025-07-03
AI Technical Summary
The existing technology is difficult to effectively protect the code property rights during the transfer and use of software products, and the code is prone to leakage and abuse.
The code property management system based on cloud smart contracts is adopted, and the authorized storage subsystem and software compilation subsystem deployed on the cloud is used to encrypt and manage private key decryption of code projects, and combine interstellar file system and blockchain storage to achieve secure storage and efficient compilation of code property data.
It improves the security and integrity of code property data during the circulation and use process, avoids code leakage and abuse, and realizes efficient automated construction of software products and transparent traceable transaction records.
Smart Images

Figure CN2024075146_03072025_PF_FP_ABST
Abstract
Description
A code property management system based on cloud smart contract compilation Technical Field
[0001] The present application relates to the field of distributed technology, and in particular to a code property management system based on cloud smart contract compilation. Background Art
[0002] With the development of internet technology, software product innovation and transactions are becoming increasingly frequent. As the core asset of software products, the protection and management of software code's intellectual property rights have become a critical issue. Traditionally, due to the reproducibility of software code during its circulation and use, it is prone to leaks, making it difficult to effectively protect code intellectual property rights. Therefore, effectively protecting software code intellectual property rights during its use is a pressing challenge. Technical issues
[0003] Existing technologies make it difficult to protect code property rights when software products are circulated and used. Technical Solutions
[0004] In response to the aforementioned technical issues and technical requirements regarding the difficulty in protecting code property rights during the circulation and use of software products, the applicant has proposed a code property rights management system based on cloud smart contract compilation. The technical solution of this application is as follows:
[0005] A code property management system based on cloud smart contract compilation includes an authorization storage subsystem, a software compilation subsystem, and a software usage platform. The authorization storage subsystem and the software compilation subsystem are both deployed in a cloud environment. The authorization storage subsystem includes a repository and is deployed with a cloud smart contract. The repository stores a property identifier and encrypted code property data of at least one code project, and the code property data of each code project is encrypted by the code project's management public key.
[0006] The software usage platform is used to receive a build request sent by a user node, and the build request carries a target property identifier and a target compilation environment corresponding to the target code project; the software usage platform is also used to send the build request to the creator user node corresponding to the target code project according to the target property identifier, and after receiving an authorization response to the build request from the creator user node corresponding to the target code project, the build request is sent to the software compilation subsystem.
[0007] The software compilation subsystem is used to parse the received build request and send the target property identifier to the authorization storage subsystem.
[0008] The authorization storage subsystem is used to call the cloud smart contract to obtain the encrypted target code property data corresponding to the target property identifier from the repository and return it to the software compilation subsystem.
[0009] The software compilation subsystem is used to push the encrypted target code property data to the virtual machine configured according to the target compilation environment, decrypt it in the isolated environment provided by the virtual machine using the management private key of the target code project, and then compile the target code property data to generate the target Docker software product. The target Docker software product is a Docker image for the software service requested by the build; the management public key and management private key of each code project form a pair of key pairs.
[0010] The software usage platform is used to deliver the target Docker software product to the user node that sends the build request.
[0011] Its further technical solution is that the code property management system also includes a creation platform, and the repository includes the Interstellar File System and blockchain.
[0012] The creation platform is used to obtain the code ownership data of the code project uploaded by the creator user node, and the user identity of the corresponding management node and upload it to the authorization storage subsystem. The management node of each code project is one of the creator user nodes of the code project.
[0013] After receiving the code property rights data of the code project and the corresponding user identity of the management node, the authorization storage subsystem reads the public key corresponding to the user identity of the management node from the blockchain as the management public key of the code project, and triggers the cloud smart contract to generate the property rights identifier of the code project; the authorization storage subsystem is also used to use the management public key of the code project to encrypt the unstructured data in the code property rights data and store it in the InterPlanetary File System and obtain the storage address, and to use the management public key of the code project to encrypt the structured data in the code property rights data and store it in the blockchain corresponding to the property rights identifier and storage address of the code project.
[0014] Obtaining the encrypted target code property rights data corresponding to the target property rights identifier from the repository includes: obtaining the storage address and encrypted structured data corresponding to the target property rights identifier from the blockchain, and obtaining the encrypted unstructured data corresponding to the storage address from the InterPlanetary File System. The obtained encrypted target code property rights data includes encrypted structured data and encrypted unstructured data.
