A cryptocurrency assisted regulation method based on keyword traffic identification

By simulating data packets and connecting to cryptocurrency network nodes, and extracting keyword features using communication protocols, the regulatory challenges in the anonymized environment of cryptocurrencies are solved, achieving efficient traffic identification and regulatory effects.

CN119067660BActive Publication Date: 2025-11-18BEIJING INST OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410983373.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-22
Publication Date
2025-11-18
Estimated Expiration
2044-07-22

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively regulate transactions in the anonymized environment of cryptocurrencies, failing to extract useful information from the blockchain ledger transaction level, resulting in coarse-grained and inaccurate regulation.

Method used

By simulating the connection between data packets and network nodes, and utilizing the communication protocols of cryptocurrencies, keyword features are extracted and traffic is identified. Combined with node connection and communication verification, efficient identification and supervision of cryptocurrency traffic can be achieved.

Benefits of technology

It enables efficient identification of cryptocurrency traffic, enhances the regulatory effectiveness of the regulatory platform, and improves the accuracy and efficiency of regulation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119067660B_ABST
    Figure CN119067660B_ABST
Patent Text Reader

Abstract

The application relates to a cryptocurrency auxiliary supervision method based on keyword traffic identification, and belongs to the technical field of blockchain supervision. The application combines data information of a blockchain network and a communication function of a network node, first collects traffic data, extracts keyword features in the traffic data according to a communication protocol, matches specific fields with categories of cryptocurrencies, and obtains a preliminary judgment result of categories corresponding to the traffic. Then, simulated data packets are created according to a communication protocol of a target cryptocurrency in the preliminary judgment, a connection is established with a target node, the data packets are sent, returned data packets are received and parsed, and key information in the returned data packets is analyzed to verify the judgment result and determine the type of the target node. The node and information thereof are stored in a database in a labeled manner, and the node label is continuously monitored and regularly updated. The application realizes efficient identification of cryptocurrency traffic, and enhances the supervision efficiency of a supervision platform on cryptocurrencies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a cryptocurrency-assisted regulatory method based on keyword traffic identification, belonging to the field of blockchain regulatory technology. Background Technology

[0002] The core foundation of cryptocurrency is blockchain technology, which is a distributed database that records transaction history through a chain-like block structure. It is a transparent, decentralized, and tamper-proof distributed ledger system.

[0003] Cryptocurrency networks have the following core features and functions:

[0004] 1. Decentralization: Cryptocurrency networks employ a distributed architecture, independent of any central authority (such as a central bank) for management and control. Transaction verification, currency issuance, and ledger maintenance are collaboratively performed by numerous participants (nodes) globally, connected through a peer-to-peer (P2P) network, forming a decentralized, autonomous system.

[0005] 2. Distributed Ledger: Blockchain technology is the core distributed ledger implementation method for cryptocurrencies. Transaction history is stored in a chain structure, with each block containing multiple transactions and linked to the hash value of the previous block through complex mathematical algorithms, ensuring data integrity and irreversibility. Each participating node also maintains a complete copy of the ledger.

[0006] 3. Consensus Mechanism: To ensure that all nodes in the network agree on the validity of transactions, cryptocurrency networks employ consensus algorithms such as Proof of Work (PoW) and Proof of Stake (PoS). These mechanisms ensure that only transactions approved by a majority of nodes are added to the blockchain, preventing double-spending and fraudulent activities.

[0007] 4. Node Communication and Network Configuration: In a cryptocurrency system, nodes interact with each other according to specific communication protocols, collectively constructing an organizational model that approximates a tree or network. This structural design not only facilitates the rapid dissemination of information and the achievement of consensus across the entire network, but also enhances the network's resistance to potential attacks and system failures to a certain extent.

[0008] 5. Security and Anonymity: Thanks to the inherent nature of its distributed architecture, the cryptocurrency system exhibits superior security performance. Tampering with its historical transaction data requires control of an absolute majority of nodes in the network, which is extremely difficult for a large-scale decentralized network. At the same time, although transaction details are publicly archived on the blockchain, cryptographic mechanisms still allow users a degree of anonymity or pseudonymous transactions.

[0009] 6. Incentive Mechanism: Cryptocurrency networks incentivize nodes to participate in transaction verification, block creation, and network maintenance through economic incentives (such as block rewards and transaction fees), forming a self-regulating and self-maintaining ecosystem.

