WO2020073859A1 - 区块链节点服务部署方法、装置、系统、计算设备及介质 - Google Patents

区块链节点服务部署方法、装置、系统、计算设备及介质 Download PDF

Info

Publication number
WO2020073859A1
WO2020073859A1 PCT/CN2019/109268 CN2019109268W WO2020073859A1 WO 2020073859 A1 WO2020073859 A1 WO 2020073859A1 CN 2019109268 W CN2019109268 W CN 2019109268W WO 2020073859 A1 WO2020073859 A1 WO 2020073859A1
Authority
WO
WIPO (PCT)
Prior art keywords
blockchain
trusted
service
user
deployment
Prior art date
Application number
PCT/CN2019/109268
Other languages
English (en)
French (fr)
Inventor
王叶松
Original Assignee
阿里巴巴集团控股有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 阿里巴巴集团控股有限公司 filed Critical 阿里巴巴集团控股有限公司
Priority to JP2021520226A priority Critical patent/JP7442516B2/ja
Priority to SG11202101917TA priority patent/SG11202101917TA/en
Publication of WO2020073859A1 publication Critical patent/WO2020073859A1/zh
Priority to US17/193,654 priority patent/US11604631B2/en

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/51Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/50Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/03Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
    • G06F2221/033Test or assess software
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • G06F8/61Installation

