Governance method, terminal, system, electronic device and readable medium of blockchain
Patent Information
- Application Number
- CN202410155311.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-02
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2044-02-02
AI Technical Summary
[0003]但以上两种治理方式中,治理策略均是透明的,特别是链上治理方式中,通过智能合约,区块链上的所有治理操作和决策过程都是公开透明的,也即不仅具有治理权限的治理参与者可以看到具体的治理策略和过程,其他链上节点也均可以获知治理策略和过程,这对于有隐私保护要求的治理策略是不利的,例如共识过程中不同共识节点的投票策略及权重分配等,在一定的应用场景中,并不希望向所有节点公开
[0046] The technical solution of the first aspect provided by the embodiments of this application brings at least the following beneficial effects: A trusted execution environment is set up in the blockchain governance terminal. The trusted execution environment further includes a distributed key protocol and one or more privacy governance contracts. In response to an on-chain governance request generated by a generation unit, the trusted execution environment runs the distributed key protocol to generate or update a distributed key, and executes the privacy governance contract to generate the latest governance state. The latest governance state is encrypted based on the distributed key to obtain the on-chain governance result, and the on-chain governance result is further sent to the blockchain for synchronization with other blockchain governance terminals. By setting up a distributed key protocol and privacy governance contracts in the trusted execution environment, it can be ensured that the blockchain governance result is synchronized only between terminals with governance permissions, achieving the purpose of privacy governance.
Smart Images

Figure CN118018210B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of blockchain technology, and more particularly to a blockchain governance method, terminal, system, electronic device, and readable medium. Background Technology
[0002] Blockchain governance refers to the establishment and implementation of a series of rules, protocols, and mechanisms within a blockchain network to ensure its secure, stable, and efficient operation. Taking consortium blockchains as an example, governance can be implemented in two ways: off-chain governance, which involves special off-chain configurations, such as a consensus node list maintained by a unified off-chain configuration file; and on-chain governance, which leverages the inherent characteristics of the blockchain itself to perform governance on the blockchain. Off-chain governance requires additional assurance of consistency of configuration information across nodes (currently achieved through transaction sending), and the governance results can impact the original consensus mechanism or permissions, making the overall design complex and prone to problems. On-chain governance, through automatic execution via smart contracts, helps reduce the costs of off-chain governance and improves governance efficiency.
[0003] However, in both of the above governance methods, the governance strategies are transparent. In particular, in the on-chain governance method, through smart contracts, all governance operations and decision-making processes on the blockchain are open and transparent. That is, not only governance participants with governance authority can see the specific governance strategies and processes, but other on-chain nodes can also know the governance strategies and processes. This is not conducive to governance strategies with privacy protection requirements, such as the voting strategies and weight allocation of different consensus nodes in the consensus process. In certain application scenarios, it is not desirable to disclose these to all nodes. Summary of the Invention
[0004] This disclosure provides a blockchain governance method, terminal, system, electronic device, and readable medium that enable privacy governance of the blockchain.
[0005] To achieve the above technical objectives, the embodiments of this disclosure adopt the following technical solutions:
[0006] In a first aspect, embodiments of this disclosure provide a blockchain governance method, wherein the method is applied to a trusted execution environment on a blockchain governance terminal, the trusted execution environment further including a distributed key protocol and one or more privacy governance contracts, and the method includes:
[0007] Receive on-chain governance requests, which include decisions to be made regarding the governance of the blockchain;
[0008] Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance request and the current governance state to generate the latest governance state;
[0009] The latest governance state is encrypted using distributed key encryption to obtain on-chain governance results, where the distributed key is generated or updated by running a distributed key protocol.
[0010] In some possible implementations, obtaining the current governance state of the blockchain further includes obtaining the current governance state from the blockchain.
[0011] In some possible implementations, after the distributed key protocol generates or updates the distributed key, the above method further includes:
[0012] Send generated or updated distributed keys to other blockchain governance terminals.
[0013] In some possible implementations, on-chain governance requests include the signature of the blockchain governance terminal's private key.
[0014] In some possible implementations, executing the privacy governance contract and generating the latest governance state also includes:
[0015] Based on the blockchain governance decisions included in the on-chain governance request, determine one or more privacy governance contracts to be executed.
[0016] In some possible implementations, blockchain governance decisions include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.
[0017] Secondly, embodiments of this disclosure provide a blockchain governance terminal, comprising:
[0018] A trusted execution environment, including a distributed key protocol and one or more privacy governance contracts, is configured as follows:
[0019] Receive on-chain governance requests, which include decisions to be made regarding the governance of the blockchain;
[0020] Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance request and the current governance state to generate the latest governance state;
[0021] The latest governance state is encrypted using distributed key encryption to obtain on-chain governance results, where the distributed key is generated or updated by running a distributed key protocol.
