Resource processing method, signature private key acquisition method, and apparatus
By generating a signed public key and a signed private key, the digital account security problem caused by theft of the main public key is solved, and the account security and virtual resource processing are improved.
Patent Information
- Application Number
- PCT/CN2024/136130
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-02
- Filing Date
- 2024-12-02
- Publication Date
- 2025-07-10
AI Technical Summary
When creating a digital account, the risk of the main public key pair being stolen by attacks leads to reduced security of the digital account.
By generating the signature public key and the signature private key, the signature private key is sent to the terminal to generate a digital signature, and after verification, the virtual resources in the digital account are processed, avoiding directly storing the main public key pair and reducing the dependence of the centralized database.
Improves the security of digital accounts, prevents the main public key from being leaked and affects the security of account, and improves the security of virtual resource processing.
Smart Images

Figure CN2024136130_10072025_PF_FP_ABST
Abstract
Description
Resource processing method, signature private key acquisition method and device
[0001] Related applications
[0002] This application claims priority to Chinese patent application number 2024100067734, filed on January 2, 2024, entitled “Digital Account Creation Method, Signature Private Key Acquisition Method, and Device,” the entire text of which is hereby incorporated by reference. Technical Field
[0003] The present application relates to the field of computer technology, and in particular to a resource processing method, a signature private key acquisition method, and a device. Background Art
[0004] With the development of science and technology, digital accounts have emerged. A digital account is a container for storing virtual resources. Each virtual resource stored in a digital account has a unique resource identifier, which uniquely identifies a virtual resource. Each virtual resource can have a different resource quantity. For example, a virtual resource with 100 resources can be considered a resource, while a virtual resource with 1 resource can also be considered a resource.
[0005] Currently, when creating a digital account, an additional master public-private key pair is created and stored in a database alongside the account creator's ID. However, storing the master public key pair alongside the account creator's ID in a database creates the risk of the master public key pair being stolen, thus reducing the security of the digital account. Summary of the Invention
[0006] The present application provides a resource processing method, a signature private key acquisition method, an apparatus, a computer device, a computer-readable storage medium, and a computer program product.
[0007] In a first aspect, the present application provides a resource processing method, which is executed by a computer device, and the method includes:
[0008] Upon receiving a digital account creation request, extracting a digital account creator identifier from the digital account creation request in response to the digital account creation request;
[0009] Creating a digital account for storing virtual resources according to the digital account creator identifier;
[0010] Obtaining a preset master public key, and generating a signature public key for the digital account based on the master public key and the digital account creator identifier;
[0011] Obtaining a master private key paired with the master public key, and generating a signature private key paired with the signature public key based on the master private key and the signature public key;
[0012] Sending the signature private key to the terminal corresponding to the digital account creator identifier; the sent signature private key is used to trigger the terminal to generate a digital signature based on the signature private key;
[0013] receiving a resource processing request including the digital signature fed back by the terminal; and
[0014] After the digital signature is verified based on the signature public key of the digital account, the virtual resources in the digital account are processed according to the resource processing request.
[0015] In a second aspect, the present application further provides a resource processing device, the device comprising:
[0016] a signature public key generation module configured to, upon receiving a digital account creation request, extract a digital account creator identifier from the digital account creation request in response to the digital account creation request; create a digital account for storing virtual resources based on the digital account creator identifier; obtain a preset master public key, and generate a signature public key for the digital account based on the master public key and the digital account creator identifier;
[0017] A signature private key generation module, configured to obtain a master private key paired with the master public key, and generate a signature private key paired with the signature public key based on the master private key and the signature public key;
[0018] A signature private key sending module, configured to send the signature private key to a terminal corresponding to the digital account creator identifier; the sent signature private key is used to trigger the terminal to generate a digital signature based on the signature private key;
[0019] a resource processing request receiving module, configured to receive the resource processing request including the digital signature fed back by the terminal; and
[0020] The resource processing module is used to process the virtual resources in the digital account according to the resource processing request after the digital signature is verified based on the signature public key of the digital account.
[0021] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the steps of any one of the resource processing methods provided in the embodiments of the present application.
[0022] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in any resource processing method provided in the embodiments of the present application are implemented.
[0023] In a fifth aspect, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of any resource processing method provided in the embodiments of the present application.
[0024] In a sixth aspect, the present application provides a method for obtaining a signature private key, the method comprising:
[0025] Obtaining a digital account creator identifier, and generating a digital account creation request based on the digital account creator identifier;
[0026] Sending the digital account creation request; the sent digital account creation request is used to trigger the creation of a digital account, a signature public key, and a signature private key according to the digital account creator identifier, and is used to trigger the generation of a verification code, and encrypting the signature private key based on the verification code to obtain an encrypted private key;
[0027] receiving the encrypted private key and the verification code;
[0028] The encrypted private key is decrypted by the verification code to obtain the signature private key; the signature private key is used to generate a resource processing request including a digital signature through the signature private key during resource processing; the digital signature is used to trigger the processing of the virtual resources in the digital account according to the resource processing request after the digital signature is verified by the signature public key bound to the digital account.
[0029] In a seventh aspect, the present application further provides a device for obtaining a signature private key, the device comprising:
[0030] The request generation module is used to obtain a digital account creator identifier and generate a digital account creation request according to the digital account creator identifier.
[0031] A request sending module is used to send the digital account creation request; the sent digital account creation request is used to trigger the creation of a digital account, a signature public key and a signature private key according to the digital account creator identifier, and is used to trigger the generation of a verification code, and encrypt the signature private key based on the verification code to obtain an encrypted private key.
[0032] A key receiving module is used to receive the encrypted private key and the verification code; the encrypted private key is decrypted by the verification code to obtain the signature private key; the signature private key is used to generate a resource processing request including a digital signature through the signature private key during resource processing; the digital signature is used to trigger the processing of virtual resources in the digital account according to the resource processing request after the digital signature is verified by the signature public key bound to the digital account.
[0033] In an eighth aspect, the present application also provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the steps in any one of the signature private key acquisition methods provided in the embodiments of the present application.
[0034] In a ninth aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in any one of the signature private key acquisition methods provided in the embodiments of the present application are implemented.
[0035] In the tenth aspect, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps in any one of the signature private key acquisition methods provided in the embodiments of the present application.
[0036] The details of one or more embodiments of the present application are set forth in the accompanying drawings and the description below. Other features, objects, and advantages of the present application will become apparent from the description, drawings, and claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the conventional technology, the following briefly introduces the drawings required for use in the embodiments or the conventional technology descriptions. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the disclosed drawings without any creative work.
[0038] FIG1 is an application environment diagram of a resource processing method according to an embodiment;
[0039] FIG2 is a schematic diagram of a blockchain network in one embodiment;
[0040] FIG3 is a schematic diagram of a flow chart of a resource processing method in one embodiment;
[0041] FIG4 is a schematic diagram of an account creation page in one embodiment;
[0042] FIG5 is a schematic diagram of generating a signature public key in one embodiment;
[0043] FIG6 is a schematic diagram of generating a signature public key in another embodiment;
[0044] FIG7 is a schematic diagram showing a signature public key in one embodiment;
[0045] FIG8 is a schematic diagram of generating a first encryption key in one embodiment;
[0046] FIG9 is a schematic diagram of a process for obtaining a signature private key in one embodiment;
[0047] FIG10 is a schematic diagram of inputting a verification code in one embodiment;
[0048] FIG11 is a schematic diagram of a details page in one embodiment;
[0049] FIG12 is a flow chart of a method for processing virtual resources in one embodiment;
[0050] FIG13 is a block diagram of a resource processing device according to an embodiment;
[0051] FIG14 is a structural block diagram of a device for obtaining a signature private key in one embodiment;
[0052] FIG15 is a diagram showing the internal structure of a computer device according to one embodiment;
[0053] FIG16 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0054] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0055] The resource processing method provided in the embodiments of the present application can be applied in the application environment shown in FIG1 . In this embodiment, a terminal 102 communicates with a server 104 via a network. A data storage system can store data that the server 104 needs to process. The data storage system can be integrated with the server 104, or it can be located in the cloud or on another server. The terminal 102 can send a digital account creation request to the server 104. In response to the creation request, the server 104 can create a digital account and a signature private key and a signature public key bound to the digital account. The signature private key is then sent to the terminal 102, so that the terminal 102 can generate a resource processing request including a digital signature based on the signature private key. When the server 104 receives the resource processing request including a digital signature, it can verify the digital signature using the signature public key bound to the digital account and, if the verification is successful, process the virtual resources in the digital account according to the resource processing request. The terminal 102 can be, but is not limited to, various desktop computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart car devices, etc. The portable wearable device may be a smart watch, a smart bracelet, a head-mounted device, etc. The server 104 may be implemented as an independent server or a server cluster consisting of multiple servers, or may be a cloud server.
[0056] It is worth noting that the present application involves blockchain technology. For example, the shared account in the present application is a shared account set up based on the blockchain. The blockchain network involved in the embodiment of the present invention can be a network generated based on a distributed system. Referring to Figure 2, Figure 2 is an optional structural diagram of the distributed system provided by the embodiment of the present invention applied to the blockchain network. The blockchain network is formed by multiple nodes (any form of computing device in the access network, such as servers, user terminals), and the nodes form a peer-to-peer (Peer To Peer) network. The peer-to-peer protocol is an application layer protocol running on the Transmission Control Protocol (TCP) protocol. In a distributed system, any machine such as a server or terminal can join and become a node. The node includes a hardware layer, an intermediate layer, an operating system layer, and an application layer. The functions of each node in the blockchain network include:
[0057] 1) Routing: A basic function of a node, used to support communication between nodes.
