A Decentralized Method for Constructing Rollup Sequencers
By implementing the decentralized construction method on the L1 and L2 layers of the Rollup sorter, the decentralization of the Rollup capacity expansion technology is solved, the decentralization degree and security of the system are improved, and the legality of transactions and the stability of the system are ensured.
Patent Information
- Application Number
- CN202411517253.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-29
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2044-10-29
AI Technical Summary
The existing Rollup expansion technology has flaws in decentralization, resulting in insufficient decentralization of the system, resulting in security problems such as denial of service and single point failure.
The decentralized Rollup sorter construction method is adopted, and multiple smart contracts are deployed on the L1 layer and the improved WRR algorithm is adopted on the L2 layer, combining trusted random numbers and linear mapping technology, multiple proposers are screened, and the legality of transaction blocks is ensured through competition process and voting audits.
The degree of decentralization and security of the system are improved. Through the pledge bucket mechanism and mapping and randomization factors, the probability of post-weighted collision is reduced, ensuring the security of transactions and the stable operation of the system.
Smart Images

Figure CN119313346B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of constructing Rollup sequencers, and particularly to a method for constructing a decentralized Rollup sequencer. Background Art
[0002] For off-chain scaling, early solutions were state channels and sidechains. Although these two solutions have been around for a long time, their development has been relatively slow. The root cause is the issue of data availability. Because in both state channels and sidechains, the complete transaction records and witness data are only stored off-chain. When a transaction dispute occurs, if the participants do not provide the correct transaction and witness data in a timely manner, the security of the transaction cannot be guaranteed, resulting in the problem of "data unavailability". Rollup scaling can effectively solve the data availability problem.
[0003] The basic principle of Rollup is to aggregate and package a large number of transaction data originally scattered in blocks into one transaction and publish it on the chain, thereby reducing the difficulty of verifying transaction validity. The chain submits the packaged transaction data block as a parameter to the contract, and the contract accounts for each participant after verifying the data is valid. This is equivalent to executing a batch of off-chain transactions at once, but only one transaction is executed on the chain. Although Rollup technology is an effective way to solve the blockchain scalability problem, it still has significant drawbacks in terms of decentralization. The decentralized nature is the core feature that differentiates blockchain from Web2.0 networks, but most of the currently launched Rollup chains adopt centralized sequencers and zero-knowledge proof schemes that require trusted settings, resulting in insufficient decentralization of the system and bringing a series of security problems, such as denial of service and single point of failure. Summary of the Invention
[0004] The purpose of this application is to provide a method for constructing a decentralized Rollup sequencer to solve the problem of insufficient decentralization of the system.
[0005] To achieve the above object, this application provides the following solution:
[0006] In a first aspect, this application provides a method for constructing a decentralized Rollup sequencer, including:
[0007] Deploying multiple smart contracts at the L1 layer of the decentralized Rollup sequencer; the smart contracts are used to execute transaction verification, generate trusted random numbers, manage challenges, and reward mechanisms;
[0008] In the L2 layer of the decentralized Rollup sorter, an improved WRR algorithm is used, and in combination with the trusted random number generated by the L1 layer, a linear mapping technology is used to screen multiple proposers; the improved WRR algorithm introduces a pledge bucket mechanism as well as mapping and randomization factors;
[0009] Use multiple proposers to package and sort the L2 layer transactions, determine the transaction blocks, and select the final proposer through a competition process;
[0010] The transaction block generated by the final proposer is submitted to the remaining proposers for voting and review, and multiple candidates monitor the operations of all proposers;
[0011] When it is found that the transaction block submitted by the final proposer to the L2 layer is illegal, the suspicious label mechanism is used to identify the illegal transaction block, and the transaction with the suspicious label is rolled back to the L1 layer for review, so that the candidate can challenge the final proposer through the challenge mechanism.
