A PBFT Consensus Calculation Method Based on Proxy and Anonymity
By introducing proxy nodes and privacy protection mechanisms into the PBFT consensus algorithm, the problem of increased consensus time caused by the vulnerability of the master node and the inability to go online in time is solved, and the security and efficiency of the algorithm are improved.
Patent Information
- Application Number
- CN202210767699.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-01
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2042-07-01
AI Technical Summary
In the PBFT consensus algorithm, the main node is easily attacked and the node cannot be launched in time and increases the consensus time.
The PBFT consensus calculation method based on proxy and privacy protection is adopted to ensure that the node identity is anonymous and improve security through steps such as selecting the proxy node, verifying the proxy node public key, forming ring signatures, negotiating tags, verifying signatures and broadcasting commitment messages.
It improves the security and efficiency of the PBFT consensus algorithm, avoids the situation where malicious nodes attack the main node, reduces the communication complexity, and can complete the consensus process when the node cannot be online in time.
Smart Images

Figure CN115174196B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical fields of blockchain and cryptography, and discloses a PBFT consensus calculation method based on proxy and privacy protection. Background Art
[0002] As an important consensus algorithm, PBFT is currently widely used in consortium blockchains. Because PBFT has disadvantages such as large communication overhead and low security, more and more improvements have been made to PBFT. For example, SBFT uses threshold signatures to reduce communication overhead, and Honey Badger BFT uses reliable broadcast to improve security. USIG is proposed as a trusted counter in MinBFT. Using ring signatures to hide the primary node can improve the security of PBFT, but since all nodes do not know who the primary node is, they cannot directly attack the primary node, and nodes that cannot go online in time are regarded as malicious nodes. Summary of the Invention
[0003] The purpose of the present invention is to provide a PBFT consensus calculation method based on proxy and privacy protection to solve the problems that the primary node in PBFT is vulnerable to attacks and the consensus time increases due to nodes being unable to go online.
[0004] To solve the above problems, the specific technical solution of a PBFT consensus calculation method based on proxy and privacy protection of the present invention is as follows:
[0005] A PBFT consensus calculation method based on proxy and anonymity, comprising the following steps:
[0006] Step 1: Generate system parameters;
[0007] Step 2: Each node selects its own proxy node and sends authorization information;
[0008] Step 3: The node verifies the public key of the proxy node. After successful verification, the public key of the proxy node is added to the ring;
[0009] Step 4: The client sends the message m to all nodes;
[0010] Step 5: After receiving the message m, the primary node forms a pre-prepare message (Pre-Prepare, H(m), s, v, σ, L);
[0011] Step 6: The node and its proxy node negotiate a label;
[0012] Step 7: After other nodes or proxy nodes receive the pre-prepare message, they verify the message and signature and form a prepare message (Prepare, H(m), s, v, σ i );
[0013] Step 8: The node forms a commitment message (Commit, s, v, σ i , r i ) and broadcasts it. If the number of received commitment messages is greater than 2f + 1, then the message m is considered to have completed the commitment.
[0014] Furthermore, the said Step 1 includes the following specific steps:
[0015] Step 1.1: Given a group The order of this group is a prime number q;
[0016] Step 1.2: Let
[0017] Step 1.3: Each node randomly selects a private key Then the public key is Furthermore, the said Step 2 includes the following specific steps:
[0018] Step 2.1: For a node with private key x π and the corresponding public key y π , the node secretly and randomly selects an integer k s ∈ [1, q - 2], and (k s , q - 1) = 1, Sends the authorization information m s , SS and the public parameter r s to the proxy node, where,
[0019] Step 2.2: The proxy node verifies If the verification is successful, then the proxy node sends the public key y′ π , r′ s and SS′ = k′ s -1 (m s - r′ s x′ π ) to the node.
[0020] Furthermore, the said Step 3 includes the following specific steps:
[0021] Step 3.1: The node verifies If the authentication is successful, then it is considered that the public key of the proxy node is correct, and the authorization certificate is completed;
[0022] Step 3.2: The master node verifies the legality of the authorization certificates of all nodes and the proxy node. After the verification passes, it adds the public keys of the nodes and the proxy node to the public key list. Finally, the formed public key set of the ring is L = {y 1 , t 2 ,..., y n , y′1 , y' 2 ,..., y' n}。
[0023] Further, step 4 includes the following specific steps:
[0024] The client packs all the data generated in the block and forms a Merkle tree. The Merkle root, the previous block header, the timestamp and other information are packed to form a message m and sent to all nodes.
