Transaction verification method, device and storage medium
By generating verification parameters and recovering encrypted public keys in the blockchain system, the problem of wasteful transmission and storage of signature public keys is solved, and the efficiency and security of blockchain transactions are improved.
Patent Information
- Application Number
- CN202410379695.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-29
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-03-29
AI Technical Summary
In blockchain transaction verification, the resource overhead of transmitting and storing signature public keys is high, especially in scenarios with large transaction volumes, resulting in resource waste and reduced efficiency.
By receiving the transaction to be verified from the transaction address sent by the client, generating verification parameters based on the signature random number and known base point, recovering the encrypted public key, and performing signature verification based on the encrypted public key and transaction content, encoding to obtain the reference address to verify the legitimacy of the transaction, reducing the need to transmit and store the signature public key.
It reduces the overhead of transmission and storage resources, improves the efficiency and performance of the blockchain system, and improves the security of transactions through multiple verifications.
Smart Images

Figure CN118211965B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of blockchain technology, and in particular to a transaction verification method, device, and storage medium. Background Art
[0002] In the blockchain verification transaction scenario, the client uses the national secret SM2 digital signature algorithm to sign the transaction information and sends the obtained signature value to the blockchain. The blockchain needs to verify the signature value generated by the client for the transaction to determine the ownership of the transaction.
[0003] Because the SM2 digital signature algorithm relies on public keys to verify the legitimacy of transactions and digital signatures, the client sends the public key to the blockchain at the same time as the signature value. This incurs additional resource overhead for transmitting and storing the public key. In scenarios with large transaction volumes, transmitting and storing the signature public key consumes a significant amount of transmission and storage resources. Summary of the Invention
[0004] Embodiments of the present application provide a transaction verification method, device, and storage medium for reducing the transmission resources and storage resources occupied by transmitting and storing signature public keys.
[0005] In one aspect, an embodiment of the present application provides a transaction verification method, which is applied to a blockchain system. The method includes the following steps:
[0006] Receive a transaction to be verified with a transaction address from a client, including transaction content, target signature, and signature random number.
[0007] generating a verification parameter based on the signature random number and the coordinates of a known base point; and recovering an encryption public key based on the verification parameter and the target signature;
[0008] Performing signature verification on the target signature based on the encrypted public key and the transaction content; and when the signature verification passes, encoding the encrypted public key to obtain a reference address;
[0009] If the reference address is consistent with the transaction address, it is determined that the transaction to be verified has passed verification.
[0010] Optionally, recovering the encryption public key based on the verification parameter and the target signature includes:
[0011] generating a public key verification factor based on the signature abscissa of the target signature and the signature abscissa of the target signature;
[0012] The encrypted public key is recovered based on the signature abscissa of the target signature, the public key verification factor, and the verification parameter.
[0013] Optionally, the performing signature verification on the target signature based on the encrypted public key and the transaction content includes:
[0014] generating a message digest based on the encrypted public key and the transaction content;
[0015] generating a first verification abscissa based on the message digest and the signature abscissa of the target signature; and using the abscissa of the verification parameter as a second verification abscissa;
[0016] If the first verification horizontal coordinate is consistent with the second verification horizontal coordinate, the signature verification is successful;
[0017] If the first verification horizontal coordinate is inconsistent with the second verification horizontal coordinate, the signature verification fails.
[0018] Optionally, generating a message digest based on the encrypted public key and the transaction content includes:
[0019] generating verification binding information based on the public parameters, the coordinates of the known base point, and the encrypted public key;
[0020] Performing a cascade operation on the transaction content and the verification binding information to obtain a transaction confirmation factor;
[0021] A message digest algorithm is used to convert the transaction confirmation factor into the message digest.
[0022] In one aspect, an embodiment of the present application provides a transaction verification method, applied to a client, comprising the following steps:
[0023] In response to a transaction request from a target account, generating a transaction to be verified, the transaction to be verified including: transaction content, a target signature, and a signature random number;
[0024] The transaction to be verified carrying the transaction address is sent to the blockchain system, so that the blockchain system generates verification parameters based on the signature random number and the coordinates of the known base point; and, based on the verification parameters and the target signature, the encrypted public key is restored; based on the encrypted public key and the transaction content, the target signature is signature verified; when the signature verification passes, the encrypted public key is encoded to obtain a reference address; if the reference address is consistent with the transaction address, it is determined that the verification of the transaction to be verified has passed.
[0025] Optionally, generating a transaction to be verified in response to a transaction request from a target account includes:
[0026] In response to a transaction request from a target account, signing the transaction content based on the original private key of the target account, the original public key of the target account, and the signature random number to obtain a target signature;
[0027] The transaction to be verified is obtained based on the transaction content, the target signature and the signature random number.
[0028] Optionally, the transaction address is a contract address, and the transaction address is obtained by encoding the original public key.