[0012] In a second aspect, the present application provides a decentralized Rollup sorter construction device, including:
[0013] The L1 layer of the decentralized Rollup sequencer is used to deploy multiple smart contracts; the smart contracts are used to perform transaction verification, generate trusted random numbers, manage challenges and reward mechanisms;
[0014] The L2 layer of the decentralized Rollup sorter is used to adopt the improved WRR algorithm, and in combination with the trusted random number generated by the L1 layer, the linear mapping technology is used to screen multiple proposers; the improved WRR algorithm introduces the pledge bucket mechanism as well as mapping and randomization factors;
[0015] Use multiple proposers to package and sort the L2 layer transactions, determine the transaction blocks, and select the final proposer through a competition process;
[0016] The transaction block generated by the final proposer is submitted to the remaining proposers for voting and review, and multiple candidates monitor the operations of all proposers;
[0017] When it is found that the transaction block submitted by the final proposer to the L2 layer is illegal, the suspicious label mechanism is used to identify the illegal transaction block, and the transaction with the suspicious label is rolled back to the L1 layer for review, so that the candidate can challenge the final proposer through the challenge mechanism.
[0018] In a third aspect, the present application provides a computer device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the computer program to implement the decentralized Rollup sequencer construction method described in any one of the above.
[0019] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the decentralized Rollup sequencer construction method described in any one of the above.
[0020] In a fifth aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the decentralized Rollup sequencer construction method described in any one of the above.
[0021] According to the specific embodiments provided by the present application, the following technical effects are disclosed:
[0022] The present application makes two improvements to the Weighted Round Robin (WRR) algorithm. One is to set up a staking bucket, allowing each participant to stake their own tokens and setting a reasonable upper limit for the staking bucket to ensure that most users can participate in the block production process, improving the decentralization level of the system and the enthusiasm of participants. The other is to add mapping and random elements to the WRR algorithm, introducing random values and mapping user weights to a larger range, reducing the probability of collisions after weighting, and improving the unpredictability of the elected person in the next round, thus greatly improving the degree of decentralization; using the improved WRR algorithm and combining with the trusted random number generated by the L1 layer, adopting linear mapping technology, screening multiple proposers to package and sort the transactions in the L2 layer, selecting the final proposer, and using the remaining proposers who are not selected to vote and review the transaction block generated by the final proposer. To ensure the security and reliability of decentralization, other candidates monitor the operations of all proposers in real time, especially timeout behaviors, to prevent proposers from abusing their rights or submitting illegal transactions; when it is found that the transaction block submitted by the final proposer to the L2 layer is illegal, the suspicious label mechanism is used to identify the illegal transaction block, and the transaction with the suspicious label is rolled back to the L1 layer for review, thus motivating more candidates to actively challenge suspicious transactions, and enabling the candidates to initiate challenges to the final proposer through the challenge mechanism to ensure the transaction security of the L2 layer and the stable operation of the overall system. Through the double-layer architecture of the decentralized Rollup sequencer, the present application effectively utilizes the security and decentralization characteristics of the L1 layer, and at the same time realizes the decentralized sorting ability in the L2 layer, thereby improving the overall decentralization degree of the system. Description of the Drawings
[0023] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0024] Figure 1 Flowchart of a method for constructing a decentralized Rollup sequencer in an embodiment of the present application;
[0025] Figure 2 Schematic diagram of the election phase process provided in an embodiment of the present application;
[0026] Figure 3 Schematic diagram of the WRR algorithm provided in an embodiment of the present application;
[0027] Figure 4 Schematic diagram of the execution phase process provided in an embodiment of the present application. Detailed implementation manners
[0028] The following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0029] To make the above objects, features, and advantages of the present application more obvious and understandable, the following further details the present application in conjunction with the drawings and specific implementation manners.
[0030] The embodiments of the present application provide a method for constructing a decentralized Rollup sequencer, which is executed by a computer device. Specifically, it can be executed alone by a computer device such as a terminal or a server, or jointly executed by a terminal and a server. In the embodiments of the present application, as Figure 1 shown, the method includes the following steps.
