A blockchain method and system based on group signature and automaton

By using a group signature and automaton-based approach, users and modifiers negotiate and verify transaction content, resolving the issue of user recognition of data usage rights, enabling fast and reliable blockchain data modification, and simplifying the blockchain architecture.

CN116388958BActive Publication Date: 2026-02-06YANGZHOU UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310329435.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-30
Publication Date
2026-02-06
Estimated Expiration
2043-03-30

AI Technical Summary

Technical Problem

Existing modifiable blockchain solutions do not consider users' rights to use data, making it difficult for users to accept the modified data. Furthermore, the modification cycle is too long, making it impossible to handle a large number of data modification operations.

Method used

The method adopts a group signature and automaton approach. The system management organization sets system parameters, users and modifiers negotiate transaction content, and elliptic curve signature and group signature technology are used to modify data. A finite automaton model is constructed to constrain the transaction modification process, ensuring that the negotiated content agreed upon by both users and modifiers is verified before updating the blockchain.

Benefits of technology

This allows users to participate in content decisions during data modification, reducing losses, ensuring that the modified data is agreed upon by both parties, and minimizing modification cycles, thus preventing exacerbating blockchain forks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116388958B_ABST
    Figure CN116388958B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on group signature and automaton's modifiable blockchain method includes, system management mechanism carries out system parameter setting, sends update transaction;Through user sends ordinary transaction, sends user negotiation transaction and modifier carries out negotiation modification;Through modifier in blockchain sends negotiation transaction so that the data of ordinary transaction sent by user is modified, sends modification transaction;Through modifiable blockchain node, whether transaction is successfully verified.The application provides a simple modifiable blockchain system and method, the method is simple and easy to realize, ensures that in the modification process, user can participate in the content modification of transaction sent by oneself, can reduce the loss caused to user due to transaction data modification, can ensure that any completed modification is negotiated by user and modifier and affirmed by both parties, meanwhile, the modification period of the modification method proposed in the present application is shorter, and the bifurcation of blockchain cannot be aggravated.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of blockchain, in particular to a modifiable blockchain method based on group signature and automaton. BACKGROUND

[0002] Blockchain is a kind of distributed ledger with tamper resistance and non-falsifiability, which is originally an electronic transaction system supporting direct payment between untrusted parties. With the vigorous development of blockchain technology, it has a huge impact on logistics, company management, games and other fields.

[0003] Due to the tamper resistance of the blockchain system, user data is difficult to modify once it is chained, but there are now various illegal and irregular data published by malicious users. The existence of these malicious data hinders the healthy development of blockchain, and thus the modifiable blockchain scheme emerges as the times require.

[0004] The existing modifiable blockchain scheme mainly falls into two categories. One is based on chameleon hash technology. This scheme has one or more modifiers with modification authority. The modifier has all or part of the chameleon hash private key. This scheme often uses attribute-based encryption or secret sharing to limit the modification authority of the modifier to avoid malicious modification of the data content by the modifier. However, this scheme does not consider the user's right to use data, and the user cannot agree with the modified data. The other is a method in which the user submits a modification request, and all nodes of the blockchain vote. When the number of votes is greater than the threshold value within a certain period of time, the data can be modified. This method has a long modification period and cannot handle a large number of data modification operations. SUMMARY

[0005] The purpose of this section is to summarize some aspects of the embodiments of the present application and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the abstract and title of the specification to avoid obscuring the purpose of this section, the abstract and the title. Such simplifications or omissions cannot be used to limit the scope of the present application.

[0006] In view of the above existing problems, the present application is proposed.

[0007] Therefore, the technical problem solved by the present application is to solve the problem that the existing modifiable blockchain does not consider the user's right to use data in the modification process and the user cannot agree with the modified data.

[0008] To solve the above technical problems, the present application provides the following technical scheme, a modifiable blockchain method based on group signature and automaton, comprising:

[0009] The system management agency sets the system parameters and sends the update transaction.

[0010] The user sends a normal transaction containing his own elliptic curve public key to the modifiable blockchain node, which is verified and broadcasted by the node;

[0011] The user selects a transaction receiver address, a transaction amount, transaction data m, and his own elliptic curve encryption scheme public key pk ECC_User and his own address addr User The elliptic curve signature is calculated and put into the normal transaction T0, and the chameleon hash random number and the number of the normal transaction T0 are generated using the hash calculation method of the normal transaction; The normal transaction T0 is then sent to the modifiable blockchain node, which is verified and broadcasted by the node;

[0012] When the normal transaction data sent by the user needs to be modified, the modifier and the user modify the transaction through modifier negotiation and user negotiation, respectively. After the negotiation is completed, the modifier sends a modified transaction to the blockchain node, which is verified and broadcasted by the node;

[0013] The modifier and the user interact in the system through a finite automaton model;

[0014] In one round of negotiation, the modifier proposes the modifier-approved negotiation content, which is group-signed and encrypted using the user's elliptic curve public key;

[0015] The modifier puts the ciphertext into the modifier negotiation transaction and broadcasts the transaction in the system;

[0016] The user decrypts the broadcasted modifier negotiation transaction using the elliptic curve private key, obtains the modifier-approved negotiation content, and proposes the user-approved negotiation content;

[0017] The user group-signs the user-approved negotiation content, encrypts it using the modifier's elliptic curve public key, and puts the ciphertext into the user negotiation transaction and broadcasts the transaction in the system;

[0018] The modifier decrypts the ciphertext in the user negotiation transaction using his own elliptic curve private key and obtains the user-approved negotiation content;

[0019] After one round of negotiation, if the modifier-approved negotiation content is different from the user-approved negotiation content, a new round of negotiation is performed. If the negotiation contents are the same, the modifier takes the negotiation contents approved by both parties as the modified content, calculates a new chameleon hash random number using the chameleon hash private key, and puts the modified content, the new chameleon hash random number, the modifier's group signature and the user's elliptic curve signature of the modified content into the modified transaction and sends it to the blockchain node;

[0020] The blockchain verifies the modifier group signature and the user elliptic curve signature of the modified content in the modification transaction, and updates the original content to the modified content after the verification is successful, and broadcasts the system;

[0021] The blockchain user and the modifier verify the transaction through the modifiable blockchain node.