[0029] Optionally, signing the transaction content based on the original private key of the target account, the original public key of the target account, and the signature random number to obtain the target signature includes:
[0030] generating a verification parameter based on the signature random number and the coordinates of the known base point;
[0031] generating an encryption factor based on public parameters, the coordinates of the known base point, and the original public key;
[0032] Performing a cascade operation on the transaction content and the encryption factor, and performing a hash operation on the result of the cascade operation to obtain a target hash value;
[0033] Determine the signature abscissa based on the abscissa of the verification parameter and the target hash value; and determine the signature ordinate based on the original private key, the signature random number and the signature abscissa;
[0034] The target signature is determined based on the signature abscissa and the signature ordinate.
[0035] In one aspect, an embodiment of the present application provides a transaction verification device, which is applied to a blockchain system. The transaction verification device includes:
[0036] A receiving module, configured to receive a transaction to be verified that carries a transaction address and is sent by a client. The transaction to be verified includes: transaction content, target signature, and signature random number;
[0037] a public key recovery module, configured to generate a verification parameter based on the signature random number and the coordinates of a known base point; and recover an encrypted public key based on the verification parameter and the target signature;
[0038] A signature verification module, configured to perform signature verification on the target signature based on the encrypted public key and the transaction content; and when the signature verification passes, encode the encrypted public key to obtain a reference address;
[0039] The address verification module is used to determine that the transaction to be verified has passed the verification if the reference address is consistent with the transaction address.
[0040] Optionally, the public key recovery module is specifically used to:
[0041] generating a public key verification factor based on the signature abscissa of the target signature and the signature abscissa of the target signature;
[0042] The encrypted public key is recovered based on the signature abscissa of the target signature, the public key verification factor, and the verification parameter.
[0043] Optionally, the signature verification module is specifically configured to:
[0044] generating a message digest based on the encrypted public key and the transaction content;
[0045] generating a first verification abscissa based on the message digest and the signature abscissa of the target signature; and using the abscissa of the verification parameter as a second verification abscissa;
[0046] If the first verification horizontal coordinate is consistent with the second verification horizontal coordinate, the signature verification is successful;
[0047] If the first verification horizontal coordinate is inconsistent with the second verification horizontal coordinate, the signature verification fails.
[0048] Optionally, the signature verification module is specifically configured to:
[0049] generating verification binding information based on the public parameters, the coordinates of the known base point, and the encrypted public key;
[0050] Performing a cascade operation on the transaction content and the verification binding information to obtain a transaction confirmation factor;
[0051] A message digest algorithm is used to convert the transaction confirmation factor into the message digest.
[0052] In one aspect, an embodiment of the present application provides a transaction verification device, which is applied to a client. The transaction verification device includes:
[0053] A generating module, configured to generate a transaction to be verified in response to a transaction request of a target account, wherein the transaction to be verified includes: transaction content, a target signature, and a signature random number;
[0054] A sending module is used to send the transaction to be verified carrying the transaction address to the blockchain system, so that the blockchain system generates verification parameters based on the signature random number and the coordinates of the known base point; and, based on the verification parameters and the target signature, restores the encrypted public key; based on the encrypted public key and the transaction content, performs signature verification on the target signature; when the signature verification passes, encodes the encrypted public key to obtain a reference address; if the reference address is consistent with the transaction address, it is determined that the verification of the transaction to be verified has passed.
[0055] Optionally, the generating module is specifically configured to:
[0056] In response to a transaction request from a target account, signing the transaction content based on the original private key of the target account, the original public key of the target account, and the signature random number to obtain a target signature;
[0057] The transaction to be verified is obtained based on the transaction content, the target signature and the signature random number.
[0058] Optionally, the transaction address is a contract address, and the transaction address is obtained by encoding the original public key.
[0059] Optionally, the generating module is specifically configured to:
[0060] generating a verification parameter based on the signature random number and the coordinates of the known base point;
[0061] generating an encryption factor based on public parameters, the coordinates of the known base point, and the original public key;
[0062] Performing a cascade operation on the transaction content and the encryption factor, and performing a hash operation on the result of the cascade operation to obtain a target hash value;
[0063] Determine the signature abscissa based on the abscissa of the verification parameter and the target hash value; and determine the signature ordinate based on the original private key, the signature random number and the signature abscissa;
[0064] The target signature is determined based on the signature abscissa and the signature ordinate.
[0065] On the one hand, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned transaction verification method when executing the program.
[0066] On the one hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program that can be executed by a computer device. When the program is run on the computer device, the computer device executes the steps of the above-mentioned transaction verification method.
[0067] On the one hand, an embodiment of the present application provides a computer program product, which includes a computer program stored on a computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer device, the computer device performs the steps of the above-mentioned transaction verification method.