[0015] Its further technical solution is that the creation platform obtains the code property rights data of the code project uploaded by the creator user node, including:
[0016] Obtain the local data uploaded by multiple creator user nodes with collaboration permissions, store the user identity identifiers of all creator user nodes with collaboration permissions and the local data uploaded by them in correspondence, and obtain the code property rights data of the code project.
[0017] Each creator user node has the right to view the local data uploaded by all creator user nodes with collaboration rights in the code project.
[0018] A further technical solution is that each software product has a corresponding total survival time.
[0019] The software usage platform is also used to stop sending the target Docker software product to the user user node and send a destruction request for the target Docker software product to the software compilation subsystem when it detects that the cumulative usage time of the target Docker software product sent to the user user node reaches the total survival time of the target Docker software product.
[0020] The software compilation subsystem destroys the target Docker software product according to the received destruction request and reclaims the port number of the target Docker software product. Different target Docker software products are assigned different port numbers.
[0021] Its further technical solution is that the software usage platform is also used to push a payment bill to the user user node of the target Docker software product when it detects that the cumulative usage time of the target Docker software product sent to the user user node reaches the total survival time of the target Docker software product, and after detecting that the payment operation in response to the payment bill is completed, execute the steps of stopping sending the target Docker software product to the user user node and sending a destruction request for the target Docker software product to the software compilation subsystem.
[0022] A further technical solution is that the code property rights management system also includes a service supervision subsystem.
[0023] The software usage platform is also used to send a transaction record registration request to the blockchain in the repository via the service supervision subsystem after detecting the payment completion operation in response to the payment of the bill. The transaction information carried by the transaction record registration request includes at least the product identification of the target Docker software product, the user identity identification of the user user node, and the transaction process data; the blockchain generates an order contract based on the transaction record registration request and completes the storage through a multi-node consensus mechanism.
[0024] The software usage platform is also used to send the query request to the blockchain when receiving the query request sent by the user user node, and send the order contract returned by the blockchain to the user user node; the query request carries the user identity of the user user node and / or the product identity of the target Docker software product.
[0025] A further technical solution is that the build request received by the software usage platform includes the basic survival time.
[0026] When the software usage platform does not receive an extension request before the cumulative usage time of the target Docker software product sent to the user's user node reaches the basic survival time, the total survival time of the target Docker software product is determined as the basic survival time.
[0027] When the software usage platform receives an extension request with an extension period before the cumulative usage time of the target Docker software product issued to the user user node reaches the basic survival time, the software usage platform sends the extension request to the creator user node corresponding to the target code project encapsulated by the target Docker software product, and after receiving the consent feedback from the creator user node corresponding to the target code project for the extension request, the software usage platform determines the total survival time of the target Docker software product as the sum of the basic survival time and the extension time.
[0028] A further technical solution is that the software platform is further used to perform the following operations:
[0029] When a pause request carrying a pause duration is received from the user node while the target Docker software product is being sent to the corresponding user node, the pause request is sent to the creator user node corresponding to the target code project encapsulated by the target Docker software product.
[0030] After receiving the consent feedback for the pause request from the creator user node corresponding to the target code project, the target Docker software product will be suspended from being sent to the corresponding user user node until the pause time is reached and then the target Docker software product will be resumed from being sent to the corresponding user user node. The cumulative usage time of the target Docker software product will not increase during the suspension process.
[0031] Its further technical solution is that the code property management system also includes a service supervision subsystem, which is also used to upload and store the transaction data corresponding to the build request to the blockchain of the repository through a multi-node consensus mechanism. The transaction data corresponding to each build request includes the user identity of the user node that sends the build request, the process data of the software compilation subsystem compiling and generating the target Docker software product, and the usage data of the software usage platform sending the target Docker software product to the corresponding user node.
[0032] Its further technical solution is that the creation platform generates a corresponding key pair for each creator user node that has completed registration, and stores the user identity of the creator user node and the public key in the generated key pair in the blockchain, and returns the private key in the generated key pair to the creator user node. Beneficial effects
[0033] This application discloses a code property management system based on cloud smart contract compilation. The system obtains code property data stored in the authorized storage subsystem through a cloud smart contract deployed in a cloud environment, and compiles it through a Docker image to generate a Docker software product. Among them, Docker technology provides operating system-level isolation for the controllable construction of software products, and then utilizes the characteristic of smart contracts that trigger execution when preset rules are met to achieve efficient and automated construction of software products. The corresponding code property data is encrypted and stored in the repository through the management public key of the code project, and then decrypted using the management private key in the same key pair when compilation is required, effectively improving the security and integrity of the code property data during the circulation and use of the software, and avoiding the risk of code leakage and abuse.