[0022] In some possible implementations, the trusted execution environment is configured to obtain the current governance state from the blockchain.
[0023] In some possible implementations, the trusted execution environment is configured to send generated or updated distributed keys to other blockchain governance terminals.
[0024] In some possible implementations, on-chain governance requests include the signature of the blockchain governance terminal's private key.
[0025] In some possible implementations, the trusted execution environment is configured to determine one or more privacy governance contracts to be executed based on the blockchain governance decisions included in the on-chain governance request.
[0026] In some possible implementations, blockchain governance decisions include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.
[0027] Thirdly, embodiments of this disclosure provide a blockchain governance system, including: a first blockchain governance terminal, and one or more second blockchain governance terminals;
[0028] The first blockchain governance terminal includes:
[0029] The first trusted execution environment, including a distributed key protocol and one or more privacy governance contracts, is configured as follows:
[0030] Receive on-chain governance requests, which include decisions to be made regarding the governance of the blockchain;
[0031] Obtain the current governance state of the blockchain, execute the privacy governance contract based on the on-chain governance request and the current governance state, and generate the latest governance state; run the distributed key protocol to generate or update the distributed key, and send the distributed key to the second blockchain governance terminal;
[0032] The latest governance state is encrypted using a distributed key to obtain on-chain governance results;
[0033] The first communicator is configured to communicate with the blockchain and upload on-chain governance results.
[0034] The second blockchain governance terminal includes:
[0035] The second communicator is configured to communicate with the blockchain and receive on-chain governance results uploaded by the first communicator.
[0036] The second trusted execution environment, including a distributed key protocol and one or more privacy governance contracts, is configured as follows:
[0037] Receive the distributed key and decrypt the on-chain governance results based on the distributed key to obtain the latest governance status;
[0038] Execute the privacy governance contract to verify the latest governance status.
[0039] In some possible implementations, a first communicator is configured to communicate with the blockchain to obtain the current governance status.
[0040] In some possible implementations, the on-chain governance request includes the signature of the private key of the first blockchain governance terminal.
[0041] In some possible implementations, the first trusted execution environment is configured to determine one or more privacy governance contracts to be executed based on the blockchain governance decisions included in the on-chain governance request;
[0042] The second trusted execution environment is configured to determine one or more privacy governance contracts to be executed based on the latest governance status.
[0043] In some possible implementations, blockchain governance decisions include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.
[0044] Fourthly, embodiments of this application provide an electronic device, including: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the blockchain governance method as described in the first aspect.
[0045] Fifthly, embodiments of this application provide a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the blockchain governance method as described in the first aspect.
[0046] The technical solution of the first aspect provided by the embodiments of this application brings at least the following beneficial effects: A trusted execution environment is set up in the blockchain governance terminal. The trusted execution environment further includes a distributed key protocol and one or more privacy governance contracts. In response to an on-chain governance request generated by a generation unit, the trusted execution environment runs the distributed key protocol to generate or update a distributed key, and executes the privacy governance contract to generate the latest governance state. The latest governance state is encrypted based on the distributed key to obtain the on-chain governance result, and the on-chain governance result is further sent to the blockchain for synchronization with other blockchain governance terminals. By setting up a distributed key protocol and privacy governance contracts in the trusted execution environment, it can be ensured that the blockchain governance result is synchronized only between terminals with governance permissions, achieving the purpose of privacy governance.
[0047] It should be noted that the technical effects of any of the implementation methods in aspects two through five can be found in the technical effects of the corresponding implementation methods in aspect one, and will not be repeated here.
[0048] The further effects of the aforementioned unconventional alternative methods will be explained below in conjunction with specific implementation methods. Attached Figure Description
[0049] Figure 1A block diagram of a blockchain governance system according to at least one embodiment of the present disclosure is shown;
[0050] Figure 2 A schematic diagram of the main modules of an exemplary blockchain system to which a blockchain governance method according to at least one embodiment of the present disclosure can be applied is shown;
[0051] Figure 3 A flowchart of a blockchain governance method according to at least one embodiment of the present disclosure is shown;
[0052] Figure 4 A schematic diagram illustrating the main steps of a blockchain governance method according to at least one embodiment of the present disclosure is shown.
