Byzantine fault-tolerant consensus method and computer equipment based on directed acyclic graph
By using broadcast special value mechanisms in consensus nodes to build or update directed acyclic graphs, the problem of throughput reduction in DAG-based consensus algorithms when low load or the presence of Byzantine nodes is solved, and a high-throughput consensus process with efficient and high robustness is achieved.
Patent Information
- Application Number
- CN202411866407.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2044-12-18
AI Technical Summary
The existing DAG-based consensus algorithm will significantly reduce throughput when the system is low in load or the presence of Byzantine nodes, making it difficult to achieve high throughput.
By introducing a mechanism for broadcasting special values in the consensus node, nodes allow nodes to build or update directed acyclic graphs without broadcastable transaction blocks, thereby maintaining the system's high throughput in low loads and the presence of Byzantine nodes.
It realizes that the system can still maintain high throughput when the system is low in load and the presence of Byzantine nodes, improving the efficiency and robustness of the system.
Smart Images

Figure CN119324931B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application belong to the field of blockchain technology, and in particular, relate to a Byzantine fault-tolerant consensus method and computer device based on a directed acyclic graph. Background Art
[0002] The first practical Byzantine fault tolerance consensus algorithm (PBFT) was proposed in 1999. The algorithm adopts a leader-follower structure. The leader node initiates a transaction request. After two rounds of voting by the followers, the algorithm can make all nodes reach a consensus on the order of executing transactions. A series of subsequent works, including HotStuff, Zyzzyva, SBFT, etc., can improve the performance of the PBFT algorithm by reducing its complexity in various ways. The leader-follower structure makes the design of the PBFT algorithm simple in general, but the structure also has its disadvantages. For example, on the one hand, such algorithms need to design a complex view-change algorithm to deal with the problem that the leader node is a Byzantine node. That is, when the leader node is a Byzantine node, such algorithms need to run the view-change algorithm to elect a new leader node to ensure the normal operation of the algorithm. On the other hand, such algorithms have the problem of load imbalance between nodes, which will cause the bottleneck of the system to depend on the leader node, and the capacity of the follower node cannot be fully utilized. There is a series of work including Mir-BFT, ISS, etc. that can achieve load balancing between nodes by running multiple consensus algorithms with a leader-follower structure in parallel. However, their essence is still based on the leader-follower structure, and it is still necessary to design a view-change algorithm to deal with the problem of the leader node being a Byzantine node. Since multiple consensus algorithms are run in parallel, there are multiple leader nodes during the algorithm operation, which further makes the view-change design more complicated.
[0003] The proposed consensus algorithm based on directed acyclic graph (DAG) solves the above-mentioned problems of the leader-follower structure consensus algorithm, namely, load imbalance and the need to design a view-change algorithm. The first practical Byzantine fault-tolerant consensus algorithm based on DAG, Tusk, was proposed in 2022. Compared with the leader-follower structure consensus algorithm in which only the leader node can make a transaction request, each node in the Tusk algorithm can make a transaction request by reliably broadcasting the hash value of the transaction request, and each node can build a DAG locally according to the hash value of the reliably confirmed transaction request. Finally, the node sorts and executes the corresponding request transactions according to the local DAG. Based on the Tusk algorithm, the Bullshark algorithm optimizes the Tusk algorithm by utilizing the characteristics of the synchronous network, that is, the Bullshark algorithm introduces a timeout mechanism, which can speed up the consensus process by allowing a specific round to receive the expected transaction request. However, when there are Byzantine nodes in the system, the timeout mechanism introduced in the Bullshark algorithm will seriously affect the throughput of the system.
[0004] The existing DAG-based consensus algorithm has a system throughput of 0 when the system is under low load, that is, when less than 1 / 3 of the total number of system nodes have unexecuted transaction requests; in addition, after using the synchronous network characteristics to accelerate the DAG-based consensus algorithm, such as using the Bullshark algorithm, when there are Byzantine nodes in the system, the system performance will also be greatly affected and the throughput will drop sharply. Therefore, how to achieve high system throughput when the system is under low load and there are Byzantine nodes is an urgent problem to be solved. Summary of the invention
[0005] In view of this, an embodiment of the present application provides a Byzantine fault-tolerant consensus method and computer device based on a directed acyclic graph, which allows nodes to build or update a directed acyclic graph by broadcasting special values in the absence of broadcastable transaction blocks, thereby ensuring that the system can still achieve high throughput when the system is under low load and there are Byzantine nodes.
[0006] A first aspect of an embodiment of the present application provides a Byzantine fault-tolerant consensus method based on a directed acyclic graph, which is applied to any consensus node in a blockchain, and the method includes:
[0007] Broadcasting a transaction block to all nodes, wherein the transaction block includes the transaction requested to be executed, and the transaction block has a transaction sequence number;
[0008] When receiving confirmation messages fed back by at least a first number of nodes after verifying the transaction block, marking the transaction block as an authenticated transaction block;
[0009] A directed acyclic graph is constructed by broadcasting a message; wherein, if the consensus node generates the authenticated transaction block, the broadcasted message includes a hash value of the authenticated transaction block; if the consensus node does not generate the authenticated transaction block, the broadcasted message includes a special value; the hash value of the authenticated transaction block and / or the special value are used to determine each vertex in the directed acyclic graph, and the message also includes auxiliary information for determining each edge in the directed acyclic graph;
[0010] The vertices in the directed acyclic graph are sorted, and the transactions contained in the transaction blocks corresponding to the sorted vertices are sequentially executed.
