A Method, Device, Equipment and Storage Medium for Operating a Consortium Blockchain System
By adopting a certificate-free public key cryptography system in the alliance chain system, the certificate management and storage burden caused by public key certificate management is solved, and more efficient operation and better security is achieved.
Patent Information
- Application Number
- CN202111604147.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-24
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-12-24
AI Technical Summary
The excessive burden of certificate management and storage caused by public key certificate management in the existing alliance chain system affects system efficiency.
Using a certificate-free public key cryptography system, the central node of the key generation generates a private key and a public key for each node, and public key parts of the public key are disclosed to avoid complex certificate verification processes.
It reduces the burden of key management and storage of the alliance chain system, improves the operating efficiency of the system, avoids key hosting issues, and improves the security of the system.
Smart Images

Figure CN114297678B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of blockchain, and particularly relates to a method, device, equipment and storage medium for operating a consortium blockchain system. Background Art
[0002] A blockchain is an immutable distributed shared ledger. In a blockchain, data is stored among multiple parties, and a consensus algorithm is used to achieve the consistency of multi-node data; in a blockchain, data can only be appended and cannot be deleted or modified; a new type of blockchain is programmable, and business rules can be encoded into the blockchain using smart contracts. The rules (codes) cannot be deleted or modified like data, the codes are automatically executed when called, cannot be skipped, and the execution results are also written into the blockchain. Since data is stored among multiple parties and the data on the chain is immutable, the blockchain can be used to achieve trusted data sharing among multiple parties. A consortium blockchain is a type of blockchain. In a consortium blockchain, relevant nodes can only join the blockchain network after being authorized and permitted, and participate in consensus and read / write block data according to the rules. In the prior art, the project system based on the consortium blockchain usually adopts public key certificate management. For example, the most common consortium blockchain system is the Hyperledger system open-sourced by IBM. The Hyperledger system realizes its system authorization and permission function based on a mature public key certificate cryptosystem. Although it can effectively control the permissions of system nodes and users, public key certificate management requires storing the root certificate of the trusted CA (Certificate Authority), its own certificate, and the corresponding private key to complete basic authentication. The cumbersome certificates still bring a great burden on certificate management and storage for the Hyperledger system. Summary of the Invention
[0003] In view of this, the purpose of the present invention is to provide a method, device, equipment and medium for operating a consortium blockchain system, which can reduce the password management and storage overhead of the consortium blockchain system. The specific solutions are as follows:
[0004] In the first aspect, the present application discloses a method for operating a consortium blockchain system, including:
[0005] Each node in the consortium blockchain system performs key initialization of the certificate-free public key cryptosystem to obtain a consortium blockchain system based on the certificate-free public key cryptosystem; the consortium blockchain system includes multiple client nodes, multiple server nodes, and multiple key generation center nodes;
[0006] A contract code running environment is constructed through the client of the consortium blockchain system to realize smart contract invocation.
[0007] Optionally, each node in the consortium blockchain system performs key initialization of the certificate-free public key cryptosystem, including:
[0008] The key generation center node within the consortium blockchain system uses a key generation algorithm to generate corresponding private key partial fields and public key partial fields for each of the server nodes and the client nodes;
[0009] The public key partial fields are made public so that each of the server nodes and the client nodes can generate their respective private keys and public keys based on the corresponding private key partial fields and public key partial fields.
[0010] Optionally, the client of the consortium blockchain system constructs a contract code running environment to implement smart contract invocation, including:
[0011] The client constructs a simulated running environment for the target contract code according to the target feature parameters corresponding to the target contract code, and obtains first transaction information based on the environment information corresponding to the simulated running environment and the target feature parameters;
[0012] The first transaction information is sent to the server according to a preset transaction process, and when it is detected that the first transaction information is included in the newly saved block locally, the simulated running environment is controlled to take effect;
[0013] The client makes simulated modifications to the simulated running environment, and obtains second transaction parameters based on the environment parameters of the modified simulated running environment;
[0014] The second transaction information is sent to the server according to the preset transaction process, and when it is detected that the second transaction information is included in the newly saved block locally, the modified simulated running environment is controlled to take effect to implement smart contract invocation.
[0015] Optionally, the preset transaction process includes:
[0016] The client generates a transaction information signature based on the current transaction information, and sends the client identifier, the client public key, the current transaction information, and the transaction information signature to the server according to a preset communication protocol;
[0017] The server verifies the transaction information signature according to a preset signature verification process, and after the signature verification passes, shares the current transaction information with the remaining servers within the consortium blockchain system so as to jointly determine the sorted transaction information, and packs the sorted transaction information and the hash value corresponding to the most recent historical block to obtain a new block, and then saves the new block locally and broadcasts it to all clients;
[0018] The client verifies the new block according to the broadcasts of all servers. If the contents of the new blocks broadcast by all servers are consistent, the new block is saved locally to complete the current transaction process.