[0058] In addition to the routing function, nodes can also have the following functions:
[0059] 2) Applications, deployed in the blockchain, implement specific services based on actual business needs, record data related to the implementation of functions to form record data, carry digital signatures in the record data to indicate the source of the task data, and send the record data to other nodes in the blockchain system for other nodes to add the record data to a temporary block when they successfully verify the source and integrity of the record data.
[0060] It is worth noting that this application also involves cloud technology. For example, the smart contract server in this application can be a cloud server that provides cloud computing services. Cloud technology refers to a hosting technology that unifies hardware, software, network and other resources within a wide area network or local area network to achieve data computing, storage, processing and sharing.
[0061] It should be noted that the terms "first", "second" and similar terms used in this application do not indicate any order, quantity or importance, but are only used to distinguish different components. Unless the context clearly indicates otherwise, the singular form "a", "an" or "the" and similar terms do not indicate a quantity limitation, but rather indicate the presence of at least one. The quantities of "multiple" or "multiple copies" mentioned in the various embodiments of this application refer to the quantity of "at least two", for example, "multiple" refers to "at least two" and "multiple copies" refers to "at least two copies".
[0062] In one embodiment, as shown in FIG3 , a resource processing method is provided, which is described by taking the method applied to the server in FIG1 as an example, including the following steps:
[0063] Step 302: In response to the digital account creation request, extract the digital account creator identifier from the digital account creation request.
[0064] Specifically, when a digital account needs to be created, the digital account creator can trigger the terminal to generate a digital account creation request and send the digital account creation request to the server, so that the server can receive the digital account creation request. For example, referring to Figure 4, the terminal corresponding to the digital creator can display the account creation page shown in Figure 4, so that the digital creator can enter the information required to create a digital account in the account creation page, for example, the digital account creator identifier can be entered. When the digital creator clicks the OK control in the account creation page, the terminal corresponding to the digital creator can generate a digital account creation request carrying the digital account creator identifier. Among them, the digital account creator identifier refers to the information used to identify the digital creator, for example, the digital account creator identifier can be a user name, mobile phone number or email address, etc. Figure 4 shows a schematic diagram of an account creation page in one embodiment.
[0065] The digital account creation request is used to create a digital account. For a digital account, each stored virtual resource has a different resource identifier, which refers to information that uniquely identifies a virtual resource. Each virtual resource can correspond to a different resource quantity. For example, a virtual resource with a quantity of 100 can be considered one resource, and a resource with a quantity of 1 can be considered another virtual resource. When a single virtual resource circulates between different digital accounts, the identifier of that virtual resource does not change with changes in the digital account. A digital account can be a standard account owned by a single digital account creator or a shared account owned by multiple digital account creators. Furthermore, the virtual resources stored in a digital account are uniformly issued by a central management agency, and only the central management agency can split a single virtual resource into multiple virtual resources and assign different identifiers to each of the multiple virtual resources. Digital accounts can exchange stored virtual resources. For example, two 50-resource shares of virtual resources in digital account A can be exchanged with one 100-resource share of virtual resources in digital account B. When two 50-resource shares of virtual resources are exchanged from digital account A to digital account B, the identities of the two 50-resource shares do not change with the change of digital accounts. Virtual resources are a general term for substances that can be utilized or are capable of being utilized. Virtual resources can be computer resources or currency. Computer resources can include CPU resources, time slice resources, GPU resources, etc.
[0066] In one embodiment, when the digital account to be created is a shared account, the digital account creator can click the shared account creation control, so that the terminal corresponding to the digital account creator can display the account creation page, and then the digital account creator can enter multiple digital account creator identifiers on the account creation page. For example, the digital account creator (user A) can enter his or her own email address and mobile phone number, and can also enter the email address and mobile phone number of user B. Then, the terminal corresponding to the digital account creator can generate a digital account creation request based on the multiple digital account creator identifiers entered. It is easy to understand that in the above example, user A and user B are users who jointly own a shared account.
[0067] Alternatively, user A can enter their own digital account creator identifier on the account creation page, for example, by entering their own email address and mobile phone number, and click the account identifier addition control, so that the terminal corresponding to user A can generate a digital account creation request carrying user A's digital account creator identifier and send the digital account creation request to the server, for example, generating digital account creation request A and sending digital account creation request A to the server. The terminal corresponding to user A can also generate an account identifier addition request carrying the request identifier of the digital account creation request, for example, generating an account identifier addition request carrying the request identifier of digital account creation request A. User A can select the next user to enter the digital account creator identifier from the friend list, for example, selecting user B, and then the terminal corresponding to user A can send the account identifier addition request to user B. When the terminal corresponding to user B receives the account identifier addition request, the terminal corresponding to user B can display the account creation page. User B can enter his or her own digital account creator identifier on the account creation page, for example, by entering his or her own email address and mobile phone number. Then, the terminal corresponding to user B can generate a digital account creation request carrying user B's digital account creator identifier and the request identifier in the received digital account creation request. For example, it can generate a digital account creation request B carrying the request identifier of digital account creation request A and user B's digital account creator identifier, and send digital account creation request B to the server. Of course, user B can also trigger his or her own terminal to generate an account identifier addition request and send the digital account identifier addition request to the remaining digital account creators (for example, user C). Then, after the last digital account creator account enters its own digital account creator identifier on the creation page, the last digital account creator can click the completion control. The terminal corresponding to the last digital account creator can generate a digital account creation request corresponding to the last digital account creator based on the request identifier in the received account identifier addition request and the identifier of the last digital account creator, and add an end identifier to the digital account creation request corresponding to the last digital account creator. When the server receives a digital account creation request with an end identifier added, the server can use the digital account creation request with the end identifier as a basis, search for digital account creation requests related to the digital account creation request with the end identifier in sequence, extract the digital account creator identifier from the found digital account creation request, and create a shared digital account based on the extracted digital account creator identifier.For example, the digital account creator identifier of user C and the identifier of digital account creation request B can be extracted from digital account creation request C. The server searches for digital account creation request B based on the identifier of digital account creation request B and extracts the digital account creator identifier of user B and the identifier of digital account creation request A from digital account creation request B. The server searches for digital account creation request A based on the identifier of digital account creation request A and extracts the digital account creator identifier of user A from digital account creation request A. Thus, the identifiers of all digital account creators are obtained.
[0068] Step 304: Create a digital account for storing virtual resources according to the digital account creator identifier.
[0069] Specifically, the server creates a digital account based on the digital account creator identifier. For example, the server encrypts the digital account creator identifier to generate an encrypted account name, which serves as the name of the digital account. In one embodiment, the server may also create a smart contract for the created digital account to manage the created digital account through the smart contract. A smart contract is a computer protocol designed to communicate, verify, or enforce contracts in an information-based manner. Smart contracts allow for trusted transactions without a third party, and these transactions are traceable and irreversible. The concept of smart contracts was first proposed by Nick Szabo in 1994. In layman's terms, a smart contract is a pre-set computer program that automatically executes trusted contract content without the involvement of a third-party intermediary, with all operations publicly traceable and irreversible. For example, smart contract parameters can be set and used to generate a smart contract for a digital account. When a smart contract is used to control the total amount of resources in a digital account, these parameters may include resource control conditions, resource control duration, and so on.
[0070] Step 306: Obtain a preset master public key, and generate a signature public key for the digital account based on the master public key and the digital account creator identifier.
[0071] Specifically, when a server creates a digital account, it may also generate a signature public key based on the digital account creator's identifier and a preset master public key. For example, the server may obtain a preset signature public key generation algorithm and use it to generate a signature public key based on the digital account creator's identifier and the master public key. The preset master public key is a pre-set public key. In one embodiment, different servers may have different preset master public keys, or different digital account creators may have different preset master public keys. Alternatively, the preset master public key in the server may be updated at preset intervals. This embodiment is not limited to this.
[0072] In one embodiment, referring to FIG5 , a virtual machine is running in the server, and a signature public key can be generated through the virtual machine. For example, multiple signature public key generation algorithms can be pre-set. When a signature public key needs to be generated, a signature public key algorithm can be screened out from the multiple signature public key generation algorithms, and the screened signature public key algorithm is referred to as the target signature public key algorithm. Furthermore, the algorithm source code corresponding to the target signature public key algorithm can be obtained, and based on a preset virtual machine instruction set, the algorithm source code is compiled into a virtual algorithm program recognizable by the virtual machine. The virtual algorithm program is run through the virtual machine to generate a signature public key using the digital account creator identifier. FIG5 shows a schematic diagram of generating a signature public key in one embodiment.
[0073] In one embodiment, the server identifier of the current server can be obtained, and based on the server identifier, a target signature public key algorithm that matches the server's operating capabilities can be selected from multiple encryption algorithms; alternatively, the target signature public key algorithm can be randomly selected from multiple encryption algorithms. In one embodiment, the algorithm source code can be compiled based on a system instruction set that matches the server's operating system to obtain an intermediate code composed of system instructions preset in the system instruction set; based on a mapping relationship between a preset virtual machine instruction set and the system instruction set, the intermediate code can be converted and compiled into a virtual algorithm program recognizable by the virtual machine.
[0074] In the embodiments of the present application, a virtual machine instruction set is pre-set. This virtual machine instruction set is not a general-purpose instruction set, but rather an instruction set specifically developed for a specific application. Each virtual machine instruction in this pre-set virtual machine instruction set corresponds to a system instruction in the system instruction set. Thus, based on the mapping between the pre-set virtual machine instruction set and the system instruction set, the server can convert and compile the intermediate code into a virtual algorithm program recognizable by the virtual machine.