[0068] In an embodiment of the present application, a blockchain system receives a transaction to be verified from a client, including a transaction address. The transaction to be verified includes the transaction content, a target signature, and a signature random number. Because the original public key is a two-dimensional coordinate, while the signature random number is a one-dimensional parameter, the present application's transmission and storage of the signature random number can reduce the public key transmission and storage overhead by half compared to existing methods of transmitting and storing public keys, thereby reducing transmission and storage resources and improving the efficiency and performance of the blockchain system.
[0069] Next, verification parameters are generated based on the signature random number and the coordinates of the known base point. Furthermore, the encrypted public key is recovered based on the verification parameters and the target signature. The target signature is then verified based on the encrypted public key and the transaction content. If signature verification passes, the encrypted public key is encoded to obtain a reference address. If the reference address matches the transaction address, the transaction is deemed to have passed verification. The blockchain system in this application uses multiple verification methods (signature verification and address verification) to determine the legitimacy of the transaction, thereby improving transaction security. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0071] Figure 1 A schematic diagram of the structure of a system architecture provided in an embodiment of the present application;
[0072] Figure 2 A flowchart of a transaction verification method provided in an embodiment of the present application;
[0073] Figure 3 A schematic diagram of the structure of a transaction verification device provided in an embodiment of the present application;
[0074] Figure 4 A schematic diagram of the structure of a transaction verification device provided in an embodiment of the present application;
[0075] Figure 5 A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0076] In order to make the purpose, technical solutions and beneficial effects of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0077] For ease of understanding, the terms involved in the embodiments of the present invention are explained below.
[0078] Blockchain is a new distributed infrastructure and computing paradigm. It utilizes a blockchain-like data structure to verify and store data, a distributed node consensus algorithm to generate and update data, cryptography to ensure secure data transmission and access control, and smart contracts composed of automated script code to program and manipulate data.
[0079] Block: Block is the basic unit of data storage in the blockchain. Each block contains the latest transaction information on the current blockchain network.
[0080] Chain: A chain is formed by connecting blocks in chronological order.
[0081] Distributed: Distributed means that all nodes in the blockchain have the right to verify transactions, unlike the traditional financial system where only centralized institutions have the right to verify transactions.
[0082] Consensus: Consensus means that in a blockchain network, all nodes must reach an agreement to complete transaction verification and add new blocks.
[0083] Cryptography: Cryptography refers to the use of cryptographic techniques in blockchain networks to ensure the security of data transmission and access control.
[0084] Smart Contract: A smart contract is a contract composed of automated script codes that is used in a blockchain network to program and manipulate data.
[0085] A digital signature (also known as a public key digital signature) is a string of numbers that can only be generated by the sender and cannot be forged by others. This string of numbers also effectively proves the authenticity of the message sent by the sender.1 Digital signatures are a technology based on public key cryptography. They use asymmetric key cryptography, which uses a pair of keys: a public key and a private key. The private key is known only to the sender, while the public key is accessible to everyone. The sender encrypts the message using their private key and then sends the encrypted message along with their public key to the recipient. The recipient decrypts the message using the sender's public key and then verifies the decrypted message using the sender's public key.
[0086] Elliptic Curve Cryptography (ECC) is a public key cryptography system based on elliptic curve mathematics.
[0087] SM2 digital signature algorithm: a signature algorithm based on elliptic curve cryptography. In the SM2 signature process, there are common public parameters IDA and ENTLA. Public key PA = (x a ,y a ), the public key is a point on the SM2 elliptic curve.
[0088] Base point (G): Generator on the SM2 elliptic curve, with coordinates (x G ,y G ).
[0089] SM3 algorithm: A cryptographic hash function. Similar to other hash functions (such as SHA-256), SM3 is primarily used to generate message digests to verify data integrity and consistency.
[0090] refer to Figure 1 , which is a system architecture diagram applicable to an embodiment of the present application. The system architecture includes at least a client 101 and a blockchain system 102. The number of clients 101 can be one or more, and the present application does not specifically limit the number of clients 101.
[0091] Client 101 is used to receive a transaction request from a target account, generate a corresponding pending transaction, and then send the pending transaction to blockchain system 102 for verification. If verification is successful, the transaction content in the pending transaction is executed.
[0092] The client 101 may be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart home appliance, a smart voice interaction device, a smart car device, etc., but is not limited thereto.
[0093] The blockchain system 102 includes multiple distributed nodes. The blockchain system 102 uses a block chain data structure to verify and store data, uses a distributed node consensus algorithm to generate and update data, uses cryptographic technology to ensure the security of data transmission and access control, and uses smart contracts composed of automated script codes to program and operate data.
[0094] A distributed node can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. The client 101 and the blockchain system 102 can be connected directly or indirectly via wired or wireless communication, which is not limited in this application.
