Governance method, terminal, electronic device and readable medium of blockchain

By introducing a trusted execution environment and a distributed key protocol into blockchain governance, combined with privacy governance contracts, the problem of transparency in existing governance strategies is solved, achieving both privacy protection and efficient synchronization of governance results.

CN117971976BActive Publication Date: 2026-07-21THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
Filing Date
2024-02-02
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In existing blockchain governance methods, the governance strategies are transparent, which cannot meet the needs of governance strategies with privacy protection requirements, especially when it is not desired to disclose information such as the voting strategies and weight allocation of different consensus nodes to all nodes during the consensus process.

Method used

By employing a Trusted Execution Environment (TEE) and a distributed key protocol, combined with a privacy governance contract, the governance results are ensured to be synchronized only among terminals with governance authority through the generation and encryption of governance state, thereby achieving privacy governance.

Benefits of technology

It achieves privacy protection for blockchain governance results, synchronizing only between authorized terminals, improving governance efficiency and security, and reducing off-chain governance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117971976B_ABST
    Figure CN117971976B_ABST
Patent Text Reader

Abstract

The embodiment of the present disclosure discloses a blockchain governance method, a terminal, an electronic device and a readable medium, and relates to the technical field of blockchain. The method is applied to a trusted execution environment on a blockchain governance terminal. The trusted execution environment includes a distributed key protocol and a privacy governance contract. A specific embodiment includes: receiving an on-chain governance voting request; obtaining a current governance state of the blockchain, and executing the privacy governance contract based on the on-chain governance voting request and the current governance state to generate a governance preliminary state; receiving an on-chain governance request and executing the privacy governance contract to generate a latest governance state; and encrypting the latest governance state based on the distributed key to obtain an on-chain governance result. By setting the distributed key protocol and the privacy governance contract in the trusted execution environment, the blockchain governance result can be synchronized only between terminals with governance authority, thereby achieving the purpose of privacy governance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of blockchain technology, and more particularly to a blockchain governance method, terminal, electronic device, and readable medium. Background Technology

[0002] Blockchain governance refers to the establishment and implementation of a series of rules, protocols, and mechanisms within a blockchain network to ensure its secure, stable, and efficient operation. Taking consortium blockchains as an example, governance can be implemented in two ways: off-chain governance, which involves special off-chain configurations, such as a consensus node list maintained by a unified off-chain configuration file; and on-chain governance, which leverages the inherent characteristics of the blockchain itself to perform governance on the blockchain. Off-chain governance requires additional assurance of consistency of configuration information across nodes (currently achieved through transaction sending), and the governance results can impact the original consensus mechanism or permissions, making the overall design complex and prone to problems. On-chain governance, through automatic execution via smart contracts, helps reduce the costs of off-chain governance and improves governance efficiency.

[0003] However, in both of the above governance methods, the governance strategies are transparent. In particular, in the on-chain governance method, through smart contracts, all governance operations and decision-making processes on the blockchain are open and transparent. That is, not only governance participants with governance authority can see the specific governance strategies and processes, but other on-chain nodes can also know the governance strategies and processes. This is not conducive to governance strategies with privacy protection requirements, such as the voting strategies and weight allocation of different consensus nodes in the consensus process. In certain application scenarios, it is not desirable to disclose these to all nodes. Summary of the Invention

[0004] This disclosure provides a blockchain governance method, terminal, electronic device, and readable medium that enable privacy governance of the blockchain.

[0005] To achieve the above technical objectives, the embodiments of this disclosure adopt the following technical solutions:

[0006] In a first aspect, embodiments of this disclosure provide a blockchain governance method, wherein the method is applied to a trusted execution environment on a blockchain governance terminal, the trusted execution environment further including a distributed key protocol and one or more privacy governance contracts, and the method includes:

[0007] Receive on-chain governance voting requests, which include governance decisions to be voted on on the blockchain;

[0008] Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance voting request and the current governance state to generate a governance preparation state;

[0009] Based on the preparatory state of distributed key cryptographic governance, where the distributed key is generated or obtained by running a distributed key protocol;

[0010] Receive on-chain governance requests, wherein the on-chain governance requests include the voting results of the blockchain governance voting terminal on the blockchain for the approval of the governance preparation state;

[0011] Execute the privacy governance contract based on the on-chain governance request and the current governance state to generate the latest governance state;

[0012] The latest governance state is encrypted using distributed key encryption to obtain on-chain governance results.

[0013] In some possible implementations, obtaining the current governance state of the blockchain further includes obtaining the current governance state from the blockchain.

[0014] In some possible implementations, after the distributed key protocol generates or updates the distributed key, the above method further includes:

[0015] Send generated or updated distributed keys to the blockchain governance voting terminal.

[0016] In some possible implementations, on-chain governance voting requests and / or on-chain governance requests include the signature of the blockchain governance terminal's private key.