[0034] This application uses the InterPlanetary File System and blockchain as repositories, combined with cloud smart contracts to achieve data access. The InterPlanetary File System realizes the distributed and decentralized storage of unstructured data, improving the addressability and reliability of data; the blockchain realizes the on-chain and backup of structured data, improving the immutability of data and solving the single point failure problem.
[0035] This application uses pooling technology and mutex locks to achieve effective allocation and management of port numbers and avoid the problem of port number conflicts.
[0036] This application monitors service usage data during software use through a service supervision subsystem, and stores the transaction data consensus on the chain, thereby improving the transparency and traceability of software service transactions.
[0037] This application implements the issuance and maintenance of user identity identification through a digital certificate issuing authority, improving the credibility and security of the code property management system. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] FIG1 is a schematic diagram of the structure of a code property management system in one embodiment of the present application.
[0039] FIG2 is a schematic diagram of the process of compiling and generating software for a cloud smart contract in one embodiment of the present application.
[0040] FIG3 is a schematic diagram of service supervision of a software product in one embodiment of the present application. Modes for Carrying Out the Invention
[0041] The specific implementation of this application will be further described below with reference to the accompanying drawings.
[0042] As shown in Figure 1, a code property management system based on cloud smart contract compilation includes an authorization storage subsystem, a software compilation subsystem and a software usage platform. The authorization storage subsystem and the software compilation subsystem are both deployed in a cloud environment; the authorization storage subsystem includes a repository and is deployed with a cloud smart contract. The repository stores the property identifier and encrypted code property data of at least one code project, and the code property data of each code project is encrypted by the management public key of the code project.
[0043] In one embodiment, each code project is matched with a pair of management keys. Each pair of management keys includes a management public key and a management private key. The management keys are pre-generated and stored in a repository. The management public key is used to encrypt the code property data of the corresponding code project, and the management private key is used to decrypt the code property data of the corresponding code project.
[0044] To facilitate multi-user interaction during the transfer and use of code property rights, the code property rights management system of this application is also connected to several user nodes. User nodes include user nodes and creator nodes. User nodes correspond to the users of code property rights, while creator nodes correspond to the creators of code property rights. The relationship between each code project and the creator node is stored in the repository.
[0045] The software usage platform is used to receive a build request sent by a user node, and the build request carries a target property identifier and a target compilation environment corresponding to the target code project; the software usage platform is also used to send the build request to the creator user node corresponding to the target code project according to the target property identifier, and after receiving an authorization response to the build request from the creator user node corresponding to the target code project, the build request is sent to the software compilation subsystem.
[0046] Optionally, the target compilation environment represents the environment that the target code project depends on when compiling and running.
[0047] In one embodiment, the authorizing response of the creator user node to the building request indicates that the creator user node agrees to the building request and authorizes the user user node.
[0048] Optionally, when the software usage platform receives a rejection response from the creator user node corresponding to the target code project to the build request, or fails to receive a response from the creator user node corresponding to the target code project to the build request within a set time, the software usage platform sends a rejection feedback to the user user node.
[0049] The software compilation subsystem is used to parse the received build request and send the target property identifier to the authorization storage subsystem.
[0050] The authorization storage subsystem is used to call the cloud smart contract to obtain the encrypted target code property data corresponding to the target property identifier from the repository and return it to the software compilation subsystem.
[0051] The software compilation subsystem is used to push the encrypted target code property data to the virtual machine configured according to the target compilation environment, decrypt it in the isolated environment provided by the virtual machine using the management private key of the target code project, and then compile the target code property data to generate the target Docker software product. The target Docker software product is a Docker image for the software service requested by the build; the management public key and management private key of each code project form a pair of key pairs.
[0052] In another embodiment, each creator user node is matched with a pair of keys, and the relationship between the creator user node and the key and code project is stored in the repository.
[0053] Optionally, when a code project has multiple creator user nodes, at least one creator user node serves as a management node, with the public key of the management node serving as the management public key and the private key of the management node serving as the management private key.
[0054] Optionally, a pair of RSA keys is generated for each creator user node using the RSA (Rivest-Shamir-Adleman) algorithm. Each pair of RSA keys includes a public key and a private key. The public keys of each pair of RSA keys are different from each other, and the private keys of each pair of RSA keys are different from each other.