[0075] In one embodiment, the server can also generate a signature public key based solely on the digital account creator's identifier. For example, referring to Figure 6 , the server can generate a signature public key based on the digital account creator's mobile phone number, email address, username, and other information and a signature public key generation algorithm. Figure 6 shows a schematic diagram of generating a signature public key in another embodiment.
[0076] In one embodiment, once a master public key is generated, the master public key may be stored in a blockchain and passed through consensus by consensus nodes in the blockchain.
[0077] Step 308: Obtain the master private key paired with the master public key, and generate a signature private key paired with the signature public key based on the master private key and the signature public key.
[0078] Specifically, when a signature public key needs to be generated, the server can obtain a preset master private key and generate a signature private key based on the master private key and the signature public key. The master private key is the private key that is paired with the master public key. When the master public key is generated, a corresponding master private key is generated at the same time.
[0079] In one embodiment, the server may generate a signature private key using the following formula: ID_Pri = s*ID_Pub, where s is the master private key and ID_Pub is the signature public key.
[0080] In one embodiment, the server may also trigger a virtual machine to generate a master private key. The method for generating the master private key through the virtual machine may refer to the method for generating the master public key through the virtual machine.
[0081] In one embodiment, a signature private key can be generated in the trusted execution environment of the server. For example, the server uses TEE (Trusted Execution Environment, a trusted execution environment protected by a hardware chip) as its hardware basis, runs the signature private key generation logic in the TEE, and the signature private key generation component is used to generate the signature private key based on the signature public key and the master private key. Among them, TEE: The trusted execution environment protected by the hardware chip is called TEE (Trusted Execution Environment). TEE has an inherent signature key for protecting data privacy and authenticating data integrity, source reliability, etc.; it has memory access control and memory encryption mechanisms with the outside world, that is, the outside world, including the operating system, has no access rights to the memory space within the trusted computing domain; TEE has a remote authentication mechanism for proving to the remote end that the logic running in a trusted computing environment has not been tampered with. The effect achieved by using trusted computing is that the data and program logic in the trusted computing domain cannot be spied on by the external environment without active output.
[0082] In step 310, the signature private key is sent to the terminal corresponding to the digital account creator identifier; the sent signature private key is used to trigger the terminal to generate a digital signature based on the signature private key; the resource processing request including the digital signature is received as feedback from the terminal; and after the digital signature is verified based on the signature public key of the digital account, the virtual resources in the digital account are processed according to the resource processing request.
[0083] Specifically, after generating a signature private key that matches the signature public key, the server can securely send the generated signature private key to the terminal corresponding to the digital account creator's identity, so that the terminal can securely store the received signature private key. In one embodiment, once the signature private key is generated, it indicates that the digital account has been created. At this time, the server can send a digital account creation success message along with the signature private key to the terminal. The terminal can then display the digital account creation success message to the digital account creator and securely store the signature private key.
[0084] In one embodiment, when a digital account creator desires to process virtual resources in a digital account, for example, when the digital account creator desires to increase virtual resources in the digital account, the digital account creator can trigger the terminal to display a virtual resource information collection page, so that the digital account creator can enter relevant information on the virtual resource information collection page, such as the desired amount of virtual resources and virtual resources to be increased. The terminal can then sign the information entered by the digital account creator based on the signature private key to generate a digital signature, generate a resource processing request based on the digital signature, and send the resource processing request to the server. When the server receives the resource processing request, the server can verify the digital signature using the signature public key paired with the issued signature private key. After verification, the server can process the virtual resources in the digital account in response to the resource processing request. For example, the server can transfer the desired amount of virtual resources from the virtual resource source to the digital account.
[0085] In one embodiment, referring to FIG7 , the digital account creator can also enter a digital account creator identifier in the terminal, such as a mobile phone number or email address. The terminal can then send the digital account creator identifier to the server. The server can determine the corresponding signature public key based on the received digital account creator identifier. For example, the server can obtain a preset signature public key generation algorithm, generate a signature public key based on the received digital account creator identifier using the signature public key generation algorithm, and return the signature public key to the terminal so that the terminal displays the received signature public key. Furthermore, after receiving the signature public key, the terminal can verify the received signature public key using a stored signature private key and display the verification result. FIG7 shows a schematic diagram of displaying the signature public key in one embodiment. The digital account creator can enter one digital account creator identifier or multiple digital account creator identifiers. If only one digital account creator identifier is entered, the server can find the remaining digital account creator identifiers used when creating the digital account based on the entered digital account creator identifier.
[0086] In the resource processing method described above, upon receiving a digital account creation request, the digital account creator identifier is extracted from the digital account creation request, and a digital account and a signature public key for the digital account are generated based on the digital account creator identifier. By generating the signature public key, a signature private key can be generated based on the signature public key. The signature private key can then be sent to the terminal corresponding to the digital account creator identifier, so that the terminal corresponding to the digital account creator identifier can generate a resource processing request including a digital signature using the received signature private key. When the digital signature is verified successfully using the signature public key, the server can respond to the resource processing request to process the virtual resources in the digital account. Because the signature public and private keys are generated based on a signature public key generation algorithm and the digital account identifier, this application does not require additional maintenance of the correspondence between the digital account creator identifier and the signature public and private keys. In other words, there is no need to store the digital account creator identifier and the signature public and private keys in a centralized database. When determining the signature public key corresponding to the digital account creator identifier is required, this application can process the digital account creator identifier based on the signature public key generation algorithm to infer the signature public key. Compared with the traditional method of storing the digital account creator identifier and public and private keys in a centralized database, this application does not need to store the digital account creator identifier and the signature public and private keys in a centralized database. Therefore, it reduces the security issues of digital accounts caused by the centralized database being attacked and information stolen, thereby improving the security of digital accounts.
[0087] In addition, a pair of signature public and private keys are additionally generated through the master public and private keys. The virtual resources in the digital account can be processed based on the signature public and private keys in the future, rather than processing the virtual resources in the digital account through the master public and private keys. In this way, even if the master public and private keys are leaked, it will not affect the security of the digital account, thereby further improving the security of the digital account.
[0088] In one embodiment, the above method also includes a master public key generation step, which includes: generating a random number and using the random number as the master private key; obtaining a first elliptic curve and determining a first base point on the first elliptic curve; performing a doubling operation on the first base point and the master private key to obtain a master public key paired with the master private key.
[0089] Specifically, before generating the signature public key and signature private key, a pair of master public and private keys can be generated. When the master public and private keys need to be generated, the server can generate a random number and use this random number as the master private key. Furthermore, the server can obtain an elliptic curve, which is referred to as the first elliptic curve. The server can determine the base point of the first elliptic curve (also known as a generator), refer to this base point of the first elliptic curve as the first base point, perform a multiplication operation on the first base point and the master private key to obtain the master private key multiplication point, and use this master private key multiplication point as the master public key paired with the master private key.
[0090] In one embodiment, a server generates a random number s∈[1, N-1] as a master private key and calculates an element P=[s]*G on a first elliptic curve as a master public key, where the first elliptic curve is an additive cyclic group of order N, which is a prime number. G is a base point of the first elliptic curve. [s]*G represents a point multiplied by s at G. The random number can be a positive integer.
[0091] A base point is a point on an elliptic curve and serves as the basis for determining its doubling points. Consider an elliptic curve in a coordinate system (X and Y axes) with a base point. If a tangent to the base point intersects the elliptic curve, then the point of intersection symmetric with respect to the coordinate system's X-axis is the double point of the base point. A line passing through the double point of the base point and intersecting the elliptic curve, and the point of intersection symmetric with respect to the coordinate system's X-axis, is the triple point, and so on. Point doubling operations are a method for calculating doubling points, and can be performed using the fast power algorithm and the Qin Jiushao algorithm.
[0092] In the above embodiment, by generating a master public key and a master private key, a signature public key and a signature private key can be subsequently generated based on the master public key and the master private key.
[0093] In one embodiment, a signature public key of a digital account is generated based on a master public key and a digital account creator identifier, including: when multiple digital account creator identifiers are extracted from a digital account creation request, concatenating the multiple digital account creator identifiers and the master public key to obtain a concatenated identifier; performing a hash operation on the concatenated identifier to obtain a hash identifier; and generating a signature public key based on the hash identifier.
[0094] Specifically, the digital account creator can enter multiple digital account creator identifiers on the account creation page, such as an email address, mobile phone number, and username, and the terminal corresponding to the digital account creator can then generate a digital account creation request carrying multiple digital account creator identifiers. When the server receives the digital account creation request, the server can extract multiple digital account creator identifiers from the digital account creation request, such as the email address, mobile phone number, and username. The server can then concatenate the master public key with the extracted multiple digital account creator identifiers, such as concatenating the email address, mobile phone number, username, and master public key to obtain a concatenated identifier.
[0095] Furthermore, the server performs a hash operation on the splicing identifier to obtain a hash identifier. For example, the server may perform a hash operation on the splicing identifier using a preset hash algorithm to obtain a hash identifier, and then generate a signature public key based on the hash identifier.
[0096] In this embodiment, when multiple digital account creator identifiers are available, a concatenated identifier can be obtained by concatenating the multiple digital account creator identifiers. Subsequently, a signature public key can be derived based on the concatenated identifier, thereby achieving the generation of a signature public key. Compared to only being able to generate a signature public key based on a single digital account creator identifier, this embodiment can generate a signature public key based on multiple digital account creator identifiers even when multiple digital account creator identifiers are received, thereby greatly improving the flexibility of signature public key generation.