[0022] As a preferred scheme of the modifiable blockchain method based on group signature and automaton, the preprocessing comprises inputting multi-component seabed node data to the header keyword program, obtaining observation system information, and sorting out common receiver point gather data of pressure component and vertical velocity component.

[0023] As a preferred scheme of the modifiable blockchain method based on group signature and automaton, the system management mechanism performs system parameter setting, comprising,

[0024] A chameleon hash key pair and a group signature key pair are generated.

[0025] The chameleon hash private key and the group signature private key are sent to each modifier.

[0026] An update transaction is sent to update the group signature public key.

[0027] As a preferred scheme of the modifiable blockchain method based on group signature and automaton, the transaction types comprise:

[0028] The ordinary transaction comprises transaction number, transaction sender address, transaction receiver address, transaction amount, transaction data, elliptic curve signature, public key of elliptic curve encryption algorithm, and random number of chameleon hash.

[0029] The update transaction comprises transaction number, transaction sender address, elliptic curve signature of the update transaction, and chameleon hash public key.

[0030] The modifier negotiation transaction comprises transaction number, transaction sender address, modified transaction number, public key of elliptic curve encryption algorithm, negotiation data ciphertext, group signature, and elliptic curve signature of the modifier negotiation transaction.

[0031] The user negotiation transaction comprises transaction number, transaction sender address, modified transaction number, negotiation data ciphertext, and elliptic curve signature of the user negotiation transaction.

[0032] The modification transaction comprises transaction number, transaction sender address, modified transaction number, group signature, elliptic curve signature of transaction data, chameleon hash random number, modified transaction data, and elliptic curve signature of the modification transaction.

[0033] As a preferred scheme of the group signature and automaton-based modifiable blockchain method of the present application, wherein the transaction types further include:

[0034] In the various transactions, the transaction sender address is an elliptic curve public key generated by the system management agency, the user or the modifier, and the transaction number is the hash value of the transaction.

[0035] As a preferred scheme of the group signature and automaton-based modifiable blockchain method of the present application, wherein the transaction types further include:

[0036] Q={S0, S1, S2} is a state set of the transaction, which has three values, S0 is the initial state of the transaction, S1 is the negotiation state of the transaction, and S2 is the completed modification state of the transaction.

[0037] I={T2, T3, T4} is the input of the model, which has three values, namely the modifier negotiation transaction T2, the user negotiation transaction T3 and the modification transaction T4.

[0038] s={S0} is the initial state set, in this model, the set only has the initial state S0 of the transaction,

[0039] F={S2} is the final state set of the model, in this model, the set only has the completed modification state S2 of the transaction.

[0040] σ={F1, F2, F3, F4} is the state transition function of the model, wherein the function F1(T2): S0→S1 represents that when the model is in the state S0, the model state transitions to S1 after inputting the modifier negotiation transaction T2; the function F2(T2): S1→S1 represents that when the model is in the state S1, the model state does not change after inputting the modifier negotiation transaction T2; the function F3(T3): S1→S1 represents that when the model is in the state S1, the model state does not change after inputting the user negotiation transaction T3; and the function F4(T4): S1→S2 represents that when the model is in the state S1, the model state transitions to S2 after inputting the user negotiation transaction T4.

[0041] As a preferred scheme of the group signature and automaton-based modifiable blockchain method of the present application, wherein the verification method of the ordinary transaction includes:

[0042] First, verify whether the hash value of the ordinary transaction is the same as the transaction number, if the same, then perform subsequent verification, if not the same, directly verify failure;

[0043] If the ordinary transaction is being negotiated for modification, after the hash value of the ordinary transaction is verified, the transaction data of the transaction is verified against the content corresponding to the transaction number in the local data dictionary, if consistent, the transaction verification is successful, otherwise the transaction verification fails;

[0044] If the ordinary transaction has been modified, after the hash value of the ordinary transaction is verified, the transaction data of the transaction is verified against the content corresponding to the transaction number in the local data dictionary, if consistent and the elliptic curve signature of the ordinary transaction can pass the elliptic curve signature verification, the transaction verification is successful, otherwise the transaction verification fails;

[0045] If the ordinary transaction has not been modified, after the hash value of the ordinary transaction is verified, the elliptic curve signature of the transaction is verified, if the signature can pass the verification, the transaction verification is successful, otherwise the transaction verification fails.

[0046] As a preferred scheme of the modifiable blockchain method based on group signature and automaton according to the application, wherein the verification method of the non-ordinary transaction comprises:

[0047] The verification method of the update transaction is: first verifying whether the transaction sender address of the transaction is the address of the system management agency, then verifying the elliptic curve signature of the transaction using the address, if the signature verification is passed, the transaction verification is successful, otherwise the transaction verification fails;

[0048] The verification method of the modifier negotiation transaction is: first calculating the information entropy of the negotiation data ciphertext, if the information entropy is higher than the information entropy threshold set by the system management agency, verifying the group signature field of the transaction using the group signature public key of the system management agency formula, and finally verifying the elliptic curve signature of the transaction, if any step fails, the transaction verification fails, and if all steps pass, the transaction authentication succeeds;

[0049] The verification method of the user negotiation transaction is: first calculating the information entropy of the negotiation data ciphertext, if the information entropy is higher than the information entropy threshold set by the system management agency, verifying the elliptic curve signature of the transaction, if all steps pass, the transaction verification passes, otherwise the transaction verification fails;

[0050] The verification method of the modified transaction is: first verifying the elliptic curve signature of the modified transaction data, then splicing the transaction data and its elliptic curve signature and verifying the group signature of the spliced data, verifying the hash value of the special transaction, if all steps pass, the transaction verification passes, otherwise the transaction verification fails.