[0010] While blockchain technology is renowned for its transparency, many cryptocurrencies have adopted privacy-enhancing measures. These clandestine transaction mechanisms, while ensuring the security of user transaction information, also provide space for illicit activities to conceal fund flows and information transmission, increasing the difficulty for regulatory agencies to identify and address potential risks. Existing technologies generally analyze account behavior at the ledger transaction level for regulatory identification; however, because blockchain achieves complete anonymity in ledger transactions, it is impossible to extract effective information from it, resulting in coarse-grained and low-accuracy regulatory techniques. In contrast, node information and traffic data in network traffic are public and abundant. Therefore, analyzing account behavior using network-level data provides a new approach for regulation.

[0011] Capturing network traffic at the network level and then using data analytics and machine learning to analyze that traffic and uncover account behavior information at the transaction level is a technologically promising approach. However, network traffic is vast and complex, making it necessary to identify cryptocurrency traffic to aid in the monitoring of cryptocurrency transactions and their scale within the blockchain. Summary of the Invention

[0012] The purpose of this invention is to solve the technical problem of how to capture and identify traffic in the anonymized environment of cryptocurrency transactions, and thus effectively supervise transactions. It creatively proposes a cryptocurrency-assisted supervision method based on keyword traffic identification.

[0013] This invention is based on a blockchain network and network nodes, providing network traffic data and data packet information respectively.

[0014] in:

[0015] Network traffic data: When a new transaction record is generated or a new block is encapsulated in the blockchain network, this information is broadcast instantly to all constituent nodes in the network. During this process, nodes engage in a series of interactions, including mutual authentication, synchronization of the latest block data, execution of on-chain state query commands, and timely responses to various external requests. These interactions form the basic framework of network communication, triggering and driving the continuous generation and efficient flow of data traffic within the blockchain network.

[0016] Network nodes: Nodes in a blockchain network have roles and functions such as data storage and verification, network maintenance and information dissemination, consensus participation and decision-making. Nodes can interact with each other through communication protocols conforming to the target cryptocurrency (such as handshakes, broadcasts, queries, and confirmations). Therefore, by simulating the construction of data packets and connecting and communicating with network nodes, the judgment results of keyword features can be further verified.

[0017] like Figure 1 As shown, the present invention includes steps such as traffic collection, feature extraction, creation of simulated data packets, connection establishment, parsing of data packets, data tagging and storage, continuous monitoring, and rapid communication verification.

[0018] A cryptocurrency-assisted regulatory method based on keyword traffic identification.

[0019] First, traffic data is collected. Keyword features are extracted based on the communication protocol, and specific fields are matched with cryptocurrency categories to obtain a preliminary judgment of the traffic category.

[0020] Then, based on the communication protocol of the target cryptocurrency initially identified, simulated data packets are created, a connection is established with the target node, data packets are sent, and the returned data packets are received and parsed. Key information within these packets is analyzed to verify the initial assessment and determine the type of the target node. Subsequently, this node and its information are tagged and stored in a database, with continuous monitoring and periodic updates to the node tags to facilitate rapid verification for subsequent traffic identification.

[0021] Beneficial effects

[0022] Compared with the prior art, the present invention has the following advantages:

[0023] This invention combines the data information of the blockchain network with the communication functions of network nodes, using protocol keyword features as a preliminary judgment indicator and node connections and communication as further verification and mining, thereby achieving efficient identification of cryptocurrency traffic and enhancing the regulatory effectiveness of regulatory platforms in supervising cryptocurrencies. Attached Figure Description

[0024] Figure 1 This is a schematic diagram of the traffic identification process of the present invention.

[0025] Figure 2 This is a flowchart of the method of the present invention.

[0026] Figure 3 This is a structural diagram of the traffic analysis related to this invention. Detailed Implementation

[0027] The method of the present invention will be further described in detail below with reference to the accompanying drawings.

[0028] like Figure 2 As shown, a cryptocurrency-assisted regulatory method based on keyword traffic identification includes the following steps:

[0029] Step 1: Traffic collection.

[0030] Traffic collection is the first step in implementing keyword-based cryptocurrency traffic identification technology. To provide downstream tasks with the most sufficient and accurate traffic data possible, various traffic collection methods can be employed to gather and integrate data from multiple sources.

[0031] Specifically, traffic collection can be carried out in the following ways:

[0032] Network sniffing: Using network sniffing tools, such as Wireshark, to capture data packets in the network, including encrypted cryptocurrency traffic.

[0033] Packet capture tools: Deploy packet capture tools, such as tcpdump or tshark, to capture network traffic in real time.