[0011] Optionally, constructing a directed acyclic graph by broadcasting messages includes:
[0012] Determine the round that the consensus node is currently in, where the round includes an even round or an odd round;
[0013] After the round is updated, the message is broadcasted, and the currently constructed directed acyclic graph is updated according to the broadcasted message, wherein the message includes the hash value of the authenticated transaction block or the special value, and the auxiliary information.
[0014] In a possible implementation, broadcasting the message after updating the round, and updating the currently constructed directed acyclic graph according to the broadcasted message, includes:
[0015] If the current round of the consensus node is an even round, add 1 to the even round and start the timer to count down;
[0016] Broadcast the message, wherein the message includes the hash value of the authenticated transaction block with the largest transaction number owned by the consensus node and auxiliary information; wherein, if the authenticated transaction block with the largest transaction number has been broadcasted, the hash value of the authenticated transaction block with the largest transaction number is replaced by the special value; the auxiliary information includes the messages from all nodes in the even-numbered round and one or more messages from all nodes in the round before the even-numbered round;
[0017] The currently constructed directed acyclic graph is updated according to the broadcasted message.
[0018] The one or more messages from all nodes in the rounds before the even-numbered rounds included in the auxiliary information all satisfy the following conditions:
[0019] If the message in the round before the even round is removed, there does not exist a path in the directed acyclic graph from the vertex corresponding to the message from the consensus node in the next round of the even round to the vertex corresponding to the removed message.
[0020] In another possible implementation, broadcasting the message after updating the round, and updating the currently constructed directed acyclic graph according to the broadcasted message, includes:
[0021] If the current round of the consensus node is an odd round, determine whether the timer countdown has ended or whether the vertex corresponding to the message broadcast by the leader vertex in the odd round has been added to the directed acyclic graph;
[0022] If the countdown of the timer ends or the vertex corresponding to the message broadcast by the leader vertex in the odd round has been added to the directed acyclic graph, then add 1 to the odd round;
[0023] Broadcast a message and update the currently constructed directed acyclic graph according to the broadcasted message.
[0024] Optionally, it also includes:
[0025] If the vertex corresponding to the message broadcast by the leader vertex in the odd round has been added to the directed acyclic graph, clearing the value of the timer;
[0026] If there are at least a second number of vertices in the directed acyclic graph corresponding to the round after the odd round, broadcast a message after clearing the value of the timer and adding 1 to the current round after the odd round; if the round after adding 1 to the current round after the odd round is an odd round, restart the timer.
[0027] In yet another possible implementation, broadcasting the message after updating the round, and updating the currently constructed directed acyclic graph according to the broadcasted message, further includes:
[0028] If the consensus node confirms the received message and the vertex corresponding to the message in the auxiliary information already exists in the directed acyclic graph and the proofs of the transaction block by other nodes are verified, the directed acyclic graph is updated according to the confirmed message.
[0029] Optionally, the sorting of the vertices in the directed acyclic graph includes:
[0030] Determining the number of votes obtained by a leader vertex in a target round of the directed acyclic graph in a current round, the target round being less than the current round;
[0031] When the number of votes reaches the first number, determining a leader vertex with the smallest round number among all unexecuted ancestors;
[0032] Sorting the leader vertices among all unexecuted ancestors in order of rounds from small to large, and sorting all vertices in the directed acyclic graph based on the sorted leader vertices;
[0033] Among them, all unexecuted ancestors refer to vertices whose corresponding transaction blocks have not been executed in the set of all vertices that can be reached from the leader vertex in the target round.
[0034] A second aspect of an embodiment of the present application provides a Byzantine fault-tolerant consensus device based on a directed acyclic graph, comprising:
[0035] A broadcast module, used to broadcast a transaction block to all nodes, wherein the transaction block includes the transaction requested to be executed, and the transaction block has a transaction sequence number;
[0036] A marking module, configured to mark the transaction block as an authenticated transaction block upon receiving confirmation messages fed back by at least a first number of nodes after verifying the transaction block;
[0037] A construction module, configured to construct a directed acyclic graph by broadcasting a message; wherein, if the consensus node generates the authenticated transaction block, the broadcasted message includes a hash value of the authenticated transaction block; if the consensus node does not generate the authenticated transaction block, the broadcasted message includes a special value; the hash value of the authenticated transaction block and / or the special value are used to determine each vertex in the directed acyclic graph, and the message also includes auxiliary information for determining each edge in the directed acyclic graph;
[0038] A sorting module, used for sorting each vertex in the directed acyclic graph;
[0039] The execution module is used to sequentially execute the transactions contained in the transaction blocks corresponding to the sorted vertices.