[0053] Figure 5 A schematic diagram of an electronic device according to at least one embodiment of the present disclosure is shown;
[0054] Figure 6 A schematic diagram of a readable storage medium according to at least one embodiment of the present disclosure is shown. Detailed Implementation
[0055] Reference will now be made in detail to specific embodiments of the present disclosure, examples of which are illustrated in the accompanying drawings. Although the present disclosure will be described in conjunction with specific embodiments, it will be understood that it is not intended to limit the present disclosure to the described embodiments. Rather, it is intended to cover variations, modifications, and equivalents included within the spirit and scope of the present disclosure as defined by the appended claims. It should be noted that the method operations described herein can be implemented by any functional block or functional arrangement, and any functional block or functional arrangement can be implemented as a physical entity or a logical entity, or a combination of both.
[0056] To enable those skilled in the art to better understand this disclosure, the disclosure will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0057] Note that the examples described below are merely specific examples and are not intended to limit the embodiments of this disclosure to the specific shapes, hardware, connections, operations, values, conditions, data, sequences, etc., shown and described. Those skilled in the art can utilize the concepts of this disclosure to construct further embodiments not mentioned herein by reading this specification.
[0058] The terminology used in this disclosure is that which is currently widely used in the art in consideration of the functionality of this disclosure; however, these terms may vary depending on the intent, precedent, or new technology of those skilled in the art. Furthermore, specific terms may be chosen by the applicant, and in such cases, their detailed meanings will be described in the detailed description of this disclosure. Therefore, the terminology used in this specification should not be construed as simple names, but rather based on the meaning of the terms and the overall description of this disclosure.
[0059] To better understand the embodiments of this disclosure, the relevant terms involved in this disclosure will first be defined and explained.
[0060] Blockchain governance refers to the process of establishing and implementing a series of rules, protocols, and mechanisms within a blockchain network to ensure its secure, stable, and efficient operation. On-chain governance is a governance model that takes place within the protocol and updates the protocol through smart contracts.
[0061] A Trusted Execution Environment (TEE) is a software runtime environment built on hardware-level isolation and secure boot mechanisms to ensure the confidentiality, integrity, authenticity, and non-repudiation of data and code related to security-sensitive applications. In other words, a TEE is an isolated and secure area of the microprocessor that guarantees that software instructions and data executed or stored within the microprocessor are not corrupted or altered.
[0062] Distributed key protocols are cryptographic techniques used for security management in distributed systems. They are key management protocols designed to solve the problems of key management and data protection in distributed systems. The core idea of distributed key protocols is to distribute keys across multiple nodes to achieve data encryption and decryption. This protocol ensures data security and integrity, preventing data from being stolen or tampered with during transmission. This architecture reduces the risk of single points of failure, improves system reliability and security, and allows encryption and decryption tasks to be processed in parallel across multiple nodes, improving computational efficiency.
[0063] Smart contracts are automated contract execution systems based on blockchain technology. They allow value transfers and condition judgments on the blockchain network, enabling automated contract execution without third-party intervention. They offer advantages such as decentralization, automated execution, immutability, and reduced transaction costs. Smart contracts typically contain a set of predefined rules, according to which the parties involved agree to interact with each other.
[0064] It should be noted that the technical solutions in this disclosure, including the collection, updating, analysis, processing, use, transmission, and storage of user personal information, all comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. Necessary measures are taken to prevent unauthorized access to user personal information data and to safeguard user personal information security, network security, and national security.
[0065] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0066] Figure 1 A block diagram of a blockchain governance system according to at least one embodiment of the present disclosure is shown. Figure 1 Consensus decision-making in a blockchain system provides the foundational capabilities of the blockchain. The consensus decision-making process involves multiple distinct roles, each with different responsibilities: ordinary nodes participate in data synchronization and transaction forwarding, are responsible for backing up node data and selecting consensus nodes; consensus nodes participate in voting during the consensus process, maintaining the security of the blockchain network; and proposal nodes participate in proposing during the consensus process, maintaining the activity of the blockchain network. In addition to these node types, the blockchain also includes ordinary users (not shown in the diagram), consisting of a user's public key address and private key. These users represent the actual service users on the blockchain. In public blockchains, a user only needs a wallet identity to send transactions on the chain. In some application scenarios of consortium blockchains, users can only send transactions after obtaining authorization.
[0067] Meanwhile, the secure, stable, and efficient operation of a blockchain network requires the formulation and implementation of a series of rules, protocols, and mechanisms. This process is blockchain governance, and the entities participating in blockchain governance constitute the set of governance providers for the blockchain system. Currently, there are two ways to implement governance: one is off-chain governance, which involves special off-chain configurations, such as maintaining the consensus node list using a unified off-chain configuration file; the other is on-chain governance, which utilizes the inherent characteristics of the blockchain to perform corresponding governance on the blockchain itself, i.e., locating, executing, or running relevant governance processes within the blockchain. For example, the consensus node list can be maintained by a unified transaction or smart contract, and the scope of governance power can be controlled by restricting the permissions that can send transactions or invoke smart contracts.