[0095] based on Figure 1 The system architecture diagram shown in FIG. 1 shows a process of a transaction verification method provided by the embodiment of the present application. Figure 2 As shown, the process of the method is interactively executed by the client 101 and the blockchain system 102, and includes the following steps:
[0096] In step 201, the client generates a transaction to be verified in response to a transaction request from a target account. The transaction to be verified includes: transaction content, target signature, and signature random number.
[0097] Specifically, the client responds to the target account's transaction request and first verifies whether the target account's identity is legitimate. Specific verification methods include but are not limited to: password verification, face recognition, and fingerprint recognition. When the target account's identity is determined to be legitimate, the client calls the target account's corresponding original private key d A , original public key P A =(x a ,y a ), where the relationship between the original private key and the original public key is: P A =d A *G, where G is the base point.
[0098] Get the transaction content M from the transaction request. The transaction content M is associated with the actual transaction. For example, if the transaction request is: Account A's contract address AddressA, transfers an amount of 100 to Account B's contract address AddressB, then the transaction content M = (AddressA (account minus 100), AddressB (account plus 100)).
[0099] The specific process of the client generating a signature random number is: randomly generate 256-bit random numbers k and r, and then generate a signature random number q = k + rp based on the random numbers k and r, where p is the curve public parameter (which can also be considered a random number).
[0100] In some embodiments, in response to a transaction request from a target account, the transaction content is signed based on the target account's original private key, the target account's original public key, and a signature random number to obtain a target signature. Then, based on the transaction content, the target signature, and the signature random number, a transaction to be verified is obtained.
[0101] Specifically, based on the signature random number and the coordinates of the known base point, the verification parameters are generated. In practical applications, the signature random number q and the coordinates of the known base point G (x G ,y G ) to generate the verification parameter Y, as shown in the following formula (1):
[0102] Y=qG=(x1,y1).............(1)
[0103] Where (x1, y1) represents the coordinate of the verification parameter Y.
[0104] Then, based on the public parameters, the coordinates of the known base point and the original public key, the encryption factor is generated. Specifically, the public parameters (IDA and ENTLA), the coordinates of the known base point G (x G ,y G ) and the original public key P A The coordinates (x a ,y a ) for splicing, and then input the splicing result into the SM3 algorithm for calculation to obtain the encryption factor ZA, which is specifically shown in the following formula (2):
[0105] ZA=SM3(IDA|ENTLA|x G |y G |x a |y a )....................(2)
[0106] The transaction content M is concatenated with the encryption factor ZA, and the result of the concatenation operation is hashed to obtain the target hash value e, as shown in the following formula (3):
[0107] e=Hv(ZA|M).............(3)
[0108] Among them, Hv is used to convert a string into a value on the elliptic curve number field.
[0109] Based on the horizontal coordinate x1 of the verification parameter Y and the target hash value e, the signature horizontal coordinate delta_r is determined, as shown in the following formula (4):
[0110] delta_r=(e+x1)mod n.............(4)
[0111] Where n is a positive integer. If delta_r = 0 or delta_r + q = n, then the signature random number q is regenerated.
[0112] Based on the original private key d A , the signature random number q and the signature horizontal coordinate delta_r, determine the signature vertical coordinate delta_s, as shown in the following formula (5):
[0113] delta_s=((1+d A ) -1 .(q-delta_r.d A ))mod n........................(5)
[0114] If delta_s=0, the signature random number q is regenerated.
[0115] Based on the signature horizontal coordinate delta_ and the signature vertical coordinate delta_s, the target signature (delta_r, delta_s) is determined. The target signature is two 256-bit random numbers.
[0116] In step 202, the client sends the transaction to be verified, including the transaction address, to the blockchain system.
[0117] Specifically, the transaction address is the contract address, and the transaction address is obtained by encoding the original public key, that is, AddressA==Encode(P A ).
[0118] In step 203, the blockchain system generates verification parameters based on the signature random number and the coordinates of the known base point.
[0119] Specifically, the blockchain system receives a transaction to be verified from the transaction address AddressA. The transaction to be verified includes: transaction content M', target signature (delta_r', delta_s') and signature random number q'.
[0120] It should be noted that if the transaction content is tampered with during the process of the client sending the transaction to be verified to the blockchain system, the transaction content M generated by the client will be different from the transaction content M' received by the blockchain system. If the transaction content is not tampered with, the transaction content M generated by the client will be the same as the transaction content M' received by the blockchain system.
[0121] Similarly, if the target signature has not been tampered with, the target signature (delta_r', delta_s') received by the blockchain system is the same as the target signature (delta_r, delta_s) generated by the client; if the target signature has been tampered with, the target signature (delta_r', delta_s') received by the blockchain system is different from the target signature (delta_r, delta_s) generated by the client.
[0122] If the signature random number is tampered with, the signature random number q generated by the client is different from the signature random number q' received by the blockchain system. If the signature random number is not tampered with, the signature random number q generated by the client is the same as the signature random number q' received by the blockchain system.