[0040] A third aspect of an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the computer device implements the method described in the first aspect above.
[0041] A fourth aspect of an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the method described in the first aspect above is implemented.
[0042] A fifth aspect of the embodiments of the present application provides a computer program product, including a computer program, which, when executed, enables the method described in the first aspect to be executed.
[0043] Compared with the prior art, the embodiments of the present application have the following beneficial effects:
[0044] In an embodiment of the present application, each consensus node in the blockchain broadcasts a transaction block to all nodes, and all nodes sign and verify the transaction block. Based on the verification results of the transaction block by all nodes, it can be determined whether the transaction block belongs to an authenticated transaction block. On this basis, the consensus node can construct a directed acyclic graph by broadcasting messages, so that the transactions contained in the transaction block can be executed based on the directed acyclic graph. In this process, if the transaction block belongs to an authenticated transaction block, the message broadcast by the consensus node can include the hash value and auxiliary information of the authenticated transaction block; if the consensus node does not generate an authenticated transaction block, a special value can be used in the message broadcast by the consensus node instead of the hash value of the authenticated transaction block. In this way, when constructing a directed acyclic graph, the hash value or special value in the broadcast message can be used to determine each vertex in the directed acyclic graph, and the auxiliary information can be used to determine each edge in the directed acyclic graph. By using special values in the broadcast messages, the embodiments of the present application can ensure that no matter whether the consensus node has generated an authenticated transaction block, the consensus node can determine a vertex in the DAG by broadcasting messages, thereby constructing the DAG or updating the constructed DAG. This can ensure that the system can still achieve high throughput when the system is under low load and there are Byzantine nodes. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or prior art descriptions. Obviously, the drawings described below are only some embodiments of the present application, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0046] Figure 1 It is a schematic diagram of a Byzantine fault-tolerant consensus method based on a directed acyclic graph provided in an embodiment of the present application;
[0047] Figure 2 It is a schematic diagram of another Byzantine fault-tolerant consensus method based on a directed acyclic graph provided in an embodiment of the present application;
[0048] Figure 3 It is a schematic diagram of a Byzantine fault-tolerant consensus process based on a directed acyclic graph from the perspective of a certain node provided in an embodiment of the present application;
[0049] Figure 4It is a schematic diagram of a Byzantine fault-tolerant consensus device based on a directed acyclic graph provided in an embodiment of the present application;
[0050] Figure 5 It is a schematic diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0051] In the following description, specific details such as specific system structures, technologies, etc. are proposed for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from hindering the description of the present application.
[0052] The technical solution of the present application is described below through specific embodiments.
[0053] Reference Figure 1 , shows a schematic diagram of a Byzantine fault-tolerant consensus method based on a directed acyclic graph provided in an embodiment of the present application, which may specifically include the following steps:
[0054] S101. Broadcast a transaction block to all nodes, wherein the transaction block includes a transaction requested to be executed and has a transaction sequence number.
[0055] It should be noted that this method can be applied to blockchain, and the executor of this method can be any consensus node in the blockchain, that is, each consensus node in the blockchain can execute each step of this method to jointly realize the consensus process based on DAG.
[0056] Taking any consensus node in the blockchain as an example, the consensus node can broadcast a transaction block to all nodes, and the above-mentioned all nodes can be all consensus nodes in the blockchain, and the above-mentioned broadcasted transaction block can contain the transaction requested to be executed. That is, by broadcasting the transaction requested to be executed to all nodes in the form of a transaction block, all nodes reach a consensus on the transaction block, thereby realizing the execution of the transaction contained in the transaction block.
[0057] In a possible implementation of an embodiment of the present application, a transaction block may have a transaction sequence number, which may be used to indicate the order of transaction blocks broadcast by a consensus node.
[0058] S102: When receiving confirmation messages fed back by at least a first number of nodes after verifying the transaction block, mark the transaction block as an authenticated transaction block.
[0059] In an embodiment of the present application, an authenticated transaction block indicates that at least one correct node owns the transaction block, so the first number can be determined based on the number of Byzantine nodes or malicious nodes in the system. Exemplarily, in the Byzantine consensus algorithm, the number of Byzantine nodes or malicious nodes can be expressed as f, and only when at least f+1 nodes own the broadcasted transaction block, the transaction block is considered to have at least one correct node owning the transaction block. Therefore, the above first number can be f+1, that is, only when the confirmation message fed back by at least f+1 nodes after verifying the transaction block is received, the consensus node that broadcasts the transaction block can mark it as an authenticated transaction block.
[0060] In the specific implementation, a consensus node broadcasts a transaction block to all nodes. After receiving the transaction block, each node can sign and verify it, and feedback confirmation information to the original node that broadcast the transaction block. After the original node receives the confirmation message fed back by each node, it can mark the transaction block as an authenticated transaction block by confirming that at least f+1 nodes have fed back confirmation messages for the transaction block. Since there are at most f Byzantine nodes or malicious nodes in the system, when at least f+1 nodes have fed back confirmation messages for the transaction block, it can be considered that there is at least one correct node in the system that owns the transaction block, that is, the transaction block is broadcast to at least one correct node by the original node.
