A Reputation-Based Consensus Method
By updating the credibility of nodes in the blockchain consensus mechanism and using the Byzantine broadcast protocol and timer mechanism to detect and punish malicious behaviors, the problem of insufficient resistance to Byzantine attacks in the existing technology is solved, and effective resistance to flash attacks and the stability of the consensus process is achieved.
Patent Information
- Application Number
- CN202210945815.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-08
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-08-08
AI Technical Summary
The existing reputation-based consensus mechanism fails to effectively resist flash attacks when facing Byzantine attacks and fails to clearly define behaviors to increase or decrease node reputation, resulting in high complexity and insufficient security in protocol communication.
By updating the node's reputation at the beginning of each round, using the Byzantine Broadcasting Protocol and Timer Mechanism, detecting and punishing malicious behaviors, praising benign behaviors, and combining the slow value-added reputation function design, ensuring the voting weight decision of honest nodes and resisting flash attacks.
Effectively resist flash attacks, reduce the credibility of malicious nodes, improve the credibility of honest nodes, ensure the security and reliability of the consensus process, and maintain system stability especially when honest nodes are no longer the majority.
Smart Images

Figure CN115714649B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of blockchain, and specifically relates to a consensus method based on credibility. Background Art
[0002] Blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm. Briefly speaking, blockchain is a decentralized, tamper-proof, traceable, and multi-party jointly maintained distributed database, which can integrate multiple isolated databases that are only related to its own business and are maintained unilaterally in the past, and store them distributively on multiple nodes jointly maintained by multiple parties. No party can completely control these data, and can only update them according to strict rules and consensus, thereby realizing trusted multi-party information sharing and supervision, avoiding cumbersome manual account reconciliation, improving business processing efficiency, and reducing transaction costs.
[0003] Blockchain can be simplified and abstracted into a five-layer technical architecture according to its core technology, namely the data layer, the incentive layer, the contract layer, the consensus layer, and the application layer; among them, the consensus layer encapsulates various consensus mechanisms for determining the accounting decision-making method, which is related to the security and reliability of the entire system. The SMR (Replicated State Machine) protocol is a type of protocol in the consensus mechanism, which allows a group of nodes to jointly maintain a consistent ledger, even when a certain proportion of nodes are Byzantine.
[0004] In related technologies, Guru proposed a credibility mechanism for SMR. This protocol assigns nodes with credibility according to the behavior of the nodes, and selects a subset of nodes, that is, a committee, according to the credibility of the nodes to execute the consensus. RepuCoin is another SMR protocol based on credibility. Nodes elect leaders and committees by solving the proof-of-work (PoW) puzzle, and the elected committee votes to determine the proposed block. Similar to Guru, RepuCoin mainly focuses on the scalability of the protocol and ignores the definition of behaviors that affect credibility and the behavior of the credibility mechanism.
[0005] Although the above two protocols focus on the committee election mechanism that reduces the protocol communication complexity, they omit the definition of behaviors that increase or decrease the reputation of nodes and the necessary security attributes of such a reputation mechanism. In addition, Guru and RepuCoin study the anti-flash attack ability provided by the reputation mechanism through simulation rather than formal proof, so they cannot show guarantees under all protocol parameters. Summary of the Invention
[0006] In order to solve the above problems existing in the prior art, the present invention provides a consensus method based on credibility. The technical problems to be solved by the present invention are realized through the following technical solutions:
[0007] The present invention provides a consensus method based on credibility, including:
[0008] In the current round, update the credibility of each node and start a timer;
[0009] Determine the leader p from the above nodes L ;
[0010] On the block B proposed by the leader p L Trigger the Byzantine broadcast protocol, so that non-leader nodes follow the Byzantine broadcast protocol to broadcast the block B and vote on the block B;
[0011] When the timer reaches the preset time, node p j Determine the first block proposed by the leader and update the local set according to the signatures involved in the first block.
[0012] In an embodiment of the present invention, after the step of triggering the Byzantine broadcast protocol on the block B proposed by the leader p L so that non-leader nodes follow the Byzantine broadcast protocol to broadcast the block B and vote on the block B, it further includes:
[0013] Judge whether node p j itself receives evidence of misbehavior from the leader or non-leader nodes;
[0014] If so, according to the evidence of misbehavior, further judge whether the misbehavior includes ambiguous block proposal behavior or withholding block proposal behavior.