[0123] Multiply the signature random number q' and the coordinates of the known base point G to obtain the verification parameter Y', as shown in the following formula (6):
[0124] Y'=q'G=(x'1,y'1)............(6)
[0125] Wherein, (x'1, y'1) represents the coordinate of the verification parameter Y'.
[0126] In step 204, the blockchain system recovers the encrypted public key based on the verification parameters and the target signature.
[0127] Specifically, based on the target signature's abscissa delta_r' and the target signature's ordinate delta_s', a public key verification factor I is generated, as shown in the following formula (7):
[0128] I=(delta_r'+delta_s') -1 ....................(7)
[0129] Based on the signature ordinate delta_s' of the target signature, the public key verification factor I and the verification parameter Y', the encrypted public key is recovered, as shown in the following formula (8):
[0130] P' A =I(Y'-delta s '.G)=............(8)
[0131] To facilitate understanding of the principle of public key recovery, the derivation process is described as follows:
[0132] Multiplying both sides of formula (5) by the coordinates of the base point G yields the following formula (9):
[0133] delta_s.G=((1+d A ) -1 .(q-delta_r.d A )).G.........(9)
[0134] Multiply both sides of formula (9) by the parameter (1+d A ), we get the following formula (10):
[0135] delta_s.G+delta_s.d A .G=qG-delta_r.d A .G.........(10)
[0136] Since the relationship between the original public key and the original private key is: A =d A *G, based on this, the above formula (10) can be converted into the following formula (11):
[0137] delta_s.G+delta_s.P A =qG-delta_r.P A .........(11)
[0138] Furthermore, formula (11) can be adjusted to the following formula (12) for restoring the public key:
[0139] P A =( delta s +delta r ) -1 .(q.G-delta s .G) .........(12)
[0140] That is, this application combines the private key d A With public key P A The relationship between the original private key d A Generate the calculation formula of the signature vertical coordinate delta_s and reverse it to obtain the restored public key P A The calculation formula is that the original public key P can be restored through the target signature (delta_r, delta_s), the signature random number q and the base point G. ATherefore, after receiving the target signature (delta_r', delta_s') and the signature random number q' sent by the client, the blockchain system substitutes the target signature (delta_r', delta_s'), the signature random number q' and the base point G into the above formula (12) to recover the encrypted public key P' A .
[0141] In step 205, the blockchain system verifies the target signature based on the encrypted public key and the transaction content.
[0142] Specifically, first based on the encryption public key P' A And transaction content M', generate message digest Lambda.
[0143] In some embodiments, verification binding information is generated based on public parameters, coordinates of known base points, and encrypted public keys. Specifically, public parameters (IDA and ENTLA), coordinates of known base points G (x G ,y G ) and the encrypted public key P' A The coordinates (x' a , y' a ) for splicing, and then input the splicing result into the SM3 algorithm for calculation to obtain the verification binding information T, as shown in the following formula (13):
[0144] T=SM3(IDA|ENTLA|x G |y G |x' a |y' a ).........(13)
[0145] The transaction content M' is concatenated with the verification binding information T to obtain the transaction confirmation factor M*. The message digest algorithm Hv is used to convert the transaction confirmation factor M* into the message digest Lambda, as shown in the following formula (14):
[0146] Lambda=Hv(M*).........(14)
[0147] Among them, the transaction confirmation factor M*=T|M'.
[0148] Next, a first verification abscissa is generated based on the message digest and the signature abscissa of the target signature; and the abscissa of the verification parameter is used as a second verification abscissa.
[0149] Specifically, the above formula (4) describes the process of generating the signature horizontal coordinate delta_r. If the parameter e in formula (4) is set to the message digest Lambda and the parameter delta_r is set to the signature horizontal coordinate delta_r' in the received target signature, the first verification horizontal coordinate x'1' can be determined.
[0150] The abscissa x'1 of the verification parameter Y' obtained by the above formula (6) is used as the second verification abscissa.
[0151] If the first verification horizontal coordinate x'1' is consistent with the second verification horizontal coordinate x'1, the signature verification is successful, that is, the received target signature (delta_r', delta_s') is legal; it also means that the target signature has not been tampered with when the client sends the transaction to be verified to the blockchain system, and the target signature (delta_r', delta_s') received by the blockchain system is the same as the target signature (delta_r, delta_s) generated by the client.
[0152] If the first verification horizontal coordinate x'1' is inconsistent with the second verification horizontal coordinate x'1, the signature verification fails, that is, the received target signature (delta_r', delta_s') is illegal; it also means that the target signature was tampered with when the client sent the transaction to be verified to the blockchain system, and the target signature (delta_r', delta_s') received by the blockchain system is different from the target signature (delta_r, delta_s) generated by the client.
