Cross-chain security assurance method, computer equipment and storage medium

Register with the security service node through the repeater and compare event information, the problem of repeater subscription error information is solved, and the security and stability of the cross-chain solution are achieved.

CN115221552BActive Publication Date: 2025-08-29HANGZHOU FUZAMEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210800189.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-06
Publication Date
2025-08-29
Estimated Expiration
2042-07-06

AI Technical Summary

Technical Problem

When repeaters perform cross-chain operations on blockchain, they subscribe to incorrect event information due to node instability or malicious fraud, which affects the security and stability of the cross-chain solution.

Method used

The repeater registers the node and event information it subscribes to the security service node. The security service node subscribes to the same event information to multiple blockchain nodes and compares it. If the comparison results are inconsistent, a warning message will be sent to the repeater, and the repeater will perform corresponding security operations.

Benefits of technology

It ensures that the repeater can receive warning messages when subscribe to the wrong event information, realizing the security and stability of the cross-chain solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115221552B_ABST
    Figure CN115221552B_ABST
Patent Text Reader

Abstract

The present invention provides a cross-chain security assurance method, computer device, and storage medium. The method includes: registering with a security service node, registering a first node, first event information, a second node, and second event information subscribed by the current relay; in response to receiving a first warning message, deleting the first event information at a first block height, changing the subscribed first node to a third node, and changing the first node registered with the security service node to the third node; in response to receiving a second warning message, deleting the second event information at a second block height, changing the subscribed second node to a fourth node, and changing the second node registered with the security service node to the fourth node. The present invention ensures the security and stability of the cross-chain solution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of blockchain technology, and specifically to a cross-chain security assurance method, computer equipment, and storage medium. Background Art

[0002] When performing cross-chain operations, the repeater needs to subscribe to event messages from the nodes of the first blockchain and the nodes of the second blockchain at the same time, and also needs to send relay transactions to the nodes of the first blockchain and the nodes of the second blockchain respectively.

[0003] When the blockchain node subscribed by the relayer is unstable or the controlling party commits malicious fraud, resulting in the relayer subscribing to incorrect event information, it will affect the security and stability of the cross-chain solution. Summary of the Invention

[0004] In view of the above-mentioned defects or deficiencies in the prior art, it is desired to provide a cross-chain security assurance method, computer device and storage medium that ensure the security and stability of cross-chain solutions.

[0005] In a first aspect, the present invention provides a cross-chain security assurance method applicable to a repeater, wherein the repeater is configured for cross-chain between a first blockchain and a second blockchain, and the repeater is configured to subscribe to first event information for cross-chain from a first node of the first blockchain and to subscribe to second event information for cross-chain from a second node of the second blockchain. The method comprises:

[0006] Register with the security service node, register the first node, first event information, second node, and second event information subscribed by the current relay, for the security service node:

[0007] Subscribe first event information to multiple nodes of a first blockchain including the first node;

[0008] subscribing to second event information from a plurality of nodes of a second blockchain including the second node;

[0009] Comparing whether the first event information of the first block height obtained from the plurality of nodes of the first blockchain are consistent: if not, sending a first warning message to the current repeater;

[0010] Comparing whether the second event information of the second block height obtained from the plurality of nodes of the second blockchain are consistent: if not, sending a second warning message to the current repeater;

[0011] In response to receiving the first warning message, deleting the first event information at the first block height, changing the subscribed first node to a third node, and changing the first node registered with the security service node to a third node;

[0012] In response to receiving the second warning message, the second event information of the second block height is deleted, the subscribed second node is modified to the fourth node, and the second node registered with the security service node is modified to the fourth node.

[0013] In a second aspect, the present invention provides a cross-chain security assurance method applicable to a security service node, wherein the security service node is used to provide security services for a repeater, the repeater is configured for cross-chain between a first blockchain and a second blockchain, and the repeater is configured to subscribe to first event information for cross-chain from a first node of the first blockchain and to subscribe to second event information for cross-chain from a second node of the second blockchain. The method includes:

[0014] Accept the registration of the first repeater, and obtain the first node, first event information, second node, and second event information subscribed by the first repeater;

[0015] Subscribe first event information to multiple nodes of a first blockchain including the first node;

[0016] subscribing to second event information from a plurality of nodes of a second blockchain including the second node;

[0017] Comparing whether the first event information of the first block height obtained by subscription from multiple nodes of the first blockchain is consistent: if not, sending a first warning message to the first repeater, so that the first repeater can delete the first event information of the first block height, change the subscribed first node to the third node, and change the registered first node to the third node;

[0018] Compare whether the second event information of the second block height obtained by subscription from multiple nodes of the second blockchain are consistent: if not, send a second warning message to the first repeater, so that the first repeater can delete the second event information of the second block height, change the subscribed second node to the fourth node, and change the registered second node to the fourth node.