Definitions

  • the present disclosure relates to the field of Internet of Things technology and blockchain technology, and in particular, to a blockchain node service deployment method, device, computing device, and storage medium.
  • Blockchain is a new application model of computer technology such as distributed data storage, point-to-point transmission, consensus mechanism, encryption algorithm and so on.
  • the Internet of Things (IoT) is an information carrier such as the Internet and traditional telecommunications networks. It is a network that allows all ordinary objects that can perform independent functions to realize interconnection.
  • the purpose of the present disclosure is to provide a solution that can more conveniently deploy blockchain node services to reduce the cost of configuring, deploying, and maintaining blockchain-related basic services for application service providers.
  • the first aspect of the fundamental disclosure provides a method for deploying a blockchain node service, including: in response to a deployment request for a blockchain node service from a user, sending a deployment request to a blockchain server so that the block
  • the chain server deploys node services on one or more blockchain nodes; based on the configuration information of the one or more blockchain nodes returned by the blockchain server, the device configuration associated with the user is configured
  • a trusted application corresponding to the blockchain node sending the trusted application to install the trusted application on the device.
  • the configuration information includes a blockchain node address.
  • the blockchain node service deployment request includes identification information of the device associated with the user and blockchain node configuration parameters.
  • the method of blockchain node service deployment may further include: receiving a service account registration request from a user and device information associated with the user; and sending the service account registration request and the location to the trusted service management server The device information; and sending the service account registration request to the blockchain server.
  • the step of sending the trusted application includes: sending the identification information of the device and the trusted application to the trusted service management server so that the trusted service management server is on the device Install the trusted application on
  • the blockchain node service deployment method may be applied to the Internet of Things, and the device may be an Internet of Things device with a trusted security chip or module.
  • a blockchain node service deployment method including: deploying node services on one or more blockchain nodes in response to a blockchain node service deployment request from a user ; Based on the configuration information of the one or more blockchain nodes, configure a trusted application corresponding to the blockchain node for the device associated with the user; and send the available application to the trusted service management server Trusted application, so that the trusted service management server installs the trusted application on the device.
  • the step of sending the trusted application may include: sending the identification information of the device and the trusted application to a trusted service management server, so that the trusted service management server is on the device Install the trusted application.
  • the blockchain node service deployment method may further include: receiving a service account registration request from a user and device information associated with the user to complete the user's service account registration and binding of related devices; Sending the service account registration request and the device information to the trusted service management server.
  • the blockchain node service deployment method may be applied to the Internet of Things, and the device may be an Internet of Things device with a trusted security chip or module.
  • a blockchain node service deployment system including: a blockchain management platform for responding to a blockchain node service deployment request from a user The terminal sends a deployment request, and based on the configuration information of the one or more blockchain nodes returned by the blockchain server, configures the trustworthiness corresponding to the blockchain node for the device associated with the user Application and send the trusted application to install the trusted application on the device; the blockchain server is used to respond to deployment requests from the blockchain management platform in one or more Node services are deployed on the blockchain nodes, and the configuration information of the one or more blockchain nodes is returned to the blockchain management platform.
  • the blockchain node service deployment system may further include: a trusted service management server, which is based on the device identification information of the device associated with the user and received from the blockchain management platform A trusted application, remotely installing a trusted application corresponding to the device on the device.
  • a trusted service management server which is based on the device identification information of the device associated with the user and received from the blockchain management platform A trusted application, remotely installing a trusted application corresponding to the device on the device.
  • the blockchain node service deployment system may further include: a trusted execution environment in the device, connected to the trusted service management server, and responding to a remote installation operation from the trusted service management server , Install a trusted application corresponding to the device on the device.
  • the blockchain management platform can also be used to: receive a service account registration request from a user and device information associated with the user; send the service account registration request and all the information to a trusted service management server The device information; and sending the service account registration request to the blockchain server.
  • the blockchain management platform sends the identification information of the device and the trusted application to the trusted service management server, so that the trusted service management server installs the device on the device Describe trusted applications.
  • the blockchain node service deployment system is applied to the Internet of Things, and the device is an Internet of Things device with a trusted security chip or module.
  • a blockchain node service deployment device including: a request sending unit for sending a blockchain node service deployment request to a blockchain server in response to a request from a user A deployment request, so that the blockchain server deploys node services on one or more blockchain nodes; an application configuration unit, based on the one or more blockchains returned by the blockchain server The configuration information of the node configures a trusted application corresponding to the blockchain node for a device associated with the user; a first sending unit is used to send the trusted application to install the device on the device Trusted application.
  • the blockchain node service deployment device may further include: a registration unit for receiving a service account registration request from a user and device information associated with the user; a second sending unit for managing services to a trusted service The terminal sends the service account registration request and the device information; and a third sending unit is used to send the service account registration request to the blockchain server.
  • the first sending unit sends the identification information of the device and the trusted application to the trusted service management server, so that the trusted service management server installs the device on the device Trusted application.
  • a computing device including: a processor; and a memory on which executable code is stored, and when the executable code is executed by the processor, the The processor executes the method as described above.
  • a non-transitory machine-readable storage medium on which executable code is stored, and when the executable code is executed by a processor of an electronic device, the processing The device performs the method described above.
  • This disclosure provides a one-click deployment service for application service providers by providing a one-click deployment and operation and maintenance platform model, so that relevant parties can focus on the development of related applications and reduce the configuration, deployment and operation and maintenance of blockchain-related basic services. cost.
  • FIG. 1 shows a schematic diagram of a distributed ledger technology network topology according to an embodiment of the present disclosure
  • FIG. 2 shows a schematic block diagram of a blockchain node service deployment system according to an embodiment of the present disclosure
  • FIG. 3 shows a schematic flowchart of a blockchain node service deployment according to an embodiment of the present disclosure
  • FIG. 4 shows a schematic flowchart of a method for deploying a blockchain node service according to an embodiment of the present disclosure
  • FIG. 5 shows a schematic flowchart of a method for deploying a blockchain node service according to an embodiment of the present disclosure
  • FIG. 6 shows a schematic block diagram of a structure of a blockchain node service deployment device according to an embodiment of the present invention
  • FIG. 7 shows a schematic structural diagram of a computing device that can be used to implement the above-mentioned blockchain node service deployment method according to an embodiment of the present disclosure.
  • Blockchain (Blockchain) is essentially a distributed ledger technology shared by multiple parties. It realizes the non-tampering modification of transaction data and historical records through mathematical methods, and realizes the common confirmation and ledger records of transactions by various parties through consensus algorithms and smart contracts. Blockchain is divided into three basic types: public chain, alliance chain and private chain.
  • Blockchain service (Blockchain as a Service, BaaS) refers to the use of data generated by the blockchain to provide a series of operational services such as search query and task submission based on the blockchain.
  • the disclosed blockchain service is an enterprise-level PaaS (Platform as a Service) platform service based on mainstream blockchain technology, helping users quickly build a more stable and secure production-grade blockchain environment, reducing Challenges in deployment, operation and maintenance, management, application development, etc., make users more focused on core business innovation, and achieve rapid business chain.
  • PaaS Platinum as a Service
  • Distributed ledger technology is a database that is shared, copied, and synchronized among network members.
  • a distributed ledger records transactions between network participants, such as the exchange of assets or data. This shared ledger reduces the time and expense costs of mediating different ledgers.
  • DLT nodes Distributed network nodes
  • Any point in the network is connected to at least two lines.
  • the communication can be completed via other links and has high reliability.
  • the network is easy to expand.
  • Edge Computing refers to an open platform that integrates network, computing, storage, and application core capabilities on the side close to the source of the object or data to provide the nearest end service. Its applications are launched on the edge to generate faster network service response, meeting the industry's basic needs in real-time business, application intelligence, security and privacy protection. Edge computing is between physical entities and industrial connections, or on top of physical entities. Cloud computing can still access historical data of edge computing.
  • Cloud computing is an increase, use and delivery model of Internet-based related services, usually involving the provision of dynamically scalable and often virtualized resources over the Internet.
  • Blockchain of Things (BoT) management platform is a cloud network management platform for cloud-on-edge devices launched by cloud service providers for the Internet of Things + blockchain upper-level application service providers. Build a two-way blockchain node data communication network between the device terminal and the cloud, device terminal and device terminal.
  • the blockchain server (such as BaaS cloud platform) is an enterprise-level PaaS (Platform as a Service) platform service based on mainstream blockchain technology, which can help users quickly build a more stable and secure blockchain environment, reducing Challenges in blockchain deployment, operation and maintenance, management, application development, etc., make users more focused on core business innovation and achieve rapid business chain.
  • users refer to IoT application service providers or users of IoT devices.
  • the Trusted Service Manager (TSM) server is a trusted service management platform for remote chip management and application distribution of devices such as SE security chips. It provides users with end-to-end services by providing one-stop services. End-point security solutions, including secure carrier lifecycle management, application distribution, key escrow, statistical analysis, etc.
  • the trusted service platform complies with GP international standards, supports multiple modes, multiple security carriers, and standard interfaces to ensure rapid implementation and implementation. In addition, it can combine the powerful cloud computing capabilities of the service provider to ensure the high performance, high security, scalability, high availability, and low cost of the service system.
  • Trusted Execution Environment is a secure area on the main processor of the Internet of Things device, which can guarantee the security, confidentiality and integrity of the code and data stored in the secure area.
  • the carrier of the trusted execution environment may be, for example, a trusted root RoT security chip (Secure Element, SIM, TEE, etc.) or a module (Secure MCU) on the device.
  • Trusted application (Trusted Application, TA), a trusted application that passes a trusted authentication service.
  • the blockchain nodes deployed in the cloud can provide blockchain services for trusted applications on the device side.
  • the trusted application is installed in a trusted security chip or module on the device.
  • the device identification the identification of the Internet of Things device, can uniquely identify the Internet of Things device in the Internet of Things.
  • This disclosure proposes a distributed ledger technology network topology for scenarios where there is a demand for deployment on the blockchain server side + device side.
  • the distributed network topology structure can be applied to any form of blockchain technology, including private chains , Public chain and / or alliance chain, this disclosure will take the alliance chain form as an example to expand the detailed description.
  • the distributed ledger technology network topology can be applied to any field or scenario where there is a demand for blockchain server + device deployment, such as the Internet of Things field and product traceability, supply chain finance, charity, mutual insurance Wait for the scene.
  • the cloud-side server side of the relevant blockchain service, and the cloud-side device side may be a device side including an IoT device with a trusted security chip or module.
  • the IoT device may include but is not limited to a mobile phone, Wearable devices, smart door locks, gateway devices, in-vehicle devices, etc.
  • FIG. 1 shows a schematic diagram of a distributed ledger technology network topology structure according to an embodiment of the present disclosure. It should be understood that this network topology is a schematic diagram of the blockchain network topology after the deployment of the on-cloud server + off-device blockchain node service of the present disclosure is completed, rather than the distributed ledger technology network of the present disclosure. The specific limitations of the topology.
  • the network topology of the distributed ledger technology may include a main chain on the cloud deployed on the cloud, and a side chain on the edge node of the Internet of Things deployed on the device side under the cloud.
  • the alliance chain For each IoT application service provider (such as enterprises, organizations, etc.), when it wants to join an alliance blockchain of the Internet of Things (referred to as the alliance chain), deploy one or more blockchain nodes in the cloud to enable As a participant of the blockchain main consortium chain, the one or more blockchain nodes deployed in the cloud form the main chain on the cloud shown on the right side of Figure 1, in order to rely on the main chain's computing power and data
  • the storage capacity performs blockchain-related operations and provides relevant blockchain services for many application service providers.
  • the blockchain nodes on the edge devices can be connected to one or more main chain nodes on the cloud according to business needs to complete the relevant collaborative operations of the blockchain.
  • the formation of the above network topology can be achieved by the blockchain node service deployment system of the present disclosure.
  • FIG. 2 shows a schematic block diagram of a blockchain node service deployment system (referred to as a deployment system for short) according to an embodiment of the present disclosure.
  • the blockchain node service deployment system of the present disclosure may include two ends, namely a cloud (on-cloud) and an Internet of Things device (under-cloud).
  • a cloud on-cloud
  • an Internet of Things device under-cloud
  • the cloud may include a blockchain management platform, a blockchain server, and a trusted service management server.
  • the above-mentioned blockchain management platform can be called the Internet of Things Blockchain (Blockchain of Things, BoT) management platform (referred to as the BoT cloud platform in the following description), which is a cloud service provider
  • BoT Internet of Things
  • the cloud-oriented + edge device blockchain network management platform launched by the upper application service provider for the Internet of Things + blockchain is designed to help build two-way blockchain node data communication between the device terminal and the cloud, device terminal and device terminal The internet.
  • the IoT blockchain management platform can provide device-side SDK, allowing IoT devices to easily access system services.
  • the blockchain server can be a Blockchain (Blockchain) service (BaaS) cloud platform (referred to as BaaS cloud platform in the following description), which is an enterprise-level PaaS (Platform based on mainstream blockchain technology) as a Service) platform service can help users quickly build a more stable and secure blockchain environment, reduce challenges in blockchain deployment, operation and maintenance, management, application development, etc., so that users can focus more on core business innovation, And achieve rapid business chain.
  • Users refer to IoT application service providers or users of IoT devices.
  • the BoT cloud platform can respond to the deployment request of the blockchain node service from the user, send a deployment request to the BaaS cloud platform, and based on the one or more (on the cloud) returned by the BaaS cloud platform ) Blockchain node configuration information, configure the trusted application corresponding to the (on-cloud) blockchain node for the device associated with the user, and send the trusted application for installation on the device The trusted application.
  • the BaaS cloud platform can respond to the on-cloud deployment request from the blockchain cloud platform, deploy node services on one or more on-cloud blockchain nodes in the cloud, and return the said to the blockchain cloud platform Configuration information of one or more blockchain nodes on the cloud.
  • Trusted Service Manager (TSM) server is a trusted service platform for remote chip management and application distribution of devices with SE security chips. It provides end-to-end security for users by providing one-stop services Solutions, including secure carrier lifecycle management, application distribution, key escrow, statistical analysis, etc.
  • the trusted service platform complies with GP international standards, supports multiple modes, multiple security carriers, and standard interfaces to ensure rapid implementation and implementation. In addition, it can combine the powerful cloud computing capabilities of service providers to ensure high performance, high security, scalability, high availability, and low cost of the service system.
  • the BoT cloud platform sends the TA to the TSM server, and also sends the device ID of the device, so that the TSM server can implement trusted application distribution to the device based on the device ID and corresponding configuration information of the device and Services such as remote installation.
  • the TSM server may remotely install the trusted application corresponding to the device on the device based on the device identification information of the device associated with the user and the received trusted application from the blockchain cloud platform. Specifically, the TSM server installs a trusted application corresponding to the device in a secure element on the device (for example, SE, SIM, eSIM, TEE, Secure, MCU, etc. as described above).
  • a secure element on the device for example, SE, SIM, eSIM, TEE, Secure, MCU, etc. as described above.
  • the device side under the cloud may include related device terminals (for example, Internet of Things IoT devices).
  • related device terminals for example, Internet of Things IoT devices.