[0031] S1: Deploy multiple smart contracts on the L1 layer of the decentralized Rollup sequencer; the smart contracts are used to execute transaction verification, generate trusted random numbers, manage challenges, and reward mechanisms.
[0032] S2: On the L2 layer of the decentralized Rollup sequencer, adopt an improved WRR algorithm, and in combination with the trusted random numbers generated by the L1 layer, adopt a linear mapping technique to screen multiple proposers; a pledge bucket mechanism and mapping and randomization factors are introduced in the improved WRR algorithm.
[0033] S3: Use multiple proposers to separately package and sort the transactions in the L2 layer, determine the transaction block, and select the final proposer through a competition process.
[0034] S4: Submit the transaction block generated by the final proposer to the remaining proposers for voting review, and have multiple candidates monitor the operations of all proposers.
[0035] S5: When it is found that the transaction block submitted by the final proposer to the L2 layer is illegal, use the suspicious label mechanism to identify the illegal transaction block, roll back the transaction with the suspicious label to the L1 layer for review, and let the candidate initiate a challenge to the final proposer through the challenge mechanism.
[0036] In an exemplary embodiment, an improved WRR algorithm is adopted, and combined with the trusted random number generated by the L1 layer, a linear mapping technique is used to screen multiple proposers, specifically including: in the election stage, perform a linear mapping process on multiple groups of the pledge buckets using the linear mapping technique to determine the current weight corresponding to the mapped pledge buckets; each group of pledge buckets includes the token amounts pledged by multiple candidates; in each round of the consensus process, combine the trusted random number, and update the current weight according to the public key of the user and the pledge bucket sequence to determine the final weight corresponding to each group of pledge buckets; determine the weight of each candidate according to the final weight, and use the candidate with the highest weight as the proposer; there are 3 proposers.
[0037] Further, in the election stage, as Figure 2 shown, the core of Tendermint's WRR algorithm is that first, candidates need to pledge a certain amount of tokens, and the weight of each candidate is determined according to the amount of tokens they pledge. In each round of the consensus process, the candidate with the highest weight will be selected as the proposer. For candidates who fail to be selected as proposers, their weights will be accumulated according to their own weights and the newly added pledged token amounts to ensure a greater chance of being selected in the next round, which can be expressed as:
[0038]
[0039] Among them, the pledged token amount is represented by S, the weight is represented by W, and an example of the rotation of each round is as Figure 3 shown.
[0040] Although Tendermint's WRR algorithm can ensure the fairness of the election process, the strategy is too simple and it is easy for malicious actors to predict the next elected person, which may lead to attacks on the elected person, such as Distributed Denial of Service (DDos) attacks and eclipse attacks, etc.
[0041] This application has made two optimizations to the WRR algorithm. One is to introduce the pledge bucket mechanism, that is, the total personal pledge amount is divided into multiple parts, and each pledge is processed separately. The other is to add mapping and randomization factors to the WRR algorithm.
[0042] First of all, in the design of the pledge bucket, compared with the maximum candidate number limit of 300 people in the Cosmos network, the Rollup network can achieve a higher degree of decentralization. This is mainly due to the security guarantee provided by the open architecture of Rollup and the on-chain challenge mechanism. Under this mechanism, each participant can pledge their tokens and set a relatively reasonable upper limit for the pledge bucket. The upper limit value is 4 to 5 times the cost of going on-chain, which is used for compensation and fund confiscation in the penalty stage. The pledge amount participating in the candidates needs to fill at least one pledge bucket. In this way, even if there is a rollback, a considerable part of the compensation can be paid after covering the cost. When the user's pledge amount exceeds this upper limit, the excess part will be filled into a new pledge bucket until the remaining amount is not enough to fill it again. Since the participation cost is reduced, more users can be motivated to participate. Compared with the traditional scheme where only oligarchs with a large amount of funds can participate, the degree of decentralization is improved.