[0019] Optionally, the communication process of the preset communication protocol includes:
[0020] A sender within the consortium blockchain system generates a first ephemeral public key and a first ephemeral private key for key negotiation, and signs the first ephemeral public key using the signature algorithm of the certificateless public key cryptosystem with the local sender private key to obtain a first signature, and sends the first ephemeral public key, the sender identifier, the sender public key, and the first signature to a receiver within the consortium blockchain system;
[0021] The receiver verifies the first signature according to a preset signature verification process, and after successful verification, generates a second ephemeral public key and a second ephemeral private key for key negotiation, then signs the second ephemeral public key using the signature algorithm of the certificateless public key cryptosystem with the local receiver private key to obtain a second signature, and generates a first symmetric key based on the first ephemeral public key and the second ephemeral private key, encrypts the first ephemeral public key and the second ephemeral public key using the first symmetric key to obtain a first ciphertext, and then sends the second ephemeral public key, the receiver identifier, the receiver public key, the second signature, and the first ciphertext to the sender;
[0022] The sender verifies the second signature according to a preset signature verification process, and after successful verification, generates a second symmetric key based on the first ephemeral private key and the second ephemeral public key, decrypts the first ciphertext using the second symmetric key and verifies the decryption result. If the verification is successful, encrypts the first ephemeral public key and the second ephemeral public key using the second symmetric key to obtain a second ciphertext, and sends the second ciphertext to the receiver;
[0023] The receiver decrypts the second ciphertext using the first symmetric key and verifies the decryption result. If the verification is successful, uses the first symmetric key and the second symmetric key as the negotiation key between the sender and the receiver.
[0024] Optionally, before the sender generates a first ephemeral public key and a first ephemeral private key for key negotiation, it further includes:
[0025] Determine whether the target historical negotiation key last used by the sender and the receiver has expired;
[0026] If not expired, use the target historical negotiation key as the negotiation key between the sender and the receiver;
[0027] If expired, perform the operation of the sender generating a first ephemeral public key and a first ephemeral private key for key negotiation.
[0028] Optionally, the preset signature verification process includes:
[0029] The receiving end searches for whether there is a key generation center node corresponding to the sending end identifier in the consortium blockchain system according to the sending end identifier, and determines the target key generation center node;
[0030] If it exists, the target public key partial field corresponding to the sending end identifier is determined through the target key generation center node according to the sending end identifier; the target public key partial field is the public key partial field generated by the target key generation center node using the key generation algorithm;
[0031] The target public key partial field is compared with the public key partial field publicly disclosed by the sending end. If the comparison result is consistent, the signature sent by the sending end is verified using the signature verification algorithm of the certificateless public key cryptosystem.
[0032] In a second aspect, the present application discloses a consortium blockchain system operation device, including:
[0033] A key initialization module for performing key initialization of the certificateless public key cryptosystem for each node in the consortium blockchain system to obtain a consortium blockchain system based on the certificateless public key cryptosystem; the consortium blockchain system includes multiple client nodes, multiple server nodes, and multiple key generation center nodes;
[0034] An operating environment construction module for constructing a contract code operating environment through the client of the consortium blockchain system to implement smart contract calls.
[0035] In a third aspect, the present application discloses an electronic device, including:
[0036] A memory for storing a computer program;
[0037] A processor for executing the computer program to implement the foregoing consortium blockchain system operation method.
[0038] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein the computer program, when executed by a processor, implements the foregoing consortium blockchain system operation method.
[0039] In this application, each node in the consortium blockchain system performs key initialization of the certificateless public key cryptosystem to obtain a consortium blockchain system based on the certificateless public key cryptosystem; the consortium blockchain system includes multiple client nodes, multiple server nodes, and multiple key generation center nodes; a contract code running environment is constructed through the clients of the consortium blockchain system to implement smart contract calls. As can be seen from the above, in this embodiment, by performing key initialization of the certificateless public key cryptosystem on each node in the consortium blockchain system, a consortium blockchain system based on the certificateless public key cryptosystem is obtained. Then, by constructing a contract code running environment through the clients, smart contract calls within the consortium blockchain are realized. On the basis of ensuring the node security authentication and communication of the consortium blockchain system, the complex certificate verification process is avoided, the key management and storage burden of the system is reduced, the operation efficiency of the system is improved, and the key escrow problem in the identity-based cryptosystem can be effectively avoided, making the entire consortium blockchain system more secure. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0041] Figure 1 It is a flowchart of a method for running a consortium blockchain system provided by this application;
[0042] Figure 2 It is a flowchart of a specific contract code call provided by this application;
[0043] Figure 3 It is a flowchart of a specific preset transaction process provided by this application;
[0044] Figure 4 It is a flowchart of communication of a specific preset communication protocol provided by this application;
[0045] Figure 5 It is a flowchart of a specific preset signature verification process provided by this application;
[0046] Figure 6 It is a schematic structural diagram of a device for running a consortium blockchain system provided by this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0048] In the prior art, the project system based on the consortium blockchain usually adopts public key certificate management. However, public key certificate management needs to store the root certificate of the trusted CA, its own certificate, and the corresponding private key to complete the basic authentication. The cumbersome certificates still bring a great burden on the certificate management and storage of the Hyperledger system. To overcome the above technical problems, the present application proposes a method for operating a consortium blockchain system based on the certificate-free public key cryptosystem, which can avoid the complex certificate verification process, reduce the key management and storage burden of the system, and improve the operation efficiency of the system.