[0017] In some possible implementations, executing a privacy governance contract to generate a governance ready state includes: determining one or more privacy governance contracts to be executed based on the governance decisions to be voted on in the blockchain included in the on-chain governance voting request;

[0018] Execute the privacy governance contract to generate the latest governance state, including: determining one or more privacy governance contracts to execute based on the governance readiness state included in the on-chain governance request.

[0019] In some possible implementations, the governance decisions to be voted on in a blockchain include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.

[0020] In some possible implementations, the governance voting status of each blockchain governance voting terminal in the governance preparation state is statistically analyzed to obtain the voting results. When the statistical value of the governance voting status indicating that the vote has passed reaches the voting threshold, the voting result is determined to be a vote that has passed.

[0021] Secondly, embodiments of this disclosure provide a blockchain governance terminal, comprising:

[0022] A trusted execution environment, including a distributed key protocol and one or more privacy governance contracts, is configured as follows:

[0023] Receive on-chain governance voting requests, which include governance decisions to be voted on on the blockchain;

[0024] Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance voting request and the current governance state to generate a governance preparation state;

[0025] Based on the preparatory state of distributed key cryptographic governance, where the distributed key is generated or obtained by running a distributed key protocol;

[0026] Receive on-chain governance requests, wherein the on-chain governance requests include the voting results of the blockchain governance voting terminal on the blockchain for the approval of the governance preparation state;

[0027] Execute the privacy governance contract based on the on-chain governance request and the current governance state to generate the latest governance state;

[0028] The latest governance state is encrypted using distributed key encryption to obtain on-chain governance results.

[0029] In some possible implementations, the trusted execution environment is configured to obtain the current governance state from the blockchain.

[0030] In some possible implementations, a trusted execution environment is configured to send generated or updated distributed keys to blockchain governance voting terminals.

[0031] In some possible implementations, on-chain governance voting requests and / or on-chain governance requests include the signature of the blockchain governance terminal's private key.

[0032] In some possible implementations, the trusted execution environment is configured to determine one or more privacy governance contracts to be executed based on the governance decisions to be voted on in the blockchain included in the on-chain governance voting request; and to determine one or more privacy governance contracts to be executed based on the governance readiness status included in the on-chain governance request.

[0033] In some possible implementations, the governance decisions to be voted on in a blockchain include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.

[0034] In some possible implementations, the governance voting status of each blockchain governance voting terminal in the governance preparation state is statistically analyzed to obtain the voting results. When the statistical value of the governance voting status indicating that the vote has passed reaches the voting threshold, the voting result is determined to be a vote that has passed.

[0035] Thirdly, embodiments of this application provide an electronic device, including: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the blockchain governance method as described in the first aspect.

[0036] Fourthly, embodiments of this application provide a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the blockchain governance method as described in the first aspect.

[0037] The technical solution of the first aspect provided by the embodiments of this application brings at least the following beneficial effects: A trusted execution environment is set up in the blockchain governance terminal. The trusted execution environment further includes a distributed key protocol and one or more privacy governance contracts. In response to an on-chain governance request generated by a generation unit, the trusted execution environment runs the distributed key protocol to generate or update a distributed key, and executes the privacy governance contract to generate the latest governance state. The latest governance state is encrypted based on the distributed key to obtain the on-chain governance result, and the on-chain governance result is further sent to the blockchain for synchronization with other blockchain governance terminals. By setting up a distributed key protocol and privacy governance contracts in the trusted execution environment, it can be ensured that the blockchain governance result is synchronized only between terminals with governance permissions, achieving the purpose of privacy governance.

[0038] It should be noted that the technical effects of any of the implementation methods in aspects two through five can be found in the technical effects of the corresponding implementation methods in aspect one, and will not be repeated here.

[0039] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description

[0040] Figure 1 A block diagram of a blockchain governance system according to at least one embodiment of the present disclosure is shown;

[0041] Figure 2 A schematic diagram of the main modules of an exemplary blockchain system to which a blockchain governance method according to at least one embodiment of the present disclosure can be applied is shown;

[0042] Figure 3 A flowchart of a blockchain governance method according to at least one embodiment of the present disclosure is shown;

[0043] Figure 4 A schematic diagram illustrating the main steps of a blockchain governance method according to at least one embodiment of the present disclosure is shown.

[0044] Figure 5 A schematic diagram of an electronic device according to at least one embodiment of the present disclosure is shown;

[0045] Figure 6 A schematic diagram of a readable storage medium according to at least one embodiment of the present disclosure is shown. Detailed Implementation

[0046] Reference will now be made in detail to specific embodiments of the present disclosure, examples of which are illustrated in the accompanying drawings. Although the present disclosure will be described in conjunction with specific embodiments, it will be understood that it is not intended to limit the present disclosure to the described embodiments. Rather, it is intended to cover variations, modifications, and equivalents included within the spirit and scope of the present disclosure as defined by the appended claims. It should be noted that the method operations described herein can be implemented by any functional block or functional arrangement, and any functional block or functional arrangement can be implemented as a physical entity or a logical entity, or a combination of both.