[0051] As a preferred scheme of the blockchain method based on group signature and automaton of the present application, wherein: all transactions need to verify whether the hash result of the content is equal to the transaction number, the hash value calculation process of the ordinary transaction is to first calculate the chameleon hash value of the transaction data field of the ordinary transaction and the chameleon hash random number (hash CH r)=CH.Hash(pk CH ,d|sig EC ),

[0052] wherein CH.Hash() is the hash algorithm of the chameleon hash scheme, pk CH is the chameleon hash public key generated by the system management institution, d is the transaction data of the ordinary transaction, sig EC is the elliptic curve signature of the user on the transaction data, d|sig EC is the splicing of the transaction data and the elliptic curve data in binary form, and the chameleon hash value is spliced with other fields and the hash value of the ordinary transaction is calculated using the standard hash function.

[0053] The present application also provides a blockchain system based on group signature and automaton, which comprises: a system management institution, a user module, a modifier module and a blockchain node.

[0054] The system management institution is used for the system management institution to set system parameters and send update transactions.

[0055] The user module is used for the user to send an ordinary transaction containing an elliptic curve public key of the user to the blockchain node, and the ordinary transaction is broadcast after being verified by the node; the user selects a transaction receiver address, a transaction amount, transaction data m, and an elliptic curve encryption scheme public key pk ECC_User and an address addr User of the user, calculates an elliptic curve signature, puts the elliptic curve signature into the ordinary transaction T0, and generates a chameleon hash random number and a number of the ordinary transaction T0 by using a hash calculation method of the ordinary transaction. Then, the ordinary transaction T0 is sent to the blockchain node, and the ordinary transaction is broadcast after being verified by the blockchain node.

[0056] The modifier module is when the normal transaction data sent by the user needs to be modified, the modifier and the user modify the negotiation through the modifier negotiation transaction and the user negotiation transaction respectively, the modifier sends the modified transaction to the blockchain node after the negotiation is completed, and the node is verified and broadcasted; the modifier and the user are in the system, and the interaction is completed through the finite automaton model; in a round of negotiation, the modifier proposes the negotiation content approved by the modifier, the negotiation content approved by the modifier is group signed and encrypted using the elliptic curve public key of the user; the modifier puts the ciphertext into the modifier negotiation transaction and broadcasts the transaction in the system; the user decrypts the broadcasted modifier negotiation transaction through the elliptic curve private key, obtains the negotiation content approved by the modifier, and proposes the negotiation content approved by the user; the user performs elliptic curve signature on the negotiation content approved by the user, encrypts using the elliptic curve public key of the modifier, and the user puts the ciphertext into the user negotiation transaction and broadcasts the transaction in the system; the modifier decrypts the ciphertext in the user negotiation transaction through the elliptic curve private key of the modifier, and obtains the negotiation content approved by the user; after a round of negotiation, if the negotiation content approved by the modifier is different from the negotiation content approved by the user, a round of negotiation is re-performed; if the negotiation contents are the same, the negotiation content approved by both parties is taken as the modified content, a new chameleon hash random number is calculated through the chameleon hash private key, and the modified content, the new chameleon hash random number, the modifier group signature and the user elliptic curve signature of the modified content are put into the modified transaction and sent to the blockchain node; after the blockchain verifies the modifier group signature and the user elliptic curve signature of the modified content in the modified transaction successfully, the original content is updated to the modified content, and the system is broadcasted.

[0057] The modifiable blockchain node is that the blockchain user and the modifier verify whether the transaction is successful through the modifiable blockchain node.

[0058] The beneficial effects of the present application are that the present application provides a simple modifiable blockchain architecture, which is simple in structure and easy to implement, adopts elliptic curve signature, elliptic curve encryption, group signature, information entropy and other technologies to ensure that the user can participate in the content modification of the transaction sent by himself in the modification process, can reduce the loss caused to the user due to transaction data modification, can ensure that any completed modification is negotiated and approved by both the user and the modifier, and the modification method proposed in the present application has a shorter modification period and does not aggravate the bifurcation of the blockchain. BRIEF DESCRIPTION OF DRAWINGS

[0059] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced below, and obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0060] Figure 1 A flowchart of a method of a modifiable blockchain based on group signature and automaton is provided for an embodiment of the present application;

[0061] Figure 2 A flowchart of a modification of a method of a modifiable blockchain based on group signature and automaton is provided for an embodiment of the present application.

[0062] Figure 3 A system framework diagram of a system of a modifiable blockchain based on group signature and automaton is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0063] In order to make the above objectives, features and advantages of the present application more apparent, specific embodiments of the present application will be described in detail below with the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work should fall within the scope of protection of the present application.

[0064] In the following description, a large number of specific details are set forth in order to facilitate a thorough understanding of the present application. However, the present application can be implemented in other different ways than those described herein, and those skilled in the art can make similar generalizations without departing from the spirit of the present application. Therefore, the present application is not limited to the specific embodiments disclosed below.

[0065] Secondly, the "one embodiment" or "embodiment" referred to herein means that a specific feature, structure or characteristic can be included in at least one implementation of the present application. The "in one embodiment" appearing in different places in the specification does not mean the same embodiment, nor is it an embodiment that is separate or alternative to other embodiments.

[0066] The present application is described in detail in conjunction with the schematic diagram. In the detailed description of the embodiments of the present application, the cross-sectional view of the device structure is locally enlarged without the general proportion for the convenience of description, and the schematic diagram is only an example, which should not limit the scope of protection of the present application herein. In addition, the three-dimensional spatial dimensions of length, width and depth should be included in actual manufacture.