[0055] In one embodiment, to ensure efficient collaboration, the public key is stored in a database; to improve privacy and security, the private key is stored locally by the creator user node.
[0056] Optionally, the software compilation subsystem includes a Docker container module, and the compilation of Docker software products is implemented based on the Docker container module.
[0057] Optionally, after decrypting the target code property data, the software compilation subsystem compares a set of hash values when the code property data is stored in the repository with a set of hash values when the code property data is retrieved from the repository. If the two sets of hash values differ, the software compilation subsystem does not respond to the build request. If the two sets of hash values are the same, the software compilation subsystem compiles the target code property data to generate the target Docker software product.
[0058] The software usage platform of the code property management system of this application is connected to a number of user user nodes. The user user nodes interact with the creator user nodes through the software usage platform, thereby realizing the use of the software products corresponding to the code property rights.
[0059] The software usage platform is used to deliver the target Docker software product to the user node that sends the build request.
[0060] In one embodiment, as shown in Figure 2, the process of cloud smart contract compilation and software generation includes: step 1, after the software usage platform receives the build request sent by the user user node, it sends the build request to the software compilation subsystem; step 2, the software compilation subsystem calls the cloud smart contract based on the build request; the cloud smart contract executes steps 3-7; step 8, the software compilation subsystem receives the management private key provided by the management node; step 9, the software compilation subsystem decrypts the code property data in the virtual machine based on the management private key; step 10, the cloud smart contract executes compilation; step 11, the repository in the authorization management subsystem stores the port number and virtual machine IP address of the Docker software product; step 12, the software usage platform carries the Docker software product; step 13, the software usage platform sends the Docker software product to the user user node that sent the build request by exposing the API interface.
[0061] This application leverages Docker technology to provide operating system-level isolation for controllable software product builds. By leveraging the ability of smart contracts to trigger execution upon meeting pre-set rules, this enables efficient, automated software product builds. The corresponding code ownership data is encrypted and stored in a repository using the project's public key. When compilation is required, the code ownership data is decrypted using the private key from the same key pair. This effectively improves the security and integrity of code ownership data during software distribution and avoids the risk of code leakage and misuse.
[0062] In order to more clearly illustrate the code property rights management system compiled based on cloud smart contracts in this application, another embodiment is described in detail below.
[0063] As shown in Figure 1, the code property management system of the present application also includes a creation platform, which is connected to a number of creator user nodes, and the repository includes an interstellar file system and a blockchain.
[0064] The creation platform is used to obtain the code ownership data of the code project uploaded by the creator user node, and the user identity of the corresponding management node and upload it to the authorization storage subsystem. The management node of each code project is one of the creator user nodes of the code project.
[0065] Optionally, the creation platform is used to obtain the code property registration application uploaded by the creator user node and send it to the authorization storage subsystem. The code property registration application carries the code property data of the code project and the user identity of the corresponding management node.
[0066] Optionally, the code property registration application also carries at least one of the project name, project version number, compilation environment, project introduction, and request time.
[0067] After receiving the code project's code ownership data and the corresponding management node's user identity, the authorization storage subsystem reads the public key corresponding to the management node's user identity from the blockchain as the code project's management public key, triggering the cloud smart contract to generate the code project's ownership identifier. The authorization storage subsystem is also used to encrypt the unstructured data within the code ownership data using the code project's management public key, then store it in the InterPlanetary File System and obtain a storage address. Furthermore, it is used to encrypt the structured data within the code ownership data using the code project's management public key, then store it on the blockchain in association with the code project's ownership identifier and storage address.
[0068] Obtaining the encrypted target code property rights data corresponding to the target property rights identifier from the repository includes: obtaining the storage address and encrypted structured data corresponding to the target property rights identifier from the blockchain, and obtaining the encrypted unstructured data corresponding to the storage address from the InterPlanetary File System. The obtained encrypted target code property rights data includes encrypted structured data and encrypted unstructured data.
[0069] Optionally, the unstructured data in the code property data includes the source code of the code project, and the structured data in the code property data includes at least one of the user identity and user name of each creator user node of the code project, the authorization time of the code project, the project name, the project version number, and the compilation environment.
[0070] Optionally, the cloud smart contract uses the MD5 algorithm (Message-Digest Algorithm 5) to operate on the code project to generate a property rights identifier for the code project.