[0043] Such a design ensures that in the WRR process, most users can actually participate in the block production process. Compared with the pure random mechanism, the expected value for users to obtain qualifications is higher, and this expected value will gradually increase with the increase of rounds, thus further stimulating the enthusiasm of participants.
[0044] Correspondingly, to ensure the effective operation of the system and the implementation of the penalty mechanism, a certain pledge lower limit is set. This lower limit needs to be higher than three times the cost of a single transaction on Rollup going on-chain, which is used as a necessary guarantee for implementing basic penalty measures. The detailed reward and punishment mechanism will be elaborated in the subsequent penalty stage. This mechanism not only improves the decentralization level of the system but also ensures the stability and security of the system.
[0045] Aiming at the potential defects of the WRR algorithm of Tendermint, in order to ensure the unpredictability of the elected person in the next round, we propose an improvement plan, that is, introducing a random value into the algorithm. In addition, considering that the introduction of the pledge bucket system and the low-threshold participation mechanism may lead to an increase in the number of participants in each round, in order to reduce the probability of collision after weighting, we map the weights of users to a larger range and then calculate the weights. This random value will float within the range of 1 to 2 times the original weight. Also, because the floating range is large, it makes it possible for candidates with lower weights to exceed candidates with higher weights after adding the random number, resulting in the situation that candidates with lower weight rankings exceed candidates with higher rankings after adding the random value. The seed of the random number is provided by the L1 layer.
[0046] The specific plan is as follows:
[0047] 1) Data mapping: Assume that there is a set of pledge buckets S = {s1, s2, ..., s n}, and s i <δ, where S i is the number of tokens in each staking bucket, and each corresponds to a real user. δ is the upper limit of the staking bucket. We linearly map S to [0, 2 160 -1]:
[0048]
[0049] The mapped data is stored in a new 256-bit space T = {x1, x2, ..., x n}, and the weight W of the kth round will be saved k ={w1, w2, ..., w n}, n represents the number of rounds, when k is equal to 1, there is x i =w i Among them, w i Indicates the current weight value corresponding to each pledge bucket, x i Indicates that the initial pledge bucket set is mapped to [0,2 160 -1] The corresponding value after the interval.
[0050] 2) Generate random numbers. The random number seed r is provided by the L1 layer and is automatically refreshed after each block submission or timeout. The seed will be saved for one week for verification. i Will be with the user's public key Pub i Related to the bucket sequence i, it can be expressed as:
[0051] r i =x i +[SHA256(r+Pub i +i)mod x i ]
[0052] The final remainder is to ensure that each increase value cannot exceed twice the initial weight. The maximum value can only be equal to [0,2 160 -1].
[0053] 3) Finally, the final weight value is obtained for each bucket i:
[0054]
[0055] If the weights obtained are equal, their respective r i Substitute the value into r in step 2) and calculate again until no collision occurs.
[0056] This application lowers the participation threshold. The more participants there are, the higher the degree of decentralization, and it does not reduce security, ensuring fairness.
[0057] Moreover, this application will select three proposers instead of one during the election phase, and their roles will be reflected in the execution phase.
[0058] In an exemplary embodiment, multiple proposers are used to package and sort the transactions at the L2 layer respectively, determine the transaction block, and filter out the final proposer through a competition process, specifically including: Competition process: In the execution phase, let 3 proposers package and sort the transactions at the L2 layer respectively, determine the transaction block, and send the fairness proof to the remaining proposers; the fairness proof includes the public key of the proposer and the size of the corresponding transaction block containing the transaction; in the OP scheme, the proof is the state transition Merkle root; in the ZK scheme, the proof is a zero-knowledge proof; The transaction block with the largest number of transactions is used as the pre-submission block, and the proposer corresponding to the pre-submission block is used as the final proposer.
[0059] In an exemplary embodiment, the transaction block generated by the final proposer is submitted to the remaining proposers for vote review, specifically including: Vote review process: Let the remaining proposers conduct a legality check on the transaction block generated by the final proposer and vote; during the voting process, if there is an opposing vote, mark the transaction block generated by the final proposer with a suspicious label, and roll back the transaction with the suspicious label to the L1 layer for review.