  • the object that uses the device terminal at different stages is different from the operation subject, it is also possible to more specifically divide the device side under the cloud based on the corresponding use related party.
  • the original IoT device manufacturers are OEMs, IoT device users / IoT application service providers, and trusted execution environments TEE in IoT devices.
  • the carrier of the trusted execution environment TEE is the relevant device security chip on the device terminal, such as the SE security chip.
  • the original IoT device manufacturer namely the OEM, as the original manufacturer of the related device, realizes the initial manufacturing of the related device, such as assigning the device identification ID and device key ID to the device, burning the relevant information in the device TEE, and recording the relevant information of the device Register to the TSM server, etc.
  • an IoT device user / IoT application service provider can register an SP account provided by a service provider and enjoy related services based on this SP account.
  • the trusted execution environment TEE in the device can be connected to the TSM server, and can respond to a remote installation operation from the trusted service management server to install on the device (the secure element) corresponding to the device Trusted application TA.
  • the above-mentioned blockchain node service deployment system of the present disclosure can provide users with a one-click cloud + cloud deployment service, so that users can focus on the development of related applications, reducing the number of configuration, deployment and operation and maintenance blocks
  • the cost of basic services related to the chain improves the user experience.
  • BoT cloud platform can also provide users with services such as service account registration and device binding.
  • the BoT cloud platform receives a service account registration request from the user (including user account registration information) and device information associated with the user, and completes the binding of the user service account and the user service account and user device. After that, the BoT cloud platform sends the service account registration request and the device information to the trusted service management server, and sends the service account registration request to the BaaS cloud platform.
  • the user only needs to perform the step of filling in the registration information once, and the BoT cloud platform can complete the user service account registration, and the user registration information and device binding information are stored in the cloud in synchronization.
  • FIG. 2 only briefly introduces the main components of the blockchain node service deployment system of the present disclosure.
  • the present disclosure does not carry out the correlation between the various parts of the deployment system and the functions that each part specifically implements. Any other restrictions.
  • For the manufacturing scheme of the related equipment involved please refer to the existing related technologies, which will not be repeated in this disclosure.
  • the deployment of the blockchain node service realized by the deployment system can be referred to the following drawings and the description of the embodiments, which will not be repeated here.
  • FIG. 3 shows a schematic flowchart of a blockchain node service deployment according to an embodiment of the present disclosure.
  • the process of the blockchain node service deployment can be divided into three parts, namely the IoT device manufacturing part, SP account registration part and blockchain node service deployment part.
  • the process of deploying the blockchain node service in this embodiment will be described in detail in conjunction with the flowchart shown in FIG. 3 as follows.
  • step 1.0 burn the relevant system application and confidential data to the TEE in the device, that is, provide the TEE certificate (Provision TEE Credentials);
  • step 1.1 the OEM uploads the relevant identification ID and key (including public and private key) ID of the IoT device TEE to its back-end trusted service management server (or third-party trusted service management server) to The successful burning of the Internet of Things devices can be registered at the trusted service management server.
  • the trusted service management server needs to be connected with cloud platforms (such as BoT cloud platform and BaaS cloud platform).
  • the SP account is a service account provided by a service provider (SP) for a user, and the user can enjoy various services provided by the service provider based on the SP account.
  • SP service provider
  • step 2.0 the user registers an SP account on the BoT (Blockchain AsThings) cloud platform and uploads device identification (ID) information about the purchased IoT device, so that the user can be registered with the BoT cloud platform Corresponding SP account, and realize the binding of the SP account and the user's device.
  • ID device identification
  • the BoT cloud platform connects with the trusted service management server and sends the relevant SP account registration request and bound device ID information to it.
  • step 2.2 the BoT cloud platform sends the relevant SP account registration request and the bound device ID information to the back end of the BaaS cloud platform.
  • each user only needs to perform an account registration and device binding request once, and the user account information and the bound device information can be stored on the cloud in one step, which greatly simplifies the user
  • the process of service account registration and device binding brings great convenience to users.
  • step 3.0 the user sends a blockchain node service deployment request on the BoT cloud platform, requesting to create on-cloud (N blockchain node services) and off-cloud (N blockchain device services on N IoT devices).
  • the necessary information may include, for example, IoT device ID, blockchain node configuration parameters (such as alliance name, alliance domain name, region, specifications, organization information, etc.), and so on.
  • the above information is not completely the same for different service providers, and it can be determined according to the service provider and the actual application scenario. The disclosure does not limit this.
  • the BoT cloud platform sends an on-cloud deployment request to the blockchain service (BaaS) cloud platform, requesting one or more cloud nodes on the cloud to deploy node services (for example, N in this embodiment ).
  • the request includes the information necessary to build a blockchain environment on the cloud, and the service provider can configure the necessary configuration parameters required in the request according to the requirements, and this disclosure does not limit this.
  • step 3.2 in response to the above cloud deployment request, the BaaS cloud platform creates, deploys, and runs node services on one or more relevant cloud nodes on the cloud, and then in step 3.3, the BaaS cloud platform sends the BoT cloud platform Return relevant information, such as the address of the blockchain node on the cloud, the genesis node (the earliest blockchain node) and other related configuration parameters.
  • the BoT cloud platform corresponds to the device configuration associated with the user on the device side corresponding to the cloud node on the cloud Trusted application (TA).
  • the relevant configuration information of the blockchain node service on the cloud may include the blockchain node address on the cloud.
  • the BoT cloud platform sends the trusted application (TA) and the IoT device ID information corresponding to the trusted application to the TSM server.
  • step 4.0 the IoT device is connected to the TSM server.
  • step 4.1 the TSM server remotely installs a trusted application (TA) corresponding to the device on the secure element of the corresponding IoT device based on the device ID information, application configuration information, and other parameters.
  • TA trusted application
  • the blockchain node service deployment solution for the Internet of Things of the present disclosure can integrate traditional vertical Internet of Things equipment security vertical technology capabilities and horizontal universal service technology on the cloud, without changing the existing related technology stack.
  • cloud one-stop BaaS technology capabilities on the cloud (the main blockchain computing and storage service platform) + under the cloud (edge computing service platform)
  • the basic blockchain service combining edge computing and cloud computing provides a cloud-cut, end-to-end secure, one-stop deployment and operation and maintenance platform model, which deeply integrates IoT technology and blockchain technology to enable IoT application services Vendors can focus on the development of related applications, reduce the cost of configuring, deploying, and maintaining blockchain-related basic services, and realize one-click building of the blockchain environment so that users can quickly develop blockchain business innovation.
  • the blockchain node service deployment process described above in the present disclosure can be implemented as a blockchain node service deployment method.
  • FIG. 4 shows a schematic flowchart of a method for deploying a blockchain node service according to an embodiment of the present disclosure.
  • the method of deploying blockchain node services can be applied to the Internet of Things and can be executed by the side of the blockchain management platform.
  • the device described below may be an Internet of Things device with a trusted security chip or module.
  • step S410 in response to the deployment request of the blockchain node service from the user, a deployment request is sent to the blockchain server so that the blockchain server is in one or more blockchain nodes Deploy the node service.
  • the blockchain node service deployment request includes identification information of the device associated with the user and blockchain node configuration parameters.
  • the device identification information may be, for example, the identity of the Internet of Things device, and the Internet of Things device may be uniquely identified in the Internet of Things.
  • Block chain node configuration parameters may include, for example, the number of block chain nodes to be configured or other related configuration parameters.
  • step S420 based on the configuration information of the one or more blockchain nodes returned by the blockchain server, a trusted application corresponding to the blockchain node is configured for the device associated with the user.
  • the configuration information of the blockchain node may include the address of the blockchain node.
  • the trusted application is sent to install the trusted application on the device.
  • the identification information of the device and the trusted application are sent to the trusted service management server, so that the trusted service management server installs the trusted application on the device.
  • the above method may further include a user service account registration process, that is, receiving a service account registration request from a user and device information associated with the user; sending the service account registration to a trusted service management server The request and the device information; and sending the service account registration request to the blockchain server.
  • a user service account registration process that is, receiving a service account registration request from a user and device information associated with the user; sending the service account registration to a trusted service management server The request and the device information; and sending the service account registration request to the blockchain server.
  • the user only needs to perform the step of filling in the registration information once, and the user management account registration can be completed by the blockchain management platform, and the user registration information and device binding information are stored synchronously in the cloud.
  • FIG. 5 shows a schematic flowchart of a method for deploying a blockchain node service according to an embodiment of the present disclosure.
  • the blockchain node service deployment method can be applied to the Internet of Things and can be executed by the deployment system shown in FIG. 2.
  • the device described below may be an Internet of Things device with a trusted security chip or module.
  • step S510 in response to a blockchain node service deployment request from a user, node services are deployed on one or more blockchain nodes.
  • step S520 based on the configuration information of the one or more blockchain nodes, a trusted application corresponding to the blockchain node is configured for the device associated with the user.
  • step S530 the trusted application is sent to the trusted service management server so that the trusted service management server installs the trusted application on the device.
  • the identification information of the device and the trusted application may be sent to the trusted service management server, so that the trusted service management server installs the trusted application on the device.
  • the above method may further include a user service account registration process, that is, receiving a service account registration request from a user and device information associated with the user to complete the service account registration of the user and related devices Bind; send the service account registration request and the device information to the trusted service management server.
  • a user service account registration process that is, receiving a service account registration request from a user and device information associated with the user to complete the service account registration of the user and related devices Bind; send the service account registration request and the device information to the trusted service management server.
  • the user only needs to perform the step of filling in the registration information once, and the user management account registration can be completed by the blockchain management platform, and the user registration information and device binding information are stored synchronously in the cloud.
  • FIG. 6 shows a schematic block diagram of the structure of a blockchain node service deployment apparatus (abbreviated as deployment apparatus) according to an embodiment of the present invention.
  • the functional modules of the deployment device may be implemented by hardware, software, or a combination of hardware and software that implements the principles of the present disclosure.
  • the functional modules described in FIG. 6 can be combined or divided into sub-modules, so as to implement the principles of the above invention. Therefore, the description herein may support any possible combination, division, or further definition of the functional modules described herein.
  • the blockchain node service deployment apparatus 600 of the present invention may include a request sending unit 610, an application configuration unit 620, and a first sending unit 630.
  • the deployment device may be set in the cloud and applied to the Internet of Things, and the device described below may be an Internet of Things device with a trusted security chip or module.
  • the request sending unit 610 may be used to send a cloud server deployment request to the blockchain server in response to a blockchain node service deployment request from a user, so that the blockchain server is on one or more blockchain nodes Deploy node services.
  • the blockchain node service deployment request may include identification information of the device associated with the user and blockchain node configuration parameters.
  • the configuration parameters of the blockchain nodes may be, for example, the number of blockchain nodes that need to be configured or other related configuration parameters.
  • the application configuration unit 620 may be used to configure, based on the configuration information of the one or more blockchain nodes returned by the blockchain server, a device corresponding to the blockchain node for the device associated with the user. ⁇ ⁇ Letter application.
  • the configuration information may include a blockchain node address.
  • the first sending unit 630 may be used to send the trusted application to install the trusted application on the device. Wherein, the first sending unit 630 may send the identification information of the device and the trusted application to the trusted service management server, so that the trusted service management server installs the device on the device Trusted application.
  • the deployment device of the present disclosure may further include a registration unit, a second sending unit, and a third sending unit (not shown in the figure) that enable the user to register the service account.
  • the registration unit may be used to receive a service account registration request from a user and device information associated with the user.
  • the second sending unit sends the service account registration request and the device information to the trusted service management server.
  • the third sending unit is configured to send the service account registration request to the BaaS cloud platform.
  • first, second, and third in the present disclosure are only for distinguishing the sending units involved, rather than limiting their functions or order.
  • the second sending unit and the third sending unit may be multiplexed here, and the present disclosure does not limit the execution order of the two.
  • the first, second, and third sending units can respectively perform the corresponding sending work according to the communication protocol they follow.
  • FIG. 7 shows a schematic structural diagram of a computing device that can be used to implement the above-mentioned blockchain node service deployment method according to an embodiment of the present disclosure.
  • the computing device 700 includes a memory 710 and a processor 720.
  • the processor 720 may be a multi-core processor or may include multiple processors.
  • the processor 720 may include a general-purpose main processor and one or more special co-processors, such as a graphics processor (GPU), a digital signal processor (DSP), and so on.
  • the processor 720 may be implemented using customized circuits, such as an application specific integrated circuit (ASIC, Application Integrated Circuit) or a field programmable logic gate array (FPGA, Field Programmable Gate Arrays).
  • ASIC application specific integrated circuit
  • FPGA Field Programmable Gate Arrays
  • the memory 710 may include various types of storage units, such as system memory, read-only memory (ROM), and permanent storage devices.
  • the ROM may store static data or instructions required by the processor 720 or other modules of the computer.
  • the permanent storage device may be a readable and writable storage device.
  • the permanent storage device may be a non-volatile storage device that does not lose stored instructions and data even after the computer is powered off.
  • the permanent storage device uses a mass storage device (eg, magnetic or optical disk, flash memory) as the permanent storage device.
  • the permanent storage device may be a removable storage device (for example, a floppy disk or an optical drive).
  • the system memory may be a readable and writable storage device or a volatile readable and writable storage device, such as dynamic random access memory.
  • the system memory can store some or all instructions and data required by the processor during operation.
  • the memory 710 may include any combination of computer-readable storage media, including various types of semiconductor memory chips (DRAM, SRAM, SDRAM, flash memory, programmable read-only memory), magnetic disks, and / or optical disks may also be used.
  • the memory 710 may include readable and / or writeable removable storage devices, such as compact discs (CD), read-only digital versatile discs (eg, DVD-ROM, dual-layer DVD-ROM), Read-only Blu-ray discs, ultra-density discs, flash memory cards (such as SD cards, min SD cards, Micro-SD cards, etc.), magnetic floppy disks, etc.
  • CD compact discs
  • DVD-ROM read-only digital versatile discs
  • dual-layer DVD-ROM Read-only Blu-ray discs
  • ultra-density discs such as SD cards, min SD cards, Micro-SD cards, etc.
  • magnetic floppy disks etc.
  • the computer-readable storage medium does not contain carrier waves and instantaneous electronic signals transmitted through wireless or wired.
  • Executable code is stored on the memory 710.
  • the processor 720 can execute the above-mentioned blockchain node service deployment method.
  • the method according to the present disclosure may also be implemented as a computer program or computer program product including computer program code instructions for performing the above steps defined in the above-described method of the present disclosure.
  • the present disclosure may also be implemented as a non-transitory machine-readable storage medium (or computer-readable storage medium, or machine-readable storage medium) on which executable code (or computer program, or computer instruction code) is stored ),
  • executable code or computer program, or computer instruction code
  • the processor of the electronic device or computing device, server, etc.
  • the processor is caused to perform the steps of the above method according to the present disclosure .
  • each block in the flowchart or block diagram may represent a module, program segment, or part of code that contains one or more of the Executable instructions.
  • the functions noted in the block may occur out of the order noted in the figures. For example, two consecutive blocks can actually be executed in parallel, and sometimes they can also be executed in the reverse order, depending on the functions involved.
  • each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts can be implemented with dedicated hardware-based systems that perform specified functions or operations Or, it can be realized by a combination of dedicated hardware and computer instructions.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Stored Programmes (AREA)

