Certificate processing method, device, electronic device and storage medium for blockchain network
By extracting and storing digital certificates in transactions in nodes of blockchain networks and replacing certificates with hash values in subsequent transactions, the problem of excessive block size in blockchain networks is solved, and the throughput and applicability of the network is improved.
Patent Information
- Application Number
- CN202110891262.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-09-12
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2039-09-12
AI Technical Summary
Due to the large block size of the existing blockchain network, the scalability of the system is limited, affecting throughput and storage efficiency. It is especially suitable for blockchain networks that use smart contracts.
By receiving transaction proposals submitted by the client in the nodes of the blockchain network, verifying them based on the endorsement strategy, and extracting digital certificates from the transactions of the block when the consensus is passed and storing them into the node's database. In subsequent transactions, the hash value of the digital certificate is used to replace the original certificate, construct a new block and make consensus, and use the hash value to query the digital certificate in the database for verification.
It effectively reduces the transaction volume and improves the throughput of the blockchain network. It is suitable for various blockchain networks, especially in scenarios where smart contracts are used.
Smart Images

Figure CN113609222B_ABST
Abstract
Description
[0001] This application is a divisional application of the application with the application number 201910866712.4, the application date of September 12, 2019, and the title: A Certificate Processing Method, Device, Electronic Device and Storage Medium for a Blockchain Network. Technical Field
[0002] The present invention relates to blockchain technology, and in particular, to a certificate processing method, device, electronic device and storage medium for a blockchain network. Background Art
[0003] The blockchain network was initially designed for encrypted transactions and has now evolved into a general-purpose backend service that supports various applications. By deploying smart contracts in the blockchain network, data submitted by applications can be stored on the chain, business logic-related processing and query services can be performed, and the characteristics of data immutability and traceability can be achieved, so it is increasingly widely used in different industries.
[0004] However, the blockchain networks provided by related technologies all have the problem of too large block volume, which seriously affects the scalability of the system; on the one hand, the volume of transactions in the block is too large, resulting in slower propagation of blocks and transactions between system nodes, limiting the throughput of the entire blockchain network; on the other hand, all historical blocks and transactions are stored in the blockchain network, and the storage space occupied increases rapidly over time.
[0005] There is no general solution for reducing the volume of the blockchain in the prior art, which is only suitable for blockchain networks that use scripts to implement asset transfer. It is not applicable to blockchain networks that use smart contracts. For example, it is not applicable to consortium blockchains that use certificates as digital identities in the blockchain. Summary of the Invention
[0006] Embodiments of the present invention provide a certificate processing method, device, electronic device and storage medium for a blockchain network, which can effectively reduce the volume of transactions and thereby improve the throughput of the blockchain network.
[0007] The technical solution of the embodiments of the present invention is implemented as follows:
[0008] Embodiments of the present invention provide a certificate processing method for a blockchain network, including:
[0009] Receiving a transaction proposal submitted by a client through a node in the blockchain network;
[0010] Verifying the transaction proposal based on an endorsement policy, and when the verification passes, returning a proposal response to the client;
[0011] Among them, the proposal response includes: a transaction result, digital certificates of nodes that have passed the endorsement policy verification, and digital signatures of nodes that have passed the endorsement policy verification for the transaction result; the transaction proposal and the proposal response are used for the client to construct a transaction and submit the transaction to nodes in the blockchain network;
[0012] Through consensus on a block by nodes in the blockchain network, when the consensus is passed, extract digital certificates from the transactions in the block and store the digital certificates in the database of the nodes;
[0013] Receive a transaction submitted by the client through nodes in the blockchain network and construct a new block based on the transaction;
[0014] Query the digital certificate corresponding to the hash value in the transaction of the new block from the database of the node, and use the queried digital certificate to verify the transaction in the new block.
[0015] An embodiment of the present invention provides a certificate processing device for a blockchain network, including:
[0016] A certificate extraction module, configured to:
[0017] Receive a transaction proposal submitted by a client through nodes in the blockchain network;
[0018] Verify the transaction proposal based on the endorsement policy, and when the verification is passed, return a proposal response to the client;
[0019] Among them, the proposal response includes: a transaction result, digital certificates of nodes that have passed the endorsement policy verification, and digital signatures of nodes that have passed the endorsement policy verification for the transaction result; the transaction proposal and the proposal response are used for the client to construct a transaction and submit the transaction to nodes in the blockchain network;
[0020] Through consensus on a block by nodes in the blockchain network, when the consensus is passed, extract digital certificates from the transactions in the block and store the digital certificates in the database of the nodes;
[0021] A transaction pruning module, configured to:
[0022] Receive the transaction submitted by the client through nodes in the blockchain network and construct a new block based on the transaction;
[0023] Query the digital certificate corresponding to the hash value in the transaction of the new block from the database of the node, and use the queried digital certificate to verify the transaction in the new block.
[0024] In the above solution, the certificate extraction module is further configured to:
[0025] Execute the following verification operations on each transaction in the block by nodes in the blockchain network:
[0026] Verify the client digital signature in the transaction through the client digital certificate in the transaction;
[0027] Verify the node digital signature in the transaction through the node digital certificate of the transaction;
[0028] Verify that the transactions in the block comply with the endorsement policy.
[0029] In the above solution, the transaction cropping module is further configured to:
[0030] Receive the transaction submitted by the client through the nodes of the blockchain network, and when the digital certificate in the submitted transaction is queried from the database, replace the digital certificate in the submitted transaction with the corresponding hash value;
[0031] Construct the transaction after replacement processing into a new block through the nodes in the blockchain network;
[0032] When consensus is performed on the new block through the nodes of the blockchain network, extract the hash value from the transactions in the new block;
[0033] Query the digital certificate corresponding to the hash value from the database of the node.
[0034] In the above solution, the certificate extraction module is further configured to:
[0035] Before consensus is performed on the block through the nodes of the blockchain network, receive the transaction proposal submitted by the client through the nodes in the blockchain network;
[0036] Verify the transaction proposal based on the endorsement policy, and when the verification passes, return a proposal response to the client;
[0037] Wherein, the proposal response includes: the transaction result, the digital certificate of the node that has passed the endorsement policy verification, and the digital signature of the node that has passed the endorsement policy verification for the transaction result, so that
[0038] When the client receives the transaction proposal, construct the transaction proposal and the proposal response into a transaction, and submit the constructed transaction to the nodes in the blockchain network.
[0039] In the above solution, the certificate extraction module is further configured to:
[0040] Nodes in the blockchain network sort the transactions that have undergone replacement processing constructed and submitted by the client in the order of receipt to form a block, and broadcast the formed block to the blockchain network so that nodes that receive the formed block can reach a consensus.
[0041] In the above solution, the certificate extraction module is further configured to:
[0042] When the consensus is passed, extract the digital certificate of the client that submitted the transaction and the digital certificate of the node that endorsed the transaction from each transaction in the block;
[0043] Store the key-value pairs of the extracted digital certificates in the database of the node; where the key in the key-value pair is the hash value of the extracted digital certificate, and the value in the key-value pair is the binary data of the extracted digital certificate.
[0044] In the above solution, the transaction pruning module is further configured to:
[0045] Before the nodes in the blockchain network reach a consensus on the new block, receive the transaction proposal submitted by the client through the nodes in the blockchain network,
[0046] When the node that receives the transaction proposal queries its own digital certificate in the local database and verifies that the transaction proposal passes based on the endorsement policy, determine to endorse the transaction and return a proposal response to the client;
[0047] Wherein, the proposal response includes: the transaction result, the hash value of the digital certificate of the node that endorsed the transaction, and the digital signature of the node that endorsed the transaction for the transaction result, so that
[0048] When the client receives the transaction proposal, construct the transaction proposal and the proposal response into a transaction, and submit the encapsulated transaction to the nodes in the blockchain network.