[0025] Further, step 5 includes the following specific steps:
[0026] Step 5.1: After receiving the message, the primary node assigns a sequence number s to this message and performs a ring signature on the message m;
[0027] Step 5.2: The primary node adds the public key list L = {y 1 , y 2 ,..., y n , y' 1 , y' 2 ,..., y' n} to the pre-prepared message;
[0028] Step 5.3: The primary node randomly selects and calculates
[0029] Step 5.4: For i = π + 1,..., n, 1,..., π - 1, select and calculate
[0030] Step 5.5: Calculate t π = u - (H(x π ) + H(x' π ))C π ;
[0031] Step 5.6: The primary node sends (Pre-Prepare, H(m), s, v, σ, L) to other nodes.
[0032] Further, step 6 includes the following specific steps:
[0033] After receiving the pre-prepared message, the node calculates h = H 2 (L), and sends to the proxy node. After receiving it, the proxy node decrypts it with its own private key to obtain The proxy node calculates and sends to the node, and the two form a unique tag
[0034] Further, step 7 includes the following specific steps:
[0035] Step 7.1: After other nodes receive the information, they verify the correctness of message m and verify the signature.
[0036] Step 7.2: For the signature, calculate h = H 2 (L);
[0037] Step 7.3: The node generates a tag and encrypts it and sends it to the proxy node;
[0038] Step 7.4: After the proxy node receives it, it decrypts it with its own private key to obtain The proxy node calculates and
[0039] sends it to the node;
[0040] Step 7.5: The two form a unique tag
[0041] Step 7.6: After other nodes receive the pre-prepared message, they verify the correctness of message m;
[0042] Step 7.7: The node verifies the correctness of signature σ, i = 1,..., n - 1, and calculates
[0043] Step 7.8: Judge If it holds, the verification passes;
[0044] Step 7.9: After the verification passes, the node will generate a prepare message (Prepare, H(m), s, v, σ i ), and broadcast the prepare message across the network, where t i = u - (H(x i ) + H(x′ i ))C i .
[0045] Further, step 8 includes the following specific steps:
[0046] Step 8.1: When the node forms a prepare credential, calculate the commit message (Commit, s, v, σ i , r i ), for the commit signature where k i is a random number randomly selected by each node, and ki Meet two conditions, k i ∈ [1, q - 2] and (k i , q - 1) = 1 and broadcast the commitment message, and at the same time the node writes the message m into the local log; Step 8.2: The node collects the commitment messages and verifies If the number of successfully verified commitment messages is greater than or equal to 2f + 1, then the commitment to the message is completed; each node returns its message indicating the completion of consensus to the client.
[0047] An PBFT consensus calculation method based on proxy and privacy protection is invented, which has the following advantages: In the present invention, the identity of each node is anonymous, and no malicious node can know which node is the primary node, thus avoiding the situation where malicious nodes attack the primary node and consensus cannot be completed, which greatly improves the security of the PBFT consensus algorithm. To a certain extent, the communication complexity is also reduced. And adding proxy nodes can further improve the efficiency of consensus. When nodes cannot go online in time, the PBFT process can also be completed. It also avoids the situation where these nodes are misidentified as malicious nodes. Therefore, the present invention improves the security and efficiency of PBFT consensus through proxy and privacy protection. Description of the Drawings
[0048] Figure 1 It is a flow block diagram of an PBFT consensus calculation method based on proxy and privacy protection of the present invention;
[0049] Figure 2 It is a process diagram of PBFT consensus based on proxy and privacy protection of the present invention. Detailed Embodiments
[0050] In order to better understand the purpose, structure and function of the present invention, the following further describes in detail an PBFT consensus calculation method based on proxy and privacy protection of the present invention with reference to the drawings.
[0051] As Figure 1 , Figure 2 shown, an PBFT consensus calculation method based on proxy and privacy protection of the present invention includes the following steps:
[0052] Step 1 Generate public parameters.
[0053] Step 1.1: Given a group The order of the group is a prime number q;
[0054] Step 1.2: Let
[0055] Step 1.3: Each node randomly selects a private key Then the public key is Step 2: The node selects its proxy node and sends authorization information.