[0061] S103. Constructing a directed acyclic graph by broadcasting messages; wherein, if the consensus node generates the authenticated transaction block, the broadcast message includes a hash value of the authenticated transaction block; if the consensus node does not generate the authenticated transaction block, the broadcast message includes a special value; the hash value of the authenticated transaction block and / or the special value are used to determine each vertex in the directed acyclic graph, and the message also includes auxiliary information for determining each edge in the directed acyclic graph.
[0062] In an embodiment of the present application, during the consensus process, each consensus node can transmit messages for building a DAG to each node by broadcasting.
[0063] In one possible implementation, each consensus node can transmit messages in the form of reliable broadcast, that is, the consensus node reliably broadcasts the message used to build the DAG. Reliable broadcast is a broadcast protocol widely used in blockchain. In the process of reliable broadcast of messages by consensus nodes, the above-mentioned "reliable broadcast" is a specific action of broadcasting messages. Consensus nodes can construct authenticated transaction blocks into DAG by reliable broadcast of messages, and implement the execution of transactions based on DAG.
[0064] In order to ensure the accuracy and reliability of the consensus process, unless otherwise specified, the forms of broadcast messages involved in the embodiments of the present application may refer to reliable broadcasts.
[0065] In an embodiment of the present application, the message reliably broadcast by the consensus node may include the hash value of the authenticated transaction block and some auxiliary information. The above hash value can be used to determine each vertex in the DAG, and the auxiliary information can be used to determine each edge in the DAG.
[0066] The above describes the specific content contained in the reliably broadcast message when the consensus node generates or has marked a transaction block as an authenticated transaction block. In a possible implementation of an embodiment of the present application, the consensus node may not generate an authenticated transaction block, that is, the consensus node fails to mark the transaction block as an authenticated transaction block in the aforementioned manner, or the transaction block does not meet the requirements for being marked as an authenticated transaction block. At this time, the message reliably broadcast by the consensus node does not contain the hash value of the authenticated transaction block, but a special value can be used to replace the hash value of the authenticated transaction block. That is, in the case where the consensus node fails to generate an authenticated transaction block, the consensus node may only include a special value and corresponding auxiliary information in the message reliably broadcast, and the special value can be used to determine the vertices in the DAG.
[0067] In this way, regardless of whether the consensus node has generated an authenticated transaction block, the consensus node can determine a vertex in the DAG through reliable broadcast messages, thereby constructing the DAG or updating the constructed DAG, which can ensure that the system can still achieve high throughput when the system is under low load and there are Byzantine nodes.
[0068] S104: Sort the vertices in the directed acyclic graph, and sequentially execute transactions included in transaction blocks corresponding to the sorted vertices.
[0069] In an embodiment of the present application, after the DAG is constructed, each vertex in the DAG may be sorted, so that transactions contained in the transaction blocks corresponding to each vertex are executed according to the sorted DAG.
[0070] In a possible implementation of the embodiment of the present application, the leader vertices among the vertices may be sorted first when sorting the vertices in the DAG. After the leader vertices are sorted, the other vertices are sorted, so that the execution process of the transactions contained in the transaction blocks corresponding to the vertices can be executed in a certain order, which ensures the orderliness of the transaction execution and improves the efficiency and robustness of the system in the consensus process and the transaction execution process.
[0071] In an embodiment of the present application, each consensus node in the blockchain broadcasts a transaction block to all nodes, and all nodes sign and verify the transaction block. Based on the verification results of the transaction block by all nodes, it can be determined whether the transaction block belongs to an authenticated transaction block. On this basis, the consensus node can construct a directed acyclic graph by broadcasting messages, so that the transactions contained in the transaction block can be executed based on the directed acyclic graph. In this process, if the transaction block belongs to an authenticated transaction block, the message broadcast by the consensus node can include the hash value and auxiliary information of the authenticated transaction block; if the consensus node does not generate an authenticated transaction block, a special value can be used in the message broadcast by the consensus node instead of the hash value of the authenticated transaction block. In this way, when constructing a directed acyclic graph, the hash value or special value in the broadcast message can be used to determine each vertex in the directed acyclic graph, and the auxiliary information can be used to determine each edge in the directed acyclic graph. By using special values in the broadcast messages, the embodiments of the present application can ensure that no matter whether the consensus node has generated an authenticated transaction block, the consensus node can determine a vertex in the DAG by broadcasting messages, thereby constructing the DAG or updating the constructed DAG. This can ensure that the system can still achieve high throughput when the system is under low load and there are Byzantine nodes.
[0072] Reference Figure 2 , shows a schematic diagram of another Byzantine fault-tolerant consensus method based on a directed acyclic graph provided in an embodiment of the present application, which may specifically include the following steps:
[0073] S201. Broadcast a transaction block to all nodes, wherein the transaction block includes a transaction requested to be executed and has a transaction sequence number.
[0074] In the embodiment of the present application, the execution subject may be any consensus node in the blockchain, and the consensus node may be a computer device that executes a corresponding program to implement the functions of each step of the method. The above-mentioned computer device may be a desktop computer or a cloud server, and the embodiment of the present application does not limit the specific type of the computer device.