[0049] In the above solution, the transaction pruning module is further configured to:
[0050] Through the nodes in the blockchain network, sort the transactions encapsulated and submitted by the client in the order of receipt to form a new block, and broadcast the formed new block to the blockchain network so that nodes that receive the formed new block can reach a consensus.
[0051] In the above solution, the transaction pruning module is further configured to:
[0052] Extract the hash value of the digital certificate of the client that submitted the transaction and the hash value of the digital certificate of the node that endorsed the transaction from each transaction in the new block;
[0053] Query the digital certificate of the client that submitted the transaction and the digital certificate of the node that endorsed the transaction from the database of the node through the extracted hash values.
[0054] In the above solution, the transaction pruning module is further configured to:
[0055] Execute the following verification operations on each transaction in the block through the nodes in the blockchain network:
[0056] Verify the digital certificate of the node that endorsed the transaction through the root certificate of the node;
[0057] When the verification passes, extract the public key of the node that endorsed the transaction from the digital certificate of the node that endorsed the transaction, and verify the node digital signature in the transaction through the extracted public key;
[0058] Verify the digital certificate of the node that endorsed the transaction through the root certificate of the node;
[0059] When the verification passes, extract the public key of the node that endorsed the transaction from the digital certificate of the node that endorsed the transaction, and verify the node digital signature in the transaction through the extracted public key.
[0060] In the above solution, the transaction pruning module is configured to:
[0061] When verifying each transaction in the block through the nodes in the blockchain network, verify that the transaction format in the block is correct;
[0062] Verify that the node that endorsed the transaction joins the channel that receives the transaction indicated in the transaction;
[0063] Verify that the transaction complies with the endorsement policy.
[0064] In the above solution, the certificate extraction module is further configured to:
[0065] Store the key-value pairs of the digital certificates with a query frequency higher than the frequency threshold in the cache of the node;
[0066] Query the digital certificate corresponding to the hash value from the cache of the node;
[0067] When not found, query the digital certificate corresponding to the hash value from the database of the node.
[0068] In the above solution, the certificate extraction module is further configured to:
[0069] Determine the frequency of use of the digital certificates used in the transactions in each channel joined by the node in the blockchain network;
[0070] Store the digital certificates with a usage frequency higher than the frequency threshold in each channel in the cache local to the node.
[0071] An embodiment of the present invention provides an electronic device for operating a node in a blockchain network, including:
[0072] A memory for storing executable instructions;
[0073] A processor, when executing the executable instructions stored in the memory, implements the certificate processing method of the blockchain network provided by the embodiment of the present invention.
[0074] An embodiment of the present invention provides a storage medium storing executable instructions for causing a processor to implement the certificate processing method of the blockchain network provided by the embodiment of the present invention when executed.
[0075] The embodiment of the present invention has the following beneficial effects:
[0076] By collecting the digital certificates in the transactions during the consensus process and storing them in the database in the form of replacing them with hash values, and verifying the transactions by extracting the corresponding digital certificates from the database using the hash values, the reuse of the digital certificates in the database is realized, so that it is not necessary to store the digital certificates in the transactions. Since the volume of the hash value is much smaller than that of the digital certificate, the volume of the transaction is effectively reduced, and thus more transactions can be stored in the block, effectively improving the throughput performance of the blockchain network; at the same time, since the transactions of various blockchain networks are based on digital certificates as vouchers, it can be widely applied to various blockchain networks. BRIEF DESCRIPTION OF THE DRAWINGS
[0077] Figure 1 is a schematic diagram of the architecture of an exemplary application system 100 of the blockchain network 200 provided by the embodiment of the present invention;
[0078] Figure 2 is a schematic diagram of the application architecture 100 of the blockchain network 200 provided by the embodiment of the present invention;
[0079] Figure 3 is a schematic diagram of the transaction processing flow of the blockchain network provided by the embodiment of the present invention;
[0080] Figure 4 is a schematic diagram of the logical function architecture of the blockchain network 200 provided by the embodiment of the present invention;
[0081] Figure 5 It is a schematic structural diagram of an electronic device for running a consensus node in the blockchain network 200 provided by an embodiment of the present invention;
[0082] Figure 6A It is a schematic flowchart of a certificate processing method for a blockchain network provided by an embodiment of the present invention;
[0083] Figure 6B It is a schematic flowchart of a certificate processing method for a blockchain network provided by an embodiment of the present invention;
[0084] Figure 7 It is a schematic flowchart of extracting a digital certificate of a transaction in a blockchain transaction process provided by an embodiment of the present invention;
[0085] Figure 8 It is a schematic flowchart of performing transaction pruning during a transaction process in a blockchain network provided by an embodiment of the present invention. Detailed implementation manners
[0086] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0087] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments and can be combined with each other without conflict.
[0088] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs. The terms used herein are only for the purpose of describing the embodiments of the present invention and are not intended to limit the present invention.
[0089] Before further elaborating on the embodiments of the present invention, the nouns and terms involved in the embodiments of the present invention are described. The nouns and terms involved in the embodiments of the present invention are applicable to the following explanations.
[0090] 1) Transaction proposal (Proposal), which is a request to execute a smart contract call (hereinafter simply referred to as executing a transaction) included in a transaction, including the identifier of the channel receiving the transaction, the identifier of the smart contract to be called in the channel, and the parameter information to be passed to the called smart contract.
[0091] 2) A transaction, also known as a transaction request, is equivalent to the computer term "Transaction". A transaction includes operations that need to be submitted to the blockchain network for execution, as well as the corresponding transaction results. It does not refer only to transactions in a business context. Given that the term "transaction" is conventionally used in blockchain technology, the embodiments of the present invention follow this convention.
[0092] For example, a transaction can include a Deploy transaction and an Invoke transaction. The Deploy transaction is used to deploy a smart contract into the nodes of the blockchain network and prepare it to be invoked; the Invoke transaction is used to perform query operations (i.e., read operations) or update operations (i.e., write operations, including addition, deletion, and modification) on the state database in the ledger.
[0093] 3) A blockchain is an encrypted, chained storage structure formed by blocks. The header of each block can include the hash values of all transactions in the block, and also contains the hash values of all transactions in the previous block, thereby achieving the anti-tampering and anti-forgery of transactions in the block based on the hash values. After newly generated transactions are filled into the block and consensus is reached among the nodes in the blockchain network, they will be appended to the end of the blockchain to form a chained growth.
[0094] 4) A blockchain network is a collection of a series of nodes that incorporate new blocks into the blockchain through consensus.
[0095] 5) A ledger is a general term for a blockchain (also known as ledger data) and a state database synchronized with the blockchain. Among them, the blockchain records transactions in the form of files in a file system; the state database records transactions in the blockchain in the form of different types of key-value pairs, which is used to support the rapid query of transactions in the blockchain.
[0096] 6) Smart Contracts, also known as Chaincode or application code, are programs deployed in the nodes of the blockchain network, carrying the business logic related to transactions and running in an isolated operating environment (such as a container or a virtual machine).
[0097] 7) Consensus is a process in a blockchain network for reaching an agreement on the transactions in a block among multiple participating nodes. The agreed-upon block will be appended to the end of the blockchain. Mechanisms for achieving consensus include Proof of Work (PoW), Proof of Stake (PoS), Delegated Proof-of-Stake (DPoS), Proof of Elapsed Time (PoET), etc.
[0098] 8) A Member, also known as a business entity, represents a specific entity identity (such as a company, enterprise, and social organization, etc.). It has its own root certificate in the blockchain network. Nodes in the blockchain belong to a certain member, and the same member can have multiple nodes in the same channel.
[0099] 9) An Organization is a domain formed by a subset of members (a subset of all members accessing the blockchain network) to achieve a specific business (not requiring all members to participate). Members within the organization have the same root certificate.