[0067] Meanwhile, in the description of the present application, it should be noted that the terms "up, down, in and out" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the indicated device or element must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. In addition, the terms "first, second or third" are only for the purpose of description, and cannot be understood as indicating or implying relative importance.

[0068] Unless otherwise defined, the terms "mounting, connecting, associating" in the present application should be interpreted broadly, for example: it can be fixed connection, detachable connection or integral connection; it can also be mechanical connection, electrical connection or direct connection, it can also be indirect connection through intermediate medium, or internal communication of two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0069] Embodiment 1

[0070] Reference Figure 1 、 2 The first embodiment of the present application provides a modifiable blockchain method based on group signature and automaton, comprising:

[0071] S1: the system management institution sets the system parameters, sends the update transaction;

[0072] The system management institution performs initial system setting, selects system security parameters λ, information entropy threshold K and the number of modifiers n, and uses the initialization algorithm CH.Setup(1 λ ) of the chameleon hash scheme, the initialization algorithm GS.Setup(1 λ ) of the group signature, and the initialization algorithm ECDSA.Setup(1 λ ) of the elliptic curve signature to generate the public parameters pp CH of the chameleon hash scheme, the public parameters pp GS of the group signature scheme and the public parameters pp ECDSA of the elliptic curve signature, respectively, and generate the chameleon hash key pair (pk CH , sk CH ) by using the key generation algorithm CH.KeyGen(pp CH ) of the chameleon hash, then generate the elliptic curve key pair by using the key generation algorithm ECDSA.KeyGen(pp ECDSA ) of the elliptic curve signature, and take the elliptic curve public key as the system management institution address addr admin ;

[0073] Further, the system management institution splices its own address addr admin and the chameleon hash public key pk CH , and then uses its own elliptic curve private key and the elliptic curve signature function ECDSA.Sign() to generate an elliptic curve signature, and then takes the address, the chameleon hash public key and the elliptic curve signature as the update transaction T0, calculates the transaction number by using the standard hash function, and sends the update transaction to the modifiable blockchain node, which broadcasts after verification.

[0074] It should be noted that the system management authority generates a group public key gpk, a group private key gmsk and n group member private keys by using a group signature key generation algorithm GS.KeyGen(pp GS ,n) and sends the n group member private keys to the n group members through a trusted channel.

[0075] S2: sending a normal transaction by a user, sending a user negotiation transaction and negotiating modification by a modifier;

[0076] The user selects a transaction receiver address, a transaction amount, transaction data m, and together with the user's own elliptic curve encryption scheme public key pk ECC_User and the user's own address addr User Calculates an elliptic curve signature and puts it into a normal transaction T0, and generates a chameleon hash random number and the number of the normal transaction T0 by using the hash calculation method of the normal transaction. Then the normal transaction T0 is sent to a modifiable blockchain node, and the normal transaction is broadcast after being verified by the modifiable blockchain node.

[0077] S3: sending a negotiation transaction by a modifier in the blockchain to modify the data of the normal transaction sent by the user, and sending a modification transaction;

[0078] A finite automaton model FA = {Q, I, sigma, s, F} of transaction state is constructed to constrain the modification of the transaction, wherein Q = {S0, S1, S2} is a state set of the transaction, which has three values, S0 is the initial state of the transaction, S1 is the negotiation state of the transaction, and S2 is the completed modification state of the transaction; I = {T2, T3, T4} is the input of the model, which has three values, namely the modifier negotiation transaction T2, the user negotiation transaction T3 and the modification transaction T4; s = {S0} is the initial state set, in this model, the set only has the initial state S0 of the transaction, F = {S2} is the final state set of the model, in this model, the set only has the completed modification state S2 of the transaction; sigma = {F1, F2, F3, F4} is the state transition function of the model, wherein the function F1(T2): S0→S1 represents that when the model is in the state S0, the model state is transferred to S1 after inputting the modifier negotiation transaction T2; the function F2(T2): S1→S1 represents that when the model is in the state S1, the model state is unchanged after inputting the modifier negotiation transaction T2; the function F3(T3): S1→S1 represents that when the model is in the state S1, the model state is unchanged after inputting the user negotiation transaction T3; and the function F4(T4): S1→S2 represents that when the model is in the state S1, the model state is transferred to S2 after inputting the user negotiation transaction T4.

[0079] S31, the modifier proposes the transaction data m' to be modified, and uses the user's elliptic curve cryptography public key pk from the previous step. ECC_User Using the elliptic curve cryptography algorithm ECC.Enc(pk) ECC_USER Generate negotiated data ciphertext c Modifier Then, using its private key gsk (a group member's key), it signs the group signature using the group signature scheme's signature algorithm GS.Sign(gpk, gsk, c). Modifier Generate group signature sig GS Finally, along with the modified transaction number Its own address addr Modifier Its own elliptic curve cryptography public key PK ECC_Modifier Generate the elliptic curve signature and transaction number of the modifier-negotiated transaction T2 and send the modifier-negotiated transaction to the blockchain node. After the modifier-blockchain node verifies the transaction, it will send the key-value pair. and The data is placed into the local transaction data dictionary (data) and the local transaction state dictionary (state) respectively, and then broadcast to the modifier to negotiate the transaction.

[0080] S32, the user uses their own elliptic curve cryptography private key and the elliptic curve cryptography decryption algorithm ECC.Dec(sk) ECC_User ,c Modifier After decrypting the proposed modification of the transaction data m', the user needs to propose the proposed modification m*. If the user agrees to the proposed modification, m* = m'; otherwise, the user can choose any value for m* in the message space M. The user needs to use their elliptic curve signature scheme private key to calculate the elliptic curve signature sig of m*. ECDSA Using the elliptic curve cryptography public key pk from the previous step, and the modifier's PK ECC_Modifier For m* and sig ECDSA The binary concatenated data is encrypted using the elliptic curve cryptography algorithm ECC.Enc(pk ECC_Modifier ,m*|sig ECDSA ) Calculate the ciphertext c User Subsequently, along with the modified transaction number Its own address addr User Generate an elliptic curve signature and transaction number for the user-negotiated transaction T3, and send the modified transaction to the modifiable blockchain node. After the modifiable blockchain node verifies the transaction, it adds the key-value pair to the local transaction data dictionary. The dictionary entry value was changed to c. User And broadcast the user's negotiated transaction.