[0097] In one embodiment, generating a signature public key based on the splicing identifier includes: obtaining a second elliptic curve and determining a second base point on the second elliptic curve; and fusing the second base point with the hash identifier according to the second elliptic curve to obtain the signature public key.
[0098] Specifically, when it is necessary to generate a signature public key based on the splicing identifier, the server can obtain the second elliptic curve and determine the base point of the second elliptic curve (also called the generator), and refer to the base point of the second elliptic curve as the second base point. Furthermore, the server fuses the second base point with the hash identifier based on the second elliptic curve to obtain the signature public key. For example, the server can obtain the signature public key through the formula: ID_PUB = H(ID) * G. Among them, H is the hash function, ID is the splicing identifier, G is the second base point on the second elliptic curve, that is, the generator, and ID_PUB is the signature public key.
[0099] In the above embodiment, by determining the second base point, the signature public key can be quickly obtained based on the second base point, thereby improving the efficiency of generating the signature public key.
[0100] In one embodiment, generating a signature private key paired with the signature public key based on the master private key and the signature public key includes: multiplying the master private key with the signature public key to obtain the signature private key paired with the signature public key.
[0101] In one embodiment, sending the signature private key includes: obtaining a verification code and determining an encryption key generation algorithm; processing the verification code through the encryption key generation algorithm to obtain a first encryption key; encrypting the signature private key according to the first encryption key to obtain an encrypted private key; sending the encrypted private key and the verification code to a terminal corresponding to the digital account creator identifier; the sent encrypted private key and verification code are used to trigger the terminal to decrypt the encrypted private key through the verification code to obtain the signature private key.
[0102] Specifically, to securely distribute the signature private key, the server may generate a verification code. For example, the server may generate a random verification code based on a verification code generation algorithm. Furthermore, the server may determine a preset encryption key generation algorithm, process the verification code using the encryption key generation algorithm to obtain a first encryption key, and then encrypt the signature private key using the first encryption key to obtain an encrypted private key. The encryption key generation algorithm can be freely configured as needed and is not limited in this embodiment.
[0103] Furthermore, the server sends the first encryption key to the terminal corresponding to the digital account creator identifier. For example, the server sends the first encryption key and the verification code to the terminal corresponding to the digital account creator identifier via a secure link (e.g., HTTPS, Hypertext Transfer Protocol Secure). When the terminal receives the first encryption key and the verification code, it can decrypt the first encryption key using the verification code to obtain the signature private key.
[0104] In this embodiment, since the specific content of the verification code has a certain degree of randomness, encrypting the signature private key with the verification code can improve the randomness of the encryption, thereby improving the encryption effect. By sending the encrypted signature private key to the terminal, the transmission security of the signature private key can be improved, reducing the risk of the signature private key being stolen during the transmission process.
[0105] In one embodiment, the verification code is processed by an encryption key generation algorithm to obtain a first encryption key, including: obtaining a salt value, and generating an initial key block of the current round based on the verification code and the salt value; obtaining the key block of the previous round, and splicing the initial key block of the current round with the key block of the previous round to obtain the key block of the current round; when the byte length of the key block of the current round does not meet the preset length condition, entering a round, taking the next one as the current round, and returning to the step of generating the initial key block of the current round based on the verification code and the salt value, and continuing to execute until the byte length of the key block of the current round meets the preset length condition; and taking the key block of the last round as the first encryption key.
[0106] In cryptography, the process of inserting a specific string at any fixed position in the password so that the hashed result does not match the hashed result of the original password is called "salting". The specific string is the salt value.
[0107] In this embodiment, when the verification code needs to be processed by an encryption key algorithm to generate a first encryption key, the server can obtain a preset salt value, which can be a string, and then the server generates an initial key block for the current round based on the verification code and the salt value.
[0108] The server can obtain the key block generated in the previous round and concatenate the key block generated in the previous round with the initial key block generated in the current round to obtain the key block of the current round. For example, referring to Figure 8, the server can place the initial key block generated in the current round (e.g., the 5th round) after the key block generated in the previous round (e.g., the 4th round) to obtain the key block generated in the current round. Furthermore, the byte length of the first encryption key to be generated can be pre-set, and the byte length of the key block generated in the current round is compared with the byte length of the first encryption key to be generated. When the byte length of the key block generated in the current round is less than the byte length of the first encryption key to be generated, it is determined that the byte length of the key block of the current round does not meet the preset length condition. At this time, it is necessary to execute the key block generation process of the next round. The server enters the next round (e.g., the 6th round), takes the next round as the current round, and returns to the step of generating the initial key block of the current round based on the verification code and the salt value and continues to execute until the byte length of the key block of the current round meets the preset length condition. For example, the server generates the initial key block of the 6th round, concatenates the initial key block of the 6th round with the key block of the 5th round to obtain the key block of the 6th round. If the byte length of the key block of the 6th round is equal to the byte length of the first encryption key to be generated, it is determined that the byte length of the key block of the current round meets the preset length condition, and the generation of the key block is terminated at this time.
[0109] Furthermore, when the key block generation process ends, the server may use the key block of the last round as the first encryption key, for example, the key block of round 6 as the first encryption key. Figure 8 shows a schematic diagram of generating the first encryption key in one embodiment.
[0110] In one embodiment, the server can obtain a preset byte length as the byte length of the first encryption key to be generated, and determine the byte length of the initial key block generated in a single round. The byte length of the first encryption key to be generated is divided by the byte length of the initial key block generated in a single round to obtain the round to be performed. After the server executes the round to be performed, the first encryption key can be obtained. When the byte length of the first encryption key to be generated is divided by the byte length of the initial key block generated in a single round, and the division result is not an integer, the server can adjust the byte length of the first encryption key to be generated, or adjust the byte length of the initial key block generated in a single round, so that the division result of the two is a positive integer. In this way, the flexibility of generating the first encryption key is improved.
[0111] In the above embodiment, by executing multiple rounds of key block generation process, the complexity of the first encryption key can be increased, so that a complex encryption private key can be obtained through the complex first encryption key, thereby reducing the probability of the encryption private key being cracked and improving the security of the encryption private key.
[0112] In one embodiment, generating an initial key block for the current round based on a verification code and a salt value includes: obtaining encoded data, concatenating the salt value with the encoded data to obtain a target salt value; performing a hash operation on the verification code and the target salt value to obtain a first hash key block; generating a current hash key block based on the verification code and the previous hash key block in a current hash key block generation process starting from the second hash key block generation process; using the next hash key block generation process as the current hash key block generation process, returning to the step of determining the current hash key block based on the verification code and the previous hash key block, and continuing to execute until a preset number of hash key blocks are generated; and using the last hash key block as the initial key block for the current round.
[0113] Specifically, in a single round, the server can obtain preset encoded data and concatenate the salt value with the preset encoded data to obtain a target salt value. The encoded data is data of a preset byte length obtained by encoding a preset number, for example, i is a 32-bit number encoded as i. The server performs a hash operation on the target salt value to obtain the first hash key block.
[0114] For the current hash block key generation process starting from the second hash key block generation process, the server may generate the current hash key block based on the verification code and the previous hash key block. For example, for the second hash key block generation process, the server generates the second hash key block based on the verification code and the first hash key block. For the third hash key block generation process, the server generates the third hash key block based on the verification code and the second hash key block. Furthermore, the server determines whether a preset number of hash key blocks have been generated. If the preset number of hash key blocks have not been generated, the server enters the next hash key block generation process and returns to the step of determining the current hash key block based on the verification code and the previous hash key block, continuing until the preset number of hash key blocks have been generated.
[0115] When a preset number of hashed key blocks have been generated, the server uses the last hashed key block as the initial key block for the current round. For example, if the preset number is 10 and 10 hashed key blocks have been generated, the server will continue to generate hashed key blocks and use the 10th hashed key block as the initial key block for the current round. This allows the server to subsequently generate key blocks for the current round based on the initial key block of the current round.
[0116] In one embodiment, the step of generating the current hash key block according to the verification code and the previous hash key block includes: performing a hash operation on the verification code and the previous hash key block to obtain the current hash key block.
[0117] In one embodiment, the step of generating a first encryption key includes:
[0118] The verification code (Code) and a salt value (Salt) are used as input parameters, and then the operation is repeated to finally generate the first encryption key Key.
[0119] The first encryption key can be generated by the following formula: Key = F1 (Code, Salt, C, kLen)
[0120] Where C is the number of iterations, kLen is the byte length of the first encryption key, and F1 is the function used to generate the first encryption key.
[0121] The value of the first encryption key Key is formed by concatenating one or more initial key blocks. The number of initial key blocks is kLen / hLen, where hLen is the byte length of the initial key block. In other words, if the result output by function F1 is shorter than the desired first encryption key, multiple results must be concatenated to meet the required first encryption key length, as shown in the following formula:
[0122] Key=T1||T2…||T(kLen / hLen), where T1, T2… are all initial key blocks. Each initial key block is obtained by function F2.
[0123] The steps of obtaining the initial key block in function F2 can be implemented using the following formula: Ti = F2(Code, Salt, R, i). In function F2, R operations are performed to obtain the initial key block. i is a preset number, and encoding i can obtain the encoded data. Among them, the first time, function F2 will concatenate the salt value Salt with the 32-bit number encoded by i to obtain the target salt value. Using the target salt value and the verification code, the first hash key block is obtained, that is, P1 = H(Code, Salt||INT_32_BE(i)), where H is the hash operation performed on Code and Salt||INT_32_BE(i) as input to obtain the output P1.