[0068] Blockchain governance typically involves decisions made by the blockchain system, including the current system's basic metadata, protocol version, consensus-related decisions, block-related decisions, user and permission management, as shown in Table 1 below.
[0069] Table 1. Governance Decisions Related to Blockchain Systems
[0070]
[0071]
[0072] from Figure 1 As can be seen, a governor is not a specific type of node, but rather a governance identity with governance authority. Governors can be proposal nodes, consensus nodes, ordinary nodes, or ordinary users; this disclosure does not impose any restrictions. Generally, the identity of a governor is determined off-chain, not on-chain. In existing governance methods, whether configured off-chain or on-chain, a common problem is that governance strategies are transparent; not only the governance participants but also unrelated parties can see the specific governance strategies. Therefore, this cannot satisfy governance strategies with privacy requirements, that is, it cannot meet the governance needs of some governance strategies that only wish to be confirmed among governors and not synchronized with other unrelated parties on the blockchain.
[0073] Figure 2 A schematic diagram of the main modules of an exemplary blockchain system to which a blockchain governance method according to at least one embodiment of the present disclosure can be applied is shown. Figure 2 As shown, the system includes a set of governance entities 21 and a blockchain 24.
[0074] like Figure 2 As shown, the governance set 21 includes multiple governance entities such as Governor A, Governor B, and Governor C. Governors A, B, and C are each configured with a TEE 212, TEE 222, TEE 232, and communicators 213, 223, and 233, respectively. Each TEE further includes a privacy governance contract 2121 and a distributed key protocol 2122. Governors A, B, and C communicate with the blockchain 24 through communicators 213, 223, and 233, utilizing the basic capabilities provided by the blockchain 24 to conduct a consensus process and produce blocks based on the latest governance state output by the governance entities, obtaining blocks n, n+1, n+2, etc. The blockchain governance method disclosed herein is typically applied in consortium blockchains.
[0075] In a blockchain governance process (where a single blockchain governance process may include multiple or more types of governance decisions as described in Table 1), the roles played by each governancer in the governance set 21 are different. The blockchain governance process can be completed by one governancer running a privacy governance contract to directly generate the governance result, and then other governancers verifying the privacy governance contract. Therefore, in some embodiments of this disclosure, governancers A, B, and C can further set up generation units 211, 221, and 231. These generation units generate on-chain governance requests based on the governance decisions to be completed. Generally, on-chain governance requests are generated locally by the governancer and sent to the local TEE. If a governancer has the authority to submit a governance request, then that governancer includes a generation unit; if a governancer only has the authority to verify the governance result, then a generation unit is not required.
[0076] Each of the three governance entities (A, B, and C) needs to configure TEEs 212, 222, and 232 on a server. When governance entities A, B, and C are nodes on the blockchain, TEEs 212, 222, and 232 can either share a server with the node or be configured with their own separate servers; this is not a limitation. Servers that support TEEs 212, 222, and 232 include, for example, Intel SGX servers. The privacy governance contract 2121 included in TEEs 212, 222, and 232 is used to execute on-chain governance requests to achieve privacy governance requirements. All governance entities A, B, and C use the same privacy governance contract 2121; each governance entity also maintains a common distributed key protocol 2122, which can generate distributed keys used to encrypt and authenticate the results of the privacy governance contract output by the TEE. TEE 212, 222, and 232 guarantee the correct execution and privacy of privacy governance contract 2121, and use the distributed key generated by distributed key protocol 2122 to encrypt the latest governance state obtained by executing privacy governance contract 2121. Blockchain 24 stores the encrypted latest governance state, and with the help of the data synchronization characteristics of blockchain, the latest governance state of the execution of privacy governance contract 2121 within TEE is synchronized to other governance entities B and C for verification.
[0077] In some embodiments of this disclosure, trusted channels are constructed between TEEs 212, 222, and 232 configured by administrators A, B, and C for synchronization among the parties, and the TEEs of each party can perform remote authentication with each other. For example, the mutual authentication process can utilize Intel SGX's Remote attestation function, typically involving pairwise authentication, i.e., the node executing TEE 212 remotely authenticating the node executing TEE 222, and then the node executing TEE 222 remotely authenticating the node executing TEE 212. Once the two nodes have authenticated each other, they can perform key exchange processing to achieve secure communication between them. For example... Figure 2 The dashed lines indicate that remote authentication has been completed between the various TEEs 212, 222, and 232. At this point, after the distributed key is generated by running the distributed key protocol 2122, the obtained distributed key can be synchronized by all parties through the trusted channel constructed by TEEs 212, 222, and 232, that is, synchronization is achieved off-chain.