[0153] When the signature verification fails, it can be directly determined that the verification of the transaction to be verified has failed and the transaction can be rolled back.
[0154] In the embodiment of the present application, the first verification horizontal coordinate x'1' and the second verification horizontal coordinate x'1 are calculated, and by comparing whether the first verification horizontal coordinate x'1' is consistent with the second verification horizontal coordinate x'1, it is determined whether the target signature is tampered with in the process of the client sending the transaction to be verified to the blockchain system, thereby further improving the security of the transaction.
[0155] Step 206: When the signature verification passes, the blockchain system encodes the encrypted public key to obtain the reference address.
[0156] Specifically, the recovered encryption public key P' A Encode to obtain the reference address AddressA', that is, AddressA'=Encode(P' A ).
[0157] In step 207, if the reference address is consistent with the transaction address, the blockchain system determines that the transaction to be verified has passed verification.
[0158] Specifically, if the reference address AddressA' is consistent with the transaction address AddressA, then the recovered encrypted public key P' A is correct, that is, the encrypted public key P' A With the original public key P A are the same.
[0159] If the reference address AddressA' is consistent with the transaction address AddressA, it also indicates that the transaction to be verified is legal. Therefore, the transaction content of the transaction to be verified is executed.
[0160] If the reference address AddressA' is inconsistent with the transaction address AddressA, it means that the transaction to be verified is illegal, so the transaction is rolled back.
[0161] In the embodiment of the present application, the blockchain system receives a transaction to be verified with a transaction address sent by the client. The transaction to be verified includes: transaction content, target signature and signature random number. A is a two-dimensional coordinate, and the signature random number q = k + rp is a one-dimensional parameter. Therefore, compared with the existing technology of transmitting and storing the public key P A For example, this application transmits and stores the signature random number q, which can reduce the public key transmission and storage overhead by half, thereby reducing the occupied transmission and storage resources and improving the efficiency and performance of the blockchain system.
[0162] Based on the signature random number and the coordinates of the known base point, verification parameters are generated; based on the verification parameters and the target signature, the encrypted public key is recovered; and the target signature is verified based on the encrypted public key and the transaction content. If the signature verification passes, the encrypted public key is encoded to obtain the reference address; if the reference address matches the transaction address, the transaction is considered to have passed verification. In other words, the blockchain system uses multiple verification methods (signature verification and address verification) to determine the legitimacy of the transaction, thereby improving transaction security.
[0163] Based on the same technical concept, the embodiment of the present application provides a structural diagram of a transaction verification device, which is applied to a blockchain system, such as Figure 3 As shown, the transaction verification device 300 includes:
[0164] Receiving module 301, configured to receive a transaction to be verified with a transaction address sent by a client, the transaction to be verified including: transaction content, target signature, and signature random number;
[0165] A public key recovery module 302 is configured to generate a verification parameter based on the signature random number and the coordinates of a known base point; and to recover an encrypted public key based on the verification parameter and the target signature;
[0166] The signature verification module 303 is configured to perform signature verification on the target signature based on the encrypted public key and the transaction content; and when the signature verification passes, encode the encrypted public key to obtain a reference address;
[0167] The address verification module 304 is configured to determine that the transaction to be verified has passed verification if the reference address is consistent with the transaction address.
[0168] Optionally, the public key recovery module 302 is specifically configured to:
[0169] generating a public key verification factor based on the signature abscissa of the target signature and the signature abscissa of the target signature;
[0170] The encrypted public key is recovered based on the signature abscissa of the target signature, the public key verification factor, and the verification parameter.
[0171] Optionally, the signature verification module 303 is specifically configured to:
[0172] generating a message digest based on the encrypted public key and the transaction content;
[0173] generating a first verification abscissa based on the message digest and the signature abscissa of the target signature; and using the abscissa of the verification parameter as a second verification abscissa;
[0174] If the first verification horizontal coordinate is consistent with the second verification horizontal coordinate, the signature verification is successful;
[0175] If the first verification horizontal coordinate is inconsistent with the second verification horizontal coordinate, the signature verification fails.
[0176] Optionally, the signature verification module 303 is specifically configured to:
[0177] generating verification binding information based on the public parameters, the coordinates of the known base point, and the encrypted public key;
[0178] Performing a cascade operation on the transaction content and the verification binding information to obtain a transaction confirmation factor;
[0179] A message digest algorithm is used to convert the transaction confirmation factor into the message digest.
[0180] In an embodiment of the present application, a blockchain system receives a transaction to be verified from a client, including a transaction address. The transaction to be verified includes the transaction content, a target signature, and a signature random number. Because the original public key is a two-dimensional coordinate, while the signature random number is a one-dimensional parameter, the present application's transmission and storage of the signature random number can reduce the public key transmission and storage overhead by half compared to existing methods of transmitting and storing public keys, thereby reducing transmission and storage resources and improving the efficiency and performance of the blockchain system.