[0019] In a third aspect, the present invention also provides a computer device comprising one or more processors and a memory, wherein the memory contains instructions executable by the one or more processors so that the one or more processors execute the cross-chain security assurance method provided according to various embodiments of the present invention.

[0020] In a fourth aspect, the present invention also provides a storage medium storing a computer program, which enables a computer to execute the cross-chain security assurance method provided according to various embodiments of the present invention.

[0021] The cross-chain security assurance method, computer device and storage medium provided by many embodiments of the present invention are achieved by having the repeater register the nodes and event information it subscribes to with the security service node, and then the security service node subscribes to the same event information from multiple different blockchain nodes and compares them, and sends a warning message to the repeater when the comparison results are inconsistent. This ensures that the repeater can receive a warning message and perform corresponding security operations when it subscribes to incorrect event information, thereby ensuring the security and stability of the cross-chain solution. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Other features, objects and advantages of the present application will become more apparent upon reading the detailed description of non-limiting embodiments made with reference to the following drawings:

[0023] Figure 1 A flowchart of a cross-chain security assurance method provided by one embodiment of the present invention.

[0024] Figure 2 A flowchart of another cross-chain security assurance method provided by one embodiment of the present invention.

[0025] Figure 3 A schematic diagram of the structure of a computer device provided in one embodiment of the present invention. DETAILED DESCRIPTION

[0026] The present application will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the relevant invention and are not intended to limit the invention. It should also be noted that, for ease of description, only portions relevant to the invention are shown in the accompanying drawings.

[0027] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0028] Figure 1 A flowchart of a cross-chain security assurance method provided by one embodiment of the present invention.

[0029] like Figure 1 As shown, in this embodiment, the present invention provides a cross-chain security assurance method applicable to a repeater, wherein the repeater is configured for cross-chain between a first blockchain and a second blockchain, and the repeater is configured to subscribe to first event information for cross-chain from a first node of the first blockchain, and to subscribe to second event information for cross-chain from a second node of the second blockchain. The method includes:

[0030] S11: Register with the security service node to register the first node, first event information, second node, and second event information subscribed by the current relay, for the security service node:

[0031] Subscribe first event information to multiple nodes of a first blockchain including the first node;

[0032] subscribing to second event information from a plurality of nodes of a second blockchain including the second node;

[0033] Comparing whether the first event information of the first block height obtained from the plurality of nodes of the first blockchain are consistent: if not, sending a first warning message to the current repeater;

[0034] Comparing whether the second event information of the second block height obtained from the plurality of nodes of the second blockchain are consistent: if not, sending a second warning message to the current repeater;

[0035] S13: In response to receiving the first warning message, deleting the first event information at the first block height, changing the subscribed first node to the third node, and changing the first node registered with the security service node to the third node;

[0036] S15: In response to receiving the second warning message, the second event information of the second block height is deleted, the subscribed second node is changed to the fourth node, and the second node registered with the security service node is changed to the fourth node.

[0037] The following example uses the deployment of relay x1 for cross-chain between blockchain A and blockchain B, and security service node y providing security services for relay x1. Figure 1 The method shown is explained by way of example.

[0038] In execution Figure 1 Before the method shown, the relay x1 is configured to subscribe to the first event information of the first cross-chain contract from the node a1 of the blockchain A, and to subscribe to the second event information of the second cross-chain contract from the node b1 of the blockchain B.

[0039] Specifically, the first event information may include information such as whether the first cross-chain transaction executed through the first cross-chain contract was successfully executed, several parameters of the first cross-chain transaction, and other information. The second event information may include information such as whether the second cross-chain transaction executed through the second cross-chain contract was successfully executed, several parameters of the second cross-chain transaction, and other information. Those skilled in the art will appreciate that the specific content of the first and second event information is determined by the cross-chain solution and may include different specific content in different cross-chain solutions.

[0040] In step S11 , the repeater x1 registers with the security service node y, and registers the first node a1 , the first event information e1 , the second node b1 , and the second event information e2 to which the current repeater subscribes.

[0041] After the security service node y successfully registers with relay x1, it subscribes to the following information based on the information registered by relay x1:

[0042] Subscribe to first event information e1 from multiple nodes (e.g., nodes a1-a7) of a first blockchain including a first node a1;

[0043] Second event information e2 is subscribed to a plurality of nodes (for example, nodes b1-b7) of the second blockchain including the second node b1.