[0015] In an embodiment of the present invention, if the misbehavior includes ambiguous block proposal behavior or withholding block proposal behavior, the step of node p j determining the first block proposed by the leader and updating the local set according to the signatures involved in the first block includes:
[0016] Node p j Broadcast the misbehavior so that all nodes reach a consensus on the misbehavior;
[0017] When the timer reaches the preset time, node p j Take the empty block ⊥ as the first block proposed by the leader p L and update the local set according to the signatures involved in the first block.
[0018] In an embodiment of the present invention, if the misbehavior includes ambiguous block proposal behavior, node p j takes the empty block ⊥ as the first block proposed by the leader p LAfter the step of proposing the first block and updating the local set according to the signatures involved in the first block, it further includes:
[0019] Node p i Record the disambiguated block B' proposed by the leader p L in its own proposal set M j and ignore all votes received in the current round.
[0020] In an embodiment of the present invention, if the misbehavior includes withholding block proposal behavior, the node p j takes the empty block ⊥ as the first block proposed by the leader p L After the step of proposing the first block and updating the local set according to the signatures involved in the first block, it further includes:
[0021] Node p i Record an empty block ⊥ in its own proposal set M j and ignore all votes received in the current round.
[0022] In an embodiment of the present invention, if the misbehavior does not include disambiguated block proposal behavior or withholding block proposal behavior, when the timer reaches the preset time, the node p j The steps of determining the first block proposed by the leader and updating the local set according to the signatures involved in the first block include:
[0023] Node p j Broadcast the misbehavior so that all nodes reach a consensus on the misbehavior;
[0024] When the timer reaches the preset time, the node p j Takes the block B as the first block and updates the local set according to the signatures involved in the first block.
[0025] In an embodiment of the present invention, when the timer reaches the preset time, before the step of determining the first block proposed by the leader and updating the local set according to the signatures involved in the first block by the node p j it further includes:
[0026] Judge whether the credibility of the nodes corresponding to the signatures contained in the block B proposed by the leader p L is greater than 1 / 2 of the sum of the credibility of all nodes after that.
[0027] In an embodiment of the present invention, the steps of updating the credibility of each node and starting the timer in the current round include:
[0028] Obtain the proposal set M of the node p j in the previous roundj and the voting set V;
[0029] For node p j , through μ j ← f Rep (C, ε, pk j , M j , V) to update its reputation and start a timer, where f Rep (·) represents the reputation function, C represents the blockchain of the current round, ε represents the initial reputation of node p j , pk j represents the public key of node p j , M j represents the proposal set of node p j in the previous round, and V represents the voting set of node p j in the previous round.
[0030] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0031] The present invention provides a reputation-based consensus method. At the beginning of each round, the reputation of each node is updated through its historical behavior, so as to collect evidence against the malicious behavior of the majority of opponents, and punish it by reducing the node's reputation, and reward the benign behavior by increasing the node's reputation. When the number of honest nodes in the network is no longer the honest majority, the design method of combining the QC (quorum certificate) determined by the voting weight with the slowly increasing reputation function is beneficial to resist flash attacks.
[0032] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Description of the Drawings
[0033] Figure 1 is a flowchart of a reputation-based consensus method provided by an embodiment of the present invention;
[0034] Figure 2 is a schematic diagram of a reputation-based consensus method provided by an embodiment of the present invention. Detailed Embodiments
[0035] The present invention will be further described in detail below with reference to specific embodiments, but the embodiments of the present invention are not limited thereto.
[0036] A blockchain can generally be simplified and abstracted into a five - layer technical architecture, namely, the data layer, the incentive layer, the contract layer, the consensus layer, and the application layer. Among them, the data layer stores basic data such as underlying data, asymmetric data encryption, and timestamps. The incentive layer contains economic means used in the blockchain technology system, such as the issuance and distribution of economic incentives. The contract layer encapsulates the script code, algorithms, and smart contracts in the blockchain system to help the blockchain flexibly process data. The consensus layer encapsulates various consensus mechanisms to determine the way of accounting decisions, which is related to the security and reliability of the entire system. The application layer encapsulates various application scenarios and cases.
[0037] For the consensus layer of a certain blockchain, the present invention provides a consensus method based on credibility.
[0038] Figure 1 It is a flowchart of the consensus method based on credibility provided by the embodiments of the present invention. As Figure 1 shown, the embodiments of the present invention provide a consensus method based on credibility, including:
[0039] S1. In the current round, update the credibility of each node and start a timer;
[0040] S2. Determine the leader p from each node L ;
[0041] S3. Trigger the Byzantine broadcast protocol on the block B proposed by the leader p L . Non - leader nodes follow the Byzantine broadcast protocol to broadcast block B and vote on block B;
[0042] S4. When the timer reaches the preset time, node p j determines the first block proposed by the leader and updates the local set according to the signatures involved in the first block.