[0124] In the subsequent R-1 hash key block generation process, the hash key obtained last time will be used to obtain the current hash key block, that is: P2 = H (Code, P1), U3 = H (Code, P2) ...
[0125] When the last hash key block is obtained, the last hash key block is used as the initial key block, for example, PR is used as the initial key block generated in a certain round.
[0126] In the above embodiment, by generating hash key blocks in multiple rounds, the generated hash key blocks can be made more complex, thereby obtaining a more complex initial key block based on the more complex hash key block, and then obtaining a more complex first encryption key based on the more complex initial key block.
[0127] In one embodiment, the method further includes: receiving a resource processing request including a digital signature; verifying the digital signature using a signature public key; after verification, responding to the resource processing request via a smart contract associated with the digital account to process resources in the digital account and obtain a resource processing result; and storing the resource processing result in a blockchain. The resource processing result stored in the blockchain may be subject to consensus by consensus nodes in the blockchain.
[0128] Specifically, after the terminal corresponding to the digital account creator identifier obtains the signature private key, when the digital account creator wishes to process virtual resources in the digital account, the terminal corresponding to the digital account creator can obtain resource processing information. The terminal can then sign the resource processing information to obtain a digital signature, generate a resource processing request based on the digital signature and the digital account creator identifier, and send the resource processing request to the server. When the server receives the resource processing request carrying the digital signature and the digital account creator identifier, the server can infer the signature public key from the digital account creator identifier. For example, the server obtains a preset master public key and calculates a signature public key based on the master public key and the digital account creator identifier in the same manner as the signature public key. The calculated signature public key is the inferred signature announcement, and the digital signature is then verified using the inferred signature public key. Once verification is successful, the server can respond to the resource processing request, determine the digital account corresponding to the digital account creator identifier, and process the virtual resources in the digital account through the smart contract bound to the digital account.
[0129] In one embodiment, assuming that resource processing information m is desired to be signed, the third elliptic curve parameters used are D = (p, a, b, G, n, h), where G is the base point corresponding to the signature private key KeyS; a random integer k is generated, 1 <= k <= n-1; the point P = k*G = (x1, y1) is calculated, where (x1, y1) is the fusion point; let e = x1 mod n, if e = 0, then return to the step of generating a random integer k and continue to execute, where e is the first remainder and n is the order of the elliptic curve; calculate z = hauh(m), and the hash function can be selected from UHA-2 calculation; calculate u = k -1(z+eEa)(mod n), if u is 0, then return to the step of generating a random integer k and continue executing, where u is the second remainder; the digital signature (e,u) is obtained by combining the first remainder and the second remainder.
[0130] In one embodiment, when the digital signature needs to be verified, the server calculates z=hash(m), where m is the resource processing information and hash() is a hash operation; calculates P1=zu -1 mod n,P2=eu -1 mod n, where n is the order of the third elliptic curve, u is the second remainder in the digital signature, P1 is the third remainder, and P2 is the fourth remainder; calculate the point (x1, y1) = P1G + P2Qa, where Qa is the signature public key and G is the base point of the third elliptic curve; verify the equation: whether e is equal to x1 mod n, where e is the first remainder in the digital signature; if so, the digital signature verification is determined to be successful, and the resource processing request can be responded to through the smart contract to process the virtual resources in the digital account.
[0131] In one embodiment, when a smart contract needs to respond to a resource processing request, the smart contract can determine whether the resource processing request is legitimate and, based on the resource processing information in the resource processing request, determine whether the resource processing request meets the conditions stipulated in the smart contract. If the conditions are met, the virtual resources in the digital account are processed according to the resource processing information in the resource processing request. For example, if the smart contract stipulates that a maximum of 1,000 virtual resources can be transferred to the digital account per day, if the resource processing information indicates that the digital account creator desires to transfer 10,000 virtual resources to the digital account, the resource processing request is determined to not meet the conditions stipulated in the smart contract, and the server returns a message indicating that the resource processing failed. If the resource processing information indicates that the digital account creator desires to transfer 500 virtual resources to the digital account, the resource processing request is determined to meet the conditions stipulated in the smart contract, and the server transfers 500 virtual resources to the digital account, and the server returns a message indicating that the resource processing was successful. Furthermore, after processing the virtual resources in the digital account, the resource processing results can be stored in the blockchain. The resource processing results stored in the blockchain can be reached through consensus among the consensus nodes in the blockchain.
[0132] In one embodiment, processing virtual resources in a digital account may include increasing or decreasing the amount of virtual resources in the digital account. For example, virtual resources may be added to the digital account to increase the amount of virtual resources in the digital account, or virtual resources may be deducted from the digital account to decrease the amount of virtual resources in the digital account.
[0133] In the above embodiment, by responding to the resource processing request after the verification is passed, the security of the virtual resource processing can be greatly improved.
[0134] In one embodiment, as shown in FIG9 , a method for obtaining a signature private key is provided. The method is described by applying the method to the terminal corresponding to the digital account creator identifier in FIG1 , including the following steps:
[0135] Step 902: Obtain a digital account creator identifier, and generate a digital account creation request according to the digital account creator identifier.
[0136] Specifically, when a digital account needs to be created, the digital account creator can trigger the terminal to display the account creation page and enter the digital account creator identifier in the account creation page, such as entering his or her own mobile phone number, email address and account name, etc. In this way, the terminal can respond to the digital account creator identifier input operation, obtain the digital account creator identifier, and generate a digital account creation request based on the digital account creator identifier.
[0137] Step 904, sending a digital account creation request; the sent digital account creation request is used to trigger the creation of a digital account, a signature public key and a signature private key according to the digital account creator identifier, and is used to trigger the generation of a verification code, and encrypt the signature private key based on the verification code to obtain an encrypted private key.
[0138] Specifically, when a terminal generates a digital account creation request, it can send the digital account creation request to the server, which then creates a digital account, a public signature key, and a private signature key based on the digital account creator identifier in the received digital account creation request. After the server generates the private signature key, it can also generate a verification code and encrypt the private signature key using the verification code to obtain an encrypted private key. The encrypted private key and verification code are then sent to the terminal.
[0139] Step 906: Receive the encrypted private key and verification code.
[0140] Step 908, decrypt the encrypted private key through the verification code to obtain the signature private key; the signature private key is used to generate a resource processing request including a digital signature through the signature private key during the resource processing process; the digital signature is used to trigger the processing of virtual resources in the digital account according to the resource processing request after the digital signature is verified through the signature public key bound to the digital account.
[0141] Specifically, after the server generates an encrypted private key, it can send the encrypted private key and verification code together to the terminal, allowing the terminal to receive the encrypted private key and verification code sent by the server. Upon receiving the encrypted private key and verification code, the terminal can decrypt the encrypted private key using the verification code to obtain the signature private key. During resource processing, the terminal can then generate a digital signature using the signature private key, generate a resource processing request using the digital signature, and send the resource processing request to the server. Upon receiving the resource processing request, the server can verify the digital signature using the signature public key and, if verification is successful, process the virtual resources in the digital account in response to the resource processing request.
[0142] In the above-described signature private key acquisition method, the digital account creator identifier can be obtained in response to a digital account creator identifier input operation. Sending the digital account creator identifier triggers the server to create a digital account, a signature public key, and a signature private key, and also triggers the server to encrypt the signature private key using a verification code to obtain an encrypted private key. By obtaining the encrypted private key and verification code generated by the server, the encrypted private key can be decrypted using the verification code to obtain the signature private key. The signature private key is then used to ensure the security of resource processing during resource processing. Because the signature public and private keys are generated based on a signature public key generation algorithm and the digital account identifier, this application eliminates the need to maintain a separate correspondence between the digital account creator identifier and the signature public and private keys. This reduces security issues associated with digital accounts caused by attacks on the database storing the correspondence between the digital account creator identifier and the signature public and private keys. Because this application distributes the encrypted private key to the terminal, compared to directly distributing the signature private key to the terminal, the risk of the signature private key being stolen during distribution is reduced, further enhancing the security of the digital account.
[0143] In one embodiment, the encrypted private key is decrypted by the verification code, and when the decryption is successful, the signature private key is obtained, including: processing the verification code through an encryption key generation algorithm to obtain a second encryption key; decrypting the encrypted private key by the second encryption key, and when the decryption is successful, obtaining the signature private key.
[0144] Specifically, since the server processes the verification code using an encryption key generation algorithm to obtain a first encryption key, and then processes the signature private key using the first encryption key, when the terminal receives the encryption private key and verification code sent by the server, it can process the verification code using the same encryption key generation algorithm to obtain a second encryption key, and then decrypt the encryption private key using the second encryption key. After successful decryption, the signature private key is obtained. It is easy to understand that the process of processing the verification code using the encryption key generation algorithm to obtain the second encryption key can be referred to as the process of processing the verification code using the encryption key generation algorithm to obtain the first encryption key. In one embodiment, the encryption key generation algorithm can be a symmetric key generation algorithm. Therefore, the generated first and second encryption keys are both symmetric keys. A symmetric key refers to a key that uses the same key for encryption and decryption. That is, under correct circumstances, the first and second encryption keys are consistent and can be used for both encryption and decryption.
[0145] In the above embodiment, by obtaining the verification code, a second encryption key can be generated based on the verification code. In this way, the encrypted private key can be decrypted based on the second encryption key to obtain the signature private key.
[0146] In one embodiment, the above method also includes: when receiving a verification code sent by the server, displaying the verification code and the verification code filling box; in response to the filling operation on the verification code filling box, displaying the filled-in verification code; sending the filled-in verification code to the server, and the sent filled-in verification code is used to trigger the server to compare the filled-in verification code with the sent verification code for consistency, and when the filled-in verification code is consistent with the sent verification code, it is determined that the signature private key has been successfully issued.