[0044] When the security service node y subscribes to obtain the first event information e1 at the first block height h1 a1 -e1 a7 After that, the security service node y compares the first event information e1 a1 -e1 a7 Is it consistent?

[0045] If not, a first warning message is sent to the repeater x1.

[0046] Specifically, in each first event information e1 a1 -e1 a7 When the comparison results are consistent, the first confirmation information may be sent to the repeater x1, or it may not be sent; accordingly, after receiving the first confirmation information, the repeater x1 may respond to the subscribed first event information e1 a1 Send relay transaction, or, according to other strategies (for example, the security block height confirmation regularly pushed by security service node y as described below, etc.), according to the subscribed first event information e1 a1 Send relay transaction.

[0047] Similarly, when security service node y subscribes to obtain the second event information e2 at the second block height h2 b1 -e2 b7 After that, the security service node y compares each second event information e2 b1 -e2 b7 Is it consistent?

[0048] If not, a second warning message is sent to the repeater x1.

[0049] In step S13, in response to receiving the first warning message, the repeater x1 deletes the first event information e1 of the first block height h1. a1 , change the subscribed first node a1 to the third node a9, and change the first node a1 registered with the security service node y to the third node a9.

[0050] In step S15, in response to receiving the second warning message, the repeater x1 deletes the second event information e2 of the second block height h2. b1, change the subscribed second node b1 to the fourth node b5, and change the second node b1 registered with the security service node y to the fourth node b5.

[0051] In a preferred embodiment, the security service node is further configured to:

[0052] Maintaining the first security block height consistent with the comparison results of each first event information and the second security block height consistent with the comparison results of each second event information; and

[0053] Regularly push the first safety block height and the second safety block height to the current repeater.

[0054] Step S13 further includes:

[0055] suspend processing of the first event information at the first block height; and

[0056] Determine whether the received first security block height is not less than the first block height: if yes, resume processing the first event information of the first block height.

[0057] Step S15 further includes:

[0058] suspending processing of the second event information at the second block height; and

[0059] Determine whether the received second security block height is not less than the second block height: if yes, resume processing the second event information of the second block height.

[0060] Specifically, in this preferred embodiment, for example, at the block height h1, each first event information e1 a1 -e1 a7 The comparison results are inconsistent, and the security service node y sends a first warning message to the repeater x1; then:

[0061] After receiving the first warning message, relayer x1 suspends processing the first event message at block height h1.

[0062] Security service node y continues to subscribe to the first event information of block height h1 and compares them until the comparison results are consistent.

[0063] Before the comparison results are consistent, the first security block height that security service node y regularly pushes to relay x1 is obviously less than h1. Relay x1 will not resume processing the first event information of block height h1.

[0064] After the comparison results are consistent, the security service node y modifies the first security block height to h1 and pushes it to the repeater x1 at a regular interval. After the repeater x1 determines that the received first security block height is not less than the first block height h1, it resumes processing the first event information of the first block height h1.

[0065] In a preferred embodiment, the security service node is further configured to maintain a first blockchain trusted node list based on the comparison of each first event information, and maintain a second blockchain trusted node list based on the comparison of each second event information;

[0066] Step S13 further includes: selecting a third node from the first blockchain trusted node list;

[0067] Step S15 also includes: selecting a fourth node from the second blockchain trusted node list.

[0068] Specifically, when a blockchain node provides incorrect event information to a relayer due to malicious fraud by the controlling party, the incorrect event information will obviously be directly identified in the comparison of the event information. Therefore, the security service node can maintain and provide a list of trusted nodes.

[0069] In a preferred embodiment, the security service node is further configured to verify the authenticity of the time information.

[0070] In the above embodiments, the repeater registers the subscribed nodes and event information with the security service node, and the security service node then subscribes to the same event information from multiple different blockchain nodes and compares them, and sends a warning message to the repeater when the comparison results are inconsistent. This ensures that the repeater can receive a warning message and perform corresponding security operations when it subscribes to incorrect event information, thereby ensuring the security and stability of the cross-chain solution.

[0071] Figure 2 A flowchart of another cross-chain security assurance method provided by one embodiment of the present invention. Figure 2 The method shown can be used with Figure 1 The method shown is executed.