[0081] It should be noted that the user and the modifier each generate an elliptic curve key pair using the key generation algorithm of the elliptic curve signature scheme, and disclose the elliptic curve public key as their own address, and then each generate a key pair of the elliptic curve encryption scheme using the key generation algorithm ECC.KeyGen() of the elliptic curve encryption scheme, and the blockchain node constructs a transaction state dictionary state and a transaction data dictionary data.

[0082] S33, the modifier uses its own private key of the elliptic curve encryption scheme and decrypts the transaction data m* and its elliptic curve signature sig ECC_Modifier that the user wants to modify by using the decryption algorithm ECC.Dec(sk User ) of the elliptic curve encryption scheme. ECDSA And verify m* and sig ECDSA by using the elliptic curve signature verification algorithm ECDSA.Verify(). If the modifier disagrees with m* proposed by the user, the modification will be restarted from step S31; if the modifier agrees with m* proposed by the user, a new chameleon hash random number r' is calculated using the modification algorithm CH.Adapt(sk CH ,m,hash CH ,r,m*) of the chameleon hash scheme, where sk CH is the chameleon hash private key sent by the system management agency to the modifier through a trusted channel, m is the original transaction data of the ordinary transaction numbered , hash CH and r are the original chameleon hash value and chameleon hash random number of m. Then the modifier generates a group signature msig GS of the transaction data m* using the group signature scheme signature algorithm GS.Sign(gpk, gsk, m*) with the group member private key gsk it owns. Modifier Finally, the elliptic curve signature of the modification transaction T4 and the address addr Modifier of the modifier are generated together with the number of the modified transaction, and the modifier negotiation transaction is sent to the modifiable blockchain node. After verification by the modifiable blockchain node, the value of the dictionary item with the key value in the local transaction data dictionary is modified to m*, the value of the dictionary item with the key value in the local transaction state dictionary is modified to S2, and the modification transaction is broadcast.

[0083] S4: Verify whether the transaction is successful through the modifiable blockchain node;

[0084] Verify the ordinary transaction sent by the user, the update transaction sent by the system management agency, the negotiation transaction and the modification transaction sent by the modifier; broadcast the transaction content that passes the verification. It has a transaction state dictionary and a transaction data dictionary locally.

[0085] The verification of the ordinary transaction (signature verification) involves the finite automaton verification when the modification is encountered. The verification of the ordinary transaction is divided into two cases:

[0086] Case one: if the ordinary transaction is under negotiation for modification, the hash value of the ordinary transaction is verified first, and then the transaction data of the transaction is verified against the content corresponding to the transaction number in the local data dictionary. If they are consistent, the transaction verification is successful, otherwise the transaction verification fails.

[0087] Case two: if the ordinary transaction has completed modification, the hash value of the ordinary transaction is verified first, and then the transaction data of the transaction is verified against the content corresponding to the transaction number in the local data dictionary. If they are consistent and the elliptic curve signature of the ordinary transaction can pass the elliptic curve signature verification, the transaction verification is successful, otherwise the transaction verification fails.

[0088] Case three: if the ordinary transaction has not been modified, the hash value of the ordinary transaction is verified first, and then the elliptic curve signature of the transaction is verified. If the signature can pass the verification, the transaction verification is successful, otherwise the transaction verification fails.

[0089] Further, the hash value verification method of the ordinary transaction is whether it is the same as the transaction number. If it is the same, subsequent verification is performed, if it is not the same, the verification fails.

[0090] The verification method of the update transaction is: first verify whether the transaction sender address of the transaction is the address of the system management agency, and then use the address to verify the elliptic curve signature of the transaction. If the signature verification is passed, the transaction verification is successful, otherwise the transaction verification fails;

[0091] The verification method of the modifier negotiation transaction is: first calculate the information entropy of the negotiation data ciphertext, if the information entropy is higher than the information entropy threshold set by the system management agency, use the group signature public key of the system management agency formula to verify the group signature field of the transaction, and finally verify the elliptic curve signature of the transaction. If any step of the above verification fails, the transaction verification fails, and the transaction authentication succeeds if all steps pass;

[0092] The verification method of the user negotiation transaction is: first calculate the information entropy of the negotiation data ciphertext, if the information entropy is higher than the information entropy threshold set by the system management agency, verify the elliptic curve signature of the transaction. If all the above steps pass the verification, the transaction verification passes, otherwise the transaction verification fails;

[0093] The verification method of the modification transaction is: first verify the elliptic curve signature of the modified transaction data, then splice the transaction data and its elliptic curve signature, and verify the group signature of the spliced data. Verify the hash value of the special transaction. If all the above steps pass the verification, the transaction verification passes, otherwise the transaction verification fails.

[0094] All transactions need to verify whether the hash result of the content is equal to the transaction number, the hash value calculation process of the ordinary transaction is to calculate the chameleon hash value of the transaction data field of the ordinary transaction and the chameleon hash random number (hash CH r) = CH.Hash(pk CH ,d|sig EC ), wherein CH.Hash() is the hash algorithm of the chameleon hash scheme, pk CH is the chameleon hash public key generated by the system management institution, d is the transaction data of the ordinary transaction, sig EC is the elliptic curve signature of the user on the transaction data, d|sig EC is the splicing of the transaction data and the elliptic curve data in binary form, and then the chameleon hash value is spliced with other fields and the hash value of the ordinary transaction is calculated using the standard hash function.