[0043] In the above step S2, according to the bias - resistant polling scheduling mechanism, all nodes can use the leader election function pk L ← f Led (PK, r, n) to elect the leader p L . Specifically, the input of the leader election function f Led (PK, r, n) → pk L includes: the set of public keys PK of all nodes, the current round number r, and the node scale n, and the output is the public key pk L ∈ PK, and the node corresponding to pk L is the leader p L .
[0044] In this embodiment, a certain node is selected as the leader p LAfter that, it will propose a block B and trigger the BB (Byzantine Broadcast) protocol on this block, that is, the leader broadcasts the block proposal, and non-leader nodes receive the block B from the leader p L After receiving the block B, non-leader nodes will follow the BB protocol, broadcast the block B and vote on it, and determine and commit the first block proposed by the leader when the timer Timer expires.
[0045] Figure 2 It is a schematic diagram of the reputation-based consensus method provided by an embodiment of the present invention. As Figure 2 shown, after triggering the Byzantine broadcast protocol on the block B proposed by the leader p L so that non-leader nodes follow the Byzantine broadcast protocol to broadcast the block B and vote on the block B, the following steps are further included:
[0046] Judge whether the node p j itself has received evidence of misbehavior from the leader or non-leader nodes;
[0047] If so, based on the evidence of misbehavior, further judge whether the misbehavior includes ambiguous block proposal behavior or withholding block proposal behavior.
[0048] In this embodiment, the delay of the BB protocol is 3Δ, and the delay of the timer Timer is 4Δ. Then it can be understood that when the timer consumes Δ, the block B sent by the leader p L only reaches one node, which means that when the timer consumes 2Δ, the block B sent by the leader p L has reached all nodes, and when the timer consumes 3Δ, the votes of any node p j have reached all nodes. Therefore, in this embodiment, the delay of the BB protocol is set to 3Δ. After the BB protocol is completed, each node broadcasts evidence to all other nodes respectively to reach a consensus on evidence collection.
[0049] Optionally, if the misbehavior includes ambiguous block proposal behavior or withholding block proposal behavior, the steps for the node p j to determine the first block proposed by the leader and update the local set according to the signatures involved in the first block include:
[0050] The node p j broadcasts the misbehavior so that all nodes reach a consensus on the misbehavior;
[0051] When the timer reaches the preset time, the node p j takes the empty block ⊥ as the first block proposed by the leader p L and updates the local set according to the signatures involved in the first block.
[0052] It should be noted that considering that the disambiguation voting and withholding voting behaviors cannot determine the accountability target and may bring higher communication complexity, the evidence collected in this embodiment is evidence of improper behaviors for which Byzantine nodes can be held accountable. Exemplarily, the improper behaviors include: malicious voting / block proposal behaviors, disambiguation block proposal behaviors, and withholding block proposal behaviors.
[0053] Further, for node p i The scenarios for broadcasting evidence of improper behaviors are as follows:
[0054] For malicious voting / block proposal behaviors, if node p i receives signature σ j , and the block B' associated with signature σ j ≠ B, then node p i will broadcast <Blame-Malicous-Vote, pk j , B', σ j > i to all the other nodes. Similarly, if node p i receives a block proposal, and the block proposal is sent by a non-leader node and accompanied by its signature σ j , then p i will broadcast <Blame-Malicous-Block, pk j , B', σ j > i to all the other nodes.
[0055] It should be understood that the above two malicious behaviors will not affect the normal process of the state machine replication protocol, because when the timer reaches the preset time, in the absence of the leader's withholding block proposal behavior and disambiguation block proposal behavior, honest nodes can still submit the block B proposed by the leader.
[0056] For disambiguation block proposal behaviors, if node p i receives two different block proposals, namely (B, B'), and accompanied by the signatures (σ, σ') of the leader p L , then p i will consider that there is a disambiguation block proposal behavior by the leader and broadcast <Blame-Block-Equivocation, pk L , B, B', σ, σ' > i to all the other nodes. Since the leader is a Byzantine node, node p i will submit an empty block ⊥ when the timer reaches the preset time.
[0057] [[ID=5i Before voting, if node p has not received the block B proposed by the leader, it means that all honest nodes have not received the block proposal from the leader, that is, the leader is withholding the block proposal. In this case, p i Submit an empty block ⊥ as the first block proposed by the leader when the timer reaches the preset time.
[0058] Please continue to refer to Figure 2 , if the misbehavior includes the behavior of obfuscating the block proposal, node p j uses the empty block ⊥ as the first block proposed by the leader p L After the step of updating the local set according to the signatures involved in the first block, it further includes:
[0059] Node p i records the obfuscated block B' proposed by the leader p L in its own proposal set M j and ignores all votes received in the current round.