[0047] To enable those skilled in the art to better understand this disclosure, the disclosure will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0048] Note that the examples described below are merely specific examples and are not intended to limit the embodiments of this disclosure to the specific shapes, hardware, connections, operations, values, conditions, data, sequences, etc., shown and described. Those skilled in the art can utilize the concepts of this disclosure to construct further embodiments not mentioned herein by reading this specification.

[0049] The terminology used in this disclosure is that which is currently widely used in the art in consideration of the functionality of this disclosure; however, these terms may vary depending on the intent, precedent, or new technology of those skilled in the art. Furthermore, specific terms may be chosen by the applicant, and in such cases, their detailed meanings will be described in the detailed description of this disclosure. Therefore, the terminology used in this specification should not be construed as simple names, but rather based on the meaning of the terms and the overall description of this disclosure.

[0050] To better understand the embodiments of this disclosure, the relevant terms involved in this disclosure will first be defined and explained.

[0051] Blockchain governance refers to the process of establishing and implementing a series of rules, protocols, and mechanisms within a blockchain network to ensure its secure, stable, and efficient operation. On-chain governance is a governance model that takes place within the protocol and updates the protocol through smart contracts.

[0052] A Trusted Execution Environment (TEE) is a software runtime environment built on hardware-level isolation and secure boot mechanisms to ensure the confidentiality, integrity, authenticity, and non-repudiation of data and code related to security-sensitive applications. In other words, a TEE is an isolated and secure area of ​​the microprocessor that guarantees that software instructions and data executed or stored within the microprocessor are not corrupted or altered.

[0053] Distributed key protocols are cryptographic techniques used for security management in distributed systems. They are key management protocols designed to solve the problems of key management and data protection in distributed systems. The core idea of ​​distributed key protocols is to distribute keys across multiple nodes to achieve data encryption and decryption. This protocol ensures data security and integrity, preventing data from being stolen or tampered with during transmission. This architecture reduces the risk of single points of failure, improves system reliability and security, and allows encryption and decryption tasks to be processed in parallel across multiple nodes, improving computational efficiency.

[0054] Smart contracts are automated contract execution systems based on blockchain technology. They allow value transfers and condition judgments on the blockchain network, enabling automated contract execution without third-party intervention. They offer advantages such as decentralization, automated execution, immutability, and reduced transaction costs. Smart contracts typically contain a set of predefined rules, according to which the parties involved agree to interact with each other.

[0055] It should be noted that the technical solutions in this disclosure, including the collection, updating, analysis, processing, use, transmission, and storage of user personal information, all comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. Necessary measures are taken to prevent unauthorized access to user personal information data and to safeguard user personal information security, network security, and national security.

[0056] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0057] Figure 1 A block diagram of a blockchain governance system according to at least one embodiment of the present disclosure is shown. Figure 1Consensus decision-making in a blockchain system provides the foundational capabilities of the blockchain. The consensus decision-making process involves multiple distinct roles, each with different responsibilities: ordinary nodes participate in data synchronization and transaction forwarding, are responsible for backing up node data and selecting consensus nodes; consensus nodes participate in voting during the consensus process, maintaining the security of the blockchain network; and proposal nodes participate in proposing during the consensus process, maintaining the activity of the blockchain network. In addition to these node types, the blockchain also includes ordinary users (not shown in the diagram), consisting of a user's public key address and private key. These users represent the actual service users on the blockchain. In public blockchains, a user only needs a wallet identity to send transactions on the chain. In some application scenarios of consortium blockchains, users can only send transactions after obtaining authorization.

[0058] Meanwhile, the secure, stable, and efficient operation of a blockchain network requires the formulation and implementation of a series of rules, protocols, and mechanisms. This process is blockchain governance, and the entities participating in blockchain governance constitute the set of governance providers for the blockchain system. Currently, there are two ways to implement governance: one is off-chain governance, which involves special off-chain configurations, such as maintaining the consensus node list using a unified off-chain configuration file; the other is on-chain governance, which utilizes the inherent characteristics of the blockchain to perform corresponding governance on the blockchain itself, i.e., locating, executing, or running relevant governance processes within the blockchain. For example, the consensus node list can be maintained by a unified transaction or smart contract, and the scope of governance power can be controlled by restricting the permissions that can send transactions or invoke smart contracts.

[0059] Blockchain governance typically involves decisions made by the blockchain system, including the current system's basic metadata, protocol version, consensus-related decisions, block-related decisions, user and permission management, as shown in Table 1 below.