[0072] like Figure 2 As shown, in this embodiment, the present invention also provides a cross-chain security assurance method applicable to a security service node, the security service node is used to provide security services for a repeater, the repeater is configured for cross-chain between a first blockchain and a second blockchain, the repeater is configured to subscribe to first event information for cross-chain from a first node of the first blockchain, and to subscribe to second event information for cross-chain from a second node of the second blockchain. The method includes:

[0073] S21: accepting the registration of the first repeater, and obtaining the first node, first event information, second node, and second event information subscribed by the first repeater;

[0074] S23: Subscribe to first event information from multiple nodes of the first blockchain including the first node;

[0075] S25: Subscribe to second event information from multiple nodes of the second blockchain including the second node;

[0076] S27: Compare the first event information of the first block height obtained by subscription from multiple nodes of the first blockchain to see if they are consistent. If not, send a first warning message to the first repeater, so that the first repeater can delete the first event information of the first block height, change the subscribed first node to the third node, and change the registered first node to the third node.

[0077] S29: Compare whether the second event information of the second block height obtained by subscription from multiple nodes of the second blockchain are consistent: if not, send a second warning message to the first repeater, so that the first repeater can delete the second event information of the second block height, change the subscribed second node to the fourth node, and change the registered second node to the fourth node.

[0078] Preferably, the above method further comprises:

[0079] Maintaining the first security block height for each first event information comparison result and the second security block height for each second event information comparison result;

[0080] Regularly push the first safety block height and the second safety block height to the first repeater;

[0081] The first repeater is further configured to:

[0082] After receiving the first warning message, the processing of the first event information of the first block height is suspended.

[0083] Determine whether the received first security block height is not less than the first block height: if yes, resume processing the first event information of the first block height;

[0084] as well as,

[0085] After receiving the second warning message, the processing of the second event information of the second block height is suspended.

[0086] Determine whether the received second security block height is not less than the second block height: if yes, resume processing the second event information of the second block height.

[0087] Preferably, the above method further comprises:

[0088] Maintaining a first blockchain trusted node list based on the comparison of each first event information, and maintaining a second blockchain trusted node list based on the comparison of each second event information;

[0089] The step of modifying the subscribed first node to the third node further includes: selecting the third node from the first blockchain trusted node list;

[0090] The above-mentioned modification of the subscribed second node to the fourth node also includes: selecting the fourth node from the second blockchain trusted node list.

[0091] Preferably, the security service node is further configured to verify the authenticity of the time information.

[0092] Figure 3 A schematic diagram of the structure of a computer device provided in one embodiment of the present invention.

[0093] like Figure 3 As shown, as another aspect, the present application also provides a computer device, including one or more central processing units (CPUs) 301, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 302 or programs loaded from a storage portion 308 into a random access memory (RAM) 303. Various programs and data required for the operation of the device 300 are also stored in the RAM 303. The CPU 301, ROM 302, and RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0094] The following components are connected to the I / O interface 305: an input section 306 including a keyboard, a mouse, and the like; an output section 307 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 308 including a hard disk; and a communication section 309 including a network interface card such as a LAN card or a modem. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as needed. Removable media 311, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 310 as needed, so that computer programs read therefrom can be installed into the storage section 308 as needed.

[0095] In particular, according to embodiments of the present disclosure, the methods described in any of the above embodiments can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product comprising a computer program tangibly embodied on a machine-readable medium, the computer program comprising program code for executing any of the above methods. In such embodiments, the computer program can be downloaded and installed from a network via the communication portion 309 and / or installed from the removable medium 311.

[0096] As another aspect, the present application further provides a computer-readable storage medium, which may be the computer-readable storage medium included in the apparatus of the above-described embodiment; or a computer-readable storage medium that exists independently and is not incorporated into the apparatus. The computer-readable storage medium stores one or more programs, which are used by one or more processors to execute the methods described in the present application.

[0097] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present invention. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the prescribed logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the prescribed function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0098] The units or modules described in the embodiments of the present application may be implemented in software or hardware. The units or modules described may also be provided in a processor. For example, each unit may be a software program provided in a computer or mobile smart device, or a separately configured hardware device. The names of these units or modules do not, in certain circumstances, constitute limitations on the units or modules themselves.

[0099] The above description is merely a preferred embodiment of the present application and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also encompasses other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the concept of this application. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this application.