[0071] This application uses the InterPlanetary File System and blockchain as repositories, combined with cloud smart contracts to achieve data access. The InterPlanetary File System realizes the distributed and decentralized storage of unstructured data, improving the addressability and reliability of data; the blockchain realizes the on-chain and backup of structured data, improving the immutability of data and solving the single point failure problem.
[0072] In this embodiment, the creation platform obtains the code property rights data of the code project uploaded by the creator user node, including:
[0073] Obtain the local data uploaded by multiple creator user nodes with collaboration permissions, store the user identity identifiers of all creator user nodes with collaboration permissions and the local data uploaded by them in correspondence, and obtain the code property rights data of the code project.
[0074] In this embodiment, the creator user nodes of the code project include a management node and a creator user node with collaboration authority for the code project.
[0075] Each creator user node has the right to view the local data uploaded by all creator user nodes with collaboration rights in the code project.
[0076] In another embodiment, the local data uploaded by the creator user node is stored on the code temporary storage platform. After a creator user node stores the local data, other creator user nodes with collaboration permissions on the same code project can access and download the local data, add to and / or modify the local data, and then store it on the code temporary storage platform, enabling collaborative creation of code projects.
[0077] Optionally, the creator user node directly uploads the local data created locally to the creation platform, and / or the creator user node creates the local data online through the creation platform.
[0078] Optionally, a MySQL database is used to temporarily store local data.
[0079] In this embodiment, each software product has a corresponding total lifetime. The software usage platform is further configured to stop delivering the target Docker software product to the user node and send a destruction request for the target Docker software product to the software compilation subsystem when detecting that the cumulative usage time of the target Docker software product delivered to the user node has reached the total lifetime of the target Docker software product.
[0080] The software compilation subsystem destroys the target Docker software product according to the received destruction request and reclaims the port number of the target Docker software product. Different target Docker software products are assigned different port numbers.
[0081] In one embodiment, the software compilation subsystem is matched with a port pool, which stores a number of unassigned port numbers. After the Docker software product is destroyed, the corresponding port numbers are recycled to the port pool.
[0082] Optionally, use a mutex to assign port numbers, and assign a port number to at most one Docker software product at a time.
[0083] Optionally, the API interface of the Docker software product is exposed to the user node through the port number and the virtual machine IP address, and the user node accesses the corresponding Docker software product through the API interface.
[0084] Optionally, when destroying a Docker software product, the software compilation subsystem deletes the corresponding code property data and Docker image in the virtual machine, releases port numbers and computing resources, and clears temporary files.
[0085] In this embodiment, the software usage platform is further configured to push a payment bill to the user user node of the target Docker software product when it detects that the cumulative usage time of the target Docker software product distributed to the user user node reaches the total life span of the target Docker software product, and after detecting that the payment operation in response to the payment bill is completed, execute the steps of stopping distribution of the target Docker software product to the user user node and sending a destruction request for the target Docker software product to the software compilation subsystem.
[0086] Optionally, after the user node receives the payment bill, it cannot send a build request corresponding to any code project to the software usage platform before the payment is completed.
[0087] In this embodiment, as shown in FIG3 , the code property management system further includes a service supervision subsystem.
[0088] The software usage platform is also used to send a transaction record registration request to the blockchain in the repository via the service supervision subsystem after detecting the payment completion operation in response to the payment of the bill. The transaction information carried by the transaction record registration request includes at least the product identification of the target Docker software product, the user identity identification of the user user node, and the transaction process data; the blockchain generates an order contract based on the transaction record registration request and completes the storage through a multi-node consensus mechanism.
[0089] Optionally, the transaction record registration request also includes at least one of transaction time, transaction amount, and transaction content.
[0090] The software usage platform is also used to send the query request to the blockchain when receiving the query request sent by the user user node, and send the order contract returned by the blockchain to the user user node; the query request carries the user identity of the user user node and / or the product identity of the target Docker software product.
[0091] This application monitors service usage data during the use of the software through the service supervision subsystem, and stores transaction records on the chain, which improves the transparency and traceability of software service transactions and provides evidence for users to protect their rights.
[0092] In this embodiment, the build request received by the software usage platform includes the basic lifetime.
[0093] When the software usage platform does not receive an extension request before the cumulative usage time of the target Docker software product sent to the user's user node reaches the basic survival time, the total survival time of the target Docker software product is determined as the basic survival time.