[0075] The consensus node of the broadcast transaction block in the embodiment of the present application can be represented as S i , that is, by node S i Broadcast transaction blocks to all nodes.
[0076] As a specific example of the embodiment of the present application, the transaction block can be represented as B k, i =⟨REQUEST, TX, H(B k-1, i ), σ i>; Where B represents a transaction block, subscript k represents the transaction sequence number of the transaction block, which usually starts from 1, subscript i of B represents the proposer of the transaction block, REQUEST is used to identify that this is a transaction block message, TX is the specific transaction requested to be executed contained in the transaction block, H() is a hash function, so H(B k-1, i ) can represent the hash value of the previous transaction block. The transaction block can "connect" all transaction blocks by including the hash value of the transaction block with the previous serial number in the current block. σ represents the signature. The subscript i of σ represents the signer, who is also the proposer of the transaction. i ←Sign(⟨REQUEST, TX, H(B k-1, i )>), Sign() is the signature function.
[0077] S202: When receiving confirmation messages fed back by at least a first number of nodes after verifying the transaction block, mark the transaction block as an authenticated transaction block.
[0078] In the embodiment of the present application, other nodes receive the node S i After the transaction block is broadcast, it can be verified and signed. If the verification is successful, each node will return a confirmation message to the recipient.
[0079] In a possible implementation of the embodiment of the present application, since each transaction block contains the hash value of the previous transaction block, the node S i In this way, the connection of each transaction block proposed by the same transaction block proposer is realized. Therefore, when each node sends a confirmation message to the feedback, it can be done after all the transaction blocks proposed by the same proposer that have been received have been signed and verified.
[0080] In the specific implementation, assume that one of the other nodes is S j , if node S j Received by node S i Broadcast transaction block B k, i , and has received transaction block B 1, i , …, B k-2,i , B k-1,i , and the signatures of each transaction block are verified, then node S j The newly received transaction block B can be k, i Sign and send ⟨ACK, H(B k, i ), σ j > Give node S i , where σ j ←Sign(⟨REQUEST, TX, H(B k-1, i )>), ACK is used to indicate that this is a confirmation message.
[0081] In the embodiment of the present application, the node S i Broadcast transaction block B k, i After that, while collecting the corresponding ACK confirmation messages, the next transaction block B can be continuously broadcast. k+1, i to all nodes.
[0082] When node S i Receive at least the first number of other nodes to trade block B k, i When the verification is successful, node S i This transaction block B can be k, i Marks the block as authenticated.
[0083] The first number can be determined based on the number of Byzantine nodes or malicious nodes in the system. If the number of Byzantine nodes or malicious nodes is f, then node S i At least f+1 other nodes should receive transaction block B k, i When the confirmation message is verified, the transaction block B can be marked k, i is a verified transaction block. And, node S i Proof C can be generated based on the signatures in the confirmation messages returned by at least f+1 nodes k, i .
[0084] In the embodiment of the present application, the number of Byzantine nodes or malicious nodes in the system is f, and the total number of nodes in the system is 3f+1. There are at most f Byzantine nodes and at least 2f+1 correct nodes in the system.
[0085] S203: Determine the round that the consensus node is currently in, where the round includes an even round or an odd round.
[0086] In the embodiment of the present application, the node S i DAG can be generated by reliable broadcasting of messages, so that transactions in each transaction block can be executed based on DAG.
[0087] Reliable broadcast is one of the broadcast protocols used to ensure message delivery and consistency in distributed systems. Reliable broadcast provides a way for one party to send messages to all other parties. It requires all honest parties to deliver the same set of messages, and the message set includes all messages broadcast by the honest party without guaranteeing the order of message delivery.
[0088] When reliably broadcasting messages, node S i The current round can be determined, that is, whether it is an even round or an odd round.
[0089] Assume that node S iThe current round is r. If r mod 2 = 0, the current round is an even round. If r mod 2 = 1, the current round is an odd round. The above mod is a modulus operator. r mod 2 represents the remainder of r divided by 2.
[0090] S204. Broadcast the message after updating the round, and update the currently constructed directed acyclic graph according to the broadcast message; wherein, if the consensus node generates the authenticated transaction block, the broadcast message contains the hash value of the authenticated transaction block, and if the consensus node does not generate the authenticated transaction block, the broadcast message contains a special value; the hash value of the authenticated transaction block and / or the special value are used to determine each vertex in the directed acyclic graph, and the message also includes auxiliary information for determining each edge in the directed acyclic graph.
[0091] In the embodiment of the present application, the node S i By reliably broadcasting messages round by round, the DAG can be constructed or updated based on the reliably broadcast messages. i The above message of reliable broadcast may contain the hash value of the authenticated transaction block and auxiliary information, and the auxiliary information may indicate the correlation between the current reliable broadcast message and the confirmed message. i If no authenticated transaction block is generated during this process, the above reliable broadcast message may contain a meaningless special value to replace the hash value of the authenticated transaction block. For example, the special value may be ⊥.