[0056] Step 2.1: For a node with private key x π and corresponding public key y π , the node secretly and randomly selects an integer k s ∈[1,q - 2], and (k s ,q - 1) = 1, The authorization information m s , SS and the public parameter r s are sent to the proxy node. Among them,
[0057] Step 2.2: The proxy node verifies If the verification is successful, the proxy node will send the public key y′ π , r′ s and SS′ = k′ s -1 (m s - r′ s x′ π ) to the node.
[0058] Step 3: The node verifies the public key of the proxy node. After successful verification, the public key of the proxy node is added to the ring.
[0059] Step 3.1: The node verifies If the authentication is successful, it is considered that the public key of the proxy node is correct and the authorization certificate is completed.
[0060] Step 3.2: The master node verifies the legality of the authorization certificates of all nodes and the proxy node. After passing the verification, the public keys of the nodes and the proxy node are added to the public key list. Finally, the set of public keys forming the ring is L = {y 1 , y 2 ,..., y n , y′ 1 , y′ 2 ,..., y′ n}.
[0061] Step 4: The client sends the collected message m to all nodes.
[0062] The client packs all the data generated in the block and forms a Merkle tree. The Merkle root, the previous block header, the timestamp, etc. are packed to form the message m and sent to all nodes.
[0063] Step 5: After receiving the message m, the master node forms a pre - prepare message (Pre - Prepare, H(m), s, v, σ, L).
[0064] Step 5.1: After receiving the message, the primary node assigns a sequence number s to this message and performs a ring signature on the message m.
[0065] Step 5.2: The primary node adds the public key list L = {y 1 , y 2 ,..., y n , y′ 1 , y′ 2 ,..., y′ n} to the pre-prepare message.
[0066] Step 5.3: The primary node randomly selects and calculates
[0067] Step 5.4: For i = π + 1,..., n, 1,..., π - 1, select and calculate
[0068] Step 5.5: Calculate t π = u - (H(x π ) + H(x′ π ))G π ;
[0069] Step 5.6: The primary node sends (Pre-Prepare, H(m), s, v, σ, L) to other nodes.
[0070] Step 6 The node and its proxy node negotiate a label.
[0071] After receiving the pre-prepare message, the node calculates h = H 2 (L), and sends to the proxy node. After receiving it, the proxy node decrypts it with its own private key to obtain The proxy node calculates and sends to the node, and the two form a unique label Step 7 After receiving the pre-prepare message, other nodes (or proxy nodes) verify the message and signature and form a prepare message (Prepare, H(m), s, v, σ i ).
[0072] Step 7.1: After receiving the information, other nodes verify the correctness of the message m and verify the signature.
[0073] Step 7.2: For the signature, calculate h = H 2 (L);
[0074] Step 7.3: The node generates a label And encrypt and send it to the proxy node;
[0075] Step 7.4: After receiving it, the proxy node decrypts it with its own private key to obtain The proxy node calculates and Send it to the node;
[0076] Step 7.5: The two form a unique tag
[0077] Step 7.6: After other nodes receive the pre-prepared message, verify the correctness of the message m;
[0078] Step 7.7: The node verifies the correctness of the signature σ, i = 1,..., n - 1, and calculates
[0079] Step 7.8: Judge If it holds, the verification passes;
[0080] Step 7.9: After the verification passes, the node will generate a prepare message (Prepare, H(m), s, v, σ i ), and broadcast the prepare message across the network. Where t i = u - (H(x i ) + H(x' i ))C i .
[0081] Step 8 The node forms a commit message (Commit, s, v, σ i , r i ) and broadcasts it. If the number of received commit messages is greater than 2f + 1, it is considered that the message m has completed the commitment.
[0082] Step 8.1: When the node forms a prepare credential, calculate the commit message (Commit, s, v, σ i , r i ). For the commit signature Where k i is a random number randomly selected by each node, and k i satisfies two conditions, k i ∈ [1, q - 2] and (k i , q - 1) = 1 and broadcast the commit message. At the same time, the node writes the message m into the local log;
[0083] Step 8.2: The node collects the commit messages and verifies If the number of successfully verified commitment messages is greater than or equal to 2f + 1, the commitment to the messages is completed; each node returns its message indicating the completion of consensus to the client.
[0084] It can be understood that the present invention is described through some embodiments. Those skilled in the art will know that, without departing from the spirit and scope of the present invention, various changes or equivalent replacements can be made to these features and embodiments. Additionally, under the teachings of the present invention, these features and embodiments can be modified to adapt to specific situations and materials without departing from the spirit and scope of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed herein, and all embodiments falling within the scope of the claims of this application belong to the scope protected by the present invention.