[0094] When the software usage platform receives an extension request with an extension period before the cumulative usage time of the target Docker software product issued to the user user node reaches the basic survival time, the software usage platform sends the extension request to the creator user node corresponding to the target code project encapsulated by the target Docker software product, and after receiving the consent feedback from the creator user node corresponding to the target code project for the extension request, the software usage platform determines the total survival time of the target Docker software product as the sum of the basic survival time and the extension time.
[0095] Optionally, the extension duration of each user node's request for the same Docker software product is less than or equal to a set extension threshold.
[0096] In this embodiment, the software usage platform is also used to perform the following operations:
[0097] When a pause request carrying a pause duration is received from the user node while the target Docker software product is being sent to the corresponding user node, the pause request is sent to the creator user node corresponding to the target code project encapsulated by the target Docker software product.
[0098] After receiving the consent feedback for the pause request from the creator user node corresponding to the target code project, the target Docker software product will be suspended from being sent to the corresponding user user node until the pause time is reached and then the target Docker software product will be resumed from being sent to the corresponding user user node. The cumulative usage time of the target Docker software product will not increase during the suspension process.
[0099] Optionally, the pause duration of each user node's request for the same Docker software product is less than or equal to a set pause threshold.
[0100] In this embodiment, the code property management system also includes a service supervision subsystem, which is also used to upload and store the transaction data corresponding to the build request to the blockchain of the repository through a multi-node consensus mechanism. The transaction data corresponding to each build request includes the user identity of the user node that sends the build request, the process data of the software compilation subsystem compiling and generating the target Docker software product, and the usage data of the software usage platform sending the target Docker software product to the corresponding user node.
[0101] Optionally, the process data for generating the target Docker software product includes the corresponding port number, IP address, product identifier, and basic lifetime; the usage data includes software release time, extension request time, extension duration, pause request time, pause duration, user payment time, software destruction time, and the specific usage content corresponding to each time.
[0102] Optionally, as shown in Figure 3, the service supervision subsystem includes an operation monitor and a temporary database. The operation monitor obtains service operation data received from the user node through the software usage platform and stores the transaction data therein in the temporary database. The cloud smart contract generates a user operation record table based on the transaction data, and stores the user operation record table on the chain for evidence.
[0103] In this embodiment, the creation platform generates a corresponding key pair for each creator user node that has completed registration, and stores the user identity of the creator user node and the public key in the generated key pair in the blockchain, and returns the private key in the generated key pair to the creator user node.
[0104] In one embodiment, the authorization storage subsystem further includes a digital certificate issuing authority. The functions of the digital certificate issuing authority include:
[0105] (1) The digital certificate authority is used to issue user identity identification for the creator user node.
[0106] After receiving a registration request carrying a creator identifier, the creation platform queries the blockchain to see if the creator identifier is stored. If the creator identifier is not stored in the blockchain, the creation platform rejects the registration request. If the creator identifier is stored in the blockchain, the creation platform generates a corresponding creator user node and RSA key pair for the creator identifier, sends an identity issuance request to the digital certificate authority, and receives the user identity of the creator user node from the digital certificate authority. The creator identifier of the creator user node, the corresponding RSA key pair, and the user identity are stored in the token. When the creation platform receives a login request carrying a token from the creator user node, it responds to the login request.
[0107] Creator user nodes are distributed across several organizations. In each organization, there is at least one creator user node with management authority. The creator user node with management authority is used to upload the creator identity to the blockchain.
[0108] Optionally, the creator identifier is the work number of the creator user node in the corresponding organization.
[0109] Optionally, each organization may have an equal upper limit on the number of creator user nodes. For example, each organization may have a maximum of 5 creator user nodes.
[0110] (2) The digital certificate authority is used to issue user identity identification to the user node.
[0111] After receiving a registration request with a user identifier, the registration platform generates a corresponding user node for the user identifier, sends an identity issuance request to a digital certificate authority, and receives the user identity of the user node from the digital certificate authority. The user identifier and user identity of the user node are then uploaded to the blockchain and stored in the token. When the registration platform receives a login request from the user node with a token, it responds to the login request.
[0112] Optionally, the registration platform is any one of the software usage platform, the authorization storage subsystem, the software compilation subsystem, and the service supervision subsystem.
[0113] Optionally, after registering a user node or creator node, user nodes that are not synchronized to the blockchain cannot participate in transactions; and after the set time period after registration is completed, user nodes that are not synchronized to the blockchain will be automatically removed by the monitoring node.