[0100] 10) A Channel is a private isolation environment provided to the nodes of members in an organization in the blockchain network. A channel is a logical structure composed of various physically existing nodes; the smart contracts and ledgers in the channel are only visible to the nodes of the members who join (also known as subscribe to) the channel. The same node can join multiple channels and maintain a ledger for each channel.
[0101] The following describes an exemplary application of the blockchain network provided by the embodiments of the present invention. Refer to Figure 1 , Figure 1 which is a schematic diagram of the architecture of an exemplary application system 100 of the blockchain network 200 provided by the embodiments of the present invention, including a blockchain network 200 (including multiple nodes), a client 510 / 410, and a Certification Authority (CA) 300.
[0102] The nodes in the blockchain network 200 have one or more functions. Among them, the ledger function (i.e., maintaining the ledger) and the consensus function (i.e., conducting consensus) are the default functions of the nodes. The nodes can also have a sorting function, an endorsement function, and a certificate database. The sorting function is used to ensure the consistency of transaction sorting among multiple nodes. The endorsement function is used to verify the endorsement of transaction proposals submitted by clients. The certificate database is used to store the digital certificates collected by the nodes from the blocks during the consensus phase. In some embodiments, the certificate database can be defaulted and the ledger database can be used instead, thereby reducing the complexity of the node function architecture and improving the database operation efficiency of the nodes.
[0103] The types of the blockchain network 200 are flexible and diverse. For example, it can be any one of a public chain, a private chain, or a consortium chain. Taking the public chain as an example, the client running in the terminal or server of any business entity can access the blockchain network 200 without authorization and become a special type of node, called a client node. Taking the consortium chain as an example, after the business entity is authorized to become a member of the blockchain network 200, the corresponding client can access the blockchain network 200 and become a client node. For the convenience of description, the client node is also simply referred to as a client in the following text.
[0104] As an example, the client can be used for various applications related to the business of the business entity, such as a social network client and a logistics client. The client can be an application on various platforms, such as a mobile APP (Android APP and iOS APP), desktop software (Windows system software and MAC system software), etc.
[0105] It should be noted that there is no limit to the number of client nodes belonging to the same business entity. Figure 1 Figure 11 shows a client 510 used by the business entity 500, which can access the blockchain network 200 and become a client node. Similarly, a client 410 used by the business entity 400 can access the blockchain network 200 and become a client node.
[0106] The client node is a special type of node different from the native nodes in the blockchain network 200. By default, it can omit the functions of the native nodes in the blockchain network 200, thereby reducing the development difficulty of the client and realizing the lightweight of the client. The client and the blockchain network 200 support the transmission of events. For example, the client can detect / subscribe to events related to smart contract calls during the operation of the blockchain network 200, such as the event of generating a new block. Thus, when a specific event occurs in the blockchain network 200, it triggers the relevant business logic of the local or external system.
[0107] In some embodiments, the client's operations on the ledger in the blockchain network 200 mainly include two types: ledger query and ledger update. For ledger query, the client initiates a transaction proposal to the blockchain network 200. The transaction data in the transaction proposal (smart contract call related to the query operation) is executed by the node of the blockchain network 200 to query the ledger, and the queried data is carried in the proposal response as a transaction result to return to the client.
[0108] For account book updates, the client node initiates a transaction proposal to the blockchain network 200, which includes a smart contract call related to the update operation (i.e., transaction data). The nodes of the blockchain network 200 simulate the execution of the account book (i.e., the account book will not be changed) and the transaction data included in the transaction proposal (i.e., the smart contract call related to the update operation) is carried in the proposal response as a transaction result to return to the client. The client node then constructs the transaction proposal and proposal response into a transaction and submits it to the blockchain network 200. The nodes of the blockchain network 200 record the transaction in the account book.
[0109] The authentication center 300 outside the blockchain network 200 is used to respond to the registration application of the client 410 / 510 (hereinafter referred to as the client), return the registration password for login, so as to obtain a digital certificate for declaring the identity information of the member to which the client belongs. As an alternative to the authentication center (CA, Certificate Authority) 300, a CA node can be set in the blockchain network 200 to realize the function of the authentication center (CA, Certificate Authority) 300.
[0110] In some embodiments, the accounting nodes in the blockchain network 200 can be divided into different types according to the functions implemented in addition to the ledger function and the consensus function, as Figure 1 For an example of the division of the blockchain network 200 into different types shown in , see Figure 2 , Figure 2 is a schematic diagram of the application architecture 100 of the blockchain network 200 provided by an embodiment of the present invention. Except for the client nodes (client 410 / 510), the nodes in the blockchain network 200 have consensus functions and account book functions by default. The nodes that only have the functions of verifying transactions and recording accounts are called account nodes (Committer) or consensus nodes. Some special types of account nodes are also included: endorsement nodes (Endorser) with endorsement functions, ordering nodes (Orderer) with sorting functions, and leader nodes (Leader Peer) representing account nodes and ordering node channels in channels.
[0111] The above nodes in the blockchain network 200 can join channels of different organizations. Each channel within an organization (Organization 1 and Organization 2) includes multiple ledger nodes belonging to organization members. For example, Figure 2 Organization 1 and Organization 2, which carry out different businesses, are shown. Nodes belonging to members of Organization 1 / 2 in the blockchain network 200 can correspondingly join the channels of Organization 1 / 2. Nodes within each channel receive transactions related to the businesses submitted by clients of the affiliated organization and record the transactions in the ledger. The ledger is isolated from nodes outside the channel.
[0112] In some embodiments, a software development kit (SDK, Software Development Kit) is built into the client to implement the control of the blockchain network 200. Thus, the native code of the client can focus only on implementing business-related logic and ignore the internal operation details of the blockchain network 200, reducing the development difficulty of the client.
[0113] As an example, the SDK provides a series of application programming interfaces (APIs, Application Programming Interface) based on remote procedure call (RPC, Remote Procedure Call) connections between the client and the nodes of the blockchain network 200 for the client to manage and use the functions of the blockchain network 200. These functions include identity management, ledger management, transaction management, smart contracts, transaction management, member management, consensus services, smart contract services, security and cryptographic services, and event handling, etc. The above functions will be specifically described below.
[0114] As an example of transaction management, the transaction management function implemented by the client through the SDK includes two stages: submitting a transaction proposal and submitting a transaction. Now refer to Figure 3 , Figure 3 which is a schematic diagram of the transaction processing flow of the blockchain network provided by the embodiments of the present invention. Combining Figure 3 the processing processes of the two stages of submitting a transaction proposal and submitting a transaction shown, the functions of the above different types of nodes will be described.
[0115] The client initiates a transaction proposal to the endorsement node in one or more channels in the blockchain network 200. The transaction proposal includes a transaction number, a timestamp (the time when the transaction proposal is initiated), and transaction data. The transaction data includes: the identifier (such as a serial number or name) of the channel where the transaction is executed (i.e., the channel where the smart contract called in the transaction is located), and the smart contract call that needs to be executed in the channel (including the identifier of the smart contract to be called, such as the name or serial number, the version of the smart contract, and the parameter information that needs to be passed to the smart contract, etc.). Smart contracts and parameters are related to the operations that the client needs to perform. For example, smart contracts can be used for adding, deleting, querying, or modifying operations, and parameter information can be data for adding, deleting, querying, or modifying operations.
[0116] The transaction proposal also carries the client digital certificate issued by the certification center to the client, and the digital signature signed by the client for the transaction data in the transaction proposal. The client digital certificate includes: the identity information of the member to which the client belongs, the client's public key, and the certification center uses the certification center's private key (corresponding to the public key in the root certificate requested by the client and the node in advance from the certification center) to sign the digital signature of the client's identity information and the client's public key. The client digital certificate is used to declare the identity information of the member to which the client belongs, and the client digital signature is used to prove that the transaction data in the transaction proposal has not been tampered with.