[0060] Table 1. Governance Decisions Related to Blockchain Systems

[0061]

[0062] from Figure 1 As can be seen, a governor is not a specific type of node, but rather a governance identity with governance authority. Governors can be proposal nodes, consensus nodes, ordinary nodes, or ordinary users; this disclosure does not impose any restrictions. Generally, the identity of a governor is determined off-chain, not on-chain. In existing governance methods, whether configured off-chain or on-chain, a common problem is that governance strategies are transparent; not only the governance participants but also unrelated parties can see the specific governance strategies. Therefore, this cannot satisfy governance strategies with privacy requirements, that is, it cannot meet the governance needs of some governance strategies that only wish to be confirmed among governors and not synchronized with other unrelated parties on the blockchain.

[0063] Figure 2 A schematic diagram of the main modules of an exemplary blockchain system to which a blockchain governance method according to at least one embodiment of the present disclosure can be applied is shown. Figure 2 As shown, the system includes a set of governance entities 21 and a blockchain 24.

[0064] like Figure 2 As shown, the governance set 21 includes multiple governance entities such as Governor A, Governor B, and Governor C. Governors A, B, and C are respectively configured with TEEs 212, 222, and 232, communicators 213, 223, and 233, and generation units 211, 221, and 231. Each TEE further includes a privacy governance contract 2121 and a distributed key protocol 2122. Through communicators 213, 223, and 233, Governors A, B, and C communicate with the blockchain 24, utilizing the basic capabilities provided by the blockchain 24 to conduct a consensus process and produce blocks based on the latest governance state output by the governance entities, obtaining blocks n, n+1, n+2, etc. The blockchain governance method disclosed herein is typically applied in consortium blockchains.

[0065] In a blockchain governance process (where a single blockchain governance process may include multiple or more types of governance decisions as described in Table 1), the roles played by each governance member in the governance set 21 are different. The blockchain governance process can involve a governance member running a privacy governance contract, with other governance members voting on the results. When the number of governance members whose votes pass exceeds a threshold, the privacy governance contract is run again to generate the governance result. Specifically, a governance member (e.g., Governor A) acts as the governance member for this blockchain governance process, and its generation unit 211 will construct on-chain governance voting requests to generate a governance preparation state and on-chain governance requests to generate on-chain governance results. Other governance members (e.g., Governors B and C) act as voters for this blockchain governance process, and their generation units 221 and 231 will construct governance vote verification requests to generate a governance voting state, thus completing the governance voting. All requests generated by each generation unit are generated locally by the governance member and sent to their local TEE.

[0066] Each of the three governance entities (A, B, and C) needs to configure TEEs 212, 222, and 232 on a server. When governance entities A, B, and C are nodes on the blockchain, TEEs 212, 222, and 232 can either share a server with the node or be configured with their own separate servers; this is not a limitation. Servers that support TEEs 212, 222, and 232 include, for example, Intel SGX servers. The privacy governance contract 2121 included in TEEs 212, 222, and 232 is used to execute on-chain governance requests to achieve privacy governance requirements. All governance entities A, B, and C use the same privacy governance contract 2121; each governance entity also maintains a common distributed key protocol 2122, which can generate distributed keys used to encrypt and authenticate the results of the privacy governance contract output by the TEE. TEE 212, 222, and 232 guarantee the correct execution and privacy of privacy governance contract 2121, and use the distributed key generated by distributed key protocol 2122 to encrypt the execution result of privacy governance contract 2121. With the help of the data synchronization characteristics of blockchain, the execution result of privacy governance contract 2121 is synchronized to other governance entities.

[0067] In some embodiments of this disclosure, trusted channels are constructed between TEEs 212, 222, and 232 configured by administrators A, B, and C for synchronization among the parties. The TEEs of each party can perform remote authentication with each other. For example, the mutual authentication process can utilize Intel SGX's Remote Attestation feature, typically a pairwise authentication process. This involves the node executing TEE 212 remotely authenticating the node executing TEE 222, and then the node executing TEE 222 remotely authenticating the node executing TEE 212. Once the two nodes have authenticated each other, they can perform key exchange processing to achieve secure communication between them. For example... Figure 2 The dashed lines indicate that remote authentication has been completed between the various TEEs 212, 222, and 232. At this point, after the distributed key is generated by running the distributed key protocol 2122, the obtained distributed key can be synchronized by all parties through the trusted channel constructed by TEEs 212, 222, and 232, that is, synchronization is achieved off-chain.