[0078] Figure 3 A flowchart of a blockchain governance method according to at least one embodiment of the present disclosure is shown. Figure 3 As shown, blockchain governance methods mainly include the following steps:
[0079] In step S301, the generation unit 211 of governor A 210 generates an on-chain governance request, and TEE 212 receives the generated on-chain governance request. Since the on-chain governance request is constructed only locally by governor A 210 and serves as input to TEE 212, this on-chain governance request can be encrypted or not; no limitation is made here. The on-chain governance request may include governance decisions to be made, used to generate or adjust blockchain governance decisions. Specifically, when the blockchain already has a governance decision, it can be adjusted through governance decisions to be made; when a new type of governance decision is added to the blockchain, it can be added through governance decisions to be made. Governance decisions to be made can be one or more of the relevant governance decisions of the blockchain system in Table 1, such as adding a new node P as a consensus node.
[0080] Optionally, the on-chain governance request can be further signed using the private key of governor A 210 to indicate the identity of the governor who generated the on-chain governance request. In the subsequent step S305, when executing the privacy governance contract 2121, the privacy governance contract 2121 determines whether the sender of the on-chain governance request has governance authority. This identity is the public key recovered from the signature, and this public key (address) represents the sender.
[0081] Step S302: Run distributed key protocol 2122 to generate or update the distributed key. All governance entities share the same key. The distributed key can be used to encrypt the latest state generated after the TEE executes the privacy governance contract. Distributed key protocol 2122 can generate the distributed key for the first time or regenerate an updated distributed key in response to an on-chain governance request.
[0082] In step S303, the generated distributed key can be synchronized among the governance entities in two ways: off-chain or on-chain. For example, in off-chain synchronization, synchronization between governance entities can be achieved through a trusted channel constructed by a TEE, meaning that the TEEs of each governance entity have already completed remote authentication with each other in advance. In on-chain synchronization, the distributed key can be encrypted and synchronized using the blockchain. That is, governance entity A210 generates a distributed key, encrypts it, and sends it to the blockchain. Other governance entities synchronize information through the blockchain and obtain the new distributed key.
[0083] In step S304, before executing the privacy governance contract 2121, the governance entity A 210 obtains the current governance state of the blockchain and uses this current governance state as input to the TEE 212. That is, based on the current governance state, the governance state of the blockchain is adjusted according to the governance decisions to be governed included in the on-chain governance requests. For example, it obtains the current list of consensus nodes on the chain and uses this as the current governance state, adding a new node P to the consensus node list. Optionally, the current governance state can be synchronized through blockchain 24, or it can directly obtain the current governance state maintained by the TEE.
[0084] In step S305, Governor A 210 executes the privacy governance contract 2121 in TEE 212 and generates the latest governance state of the blockchain. Specifically, TEE 212 executes the privacy governance contract 2121, whose inputs are the generated on-chain governance request and the current on-chain governance state obtained in step S304, and whose output is the latest governance state, such as an updated list of consensus nodes including the new consensus node P. The latest governance state is further encrypted using a distributed key in TEE 212 to obtain the on-chain governance result.
[0085] In some embodiments of this disclosure, the TEE 212 may include one or more privacy governance contracts 2121, with different privacy governance contracts 2121 corresponding to one or more governance decisions related to the blockchain system in governance table 1. The TEE 212 determines to execute one or more privacy governance contracts based on the blockchain governance decisions to be governed included in the generated on-chain governance request.
[0086] Privacy governance contract 2121 can be initialized in advance on each governance provider's TEE via off-chain methods, including contract state and code. Alternatively, it can be initialized first within a single governance provider's TEE, also including contract state and code, and then remotely authenticated to allow other governance providers to complete contract initialization. When one or more privacy governance contracts are changed or adjusted, the above contract initialization method can also be used, without limitation here.
[0087] In step S306, the governor A 210 sends the generated on-chain governance result to blockchain 24.
[0088] In step S307, other governors B 220 and C 230 synchronize the on-chain governance results sent by governor A 210 from blockchain 24, such as an updated consensus node list.
[0089] In step S308, Governors B 220 and C 230 use the on-chain governance results as input to their respective TEEs 222 and 232, decrypt using the received distributed key to obtain the latest governance state, execute the privacy governance contract 2121 within TEEs 222 and 232, and verify the latest governance state sent by Governor A 210. If the verification is successful, the state of TEEs 222 and 232 is updated.