[0049] An embodiment of the present application discloses a method for operating a consortium blockchain system. Refer to Figure 1 As shown, the method may include the following steps:
[0050] Step S11: Each node in the consortium blockchain system performs key initialization of the certificate-free public key cryptosystem to obtain a consortium blockchain system based on the certificate-free public key cryptosystem; the consortium blockchain system includes multiple client nodes, multiple server nodes, and multiple key generation center nodes.
[0051] In this embodiment, the consortium blockchain system includes multiple client (Client) nodes, multiple server (Server) nodes, and multiple key generation center (KGC, Key Generation Center) nodes. First, each node in the consortium blockchain system performs key initialization of the certificate-free public key cryptosystem, that is, according to the KGC key generation algorithm and user key generation algorithm of the certificate-free public key cryptosystem, respective private keys and public keys are generated for each client and server in the consortium blockchain system.
[0052] Compared with the certificate-based public key cryptosystem, the certificateless public key cryptosystem does not need to use certificates to bind public keys to ensure the validity of public keys, and solves the problem of private key escrow in the identity-based cryptosystem, that is, the private key of the user is completely controlled by the key generation center. When a specific user applies for a private key by using an identity (ID), the KGC only generates and securely distributes a part of the private key for the user, and the other part of the private key is generated by the user himself. This key generation method in which the KGC cannot completely control the private key effectively avoids the problem of key escrow. In the certificateless public key cryptosystem, it includes the KGC key generation algorithm, the user key generation algorithm, the signature algorithm, and the verification algorithm. Among them, the KGC key generation algorithm outputs the KGC part of the corresponding private key and the KGC part of the public key according to the input user identity. The above user identity can be the client user identity or the server user identity; the above user key generation algorithm outputs the private key and public key of the user according to the KGC part of the private key and the KGC part of the public key; the above signature algorithm outputs a signature according to the input user private key, user identity, and message to be signed; the above verification algorithm outputs whether the signature is valid according to the input signer identity, signer public key, message to be signed, and signature.
[0053] In this embodiment, the key initialization of the certificateless public key cryptosystem for each node in the consortium chain system may include: using the key generation algorithm by the key generation center node in the consortium chain system to generate the corresponding private key partial field and public key partial field for each server node and each client node respectively; publicly disclosing the public key partial field so that each server node and each client node can generate their own corresponding private key and public key according to the corresponding private key partial field and public key partial field.
[0054] That is, the KGC node responsible for Server key generation runs the KGC key generation algorithm of the certificateless public key cryptography, concatenates the KGC name and the Server name into an identification name as the input of this algorithm, generates the KGC part of the private key and the KGC part of the public key for all Servers, securely distributes the KGC part of the private key to each Server, and publishes the KGC part of the public key. The KGC node responsible for Client key generation runs the KGC key generation algorithm of the certificateless public key cryptography, concatenates the KGC name and the Client name into an identification name as the input of this algorithm, generates the KGC part of the private key and the KGC part of the public key for all Clients, securely distributes the KGC part of the private key to each Client, and publishes the KGC part of the public key. Each Server and Client run the user key generation algorithm of the certificateless public key cryptography according to the generated KGC part of their own private keys and the KGC part of the public keys, generate the user private key and the public key, and publish the public key. That is to say, after key initialization, each client node stores the client private key and the client public key generated by the KGC key generation algorithm and the user key generation algorithm based on the certificateless public key cryptography system, and the client public key is published. Similarly, the server stores the server private key and the server public key, and the server public key is published.
[0055] Step S12: Build a contract code running environment through the client of the consortium blockchain system to implement smart contract invocation.
[0056] In this embodiment, after key initialization to obtain the consortium blockchain system of the certificateless public key cryptography system, a contract code running environment is built through the client of the consortium blockchain system to implement smart contract invocation.
[0057] For example Figure 2 As shown, in this embodiment, building a contract code running environment through the client of the consortium blockchain system to implement smart contract invocation may include:
[0058] S121: Build a simulation running environment of the target contract code through the client according to the target characteristic parameters corresponding to the target contract code, and obtain the first transaction information based on the environment information corresponding to the simulation running environment and the target characteristic parameters.
[0059] That is, the target characteristic parameters such as the name, version, and content of the target contract code are entered into the client. The client builds a simulation running environment of the target contract code according to the established rules, and packages the information such as the characteristics of the target contract code and the simulation running environment into transaction information to obtain the first transaction information.
[0060] S122: Send the first transaction information to the server according to a preset transaction process, and control the simulation running environment to take effect when it is detected that the newly saved block locally contains the first transaction information.