[0092] Node S i The hash value or special value contained in the reliable broadcast message can correspond to the vertex in the DAG, and the auxiliary information indicating the association between messages can correspond to the edge in the DAG. In this way, each node can build a DAG about all confirmed messages.
[0093] Corresponding to reliable broadcast is reliable confirmation, that is, after receiving a message of reliable broadcast, a node can confirm the message or not confirm any message in a reliable confirmation manner. The above-mentioned "reliable confirmation" is a specific action to confirm a message. For example, in the aforementioned example, the correlation between the current reliably broadcast message and the confirmed message represented by the auxiliary information also represents the correlation between the current reliably broadcast message and the reliably confirmed message, and each node can build a DAG of all reliably confirmed messages.
[0094] The above-mentioned method of using reliable broadcast messages can ensure that when a node, whether a correct node or a Byzantine node, reliably broadcasts a message, all nodes will eventually be able to reliably confirm the message or unreliably confirm any message. Unless otherwise specified, in the embodiments of the present application, when describing the confirmation action corresponding to the reliable broadcast, it can refer to reliable confirmation.
[0095] In the embodiment of the present application, the node S i A two-dimensional array DAG can be maintained locally i [][], used to record the local DAG status. i [r][j] can represent the number of nodes from node S in round r. j The hash value or special value in the message can correspond to a vertex in the DAG. For ease of description, the vertex corresponding to a message is also used in the following embodiments to represent the vertex in the DAG corresponding to the hash value or special value in the message. i The module of [r][j] is |DAG i [r][j]|, when the system is initialized, the DAG state of round 0 can be determined in a hard-coded form|DAG i [0]|=2f+1 means that there are 2f+1 vertices in the initial state of DAG in round 0, that is, there are messages from 2f+1 nodes.
[0096] In a possible implementation of the embodiment of the present application, the node S i Reliable broadcasting of messages, and then updating the currently constructed directed acyclic graph based on the messages, can be based on node S i The current round is divided into different situations. Specifically, it includes:
[0097] If the node S i If the current round r is an even round, that is, r mod 2 = 0, then 1 can be added to the even round and the timer can be started to count down. Then, node S i Reliable broadcast message, updates the currently constructed directed acyclic graph according to the reliable broadcast message.
[0098] In the DAG-based Byzantine consensus algorithm, a node can only enter the next round after it receives support from a sufficient number of nodes (2f + 1) in the current round. Therefore, the above even number of rounds plus 1 should also satisfy |DAG i The condition [r]|>2f.
[0099] For example, if node S i In an even round r and |DAG i [r]|>2f, then Si Update r = r + 1 and start the timer timer i, r Start the countdown. The timer can be set to a time greater than the network latency. Then, node S i Reliably broadcast the message ⟨VEC, r, i, H(B k, i ), C k, i , se, we>, and update the DAG i [r][i] = ⟨VEC, r, i, H(B k, i ), C k, i , se, we>. Where B k, i is the largest authenticated transaction block with the largest transaction sequence number currently owned by node S i . If this transaction block B k, i has been reliably broadcast in a previous round, it is replaced with a special value ⊥. se and we are auxiliary information indicating the correlation between messages. se contains all messages in DAG i [r - 1], and we contains some messages in DAG i [r'], that is, the messages in the r'th round, r' < r - 1. More specifically, there are edges in the DAG from the vertex corresponding to DAG i [r][i] to each vertex corresponding to se and we. Each message in we satisfies: if this message is removed from we, then there is no path in the DAG i from the vertex corresponding to DAG i [r][i] to the vertex corresponding to this message.
[0100] That is, after incrementing the even round number r by 1, node S i reliably broadcasts a message, which can include the hash value of the largest authenticated transaction block owned by node S i and auxiliary information; where, if the largest authenticated transaction block with the largest transaction sequence number has been reliably broadcast, the hash value of the largest authenticated transaction block can be replaced with the special value ⊥; the above auxiliary information can include messages from all nodes in the even round and one or more messages from all nodes in the rounds before the even round. These one or more messages all satisfy the following condition, that is: if the messages in the rounds before the even round are removed, then there is no path in the DAG from the vertex corresponding to the message from node S i in the next round of the even round to the vertex corresponding to the removed message.
[0101] If node S iIf the current round r is an odd round, that is, r mod 2=1, it can be determined whether the timer countdown has ended or whether the vertex corresponding to the message reliably broadcast by the leader vertex in the above odd round has been added to the DAG; if the timer countdown has ended or the vertex corresponding to the message reliably broadcast by the leader vertex in the odd round has been added to the DAG, the odd round can be added by 1, and the currently constructed DAG can be updated according to the reliably broadcast message after the message is reliably broadcast.
[0102] Specifically, if node S i In odd round r and |DAG i [r]|>2f, then S i Determine the timer i, r Whether the countdown is over or DAG i [r][L r ] is not empty, that is, whether the leader node L in the rth round has been r The reliably broadcast message is added to the DAG. If either of the above two conditions is met, then node S i We can update r=r+1 and reliably broadcast the message ⟨VEC, r, i, H(B k, i ), C k, i , se, we>, update DAG i [r][i]=⟨VEC, r, i, H(B k, i ),C k, i , se, we>.