Abstract

一种区块链节点服务部署方法、装置、系统、计算设备及介质。该方法包括:响应于来自用户的区块链节点服务部署请求,向区块链服务端发送部署请求,以便所述区块链服务端在一个或多个区块链节点上部署节点服务(S410);基于所述区块链服务端返回的所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用(S420);发送所述可信应用,以便在所述设备上安装所述可信应用(S430)。由此,通过提供一键式部署和运维平台模式,为应用服务商提供一键式部署服务,使相关方可专注于相关应用的开发,减少配置、部署和运维区块链相关基础服务的成本。

Description

区块链节点服务部署方法、装置、系统、计算设备及介质
本申请要求2018年10月12日递交的申请号为2018111898399、发明名称为“区块链节点服务部署方法、装置、系统、计算设备及介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本公开涉及物联网技术和区块链技术领域,特别涉及一种区块链节点服务部署方法、装置、计算设备和存储介质。
背景技术
区块链(Blockchain)是分布式数据存储、点对点传输、共识机制、加密算法等计算机技术的新型应用模式。物联网(Internet of Things,IoT)是互联网、传统电信网等信息承载体,是让所有能行使独立功能的普通物体实现互联互通的网络。
虽然物联网技术的发展和应用在最近几年取得了显著成果,但其同时也面临着许多问题和挑战,这些问题有可能成为物联网在未来发展和应用的巨大障碍,而区块链技术为这些问题的解决提供了新的可能性。
但是,在目前已知的区块链+物联网的相关应用开发部署场景下,应用服务商需要先使用区块链服务(例如BaaS,Blockchain as a Service)而部署若干个区块链服务节点,然后在1-N个物联网设备上分别部署区块链相关的节点SDK以及配置相关参数,使得物联网应用服务商无法专注于相关应用的开发,给物联网应用服务商带来较高的配置、部署以及运维区块链相关基础服务的成本。
因此,仍然需要一种改进的区块链节点服务部署方案。
发明内容
本公开的目的在于提供一种能够更加便利的部署区块链节点服务的方案,以为应用服务商减少在配置、部署、运维区块链相关基础服务的成本。
根本公开的第一个方面,提供了一种区块链节点服务部署方法,包括:响应于来自用户的区块链节点服务部署请求,向区块链服务端发送部署请求,以便所述区块链服务端在一个或多个区块链节点上部署节点服务;基于所述区块链服务端返回的所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的 可信应用;发送所述可信应用,以便在所述设备上安装所述可信应用。
可选地,所述配置信息包括区块链节点地址。
可选地,所述区块链节点服务部署请求包括与所述用户关联的设备的标识信息和区块链节点配置参数。
可选地,该方法区块链节点服务部署还可以包括:接收来自用户的服务账号注册请求以及与所述用户关联的设备信息;向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息;以及向所述区块链服务端发送所述服务账号注册请求。
可选地,发送所述可信应用的步骤包括:向所述可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
可选地,所述区块链节点服务部署方法可以应用于物联网,所述设备可以是具有可信安全芯片或模组的物联网设备。
根据本公开的第二个方面,还提供了一种区块链节点服务部署方法,包括:响应于来自用户的区块链节点服务部署请求,在一个或多个区块链节点上部署节点服务;基于所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用;以及向可信服务管理服务端发送所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
可选地,发送所述可信应用的步骤可以包括:向可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
可选地,该区块链节点服务部署方法还可以包括:接收来自用户的服务账号注册请求以及与所述用户关联的设备信息,以完成所述用户的服务账号注册以及相关设备的绑定;向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息。
可选地,所述区块链节点服务部署方法可以应用于物联网,所述设备可以是具有可信安全芯片或模组的物联网设备。
根据本公开的第三个方面,还提供了一种区块链节点服务部署系统,包括:区块链管理平台,用于响应于来自用户的区块链节点服务部署请求,向区块链服务端发送部署请求,并基于所述区块链服务端返回的所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用,并发送所述可信应用,以便在所述设备上安装所述可信应用;区块链服务端,用于响应于来自所述区块链管理平 台的部署请求,在一个或多个区块链节点上部署节点服务,并向所述区块链管理平台返回所述一个或多个区块链节点的配置信息。
可选地,该区块链节点服务部署系统还可以包括:可信服务管理服务端,用于基于与所述用户关联的设备的设备标识信息以及接收到的来自所述区块链管理平台的可信应用,在所述设备上远程安装与所述设备对应的可信应用。
可选地,该区块链节点服务部署系统还可以包括:设备中的可信执行环境,与所述可信服务管理服务端连接,并响应于来自所述可信服务管理服务端的远程安装操作,在所述设备上安装与所述设备对应的可信应用。
可选地,所述区块链管理平台还可以用于:接收来自用户的服务账号注册请求以及与所述用户关联的设备信息;向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息;以及向所述区块链服务端发送所述服务账号注册请求。
可选地,所述区块链管理平台向所述可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
可选地,所述区块链节点服务部署系统应用于物联网,所述设备是具有可信安全芯片或模组的物联网设备。
根据本公开的第四个方面,还提供了一种区块链节点服务部署装置,包括:请求发送单元,用于响应于来自用户的区块链节点服务部署请求,向区块链服务端发送部署请求,以便所述区块链服务端在一个或多个区块链节点上部署节点服务;应用配置单元,用于基于所述区块链服务端返回的所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用;第一发送单元,用于发送所述可信应用,以便在所述设备上安装所述可信应用。
可选地,该区块链节点服务部署装置还可以包括:注册单元,用于接收来自用户的服务账号注册请求以及与所述用户关联的设备信息;第二发送单元,向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息;以及第三发送单元,用于向所述区块链服务端发送所述服务账号注册请求。
可选地,所述第一发送单元向所述可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
根据本公开的第五个方面,还提供了一种计算设备,包括:处理器;以及存储器,其上存储有可执行代码,当所述可执行代码被所述处理器执行时,使所述处理器执行如上所述的方法。
根据本公开的第六个方面,还提供了一种非暂时性机器可读存储介质,其上存储有可执行代码,当所述可执行代码被电子设备的处理器执行时,使所述处理器执行如上所述的方法。
本公开通过提供一键式部署和运维平台模式,为应用服务商提供一键式部署服务,使相关方可专注于相关应用的开发,减少配置、部署和运维区块链相关基础服务的成本。
附图说明
通过结合附图对本公开示例性实施方式进行更详细的描述,本公开的上述以及其它目的、特征和优势将变得更加明显,其中,在本公开示例性实施方式中,相同的参考标号通常代表相同部件。
图1示出了根据本公开一个实施例的分布式账本技术网络拓扑结构示意图;
图2示出了根据本公开一个实施例的区块链节点服务部署系统的示意性框图;
图3示出了根据本公开一个实施例的区块链节点服务部署的流程示意图;
图4示出了根据本公开一个实施例的区块链节点服务部署方法的流程示意图;
图5示出了根据本公开一个实施例的区块链节点服务部署方法的流程示意图;
图6示出了根据本发明一个实施例的区块链节点服务部署装置的结构的示意性方框图;
图7示出了根据本公开一实施例可用于实现上述区块链节点服务部署方法的计算设备的结构示意图。
具体实施方式
下面将参照附图更详细地描述本公开的优选实施方式。虽然附图中显示了本公开的优选实施方式,然而应该理解,可以以各种形式实现本公开而不应被这里阐述的实施方式所限制。相反,提供这些实施方式是为了使本公开更加透彻和完整,并且能够将本公开的范围完整地传达给本领域的技术人员。
【术语解释】
区块链(Blockchain)本质是一种多方共享的分布式账本技术。它通过数学方法实现交易数据和历史记录的不可篡改性,通过共识算法和智能合约实现各参与方对交易的共同确认和账本记录。区块链分为公有链、联盟链、私有链三种基本类型。
区块链服务:(Blockchain as a Service,BaaS),是指利用区块链产生的数据, 提供基于区块链的搜索查询、任务提交等一系列操作服务。本公开的区块链服务是一种基于主流区块链技术的企业级PaaS(Platform as a Service)平台服务,帮助用户快速构建更稳定、安全的生产级区块链环境,减少在区块链部署、运维、管理、应用开发等方面的挑战,使用户更专注于核心业务创新,并实现业务快速上链。
分布式账本技术(Distributed ledger Technology,DLT),是一种在网络成员之间共享、复制和同步的数据库。分布式账本记录网络参与者之间的交易,比如资产或数据的交换。这种共享账本降低了因调解不同账本所产生的时间和开支成本。
分布式网络节点(DLT node)是由分布在不同地点且具有多个终端的节点机互连而成的。网中任一点均至少与两条线路相连,当任意一条线路发生故障时,通信可转经其他链路完成,具有较高的可靠性。同时,网络易于扩充。
边缘计算(Edge Computing)是指在靠近物或数据源头的一侧,采用网络、计算、存储、应用核心能力为一体的开放平台,就近提供最近端服务。其应用程序在边缘侧发起,产生更快的网络服务响应,满足行业在实时业务、应用智能、安全与隐私保护等方面的基本需求。边缘计算处于物理实体和工业连接之间,或处于物理实体的顶端。而云端计算,仍然可以访问边缘计算的历史数据。
云计算(Cloud Computing)是基于互联网的相关服务的增加、使用和交付模式,通常涉及通过互联网来提供动态易扩展且经常是虚拟化的资源。
物联网区块链(Blockchain of Things,BoT)管理平台,是云服务提供商面向物联网+区块链的上层应用服务商推出的云上+边缘设备的区块链网络管理平台,旨在帮助搭建设备终端和云端、设备终端和设备终端的双向区块链节点数据通信网络。
区块链服务端(例如BaaS云平台)是一种基于主流区块链技术的企业级PaaS(Platform as a Service)平台服务,能够帮助用户快速构建更稳定、安全的区块链环境,减少在区块链部署、运维、管理、应用开发等方面的挑战,使用户更专注于核心业务创新,并实现业务快速上链。其中,用户是指物联网应用服务商或物联网设备使用方。