[0061] That is, the client submits the first transaction information according to a preset transaction process, and when it is detected that the newly saved block locally contains the first transaction information, the simulation running environment actually takes effect. It can be understood that after the client submits the first transaction information to the server according to a preset transaction process, the server will perform unified integration and feedback the integration result to the client. After the client confirms that it is correct, it will save it to a new block.
[0062] S123: Simulate and modify the simulation running environment through the client, and obtain second transaction parameters based on the environmental parameters of the modified simulation running environment.
[0063] That is, after the simulation running environment takes effect, the client calls the contract, i.e., the chain code, to simulate and modify the chain code running environment, and packages the simulated and modified contract running environment into new transaction information to obtain second transaction parameters.
[0064] S124: Send the second transaction information to the server according to the preset transaction process, and control the modified simulation running environment to take effect when it is detected that the newly saved block locally contains the second transaction information, so as to implement smart contract invocation.
[0065] The client also submits the second transaction information according to the above preset transaction process, and when it is detected that the newly saved block locally contains the second transaction information, the simulated modification of the running environment actually takes effect, completing the smart contract invocation to implement the system contract code invocation.
[0066] For example Figure 3 As shown, in this embodiment, the preset transaction process in the above step S122 may include:
[0067] S301: The client generates a transaction information signature according to the current transaction information, and sends the client identifier, the client public key, the current transaction information, and the transaction information signature to the server according to a preset communication protocol.
[0068] That is, the client runs the signature algorithm of the certificate-free public key cryptography on the current transaction information with its own private key to obtain the signature, and sends its own identifier, its own public key, the current transaction information, and the signature of the current transaction information to a certain target server.
[0069] S302: The server verifies the signature of the transaction information according to a preset signature verification process, and after the signature verification passes, shares the current transaction information with the remaining servers in the consortium blockchain system, so as to jointly determine the sorted transaction information, and packages the sorted transaction information and the hash value corresponding to the most recent historical block to obtain a new block, and then saves the new block locally and broadcasts it to all clients.
[0070] After the server receives the above client identifier, client public key, current transaction information, and transaction information signature, it verifies the signature of the transaction information according to a preset signature verification process. The above preset signature verification process is a signature verification process based on a signature verification algorithm that runs a certificate-free public key cryptography. If the signature verification is incorrect, transaction error information is sent to the above client. When the signature verification is correct, the servers send each other the transaction information they received, so as to sort the transaction information and reach a consensus. Each server packages the sorted transactions and the hash value of the previous block into a block and stores it locally on the server, and broadcasts the block information to all clients.
[0071] S303: The client verifies the new block according to the broadcasts of all servers. If the content of the new block broadcast by all servers is consistent, the new block is saved locally to complete the current transaction process.
[0072] In this embodiment, after the client receives the broadcasts of all servers, it compares whether the content of the same block number is consistent. If it is consistent, the block content is saved locally on the client; otherwise, the block is not saved, and thus a transaction process is completed.
[0073] In this embodiment, the communication process of the preset communication protocol in the above step S301 may include:
[0074] S401: The sending end in the consortium blockchain system generates a first temporary public key and a first temporary private key for key negotiation, and signs the first temporary public key according to the signature algorithm of the certificate-free public key cryptography system using the local sending end private key to obtain a first signature, and sends the first temporary public key, the sending end identifier, the sending end public key, and the first signature to the receiving end in the consortium blockchain system.
[0075] It is understandable that in the process of submitting system transactions in this embodiment, the communication operations of sending messages and receiving messages involved all adopt the above-mentioned preset communication protocol. If the two communication parties are A and B, assume that the communication sending end is A and the receiving end is B. The identifier of A is IDA, the private key is skA, and the public key is pkA, which is issued by KGC1; the identifier of B is IDB, the private key is skB, and the public key is pkB, which is issued by KGC2; both KGC1 and KGC2 are on the trusted KGC list of A and B. Then, in the communication process of the preset communication protocol, first, A calculates the first temporary public key and the first temporary private key tskA for key negotiation, and uses skA to run the signature algorithm of the certificateless public key cryptography on tpkA to obtain the first signature sigA, and sends tpkA, IDA, sigA, and pkA to B.
[0076] S402: The receiving end verifies the first signature according to the preset signature verification process, and generates a second temporary public key and a second temporary private key for key negotiation after the signature verification is correct. Then, the receiving end uses the local receiving end private key to sign the second temporary public key according to the signature algorithm of the certificateless public key cryptography system to obtain a second signature, and generates a first symmetric key based on the first temporary public key and the second temporary private key. The receiving end encrypts the first temporary public key and the second temporary public key with the first symmetric key to obtain a first ciphertext, and then sends the second temporary public key, the receiving end identifier, the receiving end public key, the second signature, and the first ciphertext to the sending end.