[0090] In some embodiments of this disclosure, when TEE 212 includes one or more privacy governance contracts 2121 and determines to execute one or more privacy governance contracts based on the blockchain governance decisions included in the generated on-chain governance request, TEE 222 and 232 also include one or more privacy governance contracts 2121 and determine to execute one or more privacy governance contracts 2121 based on the latest governance status.
[0091] In the above steps, the order of execution of the distributed key generation (step S302) and synchronization (step S303) steps with the current governance state acquisition (step S304) and privacy governance contract execution (step S305) steps is not limited and can be adjusted according to the actual situation. For example, the current governance state can be acquired and the privacy governance contract can be run first, followed by the generation of the distributed key and the synchronization between the governance participants. Generally speaking, before sending the on-chain governance results, it is sufficient to obtain the distributed key to encrypt the latest governance state.
[0092] Figure 4 This diagram illustrates the main steps of a blockchain governance method according to at least one embodiment of the present disclosure. The method is applied to a trusted execution environment on a blockchain governance terminal. The trusted execution environment further includes a distributed key protocol and one or more privacy governance contracts. The method includes:
[0093] Step S401: Receive an on-chain governance request, wherein the on-chain governance request includes the decision to be governed by the blockchain;
[0094] Step S402: Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance request and the current governance state to generate the latest governance state;
[0095] Step S403: Obtain on-chain governance results by encrypting the latest governance state based on the distributed key, wherein the distributed key is generated or updated by running the distributed key protocol.
[0096] Figure 2 Governor A 210 in the diagram illustrates a governance terminal for a blockchain according to at least one embodiment of the present disclosure, comprising:
[0097] Trusted execution environment 212, including distributed key protocol 2122 and one or more privacy governance contracts 2121, is configured as follows:
[0098] Receive on-chain governance requests, which include governance decisions to be made on blockchain 24;
[0099] Obtain the current governance state of blockchain 24, and execute privacy governance contract 2121 based on the on-chain governance request and the current governance state to generate the latest governance state;
[0100] The latest governance state is encrypted using a distributed key to obtain on-chain governance results, where the distributed key is generated or updated by running Distributed Key Protocol 2122.
[0101] Figure 2 The administrators A 210, B 220, and C 230 illustrate a blockchain governance system according to at least one embodiment of the present disclosure, comprising: a first blockchain governance terminal, such as administrator A 210, and one or more second blockchain governance terminals, such as administrator B 220 and administrator C 230;
[0102] Among them, Governor A 210 includes:
[0103] The first trusted execution environment 212, including a distributed key protocol 2122 and one or more privacy governance contracts 2121, is configured as follows:
[0104] Receive on-chain governance requests, which include governance decisions to be made on blockchain 24;
[0105] Obtain the current governance state of blockchain 24, and execute privacy governance contract 2121 based on the on-chain governance request and the current governance state to generate the latest governance state;
[0106] Run Distributed Key Protocol 2122 to generate or update distributed keys, and send the generated or updated distributed keys to Governor B 220 and Governor C 230;
[0107] The latest governance state is encrypted using a distributed key to obtain on-chain governance results;
[0108] The first communicator 213 is configured to communicate with the blockchain 24 and upload on-chain governance results;
[0109] Among them, Governor B 220 and Governor C 230 include:
[0110] The second communicators 223 and 233 are configured to communicate with the blockchain 24 and receive the on-chain governance results uploaded by the first communicator 213.
[0111] The second trusted execution environment 222, 232, including a distributed key protocol 2122 and one or more privacy governance contracts 2121, is configured as follows:
[0112] Receive the distributed key and decrypt the on-chain governance results based on the distributed key to obtain the latest governance status;
[0113] Implement Privacy Governance Contract 2121 to verify the latest governance status.
[0114] It should be noted that the above application scenarios are merely exemplary, intended to describe one or more aspects of this disclosure in specific scenarios. However, these aspects are not essential, and various modifications can be made to the application scenario. It is readily understood that the specific application scenarios described in this disclosure are not limited.
[0115] At least some embodiments of this disclosure also provide an electronic device. Figure 5 A schematic diagram of an electronic device 500 according to at least one embodiment of the present disclosure is shown.
[0116] like Figure 5 As shown, the electronic device 500 includes one or more processors 510 and a memory 520. The memory 520 includes one or more computer program modules 521. The one or more computer program modules 521 are stored in the memory 520 and configured to be executed by the processor 510. These computer program modules 521 include instructions for executing a blockchain governance method and its additional aspects according to at least one embodiment of the present disclosure. When executed by the processor 510, they can perform one or more steps of the blockchain governance method and its additional aspects according to at least one embodiment of the present disclosure. The memory 520 and the processor 510 can be interconnected via a bus system and / or other forms of connection mechanisms (not shown). For example, the bus can be a Peripheral Component Interconnect Standard (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc.