[0117] After receiving the transaction proposal, the endorsement node will perform some endorsement verification according to the endorsement strategy, including: whether the digital certificate carried by the transaction proposal is issued by a trusted certification center; whether the digital signature of the transaction proposal is valid; whether the format of the transaction proposal is correct; whether the transaction proposal has been submitted repeatedly; whether the client has been authorized to have write permission in the channel requesting the execution of the smart contract call. When all the judgments are yes, the endorsement verification is successful.
[0118] In some embodiments, when the endorsement node verifies the transaction proposal successfully, the endorsement node will simulate the execution of transaction data based on the state database of the locally maintained ledger, that is, execute the smart contract call included in the transaction proposal to obtain the transaction result. The endorsement node uses its own private key to sign (i.e. endorse) the transaction result, and the digital signature of the endorsement node is combined with the digital certificate of the endorsement node (including the public key of the endorsement node, and the digital signature signed by the certification center using the private key of the certification center on the public key and identity information of the endorsement node), and other related information to form a proposal response (Proposal Response), which is then returned to the client.
[0119] As an example, when the transaction proposal includes a smart contract call for a query operation, the transaction result is a read set, which contains the key-value pairs read from the ledger database during the simulated execution; when the transaction proposal includes a smart contract call for a query operation, the transaction result is a write set, which also contains a list of unique keys and the key-value pairs written to the ledger database during the simulated execution.
[0120] As an example, the other relevant information described above may include: a success code (indicating that the verification of the transaction proposal is successful), a timestamp (the time when the proposal response is generated), the identifier of the channel that receives the transaction (such as a sequence number or a name), and the hash value of the transaction proposal (used to bind to the transaction proposal one-to-one to prevent the transaction from being tampered with by the client during the transaction submission phase).
[0121] In some embodiments, when the endorsement node fails to verify the transaction proposal, it will return a proposal response carrying a failure code (indicating the error type of the failed verification of the transaction proposal) to the client.
[0122] When the client receives the proposal response, it will first confirm the validity of the proposal response by verifying the digital certificate and digital signature carried by the transaction proposal. When the client collects the proposal responses of a sufficient number (predetermined number) of endorsement nodes and the transaction results in the proposal responses are consistent, it will construct a transaction based on the transaction proposal and the proposal response.
[0123] As an example, the transaction includes: a timestamp (the time when the transaction is constructed), the identifier of the channel that receives the transaction, the identifier of the smart contract that needs to be called in the channel (such as a name or a sequence number), the version of the smart contract, the parameters passed to the smart contract, etc., and the transaction result (such as a read / write set), as well as the digital signature of the endorsement node for the transaction result.
[0124] It should be noted that if the smart contract call in the transaction proposal submitted by the client is only used to query the ledger (rather than update the ledger), the client will not construct a transaction and will only use the transaction result in the proposal response as the ledger query result to complete the relevant business logic.
[0125] After the client constructs the transaction, it broadcasts the transaction to the ordering nodes in the blockchain network 200. For the received transactions, the ordering nodes read the identifier of the channel to which the transaction belongs from the transaction, and construct blocks for the transactions received by each corresponding channel in the order of receipt of the transactions, and send the blocks to the primary nodes in the corresponding channels.
[0126] For Figure 2For example, when a sorting node receives a transaction, it determines whether the channel that needs to receive the transaction is the channel of Organization 1 or the channel of Organization 2 according to the identifier of the channel in the transaction. According to the order of receiving transactions corresponding to each channel, it constructs the block corresponding to the channel of Organization 1 and the block corresponding to the channel of Organization 2, and sends them to the primary nodes in the channels of Organization 1 / Organization 2 respectively.
[0127] The primary node is the node that communicates with the sorting node on behalf of other ledger nodes in the channel, and is used to obtain the latest block from the sorting node and synchronize it within the channel; the primary node can be forcibly set or dynamically elected.
[0128] The ledger nodes in the channel respectively perform consensus verification on each transaction in the received block, and after the verification passes, append it to the tail of the blockchain they each maintain, and update the ledger database using the transaction results of the transactions in the block.
[0129] In some embodiments, the consensus verification of the transaction in the block by the ledger node includes: whether the transaction format is correct, whether there is a legal signature (including the digital signature of the client and the digital signature of the endorsing node), that is, verifying whether the transaction content has been tampered with; whether the ledger node joins the channel that receives the transaction indicated in the transaction; whether the transaction conforms to the endorsement policy. The endorsement policy is the rule for the endorsing node to endorse the transaction, specifying the organization from which the endorsement required for a transaction before submission comes, the type of nodes within the corresponding organization, and the number of valid endorsements. When the judgment results are all yes, it means that the consensus verification passes.
[0130] The following describes the exemplary logical function architecture of the blockchain network provided by the embodiments of the present invention. Refer to Figure 4 , Figure 4 which is a schematic diagram of the logical function architecture of the blockchain network 200 provided by the embodiments of the present invention, and will be described separately below.
[0131] The upper layer of the blockchain network 200 is docked with the client. The client 410 / 510 provides standard RPC interfaces and encapsulates the SDK on the basis of the API, so that developers can develop various business logics based on the blockchain in the SDK; the event mechanism of the client enables the client to execute predefined callback functions when receiving various events of the blockchain network 200, such as when receiving an event of creating a new block or an event of executing a smart contract, so as to minimize the execution time for reaching consensus among the nodes.
[0132] In some embodiments, from the perspective of the top layer where the blockchain network 200 is docked with the client, the functions of the blockchain network 200 include identity management, ledger management, transaction management, and smart contract functions, which will be described separately below.
[0133] (1) Identity management
[0134] After the user of the client registers and logs in to the authentication center, the client obtains the digital certificate (EC cert) of the member. All other operations need to be signed with the private key associated with the digital certificate. The message receiver and the member hold the same root certificate from the authentication center. The message receiver will first verify the signature and digital certificate before proceeding with subsequent message processing. The node will also use the digital certificate issued by the authentication center. For example, when a member accessing the blockchain network 200 starts the system of the subordinate node and manages the subordinate node, the identity management function will authenticate and authorize the identity information of the member.
[0135] (2) Ledger Management
[0136] Members authorized to access the blockchain network 200 can query the ledger in various ways, including querying blocks by block number, querying blocks by block hash, querying blocks by transaction number, and querying transactions by transaction number. They can also obtain the queried blockchain according to the channel name.
[0137] (3) Transaction Management
[0138] The ledger can only be updated by submitting transactions. The client submits a transaction proposal through the transaction management function of the blockchain network 200, obtains the endorsement of the transaction, and then submits the transaction to the ordering node, which then constructs it into a block.
[0139] (4) Smart Contract
[0140] Implement a "programmable ledger" (Programmable Ledger), execute transactions through smart contract calls, and implement the business logic of smart contracts based on the blockchain. Only smart contracts can update the ledger.
[0141] In some embodiments, from the perspective of the blockchain network 200 docking with the underlying layer, the functions of the blockchain network 200 include member management, consensus service, chain code service, security, and cryptographic service, which will be described separately below.
[0142] (1) Member Management
[0143] Through the Root of Trust Certificate system, the identity information of members is authenticated using (PKI, Public Key Infrastructure), and the digital signatures of members are verified. In combination with the certification center within the blockchain network or a third-party certification center, a registration function for members is provided, and the digital certificates of members are managed, such as certificate addition and revocation. Exemplarily, digital certificates are divided into registration certificates (ECert), transaction certificates (TCert), and TLS certificates (TLS Cert), which are used for user identity, transaction signature, and Transport Layer Security Protocol (TLS) transmission respectively.