Claims

1. A cross-chain security assurance method, characterized in that: The method is applicable to a repeater, wherein the repeater is configured for cross-chain communication between a first blockchain and a second blockchain, and the repeater is configured to subscribe to first event information for the cross-chain communication from a first node of the first blockchain and to subscribe to second event information for the cross-chain communication from a second node of the second blockchain. The method includes: Register with a security service node to register the first node, the first event information, the second node, and the second event information subscribed by the current repeater, for the security service node: subscribing to the first event information from a plurality of nodes of the first blockchain including the first node; subscribing to the second event information from a plurality of nodes of the second blockchain including the second node; Comparing whether the first event information at the first block height obtained from the plurality of nodes of the first blockchain are consistent: if not, sending a first warning message to the current repeater; Comparing whether the second event information of the second block height obtained from the plurality of nodes of the second blockchain are consistent: if not, sending a second warning message to the current repeater; In response to receiving the first warning information, deleting the first event information of the first block height, changing the subscribed first node to a third node, and changing the first node registered with the security service node to the third node; In response to receiving the second warning information, the second event information of the second block height is deleted, the subscribed second node is modified to the fourth node, and the second node registered with the security service node is modified to the fourth node.

2. The method according to claim 1, characterized in that The security service node is further configured to: Maintaining respectively the first security block height corresponding to the comparison results of each of the first event information and the second security block height corresponding to the comparison results of each of the second event information; as well as, Regularly push the first security block height and the second security block height to the current repeater; In response to receiving the first warning information, deleting the first event information of the first block height, changing the subscribed first node to a third node, and changing the first node registered with the security service node to the third node further includes: suspending processing of the first event information at the first block height; and Determine whether the received first security block height is not less than the first block height: if yes, resume processing the first event information of the first block height; In response to receiving the second warning information, deleting the second event information of the second block height, changing the subscribed second node to the fourth node, and changing the second node registered with the security service node to the fourth node further includes: suspending processing of the second event information at the second block height; and Determine whether the received second security block height is not less than the second block height: if yes, resume processing the second event information of the second block height.

3. The method according to claim 1, characterized in that The security service node is further configured to maintain a first blockchain trusted node list based on the comparison of each first event information, and maintain a second blockchain trusted node list based on the comparison of each second event information; Modifying the subscribed first node to a third node further includes: selecting a third node from the first blockchain trusted node list; Modifying the subscribed second node to a fourth node also includes: selecting a fourth node from the second blockchain trusted node list.

4. A cross-chain security assurance method, characterized in that: The method is applicable to a security service node, the security service node is used to provide security services for a relay, the relay is configured for cross-chain between a first blockchain and a second blockchain, the relay is configured to subscribe to first event information for the cross-chain from a first node of the first blockchain, and to subscribe to second event information for the cross-chain from a second node of the second blockchain, the method comprising: Accepting registration of the first repeater, and obtaining the first node, the first event information, the second node, and the second event information subscribed by the first repeater; subscribing to the first event information from a plurality of nodes of the first blockchain including the first node; subscribing to the second event information from a plurality of nodes of the second blockchain including the second node; Comparing whether the first event information of the first block height subscribed to and obtained from multiple nodes of the first blockchain are consistent: if not, sending a first warning message to the first repeater, so that the first repeater can delete the first event information of the first block height, change the subscribed first node to a third node, and change the registered first node to the third node; Compare whether the second event information of the second block height subscribed from multiple nodes of the second blockchain are consistent: if not, send a second warning message to the first repeater, so that the first repeater can delete the second event information of the second block height, change the subscribed second node to the fourth node, and change the registered second node to the fourth node.

5. The method according to claim 4, characterized in that The method further comprises: Maintaining respectively the first security block height corresponding to the comparison results of each of the first event information and the second security block height corresponding to the comparison results of each of the second event information; Pushing the first security block height and the second security block height to the first repeater at a regular interval; The first repeater is further configured to: After receiving the first warning message, suspend processing the first event information of the first block height, Determine whether the received first security block height is not less than the first block height: if yes, resume processing the first event information of the first block height; as well as, After receiving the second warning message, suspend processing the second event information of the second block height, Determine whether the received second security block height is not less than the second block height: if yes, resume processing the second event information of the second block height.

6. The method according to claim 4, characterized in that The method further comprises: Maintaining a first blockchain trusted node list based on the comparison of each of the first event information, and maintaining a second blockchain trusted node list based on the comparison of each of the second event information; Modifying the subscribed first node to a third node further includes: selecting a third node from the first blockchain trusted node list; Modifying the subscribed second node to a fourth node also includes: selecting a fourth node from the second blockchain trusted node list.

7. A computer device, characterized in that: The device comprises: one or more processors; a memory for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors are caused to perform the method according to any one of claims 1 to 6.

8. A storage medium storing a computer program, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Cross-data-block data access method, apparatus and system, and computer readable medium

    CN108366105A

  • Systems and methods for Anti-money laundering compliance via blockchain

    US20210342828A1