[0068] Figure 3 A flowchart of a blockchain governance method according to at least one embodiment of the present disclosure is shown, comprising two main parts ( Figure 3Divided by a horizontal dotted line, the upper part of the process is mainly completed by a administrator with certain governance authority, generating an encrypted governance preparatory state; the lower part involves voting among other administrators to ultimately generate the on-chain governance result. In this blockchain governance process, Administrator A 210 acts as the blockchain governance terminal; other administrators, such as Administrator B 220 and Administrator C 230, act as blockchain governance voting terminals. Specifically, Figure 3 The main steps of blockchain governance are as follows:

[0069] In step S301, the generation unit 211 of governor A 210 generates an on-chain governance voting request, and TEE 212 receives the generated on-chain governance voting request. Since the on-chain governance voting request is constructed only locally by governor A 210 and serves as input to TEE 212, this on-chain governance voting request can be encrypted or not; no limitation is made here. The on-chain governance voting request can include governance decisions to be voted on, used to generate or adjust blockchain governance decisions. Specifically, when the blockchain already has a governance decision, it can be adjusted through the governance decisions to be voted on; when the blockchain adds a new type of governance decision, it can be added through the governance decisions to be voted on. The governance decisions to be voted on can be one or more of the relevant governance decisions of the blockchain system in Table 1. Multiple decisions can involve multiple decision categories, such as adding a new node P as a consensus node.

[0070] Optionally, the on-chain governance voting request can be further signed using the private key of governor A 210 to indicate the identity of the governor who generated the on-chain governance voting request. In subsequent step S305, when executing the privacy governance contract 2121, the privacy governance contract 2121 determines whether the sender of the on-chain governance voting request has governance authority. This identity is the public key recovered from the signature, and this public key (address) represents the sender.

[0071] Step S302: Run distributed key protocol 2122 to generate or update the distributed key. All governance stakeholders share the same key. The distributed key can be used to encrypt the latest state generated after the TEE executes the privacy governance contract. Distributed key protocol 2122 can generate the distributed key for the first time, or it can regenerate an updated distributed key in response to an on-chain governance voting request.

[0072] Step S303: The generated distributed key can be synchronized among the governance entities in either off-chain or on-chain methods. For example, in off-chain synchronization (such as...) Figure 3As shown in the figure, synchronization between the various governance entities can be achieved through a trusted channel constructed by the TEE, meaning that the TEEs of each governance entity have completed remote authentication with each other in advance; optionally, after sending the distributed key for synchronization, the governance entity receiving the distributed key can return the synchronization result information; during on-chain synchronization (not shown in the figure), the distributed key can be encrypted and synchronized using the blockchain, that is, governance entity A210 generates a distributed key, encrypts the distributed key and sends it to the blockchain, and other governance entities synchronize information through the blockchain to obtain the new distributed key.

[0073] In step S304, before executing the privacy governance contract 2121, governance provider A 210 obtains the current governance state of blockchain 24 and uses this current governance state as input to TEE 212. That is, based on the current governance state, governance provider A adjusts the blockchain's governance state according to the governance decisions to be voted on included in the on-chain governance voting requests. For example, it obtains the current list of consensus nodes on the chain and uses this as the current governance state, adding a new node P to the consensus node list. Optionally, the current governance state can be synchronized through blockchain 24, or it can directly obtain the current governance state maintained by the TEE.

[0074] In step S305, Governor A 210 executes the privacy governance contract 2121 in TEE 212 and generates a blockchain governance ready state. Specifically, TEE 212 executes the privacy governance contract 2121, whose inputs are the generated on-chain governance voting request and the current on-chain governance state obtained in step S304, and whose output is the governance ready state, such as a list of consensus nodes to be updated, including a new consensus node P. The governance ready state is further encrypted using a distributed key in TEE 212.

[0075] In some embodiments of this disclosure, the TEE 212 may include one or more privacy governance contracts 2121, with different privacy governance contracts 2121 corresponding to one or more governance decisions related to the blockchain system in governance table 1. The TEE 212 determines to execute one or more privacy governance contracts based on the blockchain governance decisions to be voted on included in the generated on-chain governance voting request.

[0076] Privacy governance contract 2121 can be initialized in advance on each governance provider's TEE via off-chain methods, including contract state and code. Alternatively, it can be initialized first within a single governance provider's TEE, also including contract state and code, and then remotely authenticated to allow other governance providers to complete contract initialization. When one or more privacy governance contracts are changed or adjusted, the above contract initialization method can also be used, without limitation here.

[0077] In the above steps, the order of execution of the distributed key generation (step S302) and synchronization (step S303) steps with the current governance state acquisition (step S304) and privacy governance contract execution (step S305) steps is not limited and can be adjusted according to the actual situation. For example, the current governance state can be acquired and the privacy governance contract can be run first, followed by the generation of the distributed key and the completion of synchronization among the governance participants. Generally speaking, before sending the governance preparation state, it is sufficient to obtain the distributed key to encrypt the governance preparation state.

[0078] In step S306, the administrator A 210 sends the generated cryptographic governance ready state to the blockchain 24.

[0079] In step S307, other governors B 220 and governor C 230 synchronize the generated cryptographic governance readiness status sent by governor A 210 from blockchain 24, such as a list of consensus nodes ready for updating.