Claims
1. A PBFT consensus calculation method based on proxy and anonymity, characterized in that, it includes the following steps: Step 1: Generate system parameters; Step 1.1: Given a group The order of the group is a prime number q; Step 1.2: Let Step 1.3: Each node randomly selects a private key The public key is then Step 2: Each node selects its own proxy node and sends authorization information; Step 2.1: For a node with private key x π and corresponding public key y π , the node secretly and randomly selects an integer k s ∈[1, q - 2], and (k s , q - 1) = 1, Send the authorization information m s , SS and the public parameter r s to the proxy node, where, Step 2.2: Agent Node Verification If the verification is successful, the agent node will send the public key y′ π , r′ s and SS′ = k′ s -1 (m s - r′ s x′ π ) to the node; Step 3: The node verifies the public key of the proxy node. After successful verification, the public key of the proxy node is added to the ring; Step 3.1: Node Verification If the authentication is successful, the public key of the proxy node is considered correct, and the authorization certificate is completed; Step 3.2: The master node verifies the legality of the authorization certificates of all nodes and proxy nodes. After the verification passes, the public keys of the nodes and proxy nodes are added to the public key list. Finally, the public key set of the ring is formed as L = {y 1 , y 2 ,..., y n , y′ 1 , y′ 2 ,..., y′ n}; Step 4: The client sends the message m to all nodes; Step 5: After receiving the message m, the primary node forms a pre-prepare message (Pre-Prepare, H(m), s, v, σ, L); Step 5.1: After the primary node receives the message, assign a sequence number s to this message and perform a ring signature on the message m; Step 5.2: The primary node adds the set of public keys of the ring L = {y 1 , y 2 ,..., y n , y' 1 , y' 2 ,..., y' n} to the pre-prepared message; Step 5.3: The master node randomly selects and calculates Step 5.4: For i = π + 1,..., n, 1,..., π - 1, select and calculate Step 5.5: Calculate t π = u - (H(x π ) + H(x' π ))C π ; Step 5.6: The primary node sends (Pre-Prepare, H(m), s, v, σ, L) to other nodes; Step 6: The node negotiates a label with its own proxy node; After receiving the pre-preparation message, the node calculates h = H 2 (L), and sends to the proxy node. After receiving it, the proxy node decrypts it with its own private key to obtain The proxy node calculates and sends to the node, and the two form a unique label Step 7: After receiving the pre-prepare message, other nodes or proxy nodes verify the message and the signature, and form a prepare message (Prepare, H(m), s, v, σ i ); Step 7.1: After receiving the information, other nodes verify the correctness of the message m and verify the signature; Step 7.2: For the signature, calculate h = H 2 (L); Step 7.3: The node generates a label and encrypts it and sends it to the proxy node; Step 7.4: After receiving it, the proxy node decrypts it with its own private key to obtain The proxy node calculates and sends it to the node; Step 7.5: The two form a unique label Step 7.6: After receiving the pre-prepare message, other nodes verify the correctness of the message m; Step 7.7: The node verifies the correctness of the signature σ, for i = 1,..., n - 1, calculate Step 7.8: Determine If it holds, the verification passes; Step 7.9: After successful verification, the node will generate a prepare message (Prepare, H(m), s, v, σ i ), and broadcast the prepare message across the network, where Step 8: The node forms a commitment message (Commit, s, v, σ i , r i ) and broadcasts it. If the number of received commitment messages is greater than 2f + 1, it is considered that the message m completes the commitment; Step 8.1: When a node forms a preparation voucher, calculate the commitment message (Commit, s, v, σ i , r i ), for the commitment signature where k i is an integer randomly selected for each node, and k i satisfies two conditions, k i ∈ [1, q - 2] and (k i , q - 1) = 1 and broadcast the commitment message, and at the same time the node writes the message m to the local log; Step 8.2: The node collects the commitment messages and verifies If the number of successfully verified commitment messages is greater than or equal to 2f + 1, the commitment to the messages is completed; each node returns its message indicating the completion of consensus to the client.
2. The PBFT consensus calculation method based on proxy and anonymity according to claim 1, characterized in that, the specific steps of step 4 include: The client packs all the data generated in the block and forms a Merkle tree. The Merkle root, the previous block header, and the timestamp information are packed to form the message m and sent to all nodes.
Citation Information
Patent Citations
Block chain network service platform, authority hosting method thereof and storage medium
CN111294379A