[0077] That is, after B receives tpkA, IDA, sigA, and pkA, it verifies whether the signature sigA is correct according to the preset signature verification process. If it is incorrect, it exits; otherwise, B calculates the second temporary public key tpkB and the second temporary private key tskB for key negotiation, uses skB to run the signature algorithm of the certificateless public key cryptography on tpkB to obtain the second signature sigB, and calculates the first symmetric key sk with tskB and tpkA. Then, B encrypts the concatenation of tpkA and tpkB with sk to obtain the first ciphertext cB. B sends tpkB, IDB, sigB, pkB, and cB to A.
[0078] S403: The sending end verifies the second signature according to the preset signature verification process, and generates a second symmetric key based on the first temporary private key and the second temporary public key after the signature verification is correct. The sending end decrypts the first ciphertext with the second symmetric key and verifies the decryption result. If the verification is successful, the sending end encrypts the first temporary public key and the second temporary public key with the second symmetric key to obtain a second ciphertext, and sends the second ciphertext to the receiving end.
[0079] That is, after A receives tpkB, IDB, sigB, and pkB, it verifies whether the signature sigB is correct according to the preset signature verification process. If it is incorrect, it exits; otherwise, it calculates the second symmetric key sk based on tskA and tpkB, and uses sk to verify whether the content decrypted from cB is the concatenation of tpkA and tpkB. If it is not, it exits; otherwise, it encrypts the content after concatenating tpkB and tpkA with the second symmetric key sk to obtain the second ciphertext cA, and sends cA to B.
[0080] S404: The receiving end decrypts the second ciphertext using the first symmetric key and verifies the decryption result. If the verification is successful, the first symmetric key and the second symmetric key are used as the negotiation key between the sending end and the receiving end.
[0081] That is, after B receives cA, it verifies whether the content decrypted from cA using the first symmetric key sk is the concatenation of tpkB and tpkA. If it is not, it exits the connection; otherwise, it uses the first symmetric key, which is also the second symmetric key, as the negotiation key between the sending end and the receiving end. Specifically, A and B encrypt the message with sk into a ciphertext and send it to the party receiving the message. The party receiving the message decrypts the ciphertext with sk to obtain the specific message and processes it.
[0082] In this embodiment, before the sending end generates the first temporary public key and the first temporary private key for key negotiation, it may further include: determining whether the target historical negotiation key last used by the sending end and the receiving end has expired; if not expired, using the target historical negotiation key as the negotiation key between the sending end and the receiving end; if expired, performing the operation of the sending end generating the first temporary public key and the first temporary private key for key negotiation. That is to say, the specific communication process within the system in this embodiment may be as Figure 4 shown. That is, after the sending end initiates a connection request to the receiving end, it first determines whether the symmetric key negotiated most recently by the sending end and the receiving end has expired. If it has not expired yet, it encrypts the sent and received messages with the symmetric key negotiated last time and then communicates; otherwise, it performs the above operations such as the sending end generating the first temporary public key and the first temporary private key for key negotiation.
[0083] For example Figure 5 shown, in this embodiment, the above preset signature verification process may include:
[0084] S501: The receiving end searches the alliance chain system according to the sending end identifier to determine whether there is a key generation center node corresponding to the sending end identifier, and determines the target key generation center node.
[0085] In this embodiment, the signature verification operations involved all adopt the above-mentioned preset signature verification process. Specifically, after the receiving end receives information including a signature, the public key of the signature party, the identifier of the signature party, and the message to be signed, etc., first, according to the identifier of the signature party, that is, the identifier of the sending end, it searches whether there is a key generation center node corresponding to the sending end identifier in the consortium blockchain system.
[0086] S502: If it exists, determine the target public key partial field corresponding to the sending end identifier through the target key generation center node according to the sending end identifier; the target public key partial field is the public key partial field generated by the target key generation center node using the key generation algorithm.
[0087] In this embodiment, if it is not found, the verification fails; if it is found, then this key generation center node is used as the target key generation center node, and then the target public key partial field is queried from the target key generation center node with the sending end identifier as the index, that is, the KGC part of the public key generated by the key generation center node using the key generation algorithm.
[0088] S503: Compare the target public key partial field with the public key partial field publicly disclosed by the sending end. If the comparison result is consistent, use the signature verification algorithm of the certificateless public key cryptosystem to verify the signature sent by the sending end.
[0089] In this embodiment, if the target public key partial field is inconsistent with the public key partial field publicly disclosed by the sending end, the verification fails; if they are consistent, use the signature verification algorithm of the certificateless public key cryptosystem to verify the signature sent by the above-mentioned sending end. The signature verification process only needs to store the address of the trusted KGC and its own public key and private key to complete the authentication. Compared with certificates, the public key is lighter and occupies less storage space. Moreover, before using the signature verification algorithm, a first verification is performed by querying the target key generation center node, and a second verification is performed by comparing the public key partial fields, which greatly improves the verification efficiency and avoids the problem of resource consumption caused by using the signature verification algorithm every time.