[0060] Aiming at the limitations of existing Rollup scaling technologies, this application is committed to the research of decentralized sequencers to enhance the decentralization ability of Rollup, ensure the integrity and reliability of data, draw inspiration from Tendermint, and combine the characteristics of Rollup itself to achieve the decentralization of the sequencer in a relatively clear and simple way. This application innovatively proposes the "suspicious label" function to support the rapid rollback of incorrect batches. This architecture aims to improve the overall efficiency of the L2 layer network, effectively make up for the deficiencies of existing systems in terms of performance, and provide strong technical support for the further development of blockchain technology.
[0061] In an exemplary embodiment, after submitting the transaction block generated by the final proposer to the remaining proposers for vote review, it further includes: If during the competition process, a proposer who packages and sorts the transactions at the L2 layer has a timeout behavior, remove this proposer from the proposer queue, and let the remaining 2 proposers package and sort the transactions corresponding to this proposer; If during the vote review process, if the remaining 2 proposers have a timeout behavior, remove this proposer from the proposer queue.
[0062] Furthermore, in the execution phase, in the Tendermint consensus mechanism, a proposer is usually elected, and other validators are responsible for participating in the voting process. However, the Rollup solution is not designed to follow this model, mainly because of the "double guarantee" provided by the on-chain challenge mechanism. Therefore, in the off-chain processing of Rollup, more attention should be paid to efficiency and decentralization characteristics. Usually, to achieve Byzantine Fault Tolerance (BFT) consensus, at least three proposers are required to participate in the consensus process.
[0063] The reason for determining it as three, rather than two or more, is that we should not forget that the essence of introducing Rollup is to expand capacity. This can effectively ensure that users can obtain better security guarantees with as few transaction fees as possible. And with three nodes producing blocks in parallel, it can ensure that the system can still operate normally and maintain consistency in the case of possible failures of some nodes. The execution phase process is as Figure 4 shown.
[0064] Step 1): The three proposers respectively package and sort the blocks and send the proofs to the other proposers. This proof is the state transition Merkle root in the Optimistic Rollup (OP) solution and the corresponding zero-knowledge proof in the ZK (Zero Knowledge) solution.
[0065] The block with the largest number of transactions is used as the pre-committed block. If the numbers are the same, the one with the highest weight in the election phase is selected. This kind of healthy competition can effectively improve the motivation of proposers to include transactions. Of course, transactions that have not been included for multiple epochs will be forced to be included in the block. Then, the selector will add the public key of each proposer and the size of the corresponding included block as a fairness proof to the pre-committed block, and then send the pre-committed block to all proposers.
[0066] Step 2): Since the selected proposer will not vote against the block it proposed, mainly the other two proposers act as validators to perform strict legality verification on the block and conduct the voting process. If there are any opposing votes, whether one or two, the block will be labeled as "suspicious" and immediately submitted to the L1 layer for further review.
[0067] For proposers who fail to respond within the specified time, they will enter the penalty process. For those who time out in step 1), they will be removed from the proposer queue and will not enter step 2. The block generation will be completed by the remaining proposers. The processing for step 2 is similar, but since the proposer who pre-submitted the block in step 1 may have timed out, in addition to removing the proposer who has timed out, the voting process needs to be re-executed. If the last chaining process times out or the three proposers all time out in the first two responses, a new round of block proposer election process will be started immediately after the penalty to ensure the continuous operation and stability of the system.
[0068] In an exemplary embodiment, during the challenge phase of the OP solution, blocks with a "suspicious" label can effectively motivate participants to challenge. Such problematic blocks are usually challenged in the shortest possible time. Once the challenge is successful, the penalty process for the proposer will be initiated, and the L2 layer transaction will be rolled back. However, if the challenge fails or no challenge occurs after the seven-day challenge period, the penalty process for the participants who voted against will be initiated.