[0147] Specifically, when the terminal receives the verification code sent by the server, the terminal may also display the verification code and a verification code entry box. In one embodiment, the verification code may specifically be a text message verification code. Furthermore, after the digital account creator views the verification code, the digital account creator may enter the verification code into the verification code entry box. In response to the entry operation in the verification code entry box, the terminal may display the verification code entered by the digital account creator. For example, referring to Figure 10, the digital account creator may enter the verification code in the verification code entry box 1001. Figure 10 shows a schematic diagram of verification code input in one embodiment.
[0148] At the same time, the terminal can also send the verification code entered by the digital account creator to the server, so that the server can compare the verification code entered with the previously sent verification code for consistency. If the verification code entered is consistent with the sent verification code, the signature private key is determined to have been successfully issued. Otherwise, the signature private key issuance process is determined to be incorrect. For example, the server can send the verification code "1234" to the terminal. When the terminal receives "1234", it can display "1234". The digital account creator can then enter "1234" into the verification code field. After the digital account creator enters "1234" into the verification code field, the terminal can send "1234" to the server. The server can then compare the received "1234" with the previously sent "1234". Since the verification code received by the server and the previously sent verification code are both "1234", the server can determine that the signature private key has been successfully issued to the terminal. If the verification code received by the server is "1111" and is inconsistent with the verification code "1234" sent previously, it is determined that the issuance process of the signature private key is incorrect. At this time, the server can generate a verification code verification failure message and send the verification code verification failure message to the terminal, so that the terminal displays the verification code verification failure message. The digital account creator can then determine that the signature private key received by the terminal is incorrect through the displayed verification code verification failure message.
[0149] In this embodiment, by entering a verification code into the verification code input box and sending the entered verification code to the server, the server can perform a consistency comparison between the received verification code and the sent verification code, and based on the comparison result, quickly determine whether the signature private key has been successfully issued to the terminal. For example, this implements the issuance verification of the signature private key, improving the accuracy of the signature private key issued to the terminal.
[0150] In one embodiment, the signature private key is used to trigger the generation of a resource processing request including a digital signature through the signature private key during the resource processing process, including: displaying multiple items, and in response to a selection operation on the multiple items, displaying a details page of the item selected by the selection operation; the details page displays an item acquisition control and the amount of resources required to acquire the item selected by the selection operation; in response to a triggering operation on the item acquisition control, generating a resource processing message based on the amount of resources required to acquire the item selected by the selection operation; signing the resource processing message through the signature private key to obtain a digital signature, and generating a resource processing request based on the digital signature.
[0151] Specifically, after successfully creating a digital account and successfully obtaining the private signature key, the digital account creator can process the virtual resources in the digital account. For example, the digital account creator can trigger the terminal to display multiple items. The digital account creator can select an item from the multiple items through a selection operation and use the selected item as the target item. Then, the terminal can respond to the digital account creator's selection operation and display the target item's details page. The target item's details page can display a target item acquisition control and the amount of resources required to obtain the target item. For example, referring to Figure 11, a confirmation control 1101 can be displayed. This confirmation control is the target item acquisition control mentioned above. The "Resource Amount: 328" 1102 in Figure 11 is the amount of resources required to obtain the target item mentioned above. Figure 11 shows a schematic diagram of a details page in one embodiment.
[0152] When the digital account creator clicks on the item acquisition control, the terminal can respond to the click operation on the item acquisition control and use the information such as the number of target items to be acquired, the amount of resources required to acquire the target items, and the resource receiving account as resource processing information, and generate a resource processing message based on the resource processing information. For example, the terminal can convert the resource processing information according to a preset message format to obtain a resource processing message, or the terminal can directly use the resource processing information as a resource processing message. Furthermore, the terminal signs the resource processing message using a signature private key to obtain a digital signature, wherein the method of signing the resource processing message using a signature private key can refer to the above-mentioned method of signing the resource processing information using a signature private key. This embodiment will not be described in detail here.
[0153] Furthermore, after obtaining the digital signature, the terminal can generate a resource processing request using the digital account creator identifier, digital signature, and resource processing message. Specifically, the terminal generates a resource processing request containing the digital account creator identifier, digital signature, and resource processing message, and sends the resource processing request to the server. Upon receiving the resource processing request, the server can infer the signature public key from the digital account creator identifier and verify the digital signature using the signature public key. Upon successful verification, the server extracts a certain amount of virtual resources from the digital account corresponding to the digital account creator identifier and transfers the extracted virtual resources to the resource receiving account. This certain amount of resources is determined based on the amount of resources required to acquire the items selected in the selection operation. For example, if the digital account creator desires to acquire two target items, and the amount of resources required to acquire each target item is 100, the server extracts 200 virtual resources from the digital account and deposits the extracted 200 virtual resources into the resource receiving account. Once the resource receiving account receives the virtual resources, the user corresponding to the resource receiving account can then send the target items to the digital account creator.
[0154] In one embodiment, when the amount of virtual resources in a digital account changes, the change can be stored in the blockchain. For example, if the amount of virtual resources in the digital account decreases by 200, the remaining amount of resources in the digital account can be stored in the blockchain. The amount of resources stored in the blockchain can be determined through consensus among the consensus nodes in the blockchain.
[0155] In the above embodiment, by obtaining the signature private key, the resource processing message can be signed with the signature private key to obtain a digital signature. After the digital signature is verified, the virtual resources in the digital account can be processed, thereby improving the security of virtual resource processing.
[0156] In one embodiment, after the digital account is created, the server is further used to receive a resource processing request, which carries the account creator identifier, resource processing information and a digital signature of the resource processing request generated by the signature private key corresponding to the digital account creator identifier; determine the corresponding signature public key based on the digital account creator identifier, and verify the digital signature of the resource processing request through the signature public key; if the verification is successful, generate a temporary identifier corresponding to the resource processing request based on the digital account creator identifier and the resource processing information; generate a temporary public key and a temporary private key corresponding to the resource processing request based on the temporary identifier; send the temporary private key, and the sent temporary private key is used to trigger the generation of a request confirmation digital signature through the temporary private key in response to a request confirmation operation triggered for the resource processing request; receive the request confirmation digital signature, and if the request confirmation digital signature is verified successfully through the temporary public key, respond to the resource processing request, process the virtual resources in the digital account corresponding to the digital account creator identifier.
[0157] Specifically, when the digital account creator expects to process the virtual resources in the digital account, the digital account creator identifier can trigger the terminal to generate a resource processing request and send the resource processing request to the server. After the server verifies the digital signature of the resource processing request carried by the resource processing request through the signature public key, the server can generate a temporary identifier corresponding to the resource processing request based on the digital account creator identifier and the resource processing information. For example, the digital account creator identifier and the resource processing order number can be spliced to obtain a temporary identifier. Afterwards, the server can generate a temporary public key and a temporary private key corresponding to the resource processing request through the temporary identifier. The method of generating a temporary public key and a temporary private key through a temporary identifier can refer to the above-mentioned method of generating a signature public key and a signature private key. The generated temporary private key is sent to the terminal corresponding to the digital account creator's identity. When the digital account creator triggers a request confirmation operation for a resource processing request, the terminal can sign the confirmation message with the temporary private key to generate a request confirmation digital signature, and send the request confirmation digital signature to the server, so that the server verifies the request confirmation digital signature with the temporary public key. When the verification is successful, the server responds to the resource processing request and processes the virtual resources in the digital account corresponding to the digital account creator's identity. By generating a temporary public key and a temporary private key for each resource processing request, even if the temporary public key and the temporary private key are leaked, it will only affect one resource processing request, and will not affect other resource processing requests, greatly improving the security of resource processing.
[0158] In one specific embodiment, referring to FIG12 , a virtual resource processing method is provided, including:
[0159] Step 1202 : In response to the digital account creator identifier input operation, the terminal obtains the digital account creator identifier, generates a digital account creation request according to the digital account creator identifier, and sends the digital account creation request to the server.
[0160] Step 1204 : The server responds to the digital account creation request, extracts the digital account creator identifier from the digital account creation request, and creates a digital account for storing virtual resources according to the digital account creator identifier.
[0161] Step 1206: When multiple digital account creator identifiers are extracted from the digital account creation request, the server concatenates the multiple digital account creator identifiers and the preset master public key to obtain a concatenated identifier, and performs a hash operation on the concatenated identifier to obtain a hash identifier.
[0162] Step 1208: Obtain a second elliptic curve through the server and determine a second base point on the second elliptic curve; merge the second base point with the hash identifier according to the second elliptic curve to obtain a signature public key, and multiply the signature public key with the preset master private key to obtain a signature private key.
[0163] Step 1210: Obtain a verification code through the server, determine an encryption key generation algorithm, and process the verification code through the encryption key generation algorithm to obtain a first encryption key; encrypt the signature private key according to the first encryption key to obtain an encrypted private key; and send the encrypted private key and verification code to the corresponding terminal.
[0164] Step 1212: Receive the encrypted private key and the verification code through the terminal; process the verification code through the encryption key generation algorithm to obtain a second encryption key; decrypt the encrypted private key through the second encryption key, and obtain the signature private key when the decryption is successful.
[0165] Step 1214: display the verification code and the verification code filling box through the terminal; in response to the filling operation on the verification code filling box, display the filled verification code; and send the filled verification code to the server.