[0090] As can be seen from the above, in this embodiment, each node in the consortium blockchain system performs key initialization of the certificateless public key cryptosystem to obtain a consortium blockchain system based on the certificateless public key cryptosystem; the consortium blockchain system includes multiple client nodes, multiple server nodes, and multiple key generation center nodes; a contract code running environment is constructed through the clients of the consortium blockchain system to implement smart contract invocation. As can be seen from the above, in this embodiment, by performing key initialization of the certificateless public key cryptosystem on each node in the consortium blockchain system, a consortium blockchain system based on the certificateless public key cryptosystem is obtained, and then a contract code running environment is constructed through the clients to implement smart contract invocation within the consortium blockchain. On the basis of ensuring the node security authentication and communication of the consortium blockchain system, complex certificate verification processes are avoided, the key management and storage burden of the system is reduced, the operation efficiency of the system is improved, and the key escrow problem in the identity-based cryptosystem can be effectively avoided, making the entire consortium blockchain system more secure.
[0091] Correspondingly, an embodiment of the present application also discloses a running device for a consortium blockchain system. Refer to Figure 6 As shown, the device includes:
[0092] A key initialization module 11, configured to perform key initialization of the certificateless public key cryptosystem for each node in the consortium blockchain system to obtain a consortium blockchain system based on the certificateless public key cryptosystem; the consortium blockchain system includes multiple client nodes, multiple server nodes, and multiple key generation center nodes;
[0093] A running environment construction module 12, configured to construct a contract code running environment through the clients of the consortium blockchain system to implement smart contract invocation.
[0094] As can be seen from the above, in this embodiment, each node in the consortium blockchain system performs key initialization of the certificateless public key cryptosystem to obtain a consortium blockchain system based on the certificateless public key cryptosystem; the consortium blockchain system includes multiple client nodes, multiple server nodes, and multiple key generation center nodes; a contract code running environment is constructed through the clients of the consortium blockchain system to implement smart contract invocation. As can be seen from the above, in this embodiment, by performing key initialization of the certificateless public key cryptosystem on each node in the consortium blockchain system, a consortium blockchain system based on the certificateless public key cryptosystem is obtained, and then a contract code running environment is constructed through the clients to implement smart contract invocation within the consortium blockchain. On the basis of ensuring the node security authentication and communication of the consortium blockchain system, complex certificate verification processes are avoided, the key management and storage burden of the system is reduced, the operation efficiency of the system is improved, and the key escrow problem in the identity-based cryptosystem can be effectively avoided, making the entire consortium blockchain system more secure.
[0095] In some specific embodiments, the key initialization module 11 may specifically include:
[0096] A key part field generation unit, configured to generate corresponding private key part fields and public key part fields for each of the server nodes and the client nodes respectively by using a key generation algorithm through a key generation central node within the consortium blockchain system;
[0097] A key generation unit, configured to publicly disclose the public key part fields so that each of the server nodes and the client nodes can generate their own corresponding private keys and public keys according to the corresponding private key part fields and public key part fields.
[0098] In some specific embodiments, the operating environment construction module 12 may specifically include:
[0099] A simulated operating environment construction unit, configured to construct a simulated operating environment of the target contract code by the client according to target feature parameters corresponding to the target contract code, and obtain first transaction information based on environment information corresponding to the simulated operating environment and the target feature parameters;
[0100] A simulated operating environment activation unit, configured to send the first transaction information to the server according to a preset transaction process, and control the simulated operating environment to become effective when it is detected that the first transaction information is included in a newly saved block locally;
[0101] A simulated modification unit, configured to perform simulated modification on the simulated operating environment by the client, and obtain second transaction parameters based on environment parameters of the modified simulated operating environment;
[0102] A modified simulated operating environment activation unit, configured to send the second transaction information to the server according to the preset transaction process, and control the modified simulated operating environment to become effective when it is detected that the second transaction information is included in a newly saved block locally, so as to implement intelligent contract invocation.
[0103] In some specific embodiments, the consortium blockchain system operating device may specifically include:
[0104] A preset transaction process running module is used for the client to generate a transaction information signature based on the current transaction information, and send the client identifier, the client public key, the current transaction information, and the transaction information signature to the server according to a preset communication protocol; the server verifies the transaction information signature according to a preset signature verification process, and after the signature verification passes, shares the current transaction information with the remaining servers in the consortium blockchain system, so as to jointly determine the sorted transaction information, and package the sorted transaction information and the hash value corresponding to the most recent historical block to obtain a new block, and then save the new block locally and broadcast it to all clients; the client verifies the new block according to the broadcasts of all servers, and if the contents of the new blocks broadcast by all servers are consistent, saves the new block locally to complete the current transaction process.