[0095] The hash calculation of other transaction types except the ordinary transaction is to splice the data of each field in binary form and then calculate the hash value of the transaction using the standard hash function.

[0096] After the modified blockchain node verifies the modification transaction, the user negotiation transaction and the modification transaction, it needs to input it into the finite automaton model FA of the transaction state and update the state of the transaction according to the current state of the modified transaction, if the input does not conform to any state transition function, the input is ignored.

[0097] Only when the state of the modified transaction is the completion modification state S2, the modification is completed.

[0098] In this embodiment, there is also a kind of modifiable blockchain system based on group signature and automaton, which includes: system management institution, user module, modifier module and modifiable blockchain node;

[0099] System management institution, user module, modifier module and modifiable blockchain node;

[0100] The system management institution is the system management institution to set the system parameters, and sends the update transaction;

[0101] The user module is that the user sends the ordinary transaction containing the elliptic curve public key of itself to the modifiable blockchain node, and broadcasts after the node verification; the user selects the transaction receiver address, the transaction quantity, the transaction data m, and together with the elliptic curve encryption scheme public key pk ECC_User and the address addr User of itself, calculates the elliptic curve signature and puts it into the ordinary transaction T0, and generates the chameleon hash random number and the number of the ordinary transaction T0 using the hash calculation method of the ordinary transaction Then the ordinary transaction T0 is sent to the modifiable blockchain node, and after verification by the modifiable blockchain node, the ordinary transaction is broadcasted;

[0102] The modifier module is that when the ordinary transaction data sent by the user needs to be modified, the modifier and the user modify and negotiate through the modifier negotiation transaction and the user negotiation transaction respectively, and after the negotiation is completed, the modifier sends the modified transaction to the blockchain node, which is verified by the node and then broadcasted; the modifier and the user interact in the system through a finite automaton model; in one round of negotiation, the modifier proposes the negotiation content approved by the modifier, group signs the negotiation content approved by the modifier, and encrypts it using the user's elliptic curve public key; the modifier puts the ciphertext into the modifier negotiation transaction and broadcasts the transaction in the system; the user decrypts the broadcasted modifier negotiation transaction through the elliptic curve private key, obtains the negotiation content approved by the modifier, and proposes the negotiation content approved by the user; the user group signs the negotiation content approved by the user, encrypts it using the modifier's elliptic curve public key, and the user puts the ciphertext into the user negotiation transaction and broadcasts the transaction in the system; the modifier decrypts the ciphertext in the user negotiation transaction through its own elliptic curve private key, and obtains the negotiation content approved by the user; after one round of negotiation, if the negotiation content approved by the modifier is different from the negotiation content approved by the user, a new round of negotiation is performed; if the negotiation contents are the same, the modifier takes the negotiation contents approved by both parties as the modified content, calculates a new chameleon hash random number through the chameleon hash private key, and puts the modified content, the new chameleon hash random number, the modifier group signature of the modified content, and the user elliptic curve signature into the modified transaction and sends it to the blockchain node; after the blockchain verifies the modifier group signature of the modified content and the user elliptic curve signature in the modified transaction successfully, the original content is updated to the modified content, and the system is broadcasted;

[0103] The modifiable blockchain node is that the blockchain user and the modifier verify whether the transaction is successful through the modifiable blockchain node.

[0104] Embodiment 2

[0105] For an embodiment of the present application, a modifiable blockchain method based on group signature and automaton is provided,

[0106] In order to verify the beneficial effects of the present application, scientific demonstration is carried out through experiments.

[0107] The values of the fields of the ordinary transaction before being modified are:

[0108] Transaction number:

[0109] a74ab18dbf1d57da42b528c323d5e9d9354e7aa86d33cb60c46e2f87671235f8 transaction sender address: (2637484768061430197157833471156942769231359906502881376356744881171

[0111] 3788806713,350231708133967445343648711578647404045523740322572962308 54472002473106576185)

[0113] Transaction receiver address: (1042986776086869481064969898632244897499732036472689512806651868049

[0115] 91196944671,28627311710790663640585414940194983339243204925493696573 695686556338858494320)

[0117] Transaction quantity: 10

[0118] Transaction data: "Hello World"

[0119] Elliptic curve signature: [B@212bf671

[0120] Elliptic curve encryption public key: (8998607661878071867055576711041590594709097566209340895773439920320

[0122] 6483281045,592602319012736451319852943858069067370659063854845801381 15557573219483098398)

[0124] Chameleon hash of transaction data: 1872669047754841284826407091210209014065552676704292258615792500368 3572512023870367006984167956886157092192163546938896949645393532850

[0127] 89568629266678621297,90305404481966999059216136750570652663398100491 7723969363313591572756955189306737405061661230621029817443947788016

[0129] 523233470061028964515816537096551941517,0

[0130] Chameleon Hashed Random Number: 516099330991536467891254837930143318241935643002

[0131] The normal hash value is the concatenation of the transaction sender address, the transaction receiver address, the transaction amount, the chameleon hashed random number and the elliptic curve encryption public key in the form of a string, and then the normal hash value is calculated by the SHA256 hash algorithm,

[0132] The normal hash value is calculated as,

[0133] a74ab18dbf1d57da42b528c323d5e9d9354e7aa86d33cb60c46e2f87671235f8,

[0134] The transaction number is consistent, the verification is passed, and then the transaction sender address and the transaction data are used to verify the elliptic curve signature verification algorithm ECDSA_verfiy(), and the algorithm returns True to indicate that the elliptic curve signature verification is passed.

[0135] Further, the blockchain node has a local transaction state dictionary, which is a HashMap<String, int> class in java implementation, storing the mapping from string to integer; the local transaction data dictionary is a HashMap<String, String> class in java implementation, storing the mapping from string to string.