[0144] (2) Consensus service
[0145] The consensus mechanism is completed in three stages: the client submits a proposal to the endorsing node to obtain an endorsement, and after obtaining the endorsement, the client submits the transaction to the ordering node for ordering to generate a block, and then broadcasts it to the accounting node to verify the transactions in the block and write them into the local ledger of the accounting node.
[0146] (3) Chaincode service
[0147] The implementation of the smart contract depends on a secure execution environment to ensure the isolation of the secure execution process and user data.
[0148] (4) Security and cryptographic services
[0149] Basic functions such as key generation, hashing, signature verification, encryption, and decryption are implemented.
[0150] The following describes the exemplary structure of the electronic device of the node for running the blockchain network provided by the embodiments of the present invention. Refer to Figure 5 , Figure 5 is a schematic structural diagram of the electronic device of the node for running the blockchain network 200 provided by the embodiments of the present invention. The electronic device can be a terminal (such as a PC), a server, or a cluster of servers, providing a virtualized node running environment. Figure 5 The electronic device 600 shown in the figure includes: at least one processor 610, a memory 650, and at least one network interface 620. Each component in the electronic device is coupled together through a bus system 640. It can be understood that the bus system 640 is used to realize the connection and communication between these components.
[0151] The processor 610 may be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or any conventional processor, etc.
[0152] The memory 650 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard disk drives, optical disc drives, etc. The memory 650 optionally includes one or more storage devices that are physically located away from the processor 610.
[0153] The memory 650 includes volatile memory or non-volatile memory, and may also include both volatile and non-volatile memory. The non-volatile memory may be a read-only memory (ROM), and the volatile memory may be a random access memory (RAM). The memory 650 described in the embodiments of the present invention is intended to include any suitable type of memory.
[0154] In some embodiments, the memory 650 is capable of storing data to support various operations. Examples of such data include programs, modules, and data structures, or subsets or supersets thereof, which are exemplarily described below.
[0155] The operating system 651 includes system programs for processing various basic system services and performing hardware-related tasks, such as the framework layer, the core library layer, the driver layer, etc., for implementing various basic services and processing hardware-based tasks;
[0156] The network communication module 652 is used to reach other computing devices via one or more (wired or wireless) network interfaces 420. Exemplary network interfaces 420 include: Bluetooth, Wi-Fi (Wireless Fidelity), and USB (Universal Serial Bus), etc.;
[0157] In some embodiments, the certificate processing device 655 of the blockchain network provided by the embodiments of the present invention may be implemented in software. Figure 5 The certificate processing device 655 stored in the memory 650 is shown, which may be software in the form of programs and plugins, etc., and includes the following software modules: the certificate extraction module 6551 and the transaction clipping module 6552. These modules are logical, so they can be arbitrarily combined or further split according to the functions implemented. The functions of each module will be described below.
[0158] In combination with the exemplary applications and implementations of the blockchain network provided in the embodiments of the present invention, the certificate processing method of the blockchain network provided in the embodiments of the present invention will be described, including a certificate collection stage and a transaction pruning stage. In each stage, the blockchain processes multiple transactions. For example, in the certificate collection stage, the blockchain network receives multiple transactions submitted by different clients / same clients, and thus collects certificates from the transactions into the certificate database; in the transaction pruning stage, multiple transactions are submitted by the same / different clients, and are pruned according to the certificate database to reduce the transaction volume. In the following, taking the processing of one transaction in each of the certificate collection stage and the transaction pruning stage as an example for illustration, but it should not be regarded as a limitation on the number of transactions processed in each stage.
[0159] In addition, the following focuses on the certificate collection scheme in the certificate collection stage and the transaction pruning scheme regarding transaction pruning. For other processing links of the blockchain network for transactions, they can be understood according to the above-mentioned transaction processing process of the blockchain network (including the two stages of submitting a transaction proposal and submitting a transaction), and will not be repeated.
[0160] See Figure 6A , Figure 6A is a schematic flowchart of the certificate processing method of the blockchain network provided in the embodiments of the present invention. The following will be described in combination with Figure 6A the steps shown.
[0161] In step 101, the nodes of the blockchain network perform consensus on the block.
[0162] In some embodiments, performing consensus on the block by the nodes of the blockchain network includes: performing the following verification operations on each transaction in the block by the nodes in the blockchain network: verifying the client digital signature in the transaction through the client digital certificate in the transaction; verifying the node digital signature in the transaction through the node digital certificate of the transaction; verifying that the transaction complies with the endorsement policy.
[0163] In some embodiments, see Figure 6B , Figure 6B is a schematic flowchart of the certificate processing method of the blockchain network provided in the embodiments of the present invention. Before performing consensus on the block by the nodes of the blockchain network, in step 108, the nodes in the blockchain network can also receive a transaction proposal submitted by the client; in step 109, perform (endorsement) verification on the transaction proposal based on the endorsement policy. When the verification passes, return a proposal response to the client; wherein, the proposal response includes: the transaction result, the digital certificate of the node that passes the endorsement policy verification, and the digital signature of the node that passes the endorsement policy verification for the transaction result, so that when the client receives the transaction proposal, in step 110, construct the transaction proposal and the proposal response into a transaction, and submit the constructed transaction to the nodes in the blockchain network.
[0164] In step 102, when the consensus is passed, digital certificates are extracted from the transactions of the block and stored in the database of the node.
[0165] In some embodiments, extracting digital certificates from the transactions of the block when the consensus is passed and storing the digital certificates in the database of the node includes: extracting the digital certificates of the clients submitting the transactions and the digital certificates of the nodes endorsing the transactions from each transaction in the block when the consensus is passed; storing the key-value pairs of the extracted digital certificates in the database of the node, such as a dedicated certificate database or the state database used by the node to store the ledger state; wherein, the key in the key-value pair is the hash value of the extracted digital certificate, and the value in the key-value pair is the binary data of the extracted digital certificate.
[0166] It should be noted that the steps described above are the certificate collection nodes of the blockchain network for collecting digital certificates from transactions to the database of the node, and the steps described below are the processing process of the blockchain network for pruning (i.e., reducing the volume) the subsequent received transactions based on the certificate database.
[0167] In step 103, the nodes of the blockchain network receive the transactions submitted by the clients.
[0168] In some embodiments, as Figure 6B shown, before receiving the transactions submitted by the clients through the nodes of the blockchain network, in step 111, the nodes in the blockchain network may also receive the transaction proposals submitted by the clients, and in step 112, when the nodes receiving the transaction proposals query their own digital certificates in the local database and verify that the transaction proposals pass based on the endorsement policy, it is determined as transaction endorsement and a proposal response is returned to the client.
[0169] The proposal response includes: the transaction result, the hash value of the digital certificate of the node endorsing the transaction, and the digital signature of the node endorsing the transaction for the transaction result, so that when the client receives the proposal response, in step 113, the transaction proposal and the proposal response are constructed into a transaction to submit the encapsulated transaction to the nodes in the blockchain network in step 103.
[0170] In step 104, when the digital certificates in the submitted transactions are queried from the database, the digital certificates in the submitted transactions are replaced with the corresponding hash values.
[0171] For example, each transaction of the block includes a client digital certificate and a node digital certificate, and the corresponding hash values are queried in the database and the digital certificates in the transaction are replaced.
[0172] In step 105, the nodes in the blockchain network construct the transactions after the replacement process into new blocks.
[0173] In some embodiments, after the transactions encapsulated and submitted by the client are sorted in the order of reception by the nodes in the blockchain network to construct a new block, as Figure 6B shown, in step 114, the constructed new block is broadcast in the blockchain network so that the nodes that receive the constructed new block perform consensus.
[0174] In step 106, when the nodes in the blockchain network perform consensus on the new block, the hash values are extracted from the transactions of the new block, and the digital certificates corresponding to the hash values are queried from the database of the nodes.