[0105] In some specific embodiments, the consortium blockchain system operating device may specifically include:
[0106] A preset communication protocol communication module is used for a sender in the consortium blockchain system to generate a first temporary public key and a first temporary private key for key negotiation, and sign the first temporary public key according to the signature algorithm of the certificateless public key cryptosystem using the local sender private key to obtain a first signature, and send the first temporary public key, the sender identifier, the sender public key, and the first signature to a receiver in the consortium blockchain system; the receiver verifies the first signature according to a preset signature verification process, and after the signature verification is correct, generates a second temporary public key and a second temporary private key for key negotiation, and then signs the second temporary public key according to the signature algorithm of the certificateless public key cryptosystem using the local receiver private key to obtain a second signature, and generates a first symmetric key based on the first temporary public key and the second temporary private key, encrypts the first temporary public key and the second temporary public key using the first symmetric key to obtain a first ciphertext, and then sends the second temporary public key, the receiver identifier, the receiver public key, the second signature, and the first ciphertext to the sender; the sender verifies the second signature according to a preset signature verification process, and after the signature verification is correct, generates a second symmetric key based on the first temporary private key and the second temporary public key, decrypts the first ciphertext using the second symmetric key and verifies the decryption result, and if the verification is successful, encrypts the first temporary public key and the second temporary public key using the second symmetric key to obtain a second ciphertext, and sends the second ciphertext to the receiver; the receiver decrypts the second ciphertext using the first symmetric key and verifies the decryption result, and if the verification is successful, uses the first symmetric key and the second symmetric key as the negotiation keys of the sender and the receiver.
[0107] In some specific embodiments, the operating device of the consortium blockchain system may specifically include:
[0108] An expiration judgment unit, configured to judge whether the target historical negotiation key last used by the sending end and the receiving end has expired;
[0109] A negotiation key determination unit, configured to, if not expired, use the target historical negotiation key as the negotiation key between the sending end and the receiving end;
[0110] A key negotiation trigger unit, configured to, if expired, perform the operation of the sending end generating a first temporary public key and a first temporary private key for key negotiation.
[0111] In some specific embodiments, the operating device of the consortium blockchain system may specifically include:
[0112] A preset signature verification process running module, configured to the receiving end searches in the consortium blockchain system for a key generation center node corresponding to the sending end identifier according to the sending end identifier, and determines a target key generation center node; if it exists, determines a target public key partial field corresponding to the sending end identifier through the target key generation center node according to the sending end identifier; the target public key partial field is a public key partial field generated by the target key generation center node using a key generation algorithm; compares the target public key partial field with the public key partial field publicly disclosed by the sending end, and if the comparison result is consistent, verifies the signature sent by the sending end using the signature verification algorithm of the certificateless public key cryptosystem.
[0113] An embodiment of the present invention further provides an electronic device, including:
[0114] A memory, configured to store a computer program;
[0115] A processor, configured to implement the steps of the consortium blockchain system operation method as described above when executing the computer program.
[0116] Since the embodiments of the electronic device part correspond to the embodiments of the consortium blockchain system operation method part, for the embodiments of the electronic device part, please refer to the description of the embodiments of the consortium blockchain system operation method part, and will not be elaborated here for the time being.
[0117] Furthermore, an embodiment of the present application also discloses a computer storage medium, in which computer executable instructions are stored, and when the computer executable instructions are loaded and executed by a processor, the steps of the consortium blockchain system operation method disclosed in any of the foregoing embodiments are implemented.
[0118] In the present specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts among the embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0119] The steps of the methods or algorithms described in connection with the embodiments disclosed herein can be implemented directly in hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0120] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0121] The above has introduced in detail a method, device, equipment and medium for operating a consortium blockchain system provided by the present invention. Specific examples are used herein to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation on the present invention.
Claims
1. A method for operating a consortium blockchain system, characterized in that Including: Each node in the consortium blockchain system performs key initialization of the certificateless public key cryptosystem to obtain a consortium blockchain system based on the certificateless public key cryptosystem; The consortium blockchain system includes multiple client nodes, multiple server nodes, and multiple key generation center nodes; Construct a contract code running environment through the client nodes of the consortium blockchain system to implement smart contract invocation; The constructing a contract code running environment through the client nodes of the consortium blockchain system to implement smart contract invocation includes: The client node constructs a simulated running environment of the target contract code according to the target feature parameters corresponding to the target contract code, and obtains the first transaction information based on the environment information corresponding to the simulated running environment and the target feature parameters; Send the first transaction information to the server node according to a preset transaction process, and control the simulated running environment to take effect when it is detected that the first transaction information is included in the newly saved block locally; The client node performs simulated modification on the simulated running environment, and obtains the second transaction information based on the environment parameters of the modified simulated running environment; Send the second transaction information to the server node according to the preset transaction process, and control the modified simulated running environment to take effect when it is detected that the second transaction information is included in the newly saved block locally, so as to implement smart contract invocation.
2. The method for operating a consortium blockchain system according to claim 1, characterized in that Each node in the consortium blockchain system performs key initialization of the certificateless public key cryptosystem, including: The key generation center node in the consortium blockchain system uses a key generation algorithm to generate corresponding private key partial fields and public key partial fields for each of the server nodes and the client nodes respectively; Disclose the public key partial fields so that each of the server nodes and the client nodes can generate their own corresponding private keys and public keys according to the corresponding private key partial fields and public key partial fields.