[0181] Next, verification parameters are generated based on the signature random number and the coordinates of the known base point. Furthermore, the encrypted public key is recovered based on the verification parameters and the target signature. The target signature is then verified based on the encrypted public key and the transaction content. If signature verification passes, the encrypted public key is encoded to obtain a reference address. If the reference address matches the transaction address, the transaction is deemed to have passed verification. The blockchain system in this application uses multiple verification methods (signature verification and address verification) to determine the legitimacy of the transaction, thereby improving transaction security.
[0182] Based on the same technical concept, the embodiment of the present application provides a structural diagram of a transaction verification device, which is applied to a client, such as Figure 4 As shown, the transaction verification device 400 includes:
[0183] A generation module 401 is configured to generate a transaction to be verified in response to a transaction request from a target account, wherein the transaction to be verified includes: transaction content, a target signature, and a signature random number;
[0184] The sending module 402 is used to send the transaction to be verified carrying the transaction address to the blockchain system, so that the blockchain system generates verification parameters based on the signature random number and the coordinates of the known base point; and restores the encrypted public key based on the verification parameters and the target signature; performs signature verification on the target signature based on the encrypted public key and the transaction content; when the signature verification passes, encodes the encrypted public key to obtain a reference address; if the reference address is consistent with the transaction address, it is determined that the verification of the transaction to be verified has passed.
[0185] Optionally, the generating module 401 is specifically configured to:
[0186] In response to a transaction request from a target account, signing the transaction content based on the original private key of the target account, the original public key of the target account, and the signature random number to obtain a target signature;
[0187] The transaction to be verified is obtained based on the transaction content, the target signature and the signature random number.
[0188] Optionally, the transaction address is a contract address, and the transaction address is obtained by encoding the original public key.
[0189] Optionally, the generating module 401 is specifically configured to:
[0190] generating a verification parameter based on the signature random number and the coordinates of the known base point;
[0191] generating an encryption factor based on public parameters, the coordinates of the known base point, and the original public key;
[0192] Performing a cascade operation on the transaction content and the encryption factor, and performing a hash operation on the result of the cascade operation to obtain a target hash value;
[0193] Determine the signature abscissa based on the abscissa of the verification parameter and the target hash value; and determine the signature ordinate based on the original private key, the signature random number and the signature abscissa;
[0194] The target signature is determined based on the signature abscissa and the signature ordinate.
[0195] In an embodiment of the present application, a blockchain system receives a transaction to be verified from a client, including a transaction address. The transaction to be verified includes the transaction content, a target signature, and a signature random number. Because the original public key is a two-dimensional coordinate, while the signature random number is a one-dimensional parameter, the present application's transmission and storage of the signature random number can reduce the public key transmission and storage overhead by half compared to existing methods of transmitting and storing public keys, thereby reducing transmission and storage resources and improving the efficiency and performance of the blockchain system.
[0196] Next, verification parameters are generated based on the signature random number and the coordinates of the known base point. Furthermore, the encrypted public key is recovered based on the verification parameters and the target signature. The target signature is then verified based on the encrypted public key and the transaction content. If signature verification passes, the encrypted public key is encoded to obtain a reference address. If the reference address matches the transaction address, the transaction is deemed to have passed verification. The blockchain system in this application uses multiple verification methods (signature verification and address verification) to determine the legitimacy of the transaction, thereby improving transaction security.
[0197] Based on the same technical concept, the embodiment of the present application provides a computer device, which can be Figure 1 The client and / or blockchain system shown, such as Figure 5 As shown, it includes at least one processor 501 and a memory 502 connected to the at least one processor. The specific connection medium between the processor 501 and the memory 502 is not limited in the embodiment of the present application. Figure 5For example, the processor 501 and the memory 502 are connected via a bus. The bus can be divided into an address bus, a data bus, a control bus, and the like.
[0198] In the embodiment of the present application, the memory 502 stores instructions that can be executed by at least one processor 501. The at least one processor 501 can perform the steps of the above-mentioned transaction verification method by executing the instructions stored in the memory 502.
[0199] The processor 501 is the control center of the computer device, connecting various components of the computer device using various interfaces and circuits. It performs transaction verification by running or executing instructions stored in the memory 502 and accessing data stored in the memory 502. Optionally, the processor 501 may include one or more processing units. The processor 501 may integrate an application processor and a modem processor. The application processor primarily processes the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into the processor 501. In some embodiments, the processor 501 and the memory 502 may be implemented on the same chip. In some embodiments, they may also be implemented on separate chips.
[0200] The processor 501 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit (ASIC), a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor.