[0166] In step 1216, the server receives the verification code filled in by the digital account creator in the terminal, compares the filled-in verification code with the sent verification code for consistency, and determines that the signature private key has been successfully issued when the filled-in verification code is consistent with the sent verification code.
[0167] Step 1218: Display multiple items through the terminal. In response to a selection operation on the multiple items, display a detail page of the item selected by the selection operation; the detail page displays an item acquisition control and the amount of resources required to acquire the item selected by the selection operation.
[0168] In step 1220, in response to the triggering operation on the item acquisition control, the terminal generates a resource processing message according to the amount of resources required to acquire the item selected by the selection operation, signs the resource processing message with the signature private key to obtain a digital signature, generates a resource processing request based on the digital signature, and sends the resource processing request to the server.
[0169] Step 1222: The server receives a resource processing request, verifies the digital signature in the resource processing request using the corresponding signature public key, and processes the virtual resources in the digital account after the verification is passed.
[0170] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0171] This application also provides an application scenario, which applies the above-mentioned resource processing method. Specifically, the application of the resource processing method in this application scenario is as follows:
[0172] When multiple digital account creators wish to create a shared account, they can each enter their own digital account creator identifiers into their own terminals, or they can enter their own digital account creator identifiers into a single terminal. After the server obtains each digital account creator identifier, it creates a shared account, along with a corresponding signature private key and signature public key, based on the obtained digital account creator identifiers and using a preset master public and private key. The server shards the signature private key to obtain multiple signature private key shards and distributes each signature private key shard to the digital account creators, ensuring that each digital account creator receives a signature private key shard. When a digital account creator wishes to process virtual resources in the shared account, the server generates a virtual resource processing authorization request and distributes it to each digital account creator. The digital account creator can then determine whether to authorize processing of the virtual resources in the shared account based on their needs. If a digital account creator authorizes processing of virtual resources in the shared account, the terminal will send the signature private key shard of the digital account creator to the terminal corresponding to the administrator. For example, when digital account creator B authorizes digital account creator A to process virtual resources in a shared account, the terminal corresponding to digital account creator B will send the signature private key fragments received by digital account creator B to the terminal corresponding to the administrator. The terminal corresponding to the administrator can restore the signature private key based on the received signature private key fragments. The more signature private key fragments received, the more likely it is to restore the signature private key. After the terminal corresponding to the administrator restores the signature private key, the terminal corresponding to the administrator can sign the resource processing information using the restored signature private key to generate a resource processing request including a digital signature, and send the resource processing request to the server, so that the server responds to the resource processing request based on the signature public key and processes the virtual resources in the shared account.
[0173] This application also provides an application scenario, which applies the above-mentioned resource processing method. Specifically, the application of the resource processing method in this application scenario is as follows:
[0174] The digital account can be a digital wallet, which can be bound to a smart contract to constrain the user's use of the digital wallet. The user can purchase items through the digital wallet.
[0175] The above application scenarios are merely illustrative. It will be understood that the application of the resource processing methods provided in the embodiments of the present application is not limited to the above scenarios.
[0176] Based on the same inventive concept, embodiments of the present application also provide a resource processing device for implementing the resource processing method described above. The implementation solution provided by this device is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more resource processing device embodiments provided below can be found in the above-mentioned limitations on the resource processing method and will not be repeated here.
[0177] In one embodiment, as shown in FIG13 , a resource processing device 1300 is provided, comprising: a signature public key generation module 1302, a signature private key generation module 1304, a signature private key sending module 1306, a resource processing request receiving module 1308, and a resource processing module 1310, wherein:
[0178] The signature public key generation module 1302 is used to extract the digital account creator identifier from the digital account creation request in response to the digital account creation request upon receiving the digital account creation request; create a digital account for storing virtual resources based on the digital account creator identifier; obtain a preset master public key, and generate the signature public key of the digital account based on the master public key and the digital account creator identifier.
[0179] The signature private key generation module 1304 is used to obtain a master private key paired with the master public key, and generate a signature private key paired with the signature public key based on the master private key and the signature public key.
[0180] The signature private key sending module 1306 is used to send the signature private key to the terminal corresponding to the digital account creator identifier; the sent signature private key is used to trigger the terminal to generate a digital signature based on the signature private key;
[0181] The resource processing request receiving module 1308 is configured to receive a resource processing request including a digital signature fed back by a terminal; and
[0182] The resource processing module 1310 is configured to process the virtual resources in the digital account according to the resource processing request after the digital signature is verified based on the signature public key of the digital account.
[0183] In one embodiment, the resource processing device 1300 also includes a master public key generation module, which is used to generate a random number and use the random number as the master private key; obtain a first elliptic curve and determine a first base point on the first elliptic curve; perform a doubling operation on the first base point and the master private key to obtain a master public key paired with the master private key.
[0184] In one embodiment, the signature public key generation module 1302 is further used to, when multiple digital account creator identifiers are extracted from a digital account creation request, concatenate the multiple digital account creator identifiers and the master public key to obtain a concatenated identifier; perform a hash operation on the concatenated identifier to obtain a hash identifier; and generate a signature public key based on the hash identifier.
[0185] In one embodiment, the signature public key generation module 1302 is further used to obtain a second elliptic curve and determine a second base point on the second elliptic curve; and merge the second base point with the hash identifier according to the second elliptic curve to obtain the signature public key.
[0186] In one embodiment, the signature private key sending module 1306 is also used to obtain a verification code and determine an encryption key generation algorithm; process the verification code through the encryption key generation algorithm to obtain a first encryption key; encrypt the signature private key according to the first encryption key to obtain an encrypted private key; send the encrypted private key and the verification code to the terminal corresponding to the digital account creator identifier; the sent encrypted private key and verification code are used to trigger the terminal to decrypt the encrypted private key through the verification code to obtain the signature private key.
[0187] In one embodiment, the signature private key sending module 1306 is further used to obtain a salt value, and generate an initial key block of the current round based on the verification code and the salt value; obtain the key block of the previous round, and concatenate the initial key block of the current round with the key block of the previous round to obtain the key block of the current round; when the byte length of the key block of the current round does not meet the preset length condition, enter a round, take the next one as the current round, and return to the step of generating the initial key block of the current round based on the verification code and the salt value, and continue to execute until the byte length of the key block of the current round meets the preset length condition; and use the key block of the last round as the first encryption key.
[0188] In one embodiment, the signature private key sending module 1306 is further used to obtain encoded data, concatenate the salt value with the encoded data to obtain a target salt value; perform a hash operation on the verification code and the target salt value to obtain a first hash key block; in the current hash key block generation process starting from the second hash key block generation process, generate a current hash key block based on the verification code and the previous hash key block; the next hash key block generation process serves as the current hash key block generation process, returns to the step of determining the current hash key block based on the verification code and the previous hash key block, and continues to execute until a preset number of hash key blocks are generated; and uses the last hash key block as the initial key block of the current round.
[0189] In one embodiment, the resource processing device 1300 also includes a resource processing module for receiving a resource processing request including a digital signature; verifying the digital signature through the signature public key; after the verification is passed, responding to the resource processing request through the smart contract bound to the digital account to process the resources in the digital account and obtain a resource processing result; storing the resource processing result in the blockchain and passing the consensus of each consensus node in the blockchain.
[0190] In one embodiment, as shown in FIG14 , a signature private key acquisition apparatus 1400 is provided, comprising: a request generation module 1402 , a request sending module 1404 , and a key receiving module 1406 , wherein:
[0191] The request generation module 1402 is configured to obtain a digital account creator identifier and generate a digital account creation request according to the digital account creator identifier.
[0192] The request sending module 1404 is used to send a digital account creation request; the sent digital account creation request is used to trigger the creation of a digital account, a signature public key and a signature private key according to the digital account creator identifier, and is used to trigger the generation of a verification code, encrypt the signature private key based on the verification code, and obtain an encrypted private key.
[0193] The key receiving module 1406 is used to receive the encrypted private key and the verification code; the encrypted private key is decrypted by the verification code to obtain the signature private key; the signature private key is used to generate a resource processing request including a digital signature through the signature private key during the resource processing process; the digital signature is used to trigger the processing of the virtual resources in the digital account according to the resource processing request after the digital signature is verified by the signature public key bound to the digital account.
[0194] In one embodiment, the key receiving module 1406 is further configured to process the verification code using an encryption key generation algorithm to obtain a second encryption key; decrypt the encrypted private key using the second encryption key, and obtain a signature private key when the decryption is successful.
[0195] In one embodiment, the key receiving module 1406 is also used to display the verification code and the verification code filling box when receiving the verification code sent by the server; in response to the filling operation on the verification code filling box, display the filled-in verification code; send the filled-in verification code to the server, and the sent filled-in verification code is used to trigger the server to compare the filled-in verification code with the sent verification code for consistency, and when the filled-in verification code is consistent with the sent verification code, determine that the signature private key has been successfully issued.
[0196] In one embodiment, the signature private key acquisition device 1400 also includes an item acquisition module, which is used to display multiple items, and in response to a selection operation on the multiple items, display a detail page of the item selected by the selection operation; the detail page displays an item acquisition control and the amount of resources required to obtain the item selected by the selection operation; in response to a trigger operation on the item acquisition control, a resource processing message is generated according to the amount of resources required to obtain the item selected by the selection operation; the resource processing message is signed by the signature private key to obtain a digital signature, and a resource processing request is generated based on the digital signature.
[0197] Each module in the resource processing device and signature private key acquisition device described above may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in hardware form, or may be stored in a memory in the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0198] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be shown in Figure 15. The computer device includes a processor, a memory, an input / output interface (I / O), and a communication interface. The processor, memory, and I / O interface are connected via a system bus, and the communication interface is connected to the system bus via the I / O interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store digital account creation data. The I / O interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a resource processing method is implemented.