可信服务管理(Trusted Service Manager,TSM)服务端是一种对具备诸如SE安全芯片的设备做远程芯片管理和应用分发的可信服务管理平台,通过提供一站式服务,为用户提供端到端的安全解决方案,包括安全载体生命周期管理、应用分发、密钥托管、统计分析等。该可信服务平台符合GP国际规范,支持多种模式、多种安全载体、标准接口,保证快速落地与实施。并且,能够结合服务提供商强大的云计算能力,保证服务 系统的高性能、高安全性、可扩展性、高可用性、以及较低的成本。
可信执行环境:(Trusted Execution Environment,TEE)是物联网设备的主处理器上的一个安全区域,其可以保证存储到该安全区域的代码和数据的安全性、机密性以及完整性。可信执行环境的载体例如可以是设备上的可信根RoT安全芯片(Secure Element、SIM、TEE等)或模组(Secure MCU)。
可信应用:(Trusted Application,TA),通过可信认证服务的可信任的应用程序。本公开中,在云端部署的区块链节点能够为设备端的可信应用提供区块链服务。并且,在本公开实施例中,可信应用被安装在设备上的可信安全芯片或模组中。
设备标识,物联网设备的身份标识,可以在物联网中唯一标识物联网设备。
【方案概述】
本公开针对在有区块链服务端+设备端部署需求的场景,提出了一种分布式账本技术网络拓扑结构,该分布式网络拓扑结构可适用于任何形态的区块链技术,包括私有链、公链和/或联盟链,本公开将以联盟链形态下为例展开详细描述。
应当理解的是,该分布式账本技术网络拓扑结构可适用于任何有区块链服务端+设备端部署需求的领域或场景,例如物联网领域和商品溯源、供应链金融、公益慈善、互助保险等场景。
为方便描述与理解,本公开中所示的附图及实施例均结合用于物联网领域的区块链节点服务部署展开描述,如下涉及的云端(或云上)是为物联网领域下提供相关区块链服务的云上服务端,而云下设备端则可以是包括具有可信安全芯片或模组的物联网设备的设备端,其中,该物联网设备可以包括但不限于手机、可穿戴设备、智能门锁、网关设备、车载设备等等。
图1示出了根据本公开一个实施例的分布式账本技术网络拓扑结构示意图。应当理解的是,该网络拓扑结构是对本公开的完成云上服务端+云下设备端区块链节点服务部署后的区块链网络拓扑结构的示意图,而非对本公开的分布式账本技术网络拓扑结构的具体限制。
如图1所示,该分布式账本技术网络拓扑结构可以包括部署于云端的云上主链,以及部署于云下设备端的物联网边缘节点侧链。
对于每一个物联网应用服务商(例如企业、组织等),当其要加入物联网的某联盟区块链(简称联盟链)时,为其在云端部署一个或多个区块链节点以使其作为区块链主联盟链的参与方,该在云端部署的一个或多个区块链节点即形成图1右侧所示的云上的 主链,以便于依托主链的运算能力、数据存储能力进行区块链相关运算,为众多应用服务商提供相关区块链服务。
同时,由于成本、数据隐私、边缘计算的实时性等因素,又需要在相关边缘运算设备(云下设备侧)上部署区块链节点服务,如图1左侧所示的物联网边缘节点侧链。其中,边缘设备上的区块链节点可以按业务需要可以与一个或多个云上主链节点连接,完成区块链的相关协同运算。
【区块链节点服务部署系统】
上述网络拓扑结构的形成可由本公开的区块链节点服务部署系统实现。
图2示出了根据本公开一个实施例的区块链节点服务部署系统(简称部署系统)的示意性框图。
如图2所示,本公开的区块链节点服务部署系统可以包括两端,即云端(云上)以及物联网设备端(云下)。
云端(云上)可以包括区块链管理平台、区块链服务端、以及可信服务管理服务端。
当应用于物联网技术领域中时,上述区块链管理平台可以被称为物联网区块链(Blockchain of Things,BoT)管理平台(在如下描述中简称为BoT云平台),是云服务提供商面向物联网+区块链的上层应用服务商推出的云上+边缘设备的区块链网络管理平台,旨在帮助搭建设备终端和云端、设备终端和设备终端的双向区块链节点数据通信网络。该物联网区块链管理平台能够提供设备端SDK,能够让物联网设备轻松接入系统服务。
区块链服务端,例如可以是区块链(Blockchain as a Service,BaaS)云平台(在如下的描述中简称为BaaS云平台),是一种基于主流区块链技术的企业级PaaS(Platform as a Service)平台服务,能够帮助用户快速构建更稳定、安全的区块链环境,减少在区块链部署、运维、管理、应用开发等方面的挑战,使用户更专注于核心业务创新,并实现业务快速上链。其中,用户是指物联网应用服务商或物联网设备使用方。
作为本公开的一个示例,BoT云平台能够响应于来自用户的区块链节点服务部署请求,向BaaS云平台发送部署请求,并基于所述BaaS云平台返回的所述一个或多个(云上)区块链节点的配置信息,针对与所述用户关联的设备配置与所述(云上)区块链节点对应的可信应用,并发送所述可信应用,以便在所述设备上安装所述可信应用。
BaaS云平台能够响应于来自所述区块链云平台的云上部署请求,在云端的一个或多个云上区块链节点上部署节点服务,并向所述区块链云平台返回所述一个或多个云上区块链节点的配置信息。
可信服务管理(Trusted Service Manager,TSM)服务端是一种对具备SE安全芯片的设备做远程芯片管理和应用分发的可信服务平台,通过提供一站式服务,为用户提供端到端的安全解决方案,包括安全载体生命周期管理、应用分发、密钥托管、统计分析等。该可信服务平台符合GP国际规范,支持多种模式、多种安全载体、标准接口,保证快速落地与实施。并且,能够结合服务提供商强大的云计算能力,保证服务系统的高性能、高安全性、可扩展性、高可用性、以及较低的成本。
BoT云平台向所述TSM服务端发送该TA,同时还发送设备的设备ID,以便于TSM服务端可以基于该设备ID以及该设备相对应的配置信息,实现向该设备的可信应用分发以及远程安装等服务。
TSM服务端可以基于与所述用户关联的设备的设备标识信息以及接收到的来自所述区块链云平台的可信应用,在所述设备上远程安装与所述设备对应的可信应用。具体来说,所述TSM服务端在所述设备上的安全元件(例如如前所述的SE、SIM、eSIM、TEE、Secure MCU等)内安装与所述设备对应的可信应用。
云下设备端可以包括相关设备终端(例如物联网IoT设备)。
由于在不同阶段使用该设备终端的对象即操作主体不同,还可以基于相对应的使用相关方对云下设备端进行更为具体的划分。例如,IoT设备原厂商即OEM商、IoT设备使用方/IoT应用服务商、IoT设备中的可信执行环境TEE。其中,该可信执行环境TEE的载体是设备终端上的相关设备安全芯片,例如SE安全芯片。
IoT设备原厂商即OEM商作为相关设备的原始制造商实现相关设备的初始制造,例如为设备分配设备标识ID和设备秘钥ID、将相关信息烧录在设备TEE中、以及将设备的相关信息注册到TSM服务端等。
IoT设备使用方/IoT应用服务商作为用户方可以注册服务提供商提供的SP账号,并基于此SP账号享受相关服务。
设备中的可信执行环境TEE能够与所述TSM服务端连接,并可以响应于来自所述可信服务管理服务端的远程安装操作,在所述设备(的安全元件)上安装与所述设备对应的可信应用TA。
通过本公开上述的区块链节点服务部署系统,能够为用户提供一键式云上+云下的 部署服务,使得用户可专注于相关应用的开发,减小在配置、部署以及运维区块链相关基础服务方面的成本,提升用户体验。
如前所述用户需要注册相关SP账号来享受服务提供方的相关服务。因此,在为用户部署相关区块链节点服务之前,上述BoT云平台还能够为用户提供服务账号注册以及设备绑定的服务。
在注册阶段,BoT云平台接收来自用户的服务账号注册请求(包括用户账号注册信息)以及与所述用户关联的设备信息,并完成用户服务账号以及该用户服务账号以及用户设备的绑定。之后,BoT云平台向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息,并且,向所述BaaS云平台发送所述服务账号注册请求。
由此,在上述注册阶段,用户只需执行一次填写注册信息的步骤,即可由BoT云平台完成用户服务账号注册,以及用户注册信息与设备绑定信息在云端的同步存储。
应当理解的是,图2仅对本公开的区块链节点服务部署系统的主要组成部分进行了简单介绍,本公开不对该部署系统的各个部分之间的关联关系以及各个部分分别具体实现的功能进行任何其它限定。其中涉及的相关设备的制造方案可参见现有的相关技术,本公开对此不再赘述。通过该部署系统所实现的区块链节点服务的部署可参见如下附图及实施例的描述,在此不再赘述。
【区块链节点服务部署流程】
图3示出了根据本公开一个实施例的区块链节点服务部署的流程示意图。
如图3所示,基于图2中示出的部署系统的云上/云下中具体涉及的部分,该区块链节点服务部署的流程主要可以分为三部分,分别为IoT设备制造部分、SP账号注册部分以及区块链节点服务部署部分。如下将结合图3所示的流程图对本实施例的区块链节点服务部署的流程进行详细说明。
IoT设备制造
参见图3所示的流程图,在物联网(IoT)设备原厂商即OEM商在生产有可信执行环境(TEE)的IoT设备时:
在步骤1.0,向设备中的TEE中烧录相关系统应用和保密数据,即提供TEE证书(Provision TEE Credentials);
在步骤1.1,OEM商向其后台可信服务管理服务端(或者第三方可信服务管理服务端)上传IoT设备TEE的相关识别ID和密钥(包括公钥和私钥)ID等信息,以使烧录成功的物联网设备在可信服务管理服务端进行设备注册。在其中,该可信服务管理服务端需 要与云平台(如BoT云平台以及BaaS云平台)均已关联对接。
SP账号注册
每一个物联网应用服务商/物联网设备使用方(即用户)在购买和部署相关IoT设备后首先可以进行SP账号注册。该SP账号是服务提供商(Service providers,SP)为用户提供的服务账号,用户可以基于此SP账号享受服务提供商为其提供的各项服务。
具体地,在步骤2.0,用户在BoT(Blockchain As Things)云平台上注册SP账号,并上传相关已购买IoT设备的设备标识(ID)信息,以使得能够在BoT云平台为该用户注册与之相对应的SP账号,并且实现该SP账号与用户的设备的绑定。
之后,在步骤2.1,BoT云平台与可信服务管理服务端连接,并向其发送相关SP账号注册请求及绑定的设备ID信息。
在步骤2.2,BoT云平台向BaaS云平台后端发送相关SP账号注册请求及绑定的设备ID信息。
由此,通过本公开的BoT云平台,每一个用户只需执行一次账号注册和设备绑定请求,即可一步实现用户账号信息和绑定的设备信息在云上的存储,极大简化了用户服务账号注册与设备绑定的流程,给用户带来极大的便利。
区块链节点服务部署
当物联网IoT应用服务商/物联网设备使用方(即用户)在物联网中有区块链云上+云下部署需求的场景下:
在步骤3.0,用户在BoT云平台上发出区块链节点服务部署请求,请求创建云上(N个区块链节点服务)和云下(N个物联网设备上的区块链节点服务)。
在此,用户只需在BoT云平台上提供搭建云上+云下区块链环境所必要的信息即可。所述必要的信息例如可以包括IoT设备ID、区块链节点配置参数(例如联盟名称、联盟域名、地域、规格、组织信息等)等。对于不同的服务提供商上述信息不完全相同,具体可根据服务提供商以及实际应用场景确定,本公开对此不做限制。
之后,在步骤3.1,BoT云平台向区块链服务(BaaS)云平台发送云上部署请求,请求在云端的一个或多个云上区块链节点部署节点服务(本实施例中例如为N个)。其中,该请求中包括搭建云上区块链环境所必要的信息,可由服务提供商根据需求自行配置该请求中所需的必要配置参数,本公开对此也不作限制。
在步骤3.2,响应于上述云上部署请求,BaaS云平台在云端的一个或多个相关云上区块链节点上创建、部署和运行节点服务,随后在步骤3.3,BaaS云平台向BoT云平台 返回相关信息,例如云上区块链节点的地址、创世节点(最早构建的区块链节点)以及其它相关配置参数。