[0069] The challenge will occur in the L1 smart contract. If the challenge interface is called, the transaction Merkle root provided by the L2 layer will be used to simulate the transaction process. If the execution result is inconsistent with the submitted content, the proposer is considered to have acted maliciously, and the challenge is successful. Otherwise, the challenge is considered to have failed.
[0070] In an exemplary embodiment, the candidate is made to challenge the final proposer through a challenge mechanism, and then further comprises: triggering a penalty phase in the execution phase and the challenge phase; wherein, in the execution phase, punishing the proposer with timeout behavior, including: destroying all the pledges of the proposer with timeout behavior, and adding users whose pledge amount is less than the upper limit of the pledge bucket to the blacklist; confiscating the pledge tokens of users whose pledge amount is greater than the upper limit of the pledge bucket, and the penalty amount increases linearly with the accumulation of timeouts.
[0071] During the challenge phase, if the challenger succeeds in the challenge, the staked tokens of the proposer of the pre-submitted block and the proposer who voted in favor will be confiscated, and the confiscated staked tokens will be used to pay the fees of the L1 layer and distributed to the challenger and the proposer who voted against. If the challenger fails in the challenge or no challenge occurs after the challenge period, the staked tokens of the proposer who voted against will be confiscated.
[0072] Furthermore, in the penalty stage, the penalty stage is mainly triggered in the execution stage and the challenge stage. In the execution stage, when a response timeout occurs, the penalty process will be triggered. For users who time out in the first and second steps, all their pledges will be destroyed. For users with a pledge amount less than δ, they will be considered to not have sufficient hardware conditions to run and produce blocks, and will be added to the blacklist and no longer allowed to pledge. Users with a pledge amount greater than δ will have δ units of tokens confiscated, and as the number of timeouts accumulates, the penalty amount will increase linearly. For the timeout in the final process of uploading to the chain, half of the pledge amount will be confiscated, and the other half will be used as compensation for the computing costs paid by the other two proposers and their weights will be reset to zero.
[0073] In the challenge stage, once the challenge is successful, the proposer of the block and the participants who voted in favor will face the confiscation of their pledged tokens. These tokens will be used to pay the fees of Layer 1. Half of the remaining part will be distributed to the challenger and the participants who voted against, and the other half will be confiscated. For a failed challenge or if there is no challenge after seven days of the challenge period, the participants who voted against will face the confiscation of their pledged tokens, and the confiscated tokens will be distributed to the proposer and the participants who voted in favor.
[0074] In the ZK scheme, after the on-chain verification process is completed, the above reward and punishment measures can be directly implemented according to the verified status. This economic incentive mechanism aims to encourage honest participants to continuously participate, maintain the vitality of the community, and effectively prevent Sybil attacks while ensuring the degree of decentralization.
[0075] In scenarios such as data trading, supply chain finance, and data element circulation, the decentralized Rollup sequencer construction method of this application, that is, the decentralized expansion method, can significantly improve the system performance and the level of decentralization. In the traditional process, transactions often need to be collected, sorted, and packaged by centralized operators, which is prone to form a centralized bottleneck in the blockchain environment, bringing risks such as delayed processing and arbitrage operations. Through the Layer 2 expansion technology, this application will greatly reduce the access threshold for directly participating in transactions, attract more participants, and ensure the fairness and diversity of transaction nodes. At the same time, relying on the distributed ledger and multi-node verification architecture with blockchain as the underlying technology, the expansion solution can more effectively support the needs of multi-business systems, so as to better serve decentralized applications such as data exchange and financial settlement, improve the overall security, and enhance the community activity.