[0103] In the embodiment of the present application, if the leader vertex L in the odd round r r The vertex corresponding to the reliable broadcast message has been added to the DAG, that is, the second of the above two conditions is met, then the node S i You also need to clear the timer i, r The value of L r It is the id of the pre-defined leader vertex in the odd round r.
[0104] In a possible implementation of the embodiment of the present application, if the node S i In an odd round r, when the timer i, r The countdown ends and |DAG i [r]|>2f, then node S i We can update r=r+1 and reliably broadcast the message ⟨VEC, r,i, H(B k, i ), C k, i , se, we>, update DAG i [r][i]=⟨VEC, r, i, H(B k, i), C k, i , se, we>.
[0105] In another possible implementation of the embodiment of the present application, if there are at least a second number of vertices in the DAG corresponding to the round r' after the odd round r, then the node S i You can clear the timer i, r The message is reliably broadcast after the current round r' after the odd round is added by 1; if the round after the current round r' after the odd round is added by 1 is an odd round, the timer timer can be restarted i, r .
[0106] Specifically, if node S i In odd round r, and |DAG i [r']|>2f, r'>r, then node S i Clear the timer i, r , update r = r' + 1, and reliably broadcast the message ⟨VEC, r, i, H(B k, i ), C k, i , se, we>, update DAG i [r][i]=⟨VEC, r, i, H(B k, i ), C k, i , se, we>. If the updated round r is an odd number, then node S i You can restart the timer i, r .
[0107] In another possible implementation of the embodiment of the present application, if the node S i If the received message is reliably confirmed and the message in the auxiliary information already exists in the DAG, and the proofs of the transaction block by other nodes are verified, then node S i The DAG can be updated based on the reliably confirmed messages.
[0108] Specifically, if node S i Reliably confirmed ⟨VEC, r, j, H(B k, j ), C k, j , se, we>, the messages in the se and we sets already exist in the DAG i In, and C k, j If the signatures in are all verified, then S i Update DAG i [r][j]=⟨VEC,r, j, H(B k, j ), C k, j , se, we>.
[0109] In the above examples, node S i Reliably broadcast messages and update DAG i The process of [][] is the process of building or updating DAG.
[0110] In the embodiment of the present application, by determining whether the current round of the consensus node is an even round or an odd round, and broadcasting corresponding messages in a targeted manner according to the different rounds, it is possible to ensure that there must be at least one leading vertex in the odd rounds through the specific information contained in the broadcasted message. In this way, the leading vertex of each odd round can directly obtain consensus in the current round, or obtain consensus indirectly in subsequent rounds.
[0111] S205: Determine the number of votes obtained by the leader vertex in the target round of the directed acyclic graph in the current round, wherein the target round is smaller than the current round.
[0112] In the embodiment of the present application, after constructing or updating the DAG, the transactions contained in each transaction block can be executed based on the DAG. In this process, the transactions in the corresponding transaction block can be executed sequentially by sorting the vertices in the DAG, thereby ensuring the sequential execution of the transactions.
[0113] In the embodiment of the present application, the leading vertex L in the target round r' of the DAG can be first determined. r The number of votes obtained in the current round r, the target round r' is less than the current round r.
[0114] Specifically, a two-dimensional array VOTE can be used i [r'][r] records the leader vertex L in round r' r The number of votes received in round r, VOTE i The initial value of [][] is 0.
[0115] When node S i When updating the DAG i [r][j], if DAG i [r][j] and DAG i [r'][L r’ ] (1≤r'≤r-1), and the path that exists contains all odd rounds r between rounds r' and r + The leader vertex in the DAG i [r + ][L r+ ], r'≤r + ≤r, that is: there is a set of edges in the constructed DAG graph, which connects the DAG i [r][j] and DAG i[r'][L r’ ] corresponding to the vertex, the set of these edges is called the DAG i [r][j] to DAG i [r'][L r’ ] path. If a vertex is an end of one of the edges, then the path contains the vertex. In this case, the node S i VOTE can be updated i [r'][r]=VOTE i [r'][r]+1, determine the leader vertex L in round r' r The number of votes received in round r.
[0116] S206. When the number of votes reaches the first number, determine the leader vertex with the smallest round number among all unexecuted ancestors; wherein all unexecuted ancestors refer to vertices whose corresponding transaction blocks have not been executed in the set of all vertices that can be reached from the leader vertex in the target round.
[0117] As mentioned above, the first number is f+1. When the number of votes reaches f+1, node S i The leader vertex with the smallest round number can be determined among all unexecuted ancestors.
[0118] Specifically, when node S i Discover VOTE i When [r'][r]=f+1, node S i Can be in DAG i [r'][L r’ ] among all the unexecuted ancestors of the DAG to find the leader vertex with the smallest round number i [r''][L r’’ ].