3. The method for operating a consortium blockchain system according to claim 2, characterized in that The preset transaction process includes: The client node generates a transaction information signature according to the current transaction information, and sends the client identifier, the client public key, the current transaction information, and the transaction information signature to the server node according to a preset communication protocol; The server node verifies the transaction information signature according to a preset signature verification process, and shares the current transaction information with the remaining server nodes in the consortium blockchain system after the signature verification passes, so as to jointly determine the sorted transaction information, and package the sorted transaction information and the hash value corresponding to the most recent historical block to obtain a new block, and then save the new block locally and broadcast it to all client nodes; The client node verifies the new block according to the broadcasts of all server nodes. If the contents of the new blocks broadcast by all server nodes are consistent, the new block is saved locally to complete the current transaction process.
4. The method for operating a consortium blockchain system according to claim 3, characterized in that The communication process of the preset communication protocol includes: In the consortium blockchain system, the sending end generates a first temporary public key and a first temporary private key for key negotiation, and uses the local sending end private key to sign the first temporary public key according to the signature algorithm of the certificateless public key cryptosystem to obtain a first signature, and sends the first temporary public key, the sending end identifier, the sending end public key, and the first signature to the receiving end in the consortium blockchain system; The receiving end verifies the first signature according to a preset signature verification process, and after the verification is correct, generates a second temporary public key and a second temporary private key for key negotiation, then uses the local receiving end private key to sign the second temporary public key according to the signature algorithm of the certificateless public key cryptosystem to obtain a second signature, and generates a first symmetric key based on the first temporary public key and the second temporary private key, encrypts the first temporary public key and the second temporary public key with the first symmetric key to obtain a first ciphertext, and then sends the second temporary public key, the receiving end identifier, the receiving end public key, the second signature, and the first ciphertext to the sending end; The sending end verifies the second signature according to a preset signature verification process, and after the verification is correct, generates a second symmetric key based on the first temporary private key and the second temporary public key, decrypts the first ciphertext with the second symmetric key and verifies the decryption result. If the verification is successful, encrypts the first temporary public key and the second temporary public key with the second symmetric key to obtain a second ciphertext, and sends the second ciphertext to the receiving end; The receiving end decrypts the second ciphertext with the first symmetric key and verifies the decryption result. If the verification is successful, uses the first symmetric key and the second symmetric key as the negotiation key between the sending end and the receiving end.
5. The method for operating a consortium blockchain system according to claim 4, characterized in that Before the sending end generates a first temporary public key and a first temporary private key for key negotiation, it further includes: Judging whether the target historical negotiation key last used by the sending end and the receiving end has expired; If it has not expired, use the target historical negotiation key as the negotiation key between the sending end and the receiving end; If it has expired, perform the operation of the sending end generating a first temporary public key and a first temporary private key for key negotiation.
6. The method for operating a consortium blockchain system according to claim 4, characterized in that The preset signature verification process includes: The receiving end searches in the consortium blockchain system for a key generation center node corresponding to the sending end identifier according to the sending end identifier, and determines the target key generation center node; If it exists, determine the target public key partial field corresponding to the sending end identifier through the target key generation center node according to the sending end identifier; the target public key partial field is the public key partial field generated by the target key generation center node using the key generation algorithm; Compare the target public key partial field with the public key partial field publicly disclosed by the sending end. If the comparison result is consistent, verify the signature sent by the sending end using the signature verification algorithm of the certificateless public key cryptosystem.
7. A device for operating a consortium blockchain system, characterized in that It includes: The key initialization module is used to perform key initialization of the certificateless public key cryptosystem for each node in the consortium blockchain system, so as to obtain a consortium blockchain system based on the certificateless public key cryptosystem; the consortium blockchain system includes multiple client nodes, multiple server nodes, and multiple key generation center nodes; The running environment construction module is used to construct a contract code running environment through the client nodes of the consortium blockchain system to implement smart contract invocation; The running environment construction module specifically includes: The simulation running environment construction unit is used to construct a simulation running environment of the target contract code through the client nodes according to the target characteristic parameters corresponding to the target contract code, and obtain the first transaction information based on the environment information corresponding to the simulation running environment and the target characteristic parameters; The simulation running environment activation unit is used to send the first transaction information to the server node according to a preset transaction process, and control the simulation running environment to take effect when it is detected that the locally newly saved block contains the first transaction information; The simulation modification unit is used to perform simulation modification on the simulation running environment through the client nodes, and obtain the second transaction information based on the environment parameters of the modified simulation running environment; The modified simulation running environment activation unit is used to send the second transaction information to the server node according to the preset transaction process, and control the modified simulation running environment to take effect when it is detected that the locally newly saved block contains the second transaction information, so as to implement smart contract invocation.
8. An electronic device, characterized in that, It includes: A memory for storing computer programs; A processor for executing the computer programs to implement the method for running the consortium blockchain system according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, For storing computer programs; wherein the computer programs, when executed by the processor, implement the method for running the consortium blockchain system according to any one of claims 1 to 6.
Citation Information
Patent Citations
Fabric alliance chain member identity management method based on certificateless authentication
CN111211905A