[0175] In some embodiments, extracting the hash values from the transactions of the new block and querying the digital certificates corresponding to the hash values from the database of the nodes includes: extracting the hash values of the digital certificates of the clients submitting the transactions and the hash values of the digital certificates of the nodes endorsing the transactions from each transaction in the new block; and querying the digital certificates of the clients submitting the transactions and the digital certificates of the nodes endorsing the transactions from the database of the nodes through the extracted hash values.
[0176] In some embodiments, as Figure 6B shown, in step 115, key-value pairs of digital certificates with a usage frequency higher than a frequency threshold may also be stored in the cache of the node; for example, determining the usage frequency of the digital certificates of the transactions in each channel joined by the node in the blockchain network; and storing the digital certificates with a usage frequency higher than the frequency threshold in each channel in the local cache of the node. Correspondingly, before querying the digital certificates corresponding to the hash values from the database of the node, when performing consensus on the new block in step 116, the digital certificates corresponding to the hash values may also be queried from the cache of the node; when not found, the digital certificates corresponding to the hash values are queried from the database of the node. Thereby reducing database access and improving the processing efficiency of digital certificates.
[0177] In step 107, the transactions in the new block are verified using the queried digital certificates.
[0178] In some embodiments, the transactions in the new block are (consensus) verified using the queried digital certificate, including: performing the following verification operations on each transaction in the block by nodes in the blockchain network: verifying the digital certificate of the node endorsing the transaction through the root certificate of the node; when the verification passes, extracting the public key of the node endorsing the transaction from the digital certificate of the node endorsing the transaction, and verifying the node digital signature in the transaction through the extracted public key; verifying the digital certificate of the node endorsing the transaction through the root certificate of the node; when the verification passes, extracting the public key of the node endorsing the transaction from the digital certificate of the node endorsing the transaction, and verifying the node digital signature in the transaction through the extracted public key. In addition, when performing verification operations on each transaction in the block by nodes in the blockchain network, it is also possible to verify that the transaction format in the block is correct; verifying that the nodes endorsing the transaction join the channel for receiving the transaction indicated in the transaction; verifying that the transaction complies with the endorsement policy.
[0179] When the nodes reach consensus on the new block, the block is also appended to the tail of the recorded blockchain, and the ledger database is updated using the transaction results (read-write sets) of the transactions in the block.
[0180] The embodiment of the present invention reduces the volume of the blockchain network by reusing the certificates in the transactions in the blockchain, and at the same time enables more valid transactions to be stored in a single block, thereby improving the throughput of the blockchain network. It should be noted that the solution provided by the embodiment of the present invention is applicable to any blockchain network that uses certificates for identity verification.
[0181] The basic process of the technical solution provided by the embodiment of the present invention is as follows: 1) When a transaction is submitted to the blockchain network, after the nodes in the blockchain network reach a consensus, the digital certificates in the transactions of the block are uniformly extracted and saved in the certificate database (such as the state database) local to the nodes; 2) For the subsequent transactions received in the blockchain network, the nodes query the local certificate database. If it is found that the digital certificates in the transactions already exist, the hash values of the digital certificates are used to replace the corresponding certificates in the transactions. Since the volume of the certificates far exceeds the transaction data itself, for example, X509 certificates are generally more than 800 bytes, while the volume of an ordinary transaction is generally within 100 bytes. Therefore, after replacing the digital certificates in the transactions, the volume of the transactions propagated in the blockchain network is greatly reduced; moreover, since the digital certificate records in the certificate database local to the nodes in the blockchain network are generated in the consensus stage, consistency can be guaranteed. When the nodes in the blockchain network verify the transactions in the consensus stage, they can query the corresponding digital certificates in the certificate database according to the hash values extracted from the transactions, and then verify the transactions through the digital certificates, ensuring the security of the transactions. To improve performance, the commonly used digital certificates can be cached in the memory of the nodes to achieve a fast speed of digital certificates, thereby improving the processing efficiency of transactions in the consensus stage.
[0182] The following describes the certificate processing solution provided by the embodiment of the present invention in combination with a specific blockchain network.
[0183] See Figure 7 , Figure 7 is a schematic flowchart of extracting the digital certificates of transactions in the blockchain transaction process provided by the embodiment of the present invention, which will be described in combination with Figure 7 for illustration.
[0184] Figure 7 shows 3 organizations (Organization 0, Organization 1, and Organization 2) joining the blockchain network. Each member of each organization has multiple peer nodes (i.e., accounting nodes, Figure 7 only 1 peer node is exemplarily shown for each organization in
[0185] Taking the example that the client initiates a transaction proposal to the endorsing peer node (also called the endorsing node) of Organization 0 in the blockchain network, the transaction proposal includes a transaction number (denoted as txid), the client's digital certificate (denoted as clientCert), transaction data, and the digital signature of the client for the transaction data (denoted as data). The transaction proposal also includes the timestamp for generating the transaction proposal.
[0186] Each peer0 node with endorsement function in Organization 0 verifies the transaction proposal according to the endorsement policy. After successful verification, the digital certificate of the peer0 node (denoted as peerCert) and the digital signature of the transaction result obtained by simulating the execution of the transaction data are added to the transaction proposal and sent to the client as a proposal response. The proposal response also includes the timestamp when the proposal response is generated.
[0187] After the client collects the signed proposal responses returned by a sufficient number of peer nodes with endorsement function in Organization 0, it constructs the transaction proposal and the proposal response into a transaction (denoted as tx) and sends it to the ordering node (orderer) in the blockchain network. Among them, the transaction includes the transaction number, the digital signature of the client for the transaction data, the digital certificate of the client, the digital certificate of the peer node, and the digital signature of the peer node for the transaction result.
[0188] For the transaction received from the client, the ordering node sorts the transactions (for example, sorts according to the timestamp of the transaction proposal or the proposal response), packs them into a block (containing multiple transactions), and sends it to all peer nodes in Organization 0; the peer nodes and the ordering node in Organization 0 will reach a consensus on the block. During the consensus process, the digital certificates and digital signatures in each transaction will be verified. After successful verification, the block will be appended to the tail of the local blockchain, and the state database will be updated according to the transaction result; at the same time, extract the digital certificates (including peerCert and clientCert) in all transactions in the block to form key-value pairs, where the key is the hash value (hash) of the digital certificate, and the value is the digital certificate (that is, the binary data of the digital certificate). The key-value pair is expressed as: key = hash(cert), value = cert, and it is stored in the local certificate database (such as the state database).
[0189] The above process will be repeated, so that the peer nodes and the ordering node in the blockchain network can comprehensively collect the digital certificates of the client and other nodes. Next, assuming that each node has collected sufficient digital certificates of the client and other nodes (including peer nodes and ordering nodes) in its respective certificate database, the processing process of subsequent transactions submitted to the blockchain network according to the certificate database and the pruning process of transactions during this processing process will be described.
[0190] See Figure 8 , Figure 8 is a schematic flow diagram of transaction pruning during the transaction process of the blockchain network provided by the embodiments of the present invention, and will be described in combination with Figure 8 the steps shown.
[0191] The client initiates a transaction proposal to the peer nodes with endorsement capabilities (also known as endorsement nodes) in Organization 0. The transaction proposal includes a transaction number, the client's certificate (denoted as clientCert), transaction data, and the client's digital signature for the transaction data; it also includes the timestamp when the transaction proposal is submitted.
[0192] After each peer node with endorsement capabilities (i.e., endorsement node) in Organization 0 verifies the transaction proposal according to the endorsement policy, it queries the local certificate database DB and finds that the peerCert of the peer0 node already exists in the form of a key-value pair. It adds the hash of its own certificate peerCert and the digital signature for the transaction result to the transaction proposal and sends it to the client as a proposal response.
[0193] After the client collects enough transaction proposals signed by peer nodes with endorsement capabilities, it constructs the transaction proposals and proposal responses into a transaction. The transaction includes a transaction number (denoted as txid), the client's digital certificate (denoted as clientCert), transaction data, and the client's digital signature for the transaction data (denoted as data). The transaction proposal also includes the timestamp when the transaction proposal is generated.