[0136] It should be noted that the above examples are only used to illustrate the technical solutions of the present application but not limit the present application. Although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or equivalently replaced, without departing from the spirit and scope of the technical solutions of the present application, which should be covered in the scope of the claims of the present application.

Claims

1. A modifiable blockchain method based on group signatures and automata, characterized in that: include, The system management organization sets system parameters and sends update transactions; Users send ordinary transactions containing their own elliptic curve public keys to modifiable blockchain nodes, which then broadcast the transactions after verification by the nodes. The user selects the transaction recipient address, transaction quantity, transaction data m, and their own elliptic curve cryptography public key pk. ECC_User and its own address addr User After calculating the elliptic curve signature, it is placed into ordinary transaction T0, and a chameleon hash random number and the number of ordinary transaction T0 are generated using the hash calculation method of ordinary transactions. The ordinary transaction T0 is then sent to the modifiable blockchain node, and the ordinary transaction is broadcast after being verified by the modifiable blockchain node. When it is necessary to modify ordinary transaction data sent by a user, the modifier and the user negotiate the modification through the modifier negotiation transaction and the user negotiation transaction, respectively. After the negotiation is completed, the modifier sends the modification transaction to the blockchain node, and broadcasts it after the node verifies it. Modifiers and users interact within the system through a finite automata model; In one round of negotiation, the modifier proposes the negotiated content that the modifier agrees with, performs a group signature on the negotiated content that the modifier agrees with, and encrypts it using the user's elliptic curve public key; The modifier inserts ciphertext into the negotiated transaction and broadcasts the transaction in the system; Users decrypt the broadcasted modifier-negotiated transaction using elliptic curve private keys, obtain the negotiated content approved by the modifier, and then propose negotiated content approved by the user. Users sign the negotiated content that they agree to, encrypt it using the modifier's elliptic curve public key, put the ciphertext into the user-negotiated transaction, and broadcast the transaction in the system. The modifier decrypts the ciphertext in the user's negotiated transaction using their own elliptic curve private key, and obtains the negotiated content agreed upon by the user. If, after one round of negotiation, the content agreed upon by the modifier differs from the content agreed upon by the user, then another round of negotiation will be conducted. If the negotiated content is the same, the modifier will use the negotiated content agreed upon by both parties as the modified content, calculate a new chameleon hash random number using the chameleon hash private key, and send the modified content, the new chameleon hash random number, the modifier's group signature and the user's elliptic curve signature into the modification transaction and send it to the blockchain node. Once the blockchain verifies the modified content of the transaction by verifying the group signature of the modifier and the user's elliptic curve signature, the original content is updated to the modified content, and the system broadcasts the changes. Blockchain users and modifiers verify the success of transactions by modifying blockchain nodes.

2. The modifiable blockchain method based on group signatures and automata as described in claim 1, characterized in that: The system management organization performs system parameter settings, including: Generate chameleon hash key pairs and group signature key pairs; Send the Chameleon Hash private key and the group signature private key to each modifier; Send an update transaction to update the group signature public key.

3. The modifiable blockchain method based on group signatures and automata as described in claim 1 or 2, characterized in that, Various transaction types, including: The ordinary transaction T0 includes the transaction number, the transaction sender address, the transaction receiver address, the transaction quantity, the transaction data, the elliptic curve signature, the public key of the elliptic curve cryptography algorithm, and the random number of the chameleon hash. The update transaction T1 includes four fields: transaction number, transaction sender address, elliptic curve signature of the update transaction, and chameleon hash public key. The modifier negotiated transaction T2 includes the transaction number, the transaction sender address, the modified transaction number, the public key of the elliptic curve cryptography algorithm, the negotiated data ciphertext, the group signature, and the elliptic curve signature of the modifier negotiated transaction. The user-negotiated transaction T3 includes the transaction number, the transaction sender address, the modified transaction number, the encrypted data of the negotiation, and the elliptic curve signature of the user-negotiated transaction. The modified transaction T4 includes the transaction number, the transaction sender address, the modified transaction number, the group signature, the elliptic curve signature of the transaction data, the chameleon hash random number, the modified transaction data, and the elliptic curve signature of the modified transaction.

4. The modifiable blockchain method based on group signatures and automata as described in claim 3, characterized in that: The various transaction types also include: In all types of transactions, the sender's address is the elliptic curve public key generated by the system administrator, user, or modifier, and the transaction number is the hash value of the transaction.

5. The modifiable blockchain method based on group signatures and automata as described in claim 4, characterized in that, Also includes: A finite automaton model FA = {Q, I, σ, s, F} is constructed to constrain changes to the transaction state. Where Q = {S0, S1, S2} is the set of transaction states, which has three values: S0 is the initial state of the transaction, S1 is the negotiation state of the transaction, and S2 is the completed modification state of the transaction. I = {T2, T3, T4} is the input to the model, which has three possible values: the modifier negotiates the transaction T2, the user negotiates the transaction T3, and the modified transaction T4. s = {S0} is the initial state set. In this model, the set only contains the initial state S0 of the transactions. F = {S2} is the set of final states of the model. In this model, the set only contains the completed and modified state S2 of the transaction. σ = {F1, F2, F3, F4} are the state transition functions of the model, where the function F1(T2): S0 → S1 means that when the model is in state S0, the model state transitions to S1 after inputting the modifier's negotiated transaction T2; the function F2(T2): S1 → S1 means that when the model is in state S1, the model state remains unchanged after inputting the modifier's negotiated transaction T2; the function F3(T3): S1 → S1 means that when the model is in state S1, the model state remains unchanged after inputting the user's negotiated transaction T3; and the function F4(T4): S1 → S2 means that when the model is in state S1, the model state transitions to S2 after inputting the user's negotiated transaction T4.