[0060] Optionally, if the misbehavior includes the behavior of withholding the block proposal, node p j uses the empty block ⊥ as the first block proposed by the leader p L After the step of updating the local set according to the signatures involved in the first block, it further includes:
[0061] Node p i records an empty block ⊥ in its own proposal set M j and ignores all votes received in the current round.
[0062] Specifically, for malicious voting / block proposal behavior, if node p j receives evidence of a malicious proposal (vote) behavior, then node p j records it in the local proposal set M j ; for the behavior of obfuscating the block proposal, if node p j receives evidence of the behavior of obfuscating the block proposal, then p j records the obfuscated block in M j and ignores all votes received in this round; for the behavior of withholding the block proposal, if node p j does not receive the block B from the leader in the current round, then node p j will record an empty block ⊥ in M j and ignores all votes received in this round.
[0063] Optionally, if the misbehavior does not include the behavior of obfuscating the block proposal or the behavior of withholding the block proposal, in step S4 above, when the timer reaches the preset time, node pj The steps of determining the first block proposed by the leader and updating the local set according to the signatures involved in the first block include:
[0064] Node p j Broadcast the misbehavior so that all nodes reach a consensus on the misbehavior;
[0065] When the timer reaches the preset time, node p j Take block B as the first block and update the local set according to the signatures involved in the first block.
[0066] Optionally, before the step of when the timer reaches the preset time and node p j determines the first block proposed by the leader and updates the local set according to the signatures involved in the first block, further includes:
[0067] Judge whether the credibility of the nodes corresponding to the signatures included in the block B proposed by the leader p L is greater than 1 / 2 of the sum of the credibility of all nodes after that.
[0068] In this embodiment, still taking the case where the timer delay is 4Δ as an example, when the timer remains 2Δ, each node votes on the received block B, that is, signs and broadcasts the leader block hash. When the timer remains Δ, for any node p j , if the block hash proposed by the leader contains any number of signatures, and these signatures satisfy that the sum of the credibility of their corresponding nodes is 1 / 2 of the total credibility of all nodes in the current round (i.e., form a Quorum certificate), then for this node p j , the block B proposed by the leader obtains the qualification to be submitted, and then at the end of the timer, it is submitted by node p j .
[0069] Optionally, in the current round, the steps of updating the credibility of each node and starting the timer include:
[0070] Obtain the proposal set M j of node p j in the previous round and the voting set V;
[0071] For node p j , update its credibility and start the timer through μ j ←f Rep (C, ε, pk j , M j , V), where f Rep (·) represents the credibility function, C represents the blockchain in the current round, ε represents the initial credibility of node p j , pkj Denote the public key of node p j and the set of proposals M of node p j in the previous round j , and the set of votes V of node p j in the previous round.
[0072] In this embodiment, when the timer reaches the preset time, node p j updates the reputation of each node p by processing the set of proposals M j and the set of votes V of each node p j , and the reputation function f Rep (C, ε, pk j , M j , V j ) → μ j takes as input: the current ledger, i.e., the blockchain C, the initial reputation ε of node p j , the public key pk of node p j , the set of proposals M of node p j up to the current time j , and the set of votes V of node p j up to the previous time j , where μ j represents the reputation value of node p j , and ε is a negligible non-zero positive number, μ j . j∈[0,1] .
[0073] Specifically, for nodes with malicious voting behavior, their reputation will be reduced. For example, for any set tuple (V j , ), if compared with the set , the set V j collects more wrong votes regarding node p j , then f Rep (C, ε, pk j , M j , V j ) < f Rep (C, ε, pk j , M j , ); for nodes with ambiguity / withholding / malicious behavior in block proposals, their reputation will be reduced. For example, for any set tuple (M j , ), if compared with the set , if the set M j collects more ambiguous block proposals or malicious block proposals of node p j or fewer valid blocks in the ledger C, then f Rep(C, ε, pk j , M j , V j ) < f Rep (C, ε, pk j , V j ); For nodes that vote honestly, their reputation will be increased. For example, for any set tuple (V j , ), if compared to the set , the set V j collects more votes regarding the node p j , then f Rep (C, ε, pk j , M j , V j ) > f Rep (C, ε, pk j , M j , ); For nodes that propose honest blocks, their reputation will be increased. For example, for any set tuple (M j , ), if compared to the set , the set M j collects more block proposals regarding the node p j , then f Rep (C, ε, pk j , M j , V j ) > f Rep (C, ε, pk j , , V j ).