[0034] Log data: Log data generated by network devices (such as firewalls, routers, and switches), including cryptocurrency transaction and communication logs.

[0035] Step 2: Feature extraction.

[0036] For each data packet, key features are extracted, such as the network magic number (a fixed field used to identify the type of cryptocurrency to which the traffic belongs). By extracting and matching these fields, the currency type of the data packet is determined, providing a preliminary understanding of the cryptocurrency to which the corresponding traffic belongs. The data packet also contains address information of both parties in the communication, revealing the target network node's IP address and port.

[0037] Step 3: Create a mock data packet.

[0038] Keyword features such as the magic number provide initial category identification for traffic, but collision errors may still occur where network traffic that does not correspond to the cryptocurrency has the same data information as the magic number. Therefore, it is necessary to create simulated data packets and communicate with the target node for further verification and confirmation, and to implement node monitoring.

[0039] Specifically, the simulated data packets should possess characteristics consistent with the communication protocol of the target cryptocurrency to ensure a similar communication pattern with the target node. Taking the most widely used cryptocurrency as an example, its data packet format is as follows: Figure 3 As shown, it includes a message header and a data payload. The message header contains the magic number, instructions, data length, and checksum, while the data payload stores the main content of the message.

[0040] Creating a mock data packet involves the following specific steps:

[0041] Step 1: Protocol Analysis. First, study the target cryptocurrency's communication protocol specifications, including details such as message types, data packet formats, field structures, and communication behavior.

[0042] Step 2: Simulate packet structure. Based on the results of protocol analysis, create a simulated packet structure, including defining the content and format of the packet header, packet body, and packet trailer.

[0043] Step 3: Populate packet fields. According to the protocol specifications, populate the values ​​of the packet fields to simulate real interaction, ensuring that the simulated packets contain keyword characteristics related to the target cryptocurrency, such as network magic numbers.

[0044] Step 4: Data Packet Encoding. The simulated data packets are encoded into the format required by the target cryptocurrency's communication protocol. This is typically binary or hexadecimal encoding.

[0045] Step 4: Establish a connection.

[0046] Once the simulated data packets are created, the next step is to establish a connection to the target node. This includes creating a network node and establishing a network connection with the target node in order to send simulated data packets and receive responses.

[0047] Establishing a connection involves the following specific steps:

[0048] Step 1: Identify the target node. Determine the IP address and port number of the target node.

[0049] Since the IP address and port number of the network node associated with the current traffic have been recorded while capturing and parsing the network traffic in step 2, the nodes obtained by sniffing can be connected directly.

[0050] Step 2: Establish a network connection. Use network socket programming or communication libraries to establish a network connection to the target node, ensuring the stability and reliability of the connection.

[0051] Step 3: Send simulated data packets. Using the established network connection, send the created simulated data packets to the target node. The simulated data packets need to be sent to the target node's IP address and port number.

[0052] Step 4: Receive the response. Wait for the target node's response. Once the response packet is received, store it for subsequent analysis.

[0053] Step 5: Parse the data packet.

[0054] Once a response is received from the target node, the returned data packet needs to be parsed to extract information and characteristics about the traffic and the node.

[0055] Parsing the returned data packet includes the following specific steps:

[0056] Step 1: Packet Decoding. If the response packets are sent in a specific encoding (such as binary or hexadecimal), they must first be decoded to restore them to readable data.

[0057] Step 2: Data packet analysis. Analyze the returned data packets and extract key information, such as node type, version, and function.

[0058] Step 3: Feature Extraction. Extract features related to the target cryptocurrency, such as the network magic number and message type. Verify that the returned information follows the traffic format of the target cryptocurrency to verify the correctness of the traffic identification.

[0059] Step 4: Node Type Determination. Based on the parsing results, determine the type of the target node, such as whether it is a light node or a full node.

[0060] Step 6: Data tagging and storage.

[0061] The results of activity detection and currency type identification are associated with the corresponding node and traffic data, and stored in the database as node tag data along with their IP addresses to support subsequent communication verification of the same type of traffic.

[0062] Step 7: Continuous monitoring.

[0063] Establish a long-term and effective monitoring mechanism for the node data and its corresponding labels in the dataset. Develop a corresponding node monitoring program for the dataset to periodically scan the node activity in the sniffer and update the node labels in a timely manner.

[0064] Step 8: Quick communication verification.

[0065] By storing and continuously monitoring node tag data, the active nodes of the target cryptocurrency were preserved. When identifying the acquired traffic, after initial judgment using magic number keywords, communication connections were prioritized with nodes in the database, and the cryptocurrency traffic type identification results were verified through simulated data packets.