[0076] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0077] In this text, specific examples are used to illustrate the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. At the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A decentralized Rollup sequencer construction method, characterized in that: The decentralized Rollup sequencer construction method includes: Deploy multiple smart contracts on the L1 layer of the decentralized Rollup sorter; the smart contracts are used to perform transaction verification, generate trusted random numbers, manage challenges and reward mechanisms; In the L2 layer of the decentralized Rollup sorter, an improved WRR algorithm is used, and in combination with the trusted random number generated by the L1 layer, a linear mapping technology is used to screen multiple proposers, including: In the election phase, linear mapping technology is used to perform linear mapping processing on multiple groups of pledge buckets to determine the current weights corresponding to the mapped pledge buckets; each group of pledge buckets includes the amount of tokens pledged by multiple candidates; In each round of consensus, the current weight is updated according to the user's public key and the pledge bucket sequence in combination with the trusted random number to determine the final weight corresponding to each group of pledge buckets; The weight of each candidate is determined according to the final weight, and the candidate with the highest weight is used as the proposer; the proposers include 3 persons; the pledge bucket mechanism and mapping and randomization factors are introduced into the improved WRR algorithm; Multiple proposers are used to package and sort the L2 layer transactions, determine the transaction blocks, and select the final proposer through a competitive process, including: Competition process: In the execution phase, three proposers are ordered to package and sort the L2 layer transactions respectively, determine the transaction block, and send the fair proof to the remaining proposers; the fair proof includes the proposer's public key and the size of the corresponding transaction block; in the OP scheme, the proof is the state transition Merkle root; in the ZK scheme, the proof is a zero-knowledge proof; The transaction block with the largest number of transactions is used as the pre-submitted block, and the proposer corresponding to the pre-submitted block is used as the final proposer; The transaction block generated by the final proposer is submitted to the remaining proposers for voting and review, and multiple candidates monitor the operations of all proposers; When it is found that the transaction block submitted by the final proposer to the L2 layer is illegal, the suspicious label mechanism is used to identify the illegal transaction block, and the transaction with the suspicious label is rolled back to the L1 layer for review, so that the candidate can challenge the final proposer through the challenge mechanism.
2. The decentralized Rollup sequencer construction method according to claim 1, characterized in that: Submit the transaction block generated by the final proposer to the remaining proposers for voting and review, including: Voting review process: The remaining proposers are required to verify the legitimacy of the transaction block generated by the final proposer and vote; During the voting process, if there is a negative vote, the transaction block generated by the final proposer will be marked with a suspicious label, and the transaction with the suspicious label will be rolled back to the L1 layer for review.
3. The decentralized Rollup sequencer construction method according to claim 2, characterized in that: The transaction block generated by the final proposer is submitted to the remaining proposers for voting and review, followed by: If, during the competition process, a proposer who packages and sorts the transactions at the L2 layer times out, the proposer will be removed from the proposer queue, and the transactions corresponding to the proposer will be packaged and sorted by the remaining two proposers; If during the voting review process, the remaining two proposers have timed out, the proposer will be removed from the proposer queue.
4. The decentralized Rollup sequencer construction method according to claim 3 is characterized in that: The candidate is instructed to challenge the final proposer through a challenge mechanism, and then: The penalty phase is triggered during the execution phase and the challenge phase; in the execution phase, the proposer with timeout behavior is punished, including: destroying all the pledges of the proposer with timeout behavior, and adding users whose pledge amount is less than the upper limit of the pledge bucket to the blacklist; confiscating the pledged tokens of users whose pledge amount is greater than the upper limit of the pledge bucket, and the penalty amount increases linearly with the accumulation of timeouts; During the challenge phase, if the challenger succeeds in the challenge, the staked tokens of the proposer of the pre-submitted block and the proposer who voted in favor will be confiscated, and the confiscated staked tokens will be used to pay the fees of the L1 layer and distributed to the challenger and the proposer who voted against. If the challenger fails in the challenge or no challenge occurs after the challenge period, the staked tokens of the proposer who voted against will be confiscated.
Citation Information
Patent Citations
Block chain contribution proof consensus method and system based on smart contract
CN115242420A
Decentralized node management method based on multi-level committee in block chain
CN118074886A