[0194] The client sends the constructed transaction to the ordering node. The ordering node preprocesses the multiple received transactions, queries the local certificate database and finds that there is already a corresponding key-value pair for the client's digital certificate in the transaction. It replaces the client's digital certificate with the hash value of the client's digital certificate in the transaction, sorts the preprocessed transactions to generate a new block (containing multiple transactions), and sends it to all peer nodes in Organization 0.
[0195] After the peer nodes in Organization 0 receive the new block, they verify the consensus of the transactions in the new block. During the verification process, when they find that the transaction carries the hash value of the digital certificate, they query the corresponding digital certificate from the local certificate database, including the client's digital certificate and the digital certificates of the peer nodes endorsing the transaction, and use the digital certificates to complete the verification of the transaction. After the verification passes, they append the block to the tail of the blockchain of the peer node and update the state database according to the transaction result.
[0196] The certificate processing solution provided by the embodiments of the present invention is applied in the consortium blockchain. For a block containing 100 transactions, the experimental data comparison is shown in Table 1 below. In the case of adopting different endorsement policies, the volume of the block is reduced by more than 80%.
[0197]
[0198] Table 1
[0199] Next, the exemplary structure of the certificate processing device 655 of the blockchain network provided by the embodiments of the present invention implemented as a software module will be further described. In some embodiments, as Figure 5 shown, the software module in the certificate processing device 655 of the blockchain network stored in the memory 650 may include a certificate extraction module 6551 and a transaction trimming module 6552, which will be described separately below.
[0200] The certificate extraction module 6551 is configured to: perform consensus on a block through a node of the blockchain network, extract a digital certificate from the transactions of the block when the consensus is passed, and store the digital certificate in the database of the node;
[0201] The transaction trimming module 6552 is configured to: receive a transaction submitted by a client through a node of the blockchain network, and when a digital certificate in the submitted transaction is queried from the database, replace the digital certificate in the submitted transaction with the hash value of the corresponding extracted digital certificate; construct the transaction after the replacement process into a new block through a node in the blockchain network; when performing consensus on the new block through a node of the blockchain network, extract the hash value from the transactions of the new block, query the digital certificate corresponding to the hash value from the database of the node, and verify the transactions in the new block using the queried digital certificate.
[0202] In some embodiments, the certificate extraction module 6551 is further configured to: perform the following verification operations on each transaction in the block through a node in the blockchain network: verify the client digital signature of the transaction through the client digital certificate in the transaction; verify the node digital signature in the transaction through the node digital certificate of the transaction; verify that the transactions in the block comply with the endorsement policy.
[0203] In some embodiments, the certificate extraction module 6551 is further configured to: receive a transaction proposal submitted by a client through a node in the blockchain network before receiving a transaction submitted by the client through a node in the blockchain network; verify the transaction proposal based on the endorsement policy, and when the verification is passed, return a proposal response to the client; wherein the proposal response includes: the transaction result, the digital certificates of the nodes that have passed the endorsement policy verification, and the digital signatures of the nodes that have passed the endorsement policy verification for the transaction result, so that when the client receives the transaction proposal, it constructs the transaction proposal and the proposal response into a transaction and submits the constructed transaction to a node in the blockchain network.
[0204] In some embodiments, the certificate extraction module 6551 is further configured to: sort the transactions constructed and submitted by the client in the order of receipt through a node in the blockchain network to construct a block, and broadcast the constructed block in the blockchain network so that the nodes that receive the constructed block perform consensus.
[0205] In some embodiments, the certificate extraction module 6551 is further configured to: when consensus is passed, extract the digital certificate of the client that submits the transaction and the digital certificate of the node that endorses the transaction from each transaction in the block; store the key-value pair of the extracted digital certificate in the database of the node; wherein, the key in the key-value pair is the hash value of the extracted digital certificate, and the value in the key-value pair is the binary data of the extracted digital certificate.
[0206] In some embodiments, the transaction trimming module 6552 is further configured to: before the nodes of the blockchain network perform consensus on the new block, receive the transaction proposal submitted by the client through the nodes in the blockchain network, and when the node that receives the transaction proposal queries its own digital certificate in the local database and verifies that the transaction proposal passes based on the endorsement policy, determine to endorse the transaction and return a proposal response to the client; wherein, the proposal response includes: the transaction result, the hash value of the digital certificate of the node that endorses the transaction, and the digital signature of the node that endorses the transaction for the transaction result, so that when the client receives the proposal response, it constructs the transaction proposal and the proposal response into a transaction and submits the encapsulated transaction to the nodes in the blockchain network.
[0207] In some embodiments, the transaction trimming module 6552 is further configured to: through the nodes in the blockchain network, sort the transactions encapsulated and submitted by the client in the order of reception to construct a new block, and broadcast the constructed new block to the blockchain network so that the nodes that receive the constructed new block perform consensus.
[0208] In some embodiments, the transaction trimming module 6552 is further configured to: extract the hash value of the digital certificate of the client that submits the transaction and the hash value of the digital certificate of the node that endorses the transaction for the node from each transaction in the new block; query the digital certificate of the client that submits the transaction and the digital certificate of the node that endorses the transaction from the database of the node through the extracted hash values.
[0209] In some embodiments, the transaction trimming module 6552 is further configured to perform the following verification operations on each transaction in the block through the nodes in the blockchain network: verify the digital certificate of the node that endorses the transaction through the root certificate of the node; when the verification passes, extract the public key of the node that endorses the transaction from the digital certificate of the node that endorses the transaction, and verify the node digital signature in the transaction through the public key; verify the digital certificate of the node that endorses the transaction through the root certificate of the node; when the verification passes, extract the public key of the node that endorses the transaction from the digital certificate of the node that endorses the transaction, and verify the node digital signature in the transaction through the public key.
[0210] In some embodiments, the transaction pruning module 6552 is configured to: when nodes in the blockchain network perform verification operations on each transaction in a block, verify that the transaction format in the block is correct; verify that the nodes endorsing the transaction join the channel indicated in the transaction to receive the transaction; and verify that the transaction complies with the endorsement policy.
[0211] In some embodiments, the certificate extraction module 6551 is further configured to: store key-value pairs of digital certificates with a query frequency higher than a frequency threshold in the cache of the node; query the digital certificate corresponding to the hash value from the cache of the node; and when not found, query the digital certificate corresponding to the hash value from the database of the node.
[0212] In some embodiments, the certificate extraction module 6551 is further configured to: determine the query frequency of the digital certificates of transactions in each channel joined by the node in the blockchain network; and store the digital certificates with a usage frequency higher than the frequency threshold in each channel in the local cache of the node.
[0213] An embodiment of the present invention provides a storage medium storing executable instructions, where the executable instructions, when executed by a processor, cause the processor to execute the method provided by the embodiment of the present invention. For example, such as Figure 3 、 Figure 6A 、 Figure 6B 、 Figure 7 and Figure 8 the certificate processing method of the blockchain network shown in any of the accompanying drawings.
[0214] In some embodiments, the storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disc, or CD-ROM; or may be various devices including one or any combination of the above memories.
[0215] As an example, the executable instructions may be deployed to be executed on one computing device, or on multiple computing devices located at one location, or on multiple computing devices distributed at multiple locations and interconnected through a communication network.
[0216] In summary, in the embodiments of the present invention, through the method of certificate reuse, for the certificates appearing in transactions, after consensus among internal nodes, the hash value of the certificate and the digital certificate binary data information are combined into a key-value pair and stored in the certificate database local to the blockchain network node. In this way, the digital certificates in all subsequent transactions will be replaced with the corresponding hash values, and when verifying transactions, the digital certificates corresponding to the hash values are obtained from the local node of the node for verification, thereby reducing the volume of transactions and blocks. It is applicable to all scenarios of consortium blockchains and any blockchain network that uses digital certificates for identity verification. Moreover, it fundamentally reduces the volume of each block and can improve the throughput of the entire blockchain network.