[0114] (3) The digital certificate authority is used to authenticate the user identity of the creator user node.
[0115] After receiving the code project's code ownership data and the corresponding management node's user identity, the authorization storage subsystem checks the integrity of the management node's token information. If the check passes, it sends an authentication request to the digital certificate authority based on the management node's user identity. If the digital certificate authority confirms successful authentication, the authorization storage subsystem reads the public key corresponding to the management node's user identity from the blockchain as the code project's management public key. If the digital certificate authority confirms failed authentication, the authorization storage subsystem executes this step.
[0116] (4) The digital certificate authority is used to authenticate the user identity of the user node.
[0117] After receiving the build request, the software compilation subsystem also parses the user ID of the user node and sends an authentication request to the digital certificate authority based on the user ID of the user node. Upon receiving a successful authentication response from the digital certificate authority, the software compilation subsystem sends the target property rights identifier to the authorization storage subsystem. Upon receiving a failed authentication response from the digital certificate authority, the software compilation subsystem does not respond to the build request.
[0118] The above description is only a preferred embodiment of the present application, and the present application is not limited to the above embodiments. It is understood that other improvements and variations directly derived or imagined by those skilled in the art without departing from the spirit and concept of the present application should be considered to be included in the scope of protection of the present application.
Claims
1. A code property rights management system based on cloud intelligent contract compilation, characterized in that The code property rights management system includes an authorization storage subsystem, a software compilation subsystem, and a software usage platform. The authorization storage subsystem and the software compilation subsystem are both deployed in a cloud environment. The authorization storage subsystem includes a repository and deploys a cloud smart contract. The repository stores the property rights identifiers of at least one code project and the encrypted code property rights data correspondingly, and the code property rights data of each code project is encrypted by the management public key of the code project. The software usage platform is used to receive a build request sent by a user node of a user, and the build request carries a target property rights identifier corresponding to a target code project and a target compilation environment. The software usage platform is further used to send the build request to the user node of the creator corresponding to the target code project according to the target property rights identifier, and after receiving the authorization response of the user node of the creator corresponding to the target code project for the build request, send the build request to the software compilation subsystem. The software compilation subsystem is used to parse the received build request and send the target property rights identifier to the authorization storage subsystem. The authorization storage subsystem is used to call the cloud smart contract to obtain the encrypted target code property rights data corresponding to the target property rights identifier from the repository and return it to the software compilation subsystem. The software compilation subsystem is used to push the encrypted target code property rights data to a virtual machine configured according to the target compilation environment, decrypt it in the isolation environment provided by the virtual machine by using the management private key of the target code project, and then compile the target code property rights data to generate a target Docker software product, where the target Docker software product is a Docker image of the software service for the build request. Among them, the management public key and the management private key of each code project are a pair of key pairs. The software usage platform is used to distribute the target Docker software product to the user node of the user who sent the build request.
2. The code property rights management system according to claim 1, wherein The code property rights management system further includes a creation platform, and the repository includes an InterPlanetary File System (IPFS) and a blockchain. The creation platform is used to obtain the code property rights data of the code project uploaded by the user node of the creator and the user identity identifier of the corresponding management node and upload them to the authorization storage subsystem. The management node of each code project is one of the user nodes of the creator of the code project. After receiving the code property rights data of the code project and the user identity identifier of the corresponding management node, the authorized storage subsystem reads the public key corresponding to the user identity identifier of the management node from the blockchain as the management public key of the code project, and triggers the cloud smart contract to generate the property rights identifier of the code project; the authorized storage subsystem is further configured to encrypt the unstructured data in the code property rights data with the management public key of the code project and store it in the InterPlanetary File System to obtain a storage address, and encrypt the structured data in the code property rights data with the management public key of the code project and store it in the blockchain corresponding to the property rights identifier and the storage address of the code project; Then, obtaining the encrypted target code property rights data corresponding to the target property rights identifier from the repository includes: obtaining the storage address and encrypted structured data corresponding to the target property rights identifier from the blockchain, and obtaining the encrypted unstructured data corresponding to the storage address from the InterPlanetary File System. The obtained encrypted target code property rights data includes encrypted structured data and encrypted unstructured data.