在步骤3.4,基于已部署完成的云上区块链节点服务的相关配置信息以及相关的设备信息,BoT云平台针对设备端与所述用户关联的设备配置与所述云上区块链节点对应的可信应用(TA)。其中,云上区块链节点服务的相关配置信息可以包括云上区块链节点地址。
在步骤3.5,BoT云平台向TSM服务端发送可信应用(TA)以及与该可信应用相对应的IoT设备ID信息。
在步骤4.0,IoT设备向TSM服务端连接。
在步骤4.1,TSM服务端基于设备ID信息、应用配置信息等参数,远程在相应的IoT设备的安全元件上安装该设备对应的可信应用(TA)。
至此,针对于有区块链服务端+设备端快速部署需求的场景,在用户发出区块链节点服务部署请求后,一键式完成了服务端+设备端的区块链服务部署,极大简化了用户的操作流程。
由此,通过本公开上述的区块链节点服务部署流程,能够帮助物联网应用服务商一键式快速创建和部署区块链环境,简化区块链服务的部署流程和应用配置。
本公开的用于物联网的区块链节点服务部署方案,通过对传统物联网设备安全垂直技术能力和云上横向通用服务技术的整合,能够在不改变现有相关技术栈的前提下,将基于IoT安全芯片和TEE端到端可信服务管理能力、云端一站式BaaS技术能力云上(主要的区块链运算和存储服务平台)+云下(边缘计算服务平台)进行结合,为IoT边缘计算和云计算结合的区块链基础服务提供由云端切入的、端到端安全的、一站式部署和运维平台模式,深度融合物联网技术和区块链技术,使物联网应用服务商可以专注于相关应用的开发,减少在配置、部署、运维区块链相关基础服务的成本,实现区块链环境的一键搭建,以便用户快速开展区块链业务创新。
【区块链节点服务部署方法】
本公开如上所述的区块链节点服务部署流程可以实现为一种区块链节点服务部署方法。
图4示出了根据本公开一个实施例的区块链节点服务部署方法的流程示意图。其中,该区块链节点服务部署方法可应用于物联网,并可由区块链管理平台侧执行,如下 所述设备可以是具有可信安全芯片或模组的物联网设备。
如图4所示,在步骤S410,响应于来自用户的区块链节点服务部署请求,向区块链服务端发送部署请求,以便所述区块链服务端在一个或多个区块链节点上部署节点服务。
区块链节点服务部署请求包括与所述用户关联的设备的标识信息和区块链节点配置参数。设备标识信息例如可以是物联网设备的身份标识,可以在物联网中唯一标识物联网设备。区块链节点配置参数例如可以包括需要配置的区块链节点的个数或是其它相关配置参数。
在步骤S420,基于所述区块链服务端返回的所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用。其中,区块链节点的配置信息可以包括区块链节点地址。
在步骤S430,发送所述可信应用,以便在所述设备上安装所述可信应用。具体地,可以是向所述可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
作为本公开的一个示例,上述方法还可以包括用户服务账号注册过程,即接收来自用户的服务账号注册请求以及与所述用户关联的设备信息;向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息;以及向所述区块链服务端发送所述服务账号注册请求。
在上述注册阶段,用户只需执行一次填写注册信息的步骤,即可由区块链管理平台完成用户服务账号注册,以及用户注册信息与设备绑定信息在云端的同步存储。
图5示出了根据本公开一个实施例的区块链节点服务部署方法的流程示意图。其中,该区块链节点服务部署方法可应用于物联网,并可由图2所示的部署系统执行,如下所述设备可以是具有可信安全芯片或模组的物联网设备。
如图5所示,在步骤S510,响应于来自用户的区块链节点服务部署请求,在一个或多个区块链节点上部署节点服务。
在步骤S520,基于所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用。
在步骤S530,向可信服务管理服务端发送所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。其中,可以是向可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可 信应用。
作为本公开的一个示例,上述方法还可以包括用户服务账号注册过程,即接收来自用户的服务账号注册请求以及与所述用户关联的设备信息,以完成所述用户的服务账号注册以及相关设备的绑定;向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息。
在上述注册阶段,用户只需执行一次填写注册信息的步骤,即可由区块链管理平台完成用户服务账号注册,以及用户注册信息与设备绑定信息在云端的同步存储。
至此,已经结合图4-图5所示的方法流程图简单示出了本公开的区块链节点服务部署方法,该部署方法的具体实现流程可参见本公开如上相关描述,在此不再赘述。
【区块链节点服务部署装置】
图6示出了根据本发明一个实施例的区块链节点服务部署装置(简称部署装置)的结构的示意性方框图。其中,部署装置的功能模块可以由实现本公开原理的硬件、软件或硬件和软件的结合来实现。本领域技术人员可以理解的是,图6所描述的功能模块可以组合起来或者划分成子模块,从而实现上述发明的原理。因此,本文的描述可以支持对本文描述的功能模块的任何可能的组合、或者划分、或者更进一步的限定。
下面就部署装置可以具有的功能模块以及各功能模块可以执行的操作做简要说明,对于其中涉及的细节部分可以参见上文相关的描述,这里不再赘述。
如图6所示,本发明的区块链节点服务部署装置(简称部署装置)600可以包括请求发送单元610、应用配置单元620和第一发送单元630。其中,该部署装置可以设置在云端并应用于物联网,如下所述设备可以是具有可信安全芯片或模组的物联网设备。
请求发送单元610可以用于响应于来自用户的区块链节点服务部署请求,向区块链服务端发送云上部署请求,以便所述区块链服务端在一个或多个区块链节点上部署节点服务。其中,区块链节点服务部署请求可以包括与所述用户关联的设备的标识信息和区块链节点配置参数。其中区块链节点配置参数例如可以是需要进行配置的区块链节点的个数或其它相关配置参数。
应用配置单元620可以用于基于所述区块链服务端返回的所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用。其中,配置信息可以包括区块链节点地址。
第一发送单元630可以用于发送所述可信应用,以便在所述设备上安装所述可信应 用。其中,所述第一发送单元630可以向所述可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
可选地,本公开的部署装置还可以包括使用户进行服务账号注册的注册单元、第二发送单元、第三发送单元(图中未示出)。
具体来说,注册单元可以用于接收来自用户的服务账号注册请求以及与所述用户关联的设备信息。第二发送单元,向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息。第三发送单元,用于向所述BaaS云平台发送所述服务账号注册请求。
应当理解的是,本公开中的第一、第二、第三仅是为了对所涉及的发送单元进行区分,而非对其功能或顺序等的限定。可选地,在此第二发送单元与第三发送单元可以复用,并且本公开也不对两者的执行顺序进行限定。第一/二/三发送单元分别可根据其遵循的通讯协议执行相应的发送工作。
图6示出的部署装置的具体功能实现可以参见上文结合图2-5的相关描述,在此不再赘述。
【计算设备】
图7示出了根据本公开一实施例可用于实现上述区块链节点服务部署方法的计算设备的结构示意图。
参见图7,计算设备700包括存储器710和处理器720。
处理器720可以是一个多核的处理器,也可以包含多个处理器。在一些实施例中,处理器720可以包含一个通用的主处理器以及一个或多个特殊的协处理器,例如图形处理器(GPU)、数字信号处理器(DSP)等等。在一些实施例中,处理器720可以使用定制的电路实现,例如特定用途集成电路(ASIC,Application Specific Integrated Circuit)或者现场可编程逻辑门阵列(FPGA,Field Programmable Gate Arrays)。
存储器710可以包括各种类型的存储单元,例如系统内存、只读存储器(ROM),和永久存储装置。其中,ROM可以存储处理器720或者计算机的其他模块需要的静态数据或者指令。永久存储装置可以是可读写的存储装置。永久存储装置可以是即使计算机断电后也不会失去存储的指令和数据的非易失性存储设备。在一些实施方式中,永久性存储装置采用大容量存储装置(例如磁或光盘、闪存)作为永久存储装置。另外一些实施方式中,永久性存储装置可以是可移除的存储设备(例如软盘、光驱)。系统内存可以是可读写存储设备或者易失性可读写存储设备,例如动态随机访问内存。系统内存可以 存储一些或者所有处理器在运行时需要的指令和数据。此外,存储器710可以包括任意计算机可读存储媒介的组合,包括各种类型的半导体存储芯片(DRAM,SRAM,SDRAM,闪存,可编程只读存储器),磁盘和/或光盘也可以采用。在一些实施方式中,存储器710可以包括可读和/或写的可移除的存储设备,例如激光唱片(CD)、只读数字多功能光盘(例如DVD-ROM,双层DVD-ROM)、只读蓝光光盘、超密度光盘、闪存卡(例如SD卡、min SD卡、Micro-SD卡等等)、磁性软盘等等。计算机可读存储媒介不包含载波和通过无线或有线传输的瞬间电子信号。
存储器710上存储有可执行代码,当可执行代码被处理器720处理时,可以使处理器720执行上文述及的区块链节点服务部署方法。
上文中已经参考附图详细描述了根据本公开的区块链节点服务部署方法、装置及系统。
此外,根据本公开的方法还可以实现为一种计算机程序或计算机程序产品,该计算机程序或计算机程序产品包括用于执行本公开的上述方法中限定的上述各步骤的计算机程序代码指令。
或者,本公开还可以实施为一种非暂时性机器可读存储介质(或计算机可读存储介质、或机器可读存储介质),其上存储有可执行代码(或计算机程序、或计算机指令代码),当所述可执行代码(或计算机程序、或计算机指令代码)被电子设备(或计算设备、服务器等)的处理器执行时,使所述处理器执行根据本公开的上述方法的各个步骤。
本领域技术人员还将明白的是,结合这里的公开所描述的各种示例性逻辑块、模块、电路和算法步骤可以被实现为电子硬件、计算机软件或两者的组合。
附图中的流程图和框图显示了根据本公开的多个实施例的系统和方法的可能实现的体系架构、功能和操作。在这点上,流程图或框图中的每个方框可以代表一个模块、程序段或代码的一部分,所述模块、程序段或代码的一部分包含一个或多个用于实现规定的逻辑功能的可执行指令。也应当注意,在有些作为替换的实现中,方框中所标记的功能也可以以不同于附图中所标记的顺序发生。例如,两个连续的方框实际上可以基本并行地执行,它们有时也可以按相反的顺序执行,这依所涉及的功能而定。也要注意的是,框图和/或流程图中的每个方框、以及框图和/或流程图中的方框的组合,可以用执行规定的功能或操作的专用的基于硬件的系统来实现,或者可以用专用硬件与计算机指令的组合来实现。
以上已经描述了本公开的各实施例,上述说明是示例性的,并非穷尽性的,并且也不限于所披露的各实施例。在不偏离所说明的各实施例的范围和精神的情况下,对于本技术领域的普通技术人员来说许多修改和变更都是显而易见的。本文中所用术语的选择,旨在最好地解释各实施例的原理、实际应用或对市场中的技术的改进,或者使本技术领域的其它普通技术人员能理解本文披露的各实施例。