[0080] In step S308 (S308'), the administrators B 220 and C 230 construct a governance vote verification request based on the encrypted governance preparation state using their respective generation units 221 and 231. Figure 3 In the process, steps 308-312 (S308'-S312') are for different governance processes. The execution order of each governance is not limited. They can be executed simultaneously or sequentially. Figure 3 The example shown illustrates a situation where governor B 220 processes data before governor C 230.

[0081] In step S309 (S309'), Governors B 220 and C 230 obtain the encrypted governance preparation state based on the governance vote verification request, and use it as input to their respective TEEs 222 and 232. They then decrypt the governance preparation state using the received distributed key, execute the privacy governance contract 2121 within TEEs 222 and 232, and vote on the governance preparation state sent by Governor A 210, generating a governance voting state. This governance voting state indicates the voting information of Governors B 220 and C 230 regarding the governance preparation state sent by Governor A 210.

[0082] Optionally, for example, a unique governance sequence number can be assigned to each governance preparation state, and the governor can vote separately for different sequence numbers. Therefore, the governance voting state only needs to reflect the voting conclusion of the current governor (Governor B 220 or Governor C 230) whether he agrees or disagrees with the governance sequence number; or, in addition to the voting conclusion, the governance voting state also includes specific governance content, such as the voting result of agreeing or disagreeing with the addition of a node to the consensus node list. In this case, the voting information can be encrypted using a distributed key before being sent.

[0083] In step S310 (S310'), Governors B 220 and C 230 send the governance voting status to blockchain 24.

[0084] In step S311 (S311'), the governor A 210 synchronizes the governance voting status from blockchain 24.

[0085] Step S312 (S312'): Governor A 210 tallies the votes. Each vote is counted when another governor (Governor B 220 or Governor C 230) agrees with the governance readiness status issued by Governor A. Each time a governance vote status is received from another governor, a tally is performed. If the number of agreeing votes does not reach the voting threshold at this time, no further action is required. For example, Figure 3 Assuming the voting threshold is set to 2, when the voter B 220 sends a vote of approval, the voter A 210 does not take any further action (step S312) since the voting threshold has not yet been reached; when the voter C 230 sends a vote of approval, the voting threshold is reached (S312'), and step S313 continues.

[0086] In step S313, governor A 210 constructs an on-chain governance request. The on-chain governance request includes the voting results obtained in step S312 (S312') of other governors B 220 and governor C 230 in favor of the governance preparation state.

[0087] The on-chain governance request can be further signed using the private key of governor A 210 to indicate the identity of the governor who generated the on-chain governance request. In the subsequent step S314, when executing the privacy governance contract 2121, the privacy governance contract 2121 determines whether the sender of the on-chain governance request has governance authority. This identity is the public key recovered from the signature, and this public key (address) represents the sender.

[0088] Step S314: Execute the privacy governance contract 2121 of TEE 212 based on the on-chain governance request and the current governance state to obtain the latest governance state, such as agreeing to add node P to the consensus node list; encrypt the latest governance state using a distributed key to obtain the on-chain governance result.

[0089] Step S315: Synchronize the on-chain governance results to blockchain 24.

[0090] In step S316, Governors B 220 and C 230 synchronize the on-chain governance results from blockchain 24. Further, based on the synchronized on-chain governance results, the states of TEEs 222 and 232 are updated. Optionally, previous states can be overwritten to save TEE space.

[0091] In some embodiments of this disclosure, when TEE 212 includes one or more privacy governance contracts 2121, and determines to execute one or more privacy governance contracts based on the blockchain governance decisions to be voted on included in the generated on-chain governance voting request; the execution of one or more privacy governance contracts 2121 is determined based on the voting results of the governance preparation state included in the on-chain governance request. TEEs 222 and 232 also include one or more privacy governance contracts 2121, and determine to execute one or more privacy governance contracts 2121 based on the governance vote verification request.

[0092] Figure 4 This diagram illustrates the main steps of a blockchain governance method according to at least one embodiment of the present disclosure. The method is applied to a trusted execution environment on a blockchain governance terminal. The trusted execution environment further includes a distributed key protocol and one or more privacy governance contracts. The method includes:

[0093] Step S401: Receive on-chain governance voting request, wherein the on-chain governance voting request includes governance decisions to be voted on in the blockchain;

[0094] Step S402: Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance voting request and the current governance state to generate a governance preparation state;

[0095] Step S403: Based on the distributed key cryptographic governance preparatory state, wherein the distributed key is generated or updated by running a distributed key protocol;

[0096] Step S404: Receive an on-chain governance request, wherein the on-chain governance request includes the voting result of the blockchain governance voting terminal on the blockchain in favor of the governance preparation state.