6. The modifiable blockchain method based on group signatures and automata as described in claim 5, characterized in that, Verification methods for ordinary transactions include: First, verify whether the hash value of a regular transaction is the same as the transaction number. If they are the same, proceed with the subsequent verification. If they are not the same, the verification fails directly. If the ordinary transaction is being negotiated for modification, after the hash value of the ordinary transaction is verified, the transaction data of the transaction is then verified to be consistent with the content corresponding to the transaction number in the local data dictionary. If they are consistent, the transaction verification is successful; otherwise, the transaction verification fails. If the ordinary transaction has been modified, after the hash value of the ordinary transaction passes, the transaction data of the transaction is then verified to be consistent with the content corresponding to the transaction number in the local data dictionary. If they are consistent and the elliptic curve signature of the ordinary transaction can be verified by the elliptic curve signature, the transaction verification is successful; otherwise, the transaction verification fails. If the ordinary transaction has not been modified, after the hash value of the ordinary transaction passes the verification, the elliptic curve signature of the transaction is then verified. If the signature passes the verification, the transaction verification is successful; otherwise, the transaction verification fails.

7. The modifiable blockchain method based on group signatures and automata as described in claim 6, characterized in that, Verification methods for non-ordinary transactions include: The verification method for updating transactions is as follows: First, verify whether the sender address of the transaction is the address of the system management organization. Then, use the address to verify the elliptic curve signature of the transaction. If the signature verification passes, the transaction verification is successful; otherwise, the transaction verification fails. The verification method for the modified negotiated transaction is as follows: First, calculate the information entropy of the negotiated data ciphertext. If the information entropy is higher than the information entropy threshold set by the system management organization, then use the group signature public key of the system management organization formula to verify the group signature field of the transaction. Finally, verify the elliptic curve signature of the transaction. If any of the above steps fails to verify, the transaction verification fails. If all steps pass, the transaction authentication is successful. The verification method for user-negotiated transactions is as follows: First, calculate the information entropy of the encrypted negotiation data. If the information entropy is higher than the information entropy threshold set by the system management agency, then verify the elliptic curve signature of the transaction. If all the above steps pass the verification, the transaction verification is successful; otherwise, the transaction verification fails. The verification method for modified transactions is as follows: First, verify the elliptic curve signature of the modified transaction data. Then, concatenate the transaction data and its elliptic curve signature and verify the group signature of the concatenated data. Verify the hash value of special transactions. If all the above steps pass the verification, the transaction verification is successful; otherwise, the transaction verification fails.

8. The modifiable blockchain method based on group signatures and automata as described in claim 7, characterized in that: All transactions require verification that the hash result of the content equals the transaction number. The hash value calculation process for ordinary transactions involves first calculating the chameleon hash value and the chameleon hash random number (hash) of the transaction data field. CH ,r)=CH.Hash(pk CH ,d|sig EC ), Where CH.Hash() is the hash algorithm of the Chameleon hash scheme, pk CH The chameleon hash public key generated by the system administration, d represents the transaction data of a normal transaction, and sig EC For users to sign elliptic curves of transaction data, d|sig EC The transaction data and elliptic curve data are concatenated in binary form, and then the chameleon hash value is concatenated with other fields and the hash value of a normal transaction is calculated using a standard hash function.

9. A modifiable blockchain system based on group signatures and automata, employing the modifiable blockchain method based on group signatures and automata as described in any one of claims 1 to 8, characterized in that, include: System management organization, user module, modifier module, and modifiable blockchain nodes; The system management organization is responsible for setting system parameters and sending update transactions. The user module involves a user sending a regular transaction containing their elliptic curve cryptography public key to a modifiable blockchain node. After verification by the node, the transaction is broadcast. The user selects the recipient address, transaction quantity, transaction data *m*, and includes their elliptic curve cryptography public key *pk*. ECC_User and its own address addr User After calculating the elliptic curve signature, it is placed into ordinary transaction T0, and a chameleon hash random number and the number of ordinary transaction T0 are generated using the hash calculation method of ordinary transactions. The ordinary transaction T0 is then sent to the modifiable blockchain node, and the ordinary transaction is broadcast after being verified by the modifiable blockchain node. The modifier module is used when it is necessary to modify ordinary transaction data sent by a user. The modifier and the user negotiate the modification through the modifier negotiation transaction and the user negotiation transaction, respectively. After the negotiation is completed, the modifier sends the modification transaction to the blockchain node, and broadcasts it after the node verifies it. Modifiers and users interact within the system through a finite automata model; In one round of negotiation, the modifier proposes the negotiated content that the modifier agrees with, performs a group signature on the negotiated content that the modifier agrees with, and encrypts it using the user's elliptic curve public key; The modifier inserts ciphertext into the negotiated transaction and broadcasts the transaction in the system; Users decrypt the broadcasted modifier-negotiated transaction using elliptic curve private keys, obtain the negotiated content approved by the modifier, and then propose negotiated content approved by the user. Users sign the negotiated content they agree to using elliptic curves, encrypt it using the modifier's elliptic curve public key, and then put the ciphertext into the user-negotiated transaction and broadcast the transaction in the system. The modifier decrypts the ciphertext in the user-negotiated transaction using their own elliptic curve private key to obtain the negotiated content agreed to by the user. If, after one round of negotiation, the content agreed upon by the modifier differs from the content agreed upon by the user, then another round of negotiation will be conducted. If the negotiated content is the same, the modifier will use the negotiated content agreed upon by both parties as the modified content, calculate a new Chameleon Hash random number using the Chameleon Hash private key, and send the modified content, the new Chameleon Hash random number, the modifier's group signature and the user's elliptic curve signature into the modification transaction and send it to the blockchain node; after the blockchain verifies the successful modification of the modifier's group signature and the user's elliptic curve signature in the modification transaction, it will update the original content with the modified content and broadcast it to the system. The modifiable blockchain node is used by blockchain users and modifiers to verify whether a transaction is successful.