[0217] The above description is only for the embodiments of the present invention and is not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and scope of the present invention are included in the protection scope of the present invention.
Claims
1. A certificate processing method for a blockchain network, characterized in that: The method comprises: Receive transaction proposals submitted by clients through nodes in the blockchain network; Verify the transaction proposal based on the endorsement policy, and return a proposal response to the client when the verification passes; The proposal response includes: a transaction result, a digital certificate of a node that has passed the endorsement policy verification, and a digital signature of the node that has passed the endorsement policy verification on the transaction result; the transaction proposal and the proposal response are used for the client to construct a transaction and submit the transaction to a node in the blockchain network; A consensus is reached on the block through the nodes of the blockchain network, and when the consensus is reached, a digital certificate is extracted from the transaction of the block, and the digital certificate is stored in the database of the node; Receiving the transaction submitted by the client through the node of the blockchain network, and when the digital certificate in the submitted transaction is queried from the database, replacing the digital certificate in the submitted transaction with the corresponding hash value; The replaced transactions encapsulated and submitted by the client are sorted in the order of receipt through the nodes in the blockchain network to construct a new block; the constructed new block is broadcasted to the blockchain network so that the nodes that receive the constructed new block can reach a consensus; The digital certificate corresponding to the hash value in the transaction of the new block is queried from the database of the node, and the transaction in the new block is verified using the queried digital certificate.
2. The method according to claim 1, characterized in that The consensus on the block through the nodes of the blockchain network includes: The following verification operations are performed on each transaction in the block by the nodes in the blockchain network: Verifying the client digital signature in the transaction through the client digital certificate in the transaction; Verify the node digital signature in the transaction through the node digital certificate of the transaction; Verify that the transaction complies with the endorsement policy.
3. The method according to claim 1, characterized in that The querying of the digital certificate corresponding to the hash value in the transaction of the new block from the database of the node includes: When consensus is reached on the new block through the nodes of the blockchain network, a hash value is extracted from the transaction of the new block; The digital certificate corresponding to the hash value is queried from the database of the node.
4. The method according to claim 3, characterized in that The step of extracting a hash value from a transaction in the new block comprises: Extracting, from each transaction in the new block, a hash value of the digital certificate of the client that submitted the transaction and a hash value of the digital certificate of the node that endorsed the node; The querying of the digital certificate corresponding to the hash value from the database of the node includes: The digital certificate of the client submitting the transaction and the digital certificate of the node endorsing the transaction are queried from the database of the node through the extracted hash value.
5. The method according to claim 1, characterized in that The verifying the transaction in the new block by using the queried digital certificate includes: The following verification operations are performed on each transaction in the block by the nodes in the blockchain network: Verifying the digital certificate of the node endorsing the transaction through the root certificate of the node; When the verification is successful, the public key of the node endorsing the transaction is extracted from the digital certificate of the node endorsing the transaction, and the digital signature of the node in the transaction is verified by the extracted public key; Verifying the digital certificate of the node endorsing the transaction through the root certificate of the node; When the verification is successful, the public key of the node endorsing the transaction is extracted from the digital certificate of the node endorsing the transaction, and the digital signature of the node in the transaction is verified by the extracted public key.
6. The method according to claim 5, characterized in that When performing a verification operation on each transaction in the block through a node in the blockchain network, the method further includes: Verify that the transactions in the block are in the correct format; Verify that the node endorsing the transaction joins the channel for receiving transactions indicated in the transaction; Verify that the transaction complies with the endorsement policy.
7. The method according to claim 1, characterized in that The method further comprises: Through the nodes in the blockchain network, the transactions constructed and submitted by the client are sorted in the order of receipt to construct blocks, and the constructed blocks are broadcast in the blockchain network so that the nodes that receive the constructed blocks can reach a consensus.
8. The method according to claim 1, characterized in that When the consensus is passed, extracting the digital certificate from the transaction of the block and storing the digital certificate in the database of the node includes: When consensus is passed, the digital certificate of the client submitting the transaction and the digital certificate of the node endorsing the transaction are extracted from each transaction in the block; The key-value pair of the extracted digital certificate is stored in the database of the node; wherein the key in the key-value pair is the hash value of the extracted digital certificate, and the value in the key-value pair is the binary data of the extracted digital certificate.
9. The method according to claim 1, characterized in that: Before receiving the transaction submitted by the client through the node of the blockchain network, the method further includes: Receive the transaction proposal submitted by the client through the node in the blockchain network, When the node receiving the transaction proposal finds its own digital certificate in the local database and verifies that the transaction proposal is passed based on the endorsement policy, it determines to endorse the transaction and returns a proposal response to the client; The proposal response includes: the transaction result, the hash value of the digital certificate of the node endorsing the transaction, and the digital signature of the node endorsing the transaction on the transaction result, so that When the client receives the proposal response, it constructs the transaction proposal and the proposal response into a transaction, and submits the encapsulated transaction to a node in the blockchain network.
10. The method according to any one of claims 1 to 9, characterized in that: The method further comprises: storing, in a cache of the node, key-value pairs of digital certificates whose query frequency is higher than a frequency threshold; The querying of the digital certificate corresponding to the hash value from the database of the node includes: Querying the digital certificate corresponding to the hash value from the cache of the node; If the digital certificate corresponding to the hash value is not found, query the database of the node.
11. The method according to claim 10, characterized in that The storing, in the cache of the node, a key-value pair of a digital certificate with a query frequency higher than a frequency threshold comprises: Determining the frequency with which digital certificates for transactions in each channel joined by the node in the blockchain network are used; The digital certificates used in each channel with a frequency higher than a frequency threshold are stored in a local cache of the node.
12. A certificate processing device for a blockchain network, characterized in that: The device comprises: Certificate extraction module for: Receive transaction proposals submitted by clients through nodes in the blockchain network; Verify the transaction proposal based on the endorsement policy, and return a proposal response to the client when the verification passes; The proposal response includes: a transaction result, a digital certificate of a node that has passed the endorsement policy verification, and a digital signature of the node that has passed the endorsement policy verification on the transaction result; the transaction proposal and the proposal response are used for the client to construct a transaction and submit the transaction to a node in the blockchain network; A consensus is reached on the block through the nodes of the blockchain network, and when the consensus is reached, a digital certificate is extracted from the transaction of the block, and the digital certificate is stored in the database of the node; Transaction tailoring module, used to: The transaction submitted by the client is received through the nodes of the blockchain network, and when the digital certificate in the submitted transaction is queried from the database, the digital certificate in the submitted transaction is replaced with the corresponding hash value; through the nodes in the blockchain network, the replaced transactions encapsulated and submitted by the client are sorted in the order of receipt to construct a new block; the constructed new block is broadcasted to the blockchain network so that the nodes that receive the constructed new block can reach a consensus; The digital certificate corresponding to the hash value in the transaction of the new block is queried from the database of the node, and the transaction in the new block is verified using the queried digital certificate.
13. An electronic device for running a node in a blockchain network, characterized in that: The electronic device comprises: A memory for storing executable instructions; A processing tool for implementing the certificate processing method of the blockchain network described in any one of claims 1 to 11 when executing the executable instructions stored in the memory.
14. A storage medium, characterized in that: Executable instructions are stored, which are used to cause the processor to execute and implement the certificate processing method of the blockchain network described in any one of claims 1 to 11.
Citation Information
Patent Citations
Block chain-based electronic invoice integrated processing method and system
CN107451874A
Block chain digital certificate generation and verification method, computer device and storage medium
CN110175436A