[0097] Step S405: Execute the privacy governance contract based on the on-chain governance request and the current governance state to generate the latest governance state;

[0098] Step S406: encrypt the latest governance state using a distributed key to obtain the on-chain governance result.

[0099] It should be noted that the above application scenarios are merely exemplary, intended to describe one or more aspects of this disclosure in specific scenarios. However, these aspects are not essential, and various modifications can be made to the application scenario. It is readily understood that the specific application scenarios described in this disclosure are not limited.

[0100] At least some embodiments of this disclosure also provide an electronic device. Figure 5 A schematic diagram of an electronic device 500 according to at least one embodiment of the present disclosure is shown.

[0101] like Figure 5 As shown, the electronic device 500 includes one or more processors 510 and a memory 520. The memory 520 includes one or more computer program modules 521. The one or more computer program modules 521 are stored in the memory 520 and configured to be executed by the processor 510. These computer program modules 521 include instructions for executing a blockchain governance method and its additional aspects according to at least one embodiment of the present disclosure. When executed by the processor 510, they can perform one or more steps of the blockchain governance method and its additional aspects according to at least one embodiment of the present disclosure. The memory 520 and the processor 510 can be interconnected via a bus system and / or other forms of connection mechanisms (not shown). For example, the bus can be a Peripheral Component Interconnect Standard (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0102] For example, processor 510 may be a central processing unit (CPU), a digital signal processor (DSP), or other processing unit with data processing and / or program execution capabilities, such as a field-programmable gate array (FPGA). Processor 510 may be a general-purpose processor or a special-purpose processor, capable of controlling other components in electronic device 500 to perform desired functions.

[0103] Exemplarily, memory 520 may include any combination of one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), USB memory, flash memory, etc. One or more computer program modules 521 may be stored on the computer-readable storage medium, and processor 510 may run one or more computer program modules 521 to implement various functions of electronic device 500. The computer program modules include multiple computer-executable instructions. Various application programs and various data, as well as various data used and / or generated by the application programs, may also be stored in the computer-readable storage medium.

[0104] For example, electronic device 500 may also include input devices such as touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, and gyroscopes; output devices such as liquid crystal displays, speakers, and vibrators; storage devices such as magnetic tapes and hard disks (HDDs or SDDs); and communication devices such as network interface cards like LAN cards and modems. The communication devices allow electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data and perform communication processing via networks such as the Internet. A drive is connected to the I / O interface as needed. Removable storage media, such as disks, optical disks, magneto-optical disks, and semiconductor memories, are installed on the drive as needed so that computer programs read from them can be installed into the storage device as required.

[0105] For example, the electronic device 500 may further include a peripheral interface (not shown in the figure). This peripheral interface can be various types of interfaces, such as a USB interface, a Lightning interface, etc. The communication device can communicate wirelessly with networks and other devices, such as the Internet, intranets and / or wireless networks such as cellular telephone networks, wireless local area networks (LANs) and / or metropolitan area networks (MANs). Wireless communication can use any of a variety of communication standards, protocols, and technologies, including but not limited to Global System for Mobile Communications (GSM), Enhanced Data GSM Environment (EDGE), Wideband Code Division Multiple Access (W-CDMA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Bluetooth, Wi-Fi (e.g., based on IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, and / or IEEE 802.11n standards), Voice over Internet Protocol (VoIP), Wi-MAX, protocols for email, instant messaging, and / or Short Message Service (SMS), or any other suitable communication protocol.

[0106] The electronic device 500 may be, for example, a system-on-a-chip (SoC) or a device including the SoC. For instance, it can be any device such as a mobile phone, tablet, laptop, e-reader, game console, television, digital photo frame, navigator, home appliance, communication base station, industrial controller, server, etc., or any combination of data processing devices and hardware. The embodiments of this disclosure do not limit this. The specific functions and technical effects of the electronic device 500 can be found in the description above of the blockchain governance method and its additional aspects according to at least one embodiment of this disclosure, and will not be repeated here.

[0107] Figure 6 A schematic diagram of a readable storage medium 600 according to at least one embodiment of the present disclosure is shown.

[0108] like Figure 6 As shown, the readable storage medium 600 stores computer instructions 610, which is a computer-readable storage medium. When the computer instructions 610 are executed by the processor, they perform one or more steps of the blockchain governance method and its additional aspects as described above.

[0109] For example, when the program code is read by a computer, the computer can execute the program code stored in the computer storage medium to perform one or more steps of, for example, the blockchain governance method and its additional aspects according to at least one embodiment of the present disclosure.

[0110] For example, the readable storage medium may include a memory card of a smartphone, a storage component of a tablet computer, a hard disk of a personal computer, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), flash memory, and other readable storage media or any combination thereof. The readable storage medium 600 may be a non-transitory readable storage medium.

[0111] At least some of the embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other.