[0199] In one embodiment, a computer device is provided, which may be a terminal. A diagram of its internal structure may be shown in FIG16 . The computer device includes a processor, memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is configured to exchange information between the processor and an external device. The communication interface of the computer device is configured to communicate with an external terminal via wired or wireless communication, where the wireless communication may be achieved via Wi-Fi, a mobile cellular network, NFC (near-field communication), or other technologies. When executed by the processor, the computer program implements a method for obtaining a signature private key. The display unit of the computer device is used to form a visually visible image, and can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse, etc.
[0200] Those skilled in the art will understand that the structures shown in Figures 15 and 16 are merely block diagrams of partial structures related to the scheme of the present application, and do not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device may include more or fewer components than shown in the figures, or combine certain components, or have a different arrangement of components.
[0201] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.
[0202] In one embodiment, a computer-readable storage medium is provided, storing a computer program, which implements the steps in the above-mentioned method embodiments when executed by a processor.
[0203] In one embodiment, a computer program product or computer program is provided, the computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps of each of the above-described method embodiments.
[0204] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.
[0205] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.
[0206] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0207] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.
Claims
1. A resource processing method, executed by a server, the method comprising: In response to a digital account creation request, extracting a digital account creator identifier from the digital account creation request; Creating a digital account for storing virtual resources according to the digital account creator identifier; Obtaining a preset master public key, and generating a signature public key for the digital account according to the master public key and the digital account creator identifier; Obtaining a master private key paired with the master public key, and generating a signature private key paired with the signature public key according to the master private key and the signature public key; Sending the signature private key to the terminal corresponding to the digital account creator identifier; the sent signature private key is used to trigger the terminal to generate a digital signature based on the signature private key; Receiving a resource processing request including the digital signature fed back by the terminal; And After the digital signature is verified through the signature public key of the digital account, processing the virtual resources in the digital account according to the resource processing request.
2. The method according to claim 1, the method further comprising: Generating a random number and using the random number as the master private key; Obtaining a first elliptic curve and determining a first base point on the first elliptic curve; Performing a multiple point operation on the first base point and the master private key to obtain a master public key paired with the master private key.
3. The method according to claim 1 or 2, the generating the signature public key for the digital account according to the master public key and the digital account creator identifier, comprising: In the case of extracting a plurality of digital account creator identifiers from the digital account creation request, performing a splicing process on the plurality of digital account creator identifiers and the master public key to obtain a spliced identifier; Performing a hash operation on the spliced identifier to obtain a hash identifier; Generating a signature public key according to the hash identifier.
4. The method according to claim 3, the generating the signature public key according to the hash identifier, comprising: Obtaining a second elliptic curve and determining a second base point on the second elliptic curve; Fusing the second base point and the hash identifier according to the second elliptic curve to obtain a signature public key.
5. The method according to any one of claims 1 to 4, the generating the signature private key paired with the signature public key according to the master private key and the signature public key, comprising: Multiplying the master private key by the signature public key to obtain a signature private key paired with the signature public key.
6. The method according to any one of claims 1 to 5, the sending the signature private key comprises: Obtaining a verification code and determining an encryption key generation algorithm; Processing the verification code through the encryption key generation algorithm to obtain a first encryption key; Encrypting the signature private key according to the first encryption key to obtain an encrypted private key; Sending the encrypted private key and the verification code to the terminal corresponding to the digital account creator identifier; the sent encrypted private key and the verification code are used to trigger the terminal to decrypt the encrypted private key through the verification code to obtain the signature private key.
7. The method according to claim 6, wherein processing the verification code by the encryption key generation algorithm to obtain a first encryption key comprises: Obtaining a salt value, and generating an initial key block for the current round according to the verification code and the salt value; Obtaining the key block of the previous round, and concatenating the initial key block of the current round with the key block of the previous round to obtain the key block of the current round; When the byte length of the key block of the current round does not meet the preset length condition, proceeding to the next round, taking the next round as the current round, and returning to the step of generating the initial key block of the current round according to the verification code and the salt value to continue execution until the byte length of the key block of the current round meets the preset length condition; Taking the key block of the last round as the first encryption key.
8. The method according to claim 7, wherein generating the initial key block of the current round according to the verification code and the salt value comprises: Obtaining encoded data, and concatenating the salt value with the encoded data to obtain a target salt value; Performing a hash operation on the verification code and the target salt value to obtain a first hash key block; In the generation process of the current hash key block starting from the generation process of the second hash key block, generating the current hash key block according to the verification code and the previous hash key block; Proceeding to the next hash key block generation process, taking the next hash key block generation process as the current hash key block generation process, and returning to the step of generating the current hash key block according to the verification code and the previous hash key block to continue execution until a preset number of hash key blocks are generated and then stopping; Taking the last hash key block as the initial key block of the current round.
9. The method according to any one of claims 1 to 8, further comprising: Receiving a resource processing request including a digital signature; Verifying the digital signature by the signature public key; After the verification is passed, responding to the resource processing request based on the smart contract bound to the digital account to process the resources in the digital account to obtain a resource processing result; Storing the resource processing result in a blockchain.
10. A method for obtaining a signature private key, which is executed by a terminal, the method comprising: Obtaining an identifier of a digital account creator, and generating a digital account creation request according to the identifier of the digital account creator; Sending the digital account creation request, where the sent digital account creation request is used to trigger the creation of a digital account, a signature public key, and a signature private key according to the identifier of the digital account creator, and is used to trigger the generation of a verification code, and encrypting the signature private key according to the verification code to obtain an encrypted private key; Receiving the encrypted private key and the verification code; The encrypted private key is decrypted by the verification code to obtain the signature private key, which is used to generate a resource processing request including a digital signature during the process of resource processing. The digital signature is used to trigger the processing of virtual resources in the digital account according to the resource processing request after the digital signature is verified based on the signature public key bound to the digital account.
11. The method according to claim 10, wherein the step of decrypting the encrypted private key by the verification code to obtain the signature private key comprises: Processing the verification code by the encryption key generation algorithm to obtain a second encryption key; Decrypting the encrypted private key by the second encryption key, and when the decryption is successful, obtaining the signature private key.
12. The method according to claim 11, further comprising: When receiving the verification code sent by the server, displaying the verification code and a verification code filling box; In response to a filling operation on the verification code filling box, displaying the filled verification code; Sending the filled verification code to the server, where the sent filled verification code is used to trigger the server to compare the filled verification code with the sent verification code for consistency, and when the filled verification code is consistent with the sent verification code, determining that the signature private key is successfully issued.
13. The method according to any one of claims 10 to 12, wherein the step of generating the resource processing request comprises: Displaying a plurality of items, and in response to a selection operation on the plurality of items, displaying a detailed page of the item selected by the selection operation; the detailed page displays an item acquisition control and the amount of resources required to acquire the item selected by the selection operation; In response to a triggering operation on the item acquisition control, generating a resource processing message according to the amount of resources required to acquire the item selected by the selection operation; Signing the resource processing message by the signature private key to obtain a digital signature, and generating a resource processing request according to the digital signature.
14. A resource processing apparatus, the apparatus comprising: A signature public key generation module, configured to, when receiving a digital account creation request, in response to the digital account creation request, extract a digital account creator identifier from the digital account creation request; Creating a digital account for storing virtual resources according to the digital account creator identifier; obtaining a preset master public key, and generating a signature public key of the digital account according to the master public key and the digital account creator identifier; A signature private key generation module, configured to obtain a master private key paired with the master public key, and generate a signature private key paired with the signature public key according to the master private key and the signature public key; A signature private key sending module, configured to send the signature private key to a terminal corresponding to the digital account creator identifier; the sent signature private key is used to trigger the terminal to generate a digital signature based on the signature private key; A resource processing request receiving module, configured to receive the resource processing request including the digital signature fed back by the terminal; And A resource processing module, configured to process virtual resources in the digital account according to the resource processing request after the digital signature is verified based on the signature public key of the digital account.
15. A signature private key acquisition device, the device comprising: A request generation module, configured to obtain an identifier of a digital account creator and generate a digital account creation request according to the identifier of the digital account creator; A request sending module, configured to send the digital account creation request; The sent digital account creation request is used to trigger the creation of a digital account, a signature public key and a signature private key according to the identifier of the digital account creator, and is used to trigger the generation of a verification code, and encrypt the signature private key based on the verification code to obtain an encrypted private key; A key receiving module, configured to receive the encrypted private key and the verification code; decrypt the encrypted private key through the verification code to obtain the signature private key, and the signature private key is used to generate a resource processing request including a digital signature during the resource processing, and the digital signature is used to trigger the processing of virtual resources in the digital account according to the resource processing request after the digital signature is verified based on the signature public key bound to the digital account.
16. A computer device, comprising a memory and a processor, where the memory stores a computer program, and the processor implements the steps of the method according to any one of claims 1 to 13 when executing the computer program.
17. A computer-readable storage medium, on which a computer program is stored, and the computer program implements the steps of the method according to any one of claims 1 to 13 when being executed by a processor.
18. A computer program product, comprising a computer program, and the computer program implements the steps of the method according to any one of claims 1 to 13 when being executed by a processor.
Citation Information
Patent Citations
A secure mobile payment method and system based on an identification password
CN109165934A
E-mail encryption and decryption method, system and device and computer readable storage medium
CN114650181A
System and method of blockchain transaction verification
US20210241270A1