[0201] The memory 502 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 502 may include at least one type of storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (Random Access Memory, RAM), a static random access memory (Static Random Access Memory, SRAM), a programmable read-only memory (Programmable Read Only Memory, PROM), a read-only memory (Read Only Memory, ROM), an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), a magnetic memory, a disk, an optical disk, etc. The memory 502 is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer device, but is not limited thereto. The memory 502 in the embodiment of the present application can also be a circuit or any other device that can realize a storage function, for storing program instructions and / or data.
[0202] Based on the same inventive concept, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program that can be executed by a computer device. When the program runs on the computer device, the computer device executes the steps of the above-mentioned transaction verification method.
[0203] Based on the same inventive concept, an embodiment of the present application provides a computer program product, which includes a computer program stored on a computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer device, the computer device executes the steps of the above-mentioned transaction verification method.
[0204] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0205] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as a combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer device or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0206] These computer program instructions may also be stored in a computer readable memory that can direct a computer device or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0207] These computer program instructions can also be loaded onto a computer device or other programmable data processing device so that a series of operating steps are executed on the computer device or other programmable device to produce a process implemented by the computer device, thereby providing instructions for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0208] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0209] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A transaction verification method, applied to a blockchain system, characterized in that: include: Receive a transaction to be verified with a transaction address from a client, including transaction content, target signature, and signature random number. generating a verification parameter based on the signature random number and the coordinates of a known base point; and generating a public key verification factor based on the signature abscissa of the target signature and the signature ordinate of the target signature; Recovering an encrypted public key based on the signature ordinate of the target signature, the public key verification factor, and the verification parameter; generating verification binding information based on the public parameters, the coordinates of the known base point, and the encrypted public key; Performing a cascade operation on the transaction content and the verification binding information to obtain a transaction confirmation factor; Using a message digest algorithm, converting the transaction confirmation factor into a message digest; generating a first verification abscissa based on the message digest and the signature abscissa of the target signature; and using the abscissa of the verification parameter as a second verification abscissa; If the first verification horizontal coordinate is consistent with the second verification horizontal coordinate, the signature verification is successful; When the signature verification passes, the encrypted public key is encoded to obtain a reference address; If the reference address is consistent with the transaction address, it is determined that the transaction to be verified has passed verification.
2. A transaction verification method, applied to a client, characterized in that: include: In response to a transaction request from a target account, generating a transaction to be verified, the transaction to be verified including: transaction content, a target signature, and a signature random number; Sending the transaction to be verified, including the transaction address, to a blockchain system, so that the blockchain system generates a verification parameter based on the signature random number and the coordinates of a known base point; and generating a public key verification factor based on the signature horizontal coordinate of the target signature and the signature vertical coordinate of the target signature; Recovering an encrypted public key based on the signature ordinate of the target signature, the public key verification factor, and the verification parameter; generating verification binding information based on the public parameters, the coordinates of the known base point, and the encrypted public key; Performing a cascade operation on the transaction content and the verification binding information to obtain a transaction confirmation factor; Using a message digest algorithm, converting the transaction confirmation factor into a message digest; generating a first verification abscissa based on the message digest and the signature abscissa of the target signature; and using the abscissa of the verification parameter as a second verification abscissa; If the first verification horizontal coordinate is consistent with the second verification horizontal coordinate, the signature verification is passed; when the signature verification is passed, the encrypted public key is encoded to obtain a reference address; if the reference address is consistent with the transaction address, it is determined that the verification of the transaction to be verified is passed.
3. The method according to claim 2, wherein The step of generating a transaction to be verified in response to a transaction request from a target account includes: In response to a transaction request from a target account, signing the transaction content based on the original private key of the target account, the original public key of the target account, and the signature random number to obtain a target signature; The transaction to be verified is obtained based on the transaction content, the target signature and the signature random number.
4. The method according to claim 3, wherein The transaction address is a contract address, and the transaction address is obtained by encoding the original public key.
5. The method according to claim 3, wherein The step of signing the transaction content based on the original private key of the target account, the original public key of the target account, and the signature random number to obtain the target signature includes: generating a verification parameter based on the signature random number and the coordinates of the known base point; generating an encryption factor based on public parameters, the coordinates of the known base point, and the original public key; Performing a cascade operation on the transaction content and the encryption factor, and performing a hash operation on the result of the cascade operation to obtain a target hash value; Determine the signature abscissa based on the abscissa of the verification parameter and the target hash value; and determine the signature ordinate based on the original private key, the signature random number and the signature abscissa; The target signature is determined based on the signature abscissa and the signature ordinate.
6. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of any one of the methods of claims 1 to 5 are implemented.
7. A computer-readable storage medium, characterized in that It stores a computer program that can be executed by a computer device. When the program is run on the computer device, the computer device executes the steps of any one of the methods described in claims 1 to 5.
Citation Information
Patent Citations
Method for restoring public key based on SM2 signature
CN111066285A
Method for recovering public key and address based on sm2 signature in block chain
CN112152814A