[0117] For example, processor 510 may be a central processing unit (CPU), a digital signal processor (DSP), or other processing unit with data processing and / or program execution capabilities, such as a field-programmable gate array (FPGA). Processor 510 may be a general-purpose processor or a special-purpose processor, capable of controlling other components in electronic device 500 to perform desired functions.
[0118] Exemplarily, memory 520 may include any combination of one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), USB memory, flash memory, etc. One or more computer program modules 521 may be stored on the computer-readable storage medium, and processor 510 may run one or more computer program modules 521 to implement various functions of electronic device 500. The computer program modules include multiple computer-executable instructions. Various application programs and various data, as well as various data used and / or generated by the application programs, may also be stored in the computer-readable storage medium.
[0119] For example, electronic device 500 may also include input devices such as touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, and gyroscopes; output devices such as liquid crystal displays, speakers, and vibrators; storage devices such as magnetic tapes and hard disks (HDDs or SDDs); and communication devices such as network interface cards like LAN cards and modems. The communication devices allow electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data and perform communication processing via networks such as the Internet. A drive is connected to the I / O interface as needed. Removable storage media, such as disks, optical disks, magneto-optical disks, and semiconductor memories, are installed on the drive as needed so that computer programs read from them can be installed into the storage device as required.
[0120] For example, the electronic device 500 may further include a peripheral interface (not shown in the figure). This peripheral interface can be various types of interfaces, such as a USB interface, a Lightning interface, etc. The communication device can communicate wirelessly with networks and other devices, such as the Internet, intranets and / or wireless networks such as cellular telephone networks, wireless local area networks (LANs) and / or metropolitan area networks (MANs). Wireless communication can use any of a variety of communication standards, protocols, and technologies, including but not limited to Global System for Mobile Communications (GSM), Enhanced Data GSM Environment (EDGE), Wideband Code Division Multiple Access (W-CDMA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Bluetooth, Wi-Fi (e.g., based on IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, and / or IEEE 802.11n standards), Voice over Internet Protocol (VoIP), Wi-MAX, protocols for email, instant messaging, and / or Short Message Service (SMS), or any other suitable communication protocol.
[0121] The electronic device 500 may be, for example, a system-on-a-chip (SoC) or a device including the SoC. For instance, it can be any device such as a mobile phone, tablet, laptop, e-reader, game console, television, digital photo frame, navigator, home appliance, communication base station, industrial controller, server, etc., or any combination of data processing devices and hardware. The embodiments of this disclosure do not limit this. The specific functions and technical effects of the electronic device 500 can be found in the description above of the blockchain governance method and its additional aspects according to at least one embodiment of this disclosure, and will not be repeated here.
[0122] Figure 6 A schematic diagram of a readable storage medium 600 according to at least one embodiment of the present disclosure is shown.
[0123] like Figure 6 As shown, the readable storage medium 600 stores computer instructions 610, which is a computer-readable storage medium. When the computer instructions 610 are executed by the processor, they perform one or more steps of the blockchain governance method and its additional aspects as described above.
[0124] For example, when the program code is read by a computer, the computer can execute the program code stored in the computer storage medium to perform one or more steps of, for example, the blockchain governance method and its additional aspects according to at least one embodiment of the present disclosure.
[0125] For example, the readable storage medium may include a memory card of a smartphone, a storage component of a tablet computer, a hard disk of a personal computer, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), flash memory, and other readable storage media or any combination thereof. The readable storage medium 600 may be a non-transitory readable storage medium.
[0126] At least some of the embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other.
[0127] It should be noted that, in this disclosure, relational terms such as "first," "second," etc., are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0128] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, or they may sometimes be executed in reverse order, depending on the functions involved; that is, the preceding or following operations are not necessarily executed precisely in sequence. Instead, various steps may be processed in reverse order or simultaneously as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.
[0129] The units described in the embodiments of this disclosure can be implemented in software or hardware. The described units can also be located in a processor. The names of these units do not, in some cases, constitute a limitation on the unit itself.
[0130] The following points should be noted regarding this disclosure:
[0131] (1) The accompanying drawings of the embodiments of this disclosure only involve the structures involved in the embodiments of this disclosure. Other structures can be referred to the general design.
[0132] (2) Where there is no conflict, the embodiments of this disclosure and the features in the embodiments can be combined with each other to obtain new embodiments.
[0133] The above description is merely an exemplary embodiment of this disclosure and is not intended to limit the scope of protection of this disclosure, which is determined by the appended claims.