Claims (21)

  1. 一种区块链节点服务部署方法,包括:
    响应于来自用户的区块链节点服务部署请求,向区块链服务端发送部署请求,以便所述区块链服务端在一个或多个区块链节点上部署节点服务;
    基于所述区块链服务端返回的所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用;
    发送所述可信应用,以便在所述设备上安装所述可信应用。
  2. 根据权利要求1所述的方法,其中,
    所述配置信息包括区块链节点地址。
  3. 根据权利要求1所述的方法,其中,
    所述区块链节点服务部署请求包括与所述用户关联的设备的标识信息和区块链节点配置参数。
  4. 根据权利要求1所述的方法,还包括:
    接收来自用户的服务账号注册请求以及与所述用户关联的设备信息;
    向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息;以及
    向所述区块链服务端发送所述服务账号注册请求。
  5. 根据权利要求4所述的方法,其中,发送所述可信应用的步骤包括:
    向所述可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
  6. 根据权利要求1所述的方法,其中,所述区块链节点服务部署方法应用于物联网,所述设备是物联网设备。
  7. 一种区块链节点服务部署方法,包括:
    响应于来自用户的区块链节点服务部署请求,在一个或多个区块链节点上部署节点服务;
    基于所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用;以及
    向可信服务管理服务端发送所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
  8. 根据权利要求7所述的方法,其中,发送所述可信应用的步骤包括:
    向可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
  9. 根据权利要求7所述的方法,还包括:
    接收来自用户的服务账号注册请求以及与所述用户关联的设备信息,以完成所述用户的服务账号注册以及相关设备的绑定;
    向所述设备的可信服务管理服务端发送所述服务账号注册请求以及所述设备信息。
  10. 根据权利要求7所述的方法,其中,所述区块链节点服务部署方法应用于物联网,所述设备是具有可信安全芯片或模组的物联网设备。
  11. 一种区块链节点服务部署系统,包括:
    区块链管理平台,用于响应于来自用户的区块链节点服务部署请求,向区块链服务端发送部署请求,并基于所述区块链服务端返回的一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用,并发送所述可信应用,以便在所述设备上安装所述可信应用;
    区块链服务端,用于响应于来自所述区块链管理平台的部署请求,在一个或多个区块链节点上部署节点服务,并向所述区块链管理平台返回所述一个或多个区块链节点的配置信息。
  12. 根据权利要求11所述的系统,还包括:
    可信服务管理服务端,用于基于与所述用户关联的设备的设备标识信息以及接收到的来自所述区块链管理平台的可信应用,在所述设备上远程安装与所述设备对应的可信应用。
  13. 根据权利要求12所述的系统,还包括:
    设备中的可信执行环境,与所述可信服务管理服务端连接,并响应于来自所述可信服务管理服务端的远程安装操作,在所述设备上安装与所述设备对应的可信应用。
  14. 根据权利要求11所述的系统,其中,所述区块链云平台还用于:
    接收来自用户的服务账号注册请求以及与所述用户关联的设备信息;
    向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息;以及
    向所述区块链服务端发送所述服务账号注册请求。
  15. 根据权利要求14所述的系统,其中,
    所述区块链管理平台向所述可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
  16. 根据权利要求11所述的系统,其中,所述区块链节点服务部署系统应用于物联网,所述设备是具有可信安全芯片或模组的物联网设备。
  17. 一种区块链节点服务部署装置,包括:
    请求发送单元,用于响应于来自用户的区块链节点服务部署请求,向区块链服务端发送部署请求,以便所述区块链服务端在一个或多个区块链节点上部署节点服务;
    应用配置单元,用于基于所述区块链服务端返回的所述一个或多个区块链节点的配置信息,针对与所述用户关联的设备配置与所述区块链节点对应的可信应用;
    第一发送单元,用于发送所述可信应用,以便在所述设备上安装所述可信应用。
  18. 根据权利要求17所述的装置,还包括:
    注册单元,用于接收来自用户的服务账号注册请求以及与所述用户关联的设备信息;
    第二发送单元,向可信服务管理服务端发送所述服务账号注册请求以及所述设备信息;以及
    第三发送单元,用于向所述区块链服务端发送所述服务账号注册请求。
  19. 根据权利要求17所述的装置,其中,
    所述第一发送单元向所述可信服务管理服务端发送所述设备的标识信息和所述可信应用,以便所述可信服务管理服务端在所述设备上安装所述可信应用。
  20. 一种计算设备,包括:
    处理器;以及
    存储器,其上存储有可执行代码,当所述可执行代码被所述处理器执行时,使所述处理器执行如权利要求1-10中任何一项所述的方法。
  21. 一种非暂时性机器可读存储介质,其上存储有可执行代码,当所述可执行代码被电子设备的处理器执行时,使所述处理器执行如权利要求1至10中任一项所述的方法。
PCT/CN2019/109268 2018-10-12 2019-09-30 区块链节点服务部署方法、装置、系统、计算设备及介质 WO2020073859A1 (zh)

Priority Applications (3)

Application Number Priority Date Filing Date Title
JP2021520226A JP7442516B2 (ja) 2018-10-12 2019-09-30 ブロックチェーンノードサービスの展開方法、装置およびシステム、ならびにコンピューティングデバイスおよび媒体
SG11202101917TA SG11202101917TA (en) 2018-10-12 2019-09-30 Blockchain node service deployment method, apparatus and system, and computing device and medium
US17/193,654 US11604631B2 (en) 2018-10-12 2021-03-05 Blockchain node service deployment method, apparatus and system and computing device and medium

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201811189839.9 2018-10-12
CN201811189839.9A CN111045690B (zh) 2018-10-12 2018-10-12 区块链节点服务部署方法、装置、系统、计算设备及介质

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US17/193,654 Continuation US11604631B2 (en) 2018-10-12 2021-03-05 Blockchain node service deployment method, apparatus and system and computing device and medium

Publications (1)

Publication Number Publication Date
WO2020073859A1 true WO2020073859A1 (zh) 2020-04-16

Family

ID=70163777

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/109268 WO2020073859A1 (zh) 2018-10-12 2019-09-30 区块链节点服务部署方法、装置、系统、计算设备及介质

Country Status (6)

Country Link
US (1) US11604631B2 (zh)
JP (1) JP7442516B2 (zh)
CN (1) CN111045690B (zh)
SG (1) SG11202101917TA (zh)
TW (1) TW202014878A (zh)
WO (1) WO2020073859A1 (zh)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111984271A (zh) * 2020-08-27 2020-11-24 北京海益同展信息科技有限公司 一种区块链应用程序处理方法、装置及区块链应用系统
CN113220453A (zh) * 2021-05-11 2021-08-06 支付宝(杭州)信息技术有限公司 区块链系统中发起交易的方法及装置
CN113259458A (zh) * 2021-06-02 2021-08-13 支付宝(杭州)信息技术有限公司 一种启动/关闭区块链节点服务的方法和装置
CN114679467A (zh) * 2022-03-23 2022-06-28 中国联合网络通信集团有限公司 多区块链协同服务方法、区块链服务系统和协同服务系统
CN115297117A (zh) * 2022-10-08 2022-11-04 中国人民解放军国防科技大学 基于区块链的云边端安全可信交互计算系统及装置
CN117041264A (zh) * 2023-10-08 2023-11-10 广东省科技基础条件平台中心 一种基于数据处理的区块链资源管理系统及方法
CN113220453B (zh) * 2021-05-11 2024-05-31 支付宝(杭州)信息技术有限公司 区块链系统中发起交易的方法及装置