Claims

1. A cryptocurrency-assisted regulatory method based on keyword traffic identification, characterized in that, First, traffic data is collected, and keyword features are extracted based on the communication protocol. Specific fields are then matched with cryptocurrency categories to obtain a preliminary judgment result on the traffic category. Next, simulated data packets are created based on the communication protocol of the target cryptocurrency, and a connection is established with the target node. Data packets are sent, and the returned data packets are received and parsed to analyze key information, thereby verifying the judgment result and determining the type of the target node. Afterward, this node and its information are tagged and stored in the database, and the node tags are continuously monitored and updated periodically. Step 1: Collect traffic data; Step 2: Feature extraction; For each data packet, extract its keyword features; By extracting and matching these fields, the currency type of the data packet can be determined, and the type of encrypted digital currency to which the corresponding traffic belongs can be preliminarily known. The data packet contains the address information of both parties in the traffic communication, which allows us to know the IP address and port of the target network node; Step 3: Create a mock data packet; the mock data packet should have characteristics consistent with the communication protocol of the target cryptocurrency to ensure a similar communication pattern with the target node; Step 4: Establish a connection; After creating the simulated data packet, a connection to the target node needs to be established, including creating a network node and establishing a network connection with the target node in order to send the simulated data packet and receive the response; Step 5: Parse the data packet; Upon receiving a response from the target node, the returned data packet is parsed to extract information and characteristics about the traffic and the node. Step 6: Data tagging and storage; The results of activity detection and currency type identification are associated with the corresponding nodes and traffic data, and stored in the database as node tag data along with their IP addresses to support subsequent communication verification of the same type of traffic. Step 7: Continuous monitoring; Establish a monitoring mechanism for node data and its corresponding labels in the dataset; write a matching node monitoring program for the dataset to regularly scan the node activity in the sniffer and update the node labels in a timely manner. Step 8: Quick communication verification; Active nodes containing the target cryptocurrency are stored and continuously monitored through the storage of node tag data; When identifying the acquired traffic, after a preliminary judgment based on the magic number keywords, a communication connection is first established with the nodes in the database, and the identification result of the cryptocurrency traffic type is verified by simulating data packets.

2. The cryptocurrency-assisted regulatory method based on keyword traffic identification as described in claim 1, characterized in that, In step 1, the collection methods include network sniffing, packet capture tools, and log data; The log data includes cryptocurrency transaction and communication logs.

3. The cryptocurrency-assisted regulatory method based on keyword traffic identification as described in claim 1, characterized in that, Step 3 involves creating a simulated data packet, including the following steps: Step 1: Protocol Analysis; Study the communication protocol specifications of the target cryptocurrency, including details on message types, packet formats, field structures, and communication behavior; Step 2: Simulate packet structure; Based on the results of protocol analysis, create a simulated packet structure, including defining the content and format of the packet header, packet body, and packet trailer; Step 3: Populate data packet fields; According to the protocol specification, populate the values ​​of the data packet fields to simulate real interaction and ensure that the simulated data packet contains keyword features related to the target cryptocurrency; Step 4: Data packet encoding; Encode the simulated data packets into the format required by the target cryptocurrency's communication protocol.

4. The cryptocurrency-assisted regulatory method based on keyword traffic identification as described in claim 1, characterized in that, Step 4 includes the following steps: Step 1: Identify the target node, including determining its IP address and port number; Step 2: Establish a network connection; Use network socket programming or a communication library to establish a network connection to the target node; Step 3: Send simulated data packets; using the established network connection, send the created simulated data packets to the target node; the simulated data packets need to be sent to the target node's IP address and port number; Step 4: Receive response; wait for the target node's response, and store it once the response data packet is received.

5. A cryptocurrency-assisted regulatory method based on keyword traffic identification as described in claim 1, characterized in that, Step 5 includes the following steps: Step 1: Data packet decoding; If the response data packet is sent in a specific encoding method, it is first decoded to restore it to readable data; Step 2: Data packet analysis; Analyze the returned data packets and extract key information, including node type, version, and function; Step 3: Feature extraction; extract features related to the target cryptocurrency; verify whether the information is returned in the traffic format of the target cryptocurrency to verify whether the traffic is correctly identified; Step 4: Based on the parsing results, determine the type of the target node.

Citation Information

Patent Citations

  • Lightweight Ethereum encrypted traffic identification method

    CN111865823A

  • Cryptocurrency network mining flow detection method

    CN116668053A