[0074] As can be seen from the above embodiments, the beneficial effects of the present invention are as follows:
[0075] The present invention provides a reputation-based consensus method. At the beginning of each round, the reputation of each node is updated based on its historical behavior, so as to collect evidence against the malicious behavior of the majority of opponents, and punish them by reducing the node's reputation and reward good behavior by increasing the node's reputation. When the number of honest nodes in the network is no longer a majority of the honest nodes, the design method of combining the QC (quorum certificate) determined by the voting weight with the slowly increasing reputation function is beneficial to resist flash attacks.
[0076] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality of" means two or more, unless otherwise specifically defined.
[0077] In the description of this specification, descriptions with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.
[0078] Although the present application has been described in connection with various embodiments herein, however, in the process of implementing the claimed present application, those skilled in the art can understand and achieve other variations of the disclosed embodiments by viewing the accompanying drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0079] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.
Claims
1. A reputation-based consensus method, characterized in that, Including: In the current round, update the reputation of each node and start a timer; Determine a leader from the respective nodes p L ; On the said leader p L The proposed block B Trigger the Byzantine broadcast protocol on the block, so that non-leader nodes follow the Byzantine broadcast protocol to broadcast the block B and vote on the block B ; When the timer reaches the preset time, the node p j determines the first block proposed by the leader and updates the local set according to the signatures involved in the first block; After the above-mentioned leader p L Proposed block B Trigger the Byzantine broadcast protocol on the block, so that non-leader nodes follow the Byzantine broadcast protocol to broadcast the block B And for the block B After the step of voting, it further includes: Judgment node p j itself has received evidence of misbehavior from the leader or non-leader nodes; If so, further determine whether the improper behavior includes an ambiguous block proposal behavior or a withheld block proposal behavior according to the evidence of the improper behavior; If the improper behavior includes the act of ambiguous block proposal or the act of withholding block proposal, the node p j The steps of determining the first block proposed by the leader and updating the local set according to the signatures involved in the first block include: Node p j Broadcast the misbehavior so that all nodes reach a consensus on the misbehavior; When the timer reaches the preset time, the node p j uses the empty block ⊥ as the leader p L to propose the first block, and updates the local set according to the signatures involved in the first block.
2. The consensus method based on credibility according to claim 1, wherein If the improper behavior includes the act of ambiguous block proposal, the node p j uses the empty block ⊥ as the first block p L proposed by the leader, and after the step of updating the local set according to the signatures involved in the first block, further includes: Node p i The said leader p L Proposed disambiguation block B’ Record in its own proposal set M j And ignore all votes received in the current round.
3. The consensus method based on credibility according to claim 1, wherein If the improper behavior includes withholding block proposal behavior, the node p j uses the empty block ⊥ as the first block proposed by the leader p L After the step of updating the local set according to the signatures involved in the first block, the method further includes: Node p i Record an empty block ⊥ in its own proposal set and ignore all votes received in the current round. M j Record an empty block ⊥ in its own proposal set and ignore all votes received in the current round.
4. The consensus method based on credibility according to claim 1, wherein If the improper behavior does not include the act of ambiguous block proposal or the act of withholding block proposal, when the timer reaches the preset time, the node p j The steps of determining the first block proposed by the leader and updating the local set according to the signatures involved in the first block include: Node p j Broadcast misbehavior so that all nodes reach a consensus on the misbehavior; When the timer reaches the preset time, the node p j takes the block B as the first block and updates the local set according to the signatures involved in the first block.
5. The consensus method based on credibility according to claim 1, wherein When the timer reaches a preset time, the node p j Before the step of determining the first block proposed by the leader and updating the local set according to the signatures involved in the first block, further comprising: Determine the leader p L Proposed block B Whether the credibility of the node corresponding to the signature included in is greater than 1 / 2 of the sum of the credibility of all nodes after that.
6. The consensus method based on credibility according to claim 1, characterized in that The step of updating the reputation of each node and starting a timer in the current round includes: Obtain node p j The proposed set in the previous round M j and the voting set V ; For a node p j , update its reputation and start a timer through µ j ← f Rep ( C , ,pk j ,M j ,V ), where represents the reputation function, C represents the blockchain of the current round, represents the node p j 's initial reputation, pk j represents the public key of the node p j , M j represents the proposal set of the node p j in the previous round, V represents the vote set of the node p j in the previous round.
Citation Information
Patent Citations
Consensus method based on parallel voting
CN112104482A
Byzantine fault-tolerant consensus optimization method applied to industrial internet
CN114499874A