Families Citing this family (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111369710A (zh) * 2018-12-06 2020-07-03 开利公司 由区块链支持的智能锁系统
US10839377B2 (en) * 2019-01-25 2020-11-17 Coinbase, Inc. Syncing blockchain nodes with snapshots
CN111683117B (zh) * 2020-05-11 2021-12-10 厦门潭宏信息科技有限公司 一种方法、设备及存储介质
CN111552215B (zh) * 2020-05-22 2022-02-11 中国联合网络通信集团有限公司 物联网设备安全防护方法和系统
CN111641715A (zh) * 2020-05-29 2020-09-08 深圳壹账通智能科技有限公司 基于区块链的数据处理方法、装置、设备及介质
CN111753269A (zh) * 2020-06-24 2020-10-09 海南大学 一种基于区块链的身份认证方法及装置
CN112380574A (zh) * 2020-11-11 2021-02-19 杭州甘道智能科技有限公司 一种基于区块链及se芯片的数据上链方法
CN114666340A (zh) * 2020-12-22 2022-06-24 北京八分量信息科技有限公司 一种区块链节点设备及区块链网络系统
CN112699418A (zh) * 2021-01-29 2021-04-23 杭州宇链科技有限公司 一种基于区块链的流动人口管理方法及其系统
CN112445865B (zh) * 2021-01-29 2021-05-18 支付宝(杭州)信息技术有限公司 自动化部署区块链网络的方法、装置及云计算平台
CN115604106A (zh) * 2021-06-28 2023-01-13 华为技术有限公司(Cn) 算力发布方法、算力更新方法及装置
WO2023168970A1 (zh) * 2022-03-10 2023-09-14 华为云计算技术有限公司 一种区块链网络的管理方法及相关设备
CN115314374B (zh) * 2022-07-06 2024-02-06 京东科技信息技术有限公司 区块链节点的部署方法、设备、存储介质及程序产品
CN115348265B (zh) * 2022-08-15 2024-04-19 中南大学 一种基于服务特征值计算的节点动态服务部署策略
TWI818850B (zh) * 2023-01-06 2023-10-11 臺灣網路認證股份有限公司 基於公鑰基礎建設的數位銘牌建立系統及其方法

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106411901A (zh) * 2016-10-08 2017-02-15 北京三未信安科技发展有限公司 一种数字身份标识管理方法及系统
CN107659536A (zh) * 2016-07-25 2018-02-02 中兴通讯股份有限公司 一种应用区块链的方法、装置及系统
US20180254905A1 (en) * 2015-11-30 2018-09-06 Sam Gu Chun Iot-based things management system and method using block-chain authentication
CN108512935A (zh) * 2018-04-16 2018-09-07 腾讯科技(深圳)有限公司 数据服务系统、方法、服务器和计算机可读存储介质
CN108540316A (zh) * 2018-03-29 2018-09-14 长沙汉拓信息技术有限公司 一种物联网管理系统

Family Cites Families (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP4568262B2 (ja) 2006-09-29 2010-10-27 日本たばこ産業株式会社 データ収集システム
CN106452785B (zh) 2016-09-29 2019-05-17 财付通支付科技有限公司 区块链网络、分支节点及区块链网络应用方法
US11128603B2 (en) 2016-09-30 2021-09-21 Nec Corporation Method and system for providing a transaction forwarding service in blockchain implementations
KR102470727B1 (ko) 2016-12-30 2022-11-25 비씨 디벨롭먼트 랩스 게엠베하 블록체인 가능한 서비스 제공자 시스템
US10452998B2 (en) * 2017-03-19 2019-10-22 International Business Machines Corporation Cognitive blockchain automation and management
US10320566B2 (en) 2017-04-04 2019-06-11 International Business Machines Corporation Distributed logging of application events in a blockchain
US10944546B2 (en) 2017-07-07 2021-03-09 Microsoft Technology Licensing, Llc Blockchain object interface
CN107392619B (zh) * 2017-07-31 2020-12-29 众安信息技术服务有限公司 智能合约处理方法及装置
CN107579931B (zh) * 2017-09-08 2019-09-10 杭州云象网络技术有限公司 一种基于Kubernetes的区块链即服务资源适配方法
US11556521B2 (en) 2017-09-29 2023-01-17 Oracle International Corporation System and method for providing an interface for a blockchain cloud service
CN108305072B (zh) * 2018-01-04 2021-02-26 上海点融信息科技有限责任公司 部署区块链网络的方法、设备和计算机存储介质
CN108520462B (zh) 2018-03-30 2020-07-24 阿里巴巴集团控股有限公司 基于区块链的业务执行方法及装置、电子设备
MY197067A (en) * 2018-05-24 2023-05-24 Soft Space Sdn Bhd Method for processing a secure financial transaction using a commercial off-the-shelf or an internet of things device
CN108965468B (zh) 2018-08-16 2021-04-30 北京京东尚科信息技术有限公司 区块链网络服务平台及其链码安装方法、存储介质
US10725744B2 (en) 2018-12-27 2020-07-28 Silver Rocket Data Technology (Shanghai) Co., Ltd Method for adapting to blockchain and device, terminal and medium performing the same
CN114930313A (zh) 2019-09-17 2022-08-19 科恩巴斯公司 用于管理区块链节点的系统和方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20180254905A1 (en) * 2015-11-30 2018-09-06 Sam Gu Chun Iot-based things management system and method using block-chain authentication
CN107659536A (zh) * 2016-07-25 2018-02-02 中兴通讯股份有限公司 一种应用区块链的方法、装置及系统
CN106411901A (zh) * 2016-10-08 2017-02-15 北京三未信安科技发展有限公司 一种数字身份标识管理方法及系统
CN108540316A (zh) * 2018-03-29 2018-09-14 长沙汉拓信息技术有限公司 一种物联网管理系统
CN108512935A (zh) * 2018-04-16 2018-09-07 腾讯科技(深圳)有限公司 数据服务系统、方法、服务器和计算机可读存储介质

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111984271A (zh) * 2020-08-27 2020-11-24 北京海益同展信息科技有限公司 一种区块链应用程序处理方法、装置及区块链应用系统
CN111984271B (zh) * 2020-08-27 2023-11-03 京东科技信息技术有限公司 一种区块链应用程序处理方法、装置及区块链应用系统
CN113220453A (zh) * 2021-05-11 2021-08-06 支付宝(杭州)信息技术有限公司 区块链系统中发起交易的方法及装置
CN113220453B (zh) * 2021-05-11 2024-05-31 支付宝(杭州)信息技术有限公司 区块链系统中发起交易的方法及装置
CN113259458A (zh) * 2021-06-02 2021-08-13 支付宝(杭州)信息技术有限公司 一种启动/关闭区块链节点服务的方法和装置
CN114679467A (zh) * 2022-03-23 2022-06-28 中国联合网络通信集团有限公司 多区块链协同服务方法、区块链服务系统和协同服务系统
CN115297117A (zh) * 2022-10-08 2022-11-04 中国人民解放军国防科技大学 基于区块链的云边端安全可信交互计算系统及装置
CN115297117B (zh) * 2022-10-08 2022-12-23 中国人民解放军国防科技大学 基于区块链的云边端安全可信交互计算系统及装置
CN117041264A (zh) * 2023-10-08 2023-11-10 广东省科技基础条件平台中心 一种基于数据处理的区块链资源管理系统及方法
CN117041264B (zh) * 2023-10-08 2024-01-12 广东省科技基础条件平台中心 一种基于数据处理的区块链资源管理系统及方法

Also Published As

Publication number Publication date
US20210191702A1 (en) 2021-06-24
CN111045690A (zh) 2020-04-21
SG11202101917TA (en) 2021-03-30
JP7442516B2 (ja) 2024-03-04
JP2022506016A (ja) 2022-01-17
TW202014878A (zh) 2020-04-16
CN111045690B (zh) 2023-04-28
US11604631B2 (en) 2023-03-14

Similar Documents

Publication Publication Date Title
WO2020073859A1 (zh) 区块链节点服务部署方法、装置、系统、计算设备及介质
US10666638B2 (en) Certificate-based dual authentication for openflow enabled switches
CN110622474B (zh) 安全区块链路由技术
CN111541727B (zh) 区块链一体机及其自动建链方法、装置
US11424942B2 (en) Blockchain integrated stations and automatic node adding methods and apparatuses
WO2018214165A1 (zh) 通信方法、装置、系统、电子设备及计算机可读存储介质
EP3937458B1 (en) Blockchain integrated stations and automatic node adding methods and apparatuses
US20200084097A1 (en) Blockchain-based configuration profile provisioning system
WO2018196643A1 (zh) 一种私有数据云存储系统及私有数据云存储方法
US11343247B1 (en) Local delegation of remote key management service
US11095730B1 (en) Automated device discovery system
US20150350601A1 (en) Domain trusted video network
JP6920442B2 (ja) ブロックチェーンシステムのノード間の通信を確立するための方法及びデバイス
US20210234835A1 (en) Private cloud routing server connection mechanism for use in a private communication architecture
WO2018001023A1 (zh) 一种云终端登录虚拟桌面方法及装置
US11233696B1 (en) Preconfiguring a device for a network
CN114363165A (zh) 一种电子设备的配置方法、电子设备和服务器
CN111212071B (zh) 信息处理方法及其装置、电子设备和介质
US11683292B2 (en) Private cloud routing server connection mechanism for use in a private communication architecture
CN113839949A (zh) 一种访问权限管控系统、方法、芯片及电子设备
GB2607362A (en) Private cloud routing server connection mechanism for use in a private communication architecture
CN117356070A (zh) 零知识证明私有交易认可
US10680879B2 (en) WWAN-enabled remote switch management system
WO2012144462A1 (ja) ポート番号特定システム、ポート番号特定システム制御方法およびその制御用プログラム
GB2609677A (en) Private cloud routing server connection mechanism for use in a private communication architecture

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19870671

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2021520226

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19870671

Country of ref document: EP

Kind code of ref document: A1