Claims
1. A blockchain governance method, characterized in that, The method is applied to a trusted execution environment on a blockchain governance terminal, wherein the trusted execution environment further includes a distributed key protocol and one or more privacy governance contracts, and the method includes: Receive an on-chain governance request, wherein the on-chain governance request includes a governance decision to be made on the blockchain, and determine to execute one or more of the privacy governance contracts based on the governance decision to be made on the blockchain included in the on-chain governance request; Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance request and the current governance state to generate the latest governance state; The latest governance state is encrypted using a distributed key to obtain on-chain governance results, wherein the distributed key is generated or updated by running the distributed key protocol; The method further includes, after generating or updating the distributed key using the distributed key protocol, sending the generated or updated distributed key to other blockchain governance terminals through a trusted channel constructed between the trusted execution environment and the trusted execution environments of other blockchain governance terminals. This allows the other blockchain governance terminals to decrypt the on-chain governance results based on the distributed key, obtain the latest governance state, and execute the privacy governance contract to verify the latest governance state.
2. The method according to claim 1, characterized in that, The step of obtaining the current governance status of the blockchain further includes: The current governance status is obtained from the blockchain.
3. The method according to claim 1, characterized in that, The on-chain governance request includes a signature of the private key of the blockchain governance terminal.
4. The method according to claim 1, characterized in that, The blockchain governance decisions include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.
5. A blockchain governance terminal, characterized in that, include: A trusted execution environment, including a distributed key protocol and one or more privacy governance contracts, is configured as follows: Receive an on-chain governance request, wherein the on-chain governance request includes a governance decision to be made on the blockchain, and determine to execute one or more of the privacy governance contracts based on the governance decision to be made on the blockchain included in the on-chain governance request; Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance request and the current governance state to generate the latest governance state; The latest governance state is encrypted using a distributed key to obtain on-chain governance results, wherein the distributed key is generated or updated by running the distributed key protocol; Specifically, after generating or updating the distributed key using the distributed key protocol, the generated or updated distributed key is further sent to other blockchain governance terminals through a trusted channel constructed between the trusted execution environment and the trusted execution environments of other blockchain governance terminals. This allows the other blockchain governance terminals to decrypt the on-chain governance results based on the distributed key, obtain the latest governance status, and execute the privacy governance contract to verify the latest governance status.
6. The treatment terminal according to claim 5, characterized in that, The trusted execution environment is configured to obtain the current governance status from the blockchain.
7. The treatment terminal according to claim 5, characterized in that, The on-chain governance request includes a signature of the private key of the blockchain governance terminal.
8. The treatment terminal according to claim 5, characterized in that, The blockchain governance decisions include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.
9. A governance system for a blockchain, characterized in that, include: A first blockchain governance terminal, and one or more second blockchain governance terminals; The first blockchain governance terminal includes: The first trusted execution environment, including a distributed key protocol and one or more privacy governance contracts, is configured as follows: Receive an on-chain governance request, wherein the on-chain governance request includes a governance decision to be made on the blockchain, and determine to execute one or more of the privacy governance contracts based on the governance decision to be made on the blockchain included in the on-chain governance request; Obtain the current governance state of the blockchain, and execute the privacy governance contract based on the on-chain governance request and the current governance state to generate the latest governance state; The distributed key is generated or updated by running the distributed key protocol, and then sent to the second blockchain governance terminal through a trusted channel constructed between the first trusted execution environment and the second trusted execution environment of the second blockchain governance terminal. The latest governance state is encrypted using the distributed key to obtain the on-chain governance result; A first communicator is configured to communicate with the blockchain and upload the on-chain governance results; The second blockchain governance terminal includes: The second communicator is configured to communicate with the blockchain and receive the on-chain governance results uploaded by the first communicator; The second trusted execution environment, including the distributed key protocol and the one or more privacy governance contracts, is configured as follows: Receive the distributed key and decrypt the on-chain governance result based on the distributed key to obtain the latest governance status; Execute the privacy governance contract to verify the latest governance status.
10. The governance system according to claim 9, characterized in that, The first communicator is configured to communicate with the blockchain to obtain the current governance status.
11. The governance system according to claim 9, characterized in that, The on-chain governance request includes a signature of the private key of the first blockchain governance terminal.
12. The governance system according to claim 9, characterized in that, The second trusted execution environment is configured to determine, based on the latest governance state, to execute one or more of the privacy governance contracts.
13. The governance system according to claim 9, characterized in that, The blockchain governance decisions include one or more of the following: basic metadata, protocol version, user permissions, block-related decisions, and consensus-related decisions.
14. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-4.
15. A computer-readable medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-4.
Citation Information
Patent Citations
Alliance chain treatment method and device, computer equipment and storage medium
CN110288179A