[0112] It should be noted that, in this disclosure, relational terms such as "first," "second," etc., are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0113] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, or they may sometimes be executed in reverse order, depending on the functions involved; that is, the preceding or following operations are not necessarily executed precisely in sequence. Instead, various steps may be processed in reverse order or simultaneously as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.

[0114] The units described in the embodiments of this disclosure can be implemented in software or hardware. The described units can also be located in a processor. The names of these units do not, in some cases, constitute a limitation on the unit itself.

[0115] The following points should be noted regarding this disclosure:

[0116] (1) The accompanying drawings of the embodiments of this disclosure only involve the structures involved in the embodiments of this disclosure. Other structures can be referred to the general design.

[0117] (2) Where there is no conflict, the embodiments of this disclosure and the features in the embodiments can be combined with each other to obtain new embodiments.

[0118] The above description is merely an exemplary embodiment of this disclosure and is not intended to limit the scope of protection of this disclosure, which is determined by the appended claims.

Claims

1. A blockchain governance method, characterized in that, The method is applied to a trusted execution environment on a blockchain governance terminal, the trusted execution environment including a distributed key protocol and one or more privacy governance contracts, the method comprising: Receive on-chain governance voting requests, wherein the on-chain governance voting requests include governance decisions to be voted on in the blockchain; Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance voting request and the current governance state to generate a governance preparation state; The governance preparation state is encrypted based on a distributed key, wherein the distributed key is generated or updated by running the distributed key protocol; Receive on-chain governance requests, wherein the on-chain governance requests include the voting results of the blockchain governance voting terminal on the blockchain for the approval of the governance preparation state; The privacy governance contract is executed based on the on-chain governance request and the current governance state to generate the latest governance state; The latest governance state is encrypted using the distributed key to obtain the on-chain governance result; The step of executing the privacy governance contract to generate a governance preparation state includes: determining one or more of the privacy governance contracts to be executed based on the governance decisions to be voted on in the blockchain included in the on-chain governance voting request; The execution of the privacy governance contract to generate the latest governance state includes: determining to execute one or more of the privacy governance contracts based on the voting results of the governance preparation state included in the on-chain governance request.

2. The method according to claim 1, characterized in that, The step of obtaining the current governance status of the blockchain further includes: The current governance status is obtained from the blockchain.

3. The method according to claim 1, characterized in that, After generating or updating the distributed key using the distributed key protocol, the method further includes: Send the generated or updated distributed key to the blockchain governance voting terminal.

4. The method according to claim 1, characterized in that, The on-chain governance voting request and / or the on-chain governance request includes the signature of the private key of the blockchain governance terminal.

5. The method according to claim 1, characterized in that, The governance decisions to be voted on in the blockchain include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.

6. The method according to claim 1, characterized in that, The governance voting status of each blockchain governance voting terminal in the governance preparation state is statistically analyzed to obtain the voting results. When the statistical value of the governance voting status indicating that the vote has passed reaches the voting threshold, the voting result is determined to be a vote that has passed.

7. A blockchain governance terminal, characterized in that, include: A trusted execution environment, including a distributed key protocol and one or more privacy governance contracts, is configured as follows: Receive on-chain governance voting requests, wherein the on-chain governance voting requests include governance decisions to be voted on in the blockchain; Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance voting request and the current governance state to generate a governance preparation state; The governance preparation state is encrypted based on a distributed key, wherein the distributed key is generated or updated by running the distributed key protocol; Receive on-chain governance requests, wherein the on-chain governance requests include the voting results of the blockchain governance voting terminal on the blockchain for the approval of the governance preparation state; The privacy governance contract is executed based on the on-chain governance request and the current governance state to generate the latest governance state; The latest governance state is encrypted using the distributed key to obtain the on-chain governance result; The trusted execution environment is further configured to determine, based on the governance decisions to be voted on in the blockchain included in the on-chain governance voting request, to execute one or more of the privacy governance contracts; and to determine, based on the governance readiness state included in the on-chain governance request, to execute one or more of the privacy governance contracts.

8. The treatment terminal according to claim 7, characterized in that, The trusted execution environment is configured to obtain the current governance status from the blockchain.

9. The treatment terminal according to claim 7, characterized in that, The trusted execution environment is configured to send the generated or updated distributed key to the blockchain governance voting terminal.

10. The governance terminal according to claim 7, characterized in that, The on-chain governance voting request and / or the on-chain governance request includes the signature of the private key of the blockchain governance terminal.

11. The governance terminal according to claim 7, characterized in that, The governance decisions to be voted on in the blockchain include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.

12. The governance terminal according to claim 7, characterized in that, The governance voting status of each blockchain governance voting terminal in the governance preparation state is statistically analyzed to obtain the voting results. When the statistical value of the governance voting status indicating that the vote has passed reaches the voting threshold, the voting result is determined to be a vote that has passed.

13. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-6.

14. A computer-readable medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-6.