3. The code property rights management system according to claim 2, characterized in that The creation platform obtains the code property rights data of the code project uploaded by the creator user node, including: Obtaining the partial data uploaded by multiple creator user nodes with collaboration permissions, and storing the user identity identifiers of all creator user nodes with collaboration permissions and the partial data they upload in a corresponding manner to obtain the code property rights data of the code project; Each creator user node has the right to view the partial data uploaded by all creator user nodes with collaboration permissions for the code project.
4. The code property rights management system according to claim 1, characterized in that Each software product has a corresponding total lifetime; The software usage platform is further configured to stop sending the target Docker software product to the user node of the user when it detects that the cumulative usage duration of the target Docker software product sent to the user node of the user reaches the total lifetime of the target Docker software product, and send a destruction request for the target Docker software product to the software compilation subsystem; The software compilation subsystem destroys the target Docker software product according to the received destruction request and recovers the port number of the target Docker software product. Different target Docker software products are assigned different port numbers.
5. The code property rights management system according to claim 4, wherein The software usage platform is further configured to push a payment bill to the user node of the user of the target Docker software product when it detects that the cumulative usage duration of the target Docker software product sent to the user node of the user reaches the total lifetime of the target Docker software product, and after detecting the payment completion operation in response to the payment bill, Docker executes the steps of stopping sending the target Docker software product to the user node of the user and sending a destruction request for the target Docker software product to the software compilation subsystem.
6. The code property management system according to claim 5, wherein The code property rights management system further includes a service supervision subsystem; The software usage platform is also used to, after detecting a payment completion operation in response to the payment bill, send a transaction record registration request to the blockchain in the repository via the service supervision subsystem. The transaction information carried in the transaction record registration request includes at least the product identifier of the target Docker software product, the user identity identifier of the user node of the user, and the transaction process data. The blockchain generates an order contract according to the transaction record registration request and completes the storage through a multi-node consensus mechanism. The software usage platform is also used to, when receiving a query request sent by a user node of a user, send the query request to the blockchain and send the order contract returned by the received blockchain to the user node of the user. The query request carries the user identity identifier of the user node of the user and / or the product identifier of the target Docker software product.
7. The code property management system according to claim 4, characterized in that, The build request received by the software usage platform includes a basic survival duration. When the software usage platform does not receive an extension request before the cumulative usage duration of the target Docker software product sent to the user node of the user reaches the basic survival duration, it determines that the total survival duration of the target Docker software product is the basic survival duration. When the software usage platform receives an extension request carrying an extension duration before the cumulative usage duration of the target Docker software product sent to the user node of the user reaches the basic survival duration, the software usage platform sends the extension request to the user node of the creator corresponding to the target code project encapsulated by the target Docker software product, and after receiving the consent feedback of the user node of the creator corresponding to the target code project for the extension request, determines that the total survival duration of the target Docker software product is the sum of the basic survival duration and the extension duration.
8. The code property management system according to claim 4, characterized in that, The software usage platform is also used to perform the following operations: When, during the process of sending the target Docker software product to the corresponding user node of the user, a suspension request carrying a suspension duration sent by the user node of the user is received, send the suspension request to the user node of the creator corresponding to the target code project encapsulated by the target Docker software product. After receiving the consent feedback of the user node of the creator corresponding to the target code project for the suspension request, suspend sending the target Docker software product to the corresponding user node of the user until the suspension duration is reached and then continue to send the target Docker software product to the corresponding user node of the user. The cumulative usage duration of the target Docker software product does not increase during the suspension of sending.
9. The code property rights management system according to claim 1, wherein The code property rights management system further includes a service supervision subsystem, and the service supervision subsystem is further configured to upload and store the transaction data corresponding to the build request to the blockchain of the repository through a multi-node consensus mechanism. The transaction data corresponding to each build request includes the user identity identifier of the user node of the user who sends the build request, the process data of the software compilation subsystem for compiling and generating the target Docker software product, and the usage data of the software usage platform for distributing the target Docker software product to the corresponding user node of the user.
10. The code property management system according to claim 2, characterized in that, The creation platform generates a corresponding key pair for each registered creator user node, stores the user identity identifier of the creator user node and the public key in the generated key pair correspondingly in the blockchain, and returns the private key in the generated key pair to the creator user node.
Citation Information
Patent Citations
Visualized Docker container automatic compilation deployment operation and maintenance method
CN108196843A
Code compiling method, device and system, computer device and storage medium
CN110531984A
Software interaction platform and method for automatically deploying resources in cloud environment
CN111897541A
Smart contract management method and apparatus based on blockchain, and electronic device
WO2020238255A1