[0119] All the above unexecuted ancestors can refer to the leader vertex L in the target round r' r The vertex whose corresponding transaction block has not been executed in the set of all vertices that can be reached. For example, the leader vertex DAG i [r'][L r’ ] is the ancestor of the DAG i [r'][L r’ ] The set of all vertices that can be reached from the corresponding vertex. The unexecuted ancestors, that is, the transactions contained in the corresponding transaction blocks in the ancestors have not yet been executed.
[0120] S207 , sorting the leader vertices in all unexecuted ancestors in order of rounds from small to large, and sorting all vertices in the directed acyclic graph based on the sorted leader vertices.
[0121] Specifically, node S i DAG can be i [r'][L r’ ] and DAG i [r''][L r’’ ] are sorted from smallest to largest according to the rounds, and all vertices in the DAG are sorted based on the sorted leader vertex. When the rounds of the unexecuted ancestors are the same, they can be sorted in the order of arrival of the corresponding id from smallest to largest.
[0122] S208. Execute the transactions contained in the transaction blocks corresponding to the sorted vertices in sequence.
[0123] In the embodiment of the present application, after sorting the vertices in the DAG, the transactions contained in the transaction blocks corresponding to the vertices can be executed in the corresponding order until the vertex DAG i [r'][L r’ ] The transactions contained in the corresponding transaction block are executed. The above steps S205-S207 can be repeatedly executed in this process.
[0124] Among them, execute DAG i [r'][L r’ ] That is, execute DAG i [r'][L r’ ] k, j ) The corresponding transaction block B k, j If transaction block B 1, j , …, B k-2,j , B k-1,j If there are unexecuted transactions in the transaction block, the transactions in the transaction block with the smallest sequence number can be repeatedly executed first until the transaction block B is executed. k, j Each transaction in .
[0125] In a possible implementation of the embodiment of the present application, if the node S i Need to execute H(B k, j ) The corresponding transaction block B k, j , but node S i Transaction block B was not received k, j , then node S i Can broadcast ⟨FETCH, i, k, j,H(B k, j )> to each node. When any node receives the message ⟨FETCH, i, k, j, H(B k, j )> and the node has transaction block B k, j , then the node can send transaction block B k, j Give node S i .
[0126] Applying the method provided in the embodiment of the present application allows consensus nodes to reliably broadcast special values when there are no transaction blocks to broadcast. This can avoid the situation where the condition cannot be met or cannot be met quickly during the broadcast of the transaction block due to low load or the behavior of Byzantine nodes. | DAG i [r]|>2f, because the above situation directly causes the consensus node to be unable or unable to quickly and reliably broadcast new transaction blocks, resulting in a decrease in system throughput, the embodiment of the present application can effectively solve this problem by reliably broadcasting special values, ensuring that the system achieves high throughput under normal circumstances, and can also have a high throughput when the system is under low load or there are Byzantine nodes in the system, with high efficiency and high robustness. In addition, the method provided by the embodiment of the present application separates the broadcasting of transactions from the sorting of transactions, the entire process is simple to implement, the code quality is easy to ensure, and it has high feasibility.
[0127] It should be noted that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0128] The efficient and robust DAG-based Byzantine fault-tolerant consensus method provided by the embodiment of the present application can be applied to a distributed system, in which there are 3f+1 nodes, including a maximum of f Byzantine nodes and at least 2f+1 correct nodes, and each node performs the same process in the process of applying the method to reach a consensus. For ease of understanding, the method provided by the embodiment of the present application is introduced below in conjunction with a specific example using the consensus process of a specific node.
[0129] like Figure 3 As shown, it is a schematic diagram of a DAG-based Byzantine fault-tolerant consensus process from the perspective of a certain node S1 provided in an embodiment of the present application. Node S1 applies the efficient and robust DAG-based Byzantine fault-tolerant consensus method provided in an embodiment of the present application, which may include the following steps:
[0130] (1) Node broadcasts transaction.
[0131] Node S1 broadcasts transaction B k, 1 =⟨REQUEST, TX, H(B k-1, 1 ), σ1> for all nodes, where B represents the transaction, subscript k represents the transaction sequence number, subscript 1 represents the owner of the transaction, TX is the specific transaction requested to be executed, H() is the hash function, σ represents the signature, subscript 1 represents the signer, σ1←Sign(⟨REQUEST, TX, H(B k-1, 1 )>), Sign() is the signature function;
[0132] If the node S j Receive transaction B k, 1 , and has received B 1, 1 , …, B k-2,1 , B k-1,1 , and their signatures are verified, then node S j Send ⟨ACK, H(B k, 1 ), σ j >For node S1, where σ j ←Sign(⟨REQUEST, TX, H(B k-1, 1 )>).
[0133] (2) Collect evidence (for use in step (3)).
[0134] Node S1 broadcasts transaction B k, 1 After that, while collecting the corresponding ACK, the next transaction B can be broadcast directly k+1, 1 , when f+1 pairs of B are collected (including those generated by itself) that have passed verification k, 1 When the signature is k, 1 For authenticated transactions, S1 records these f+1 signatures as proof C k, 1 .
[0135] (3) Node S1 reliably broadcasts authenticated transactions (if there are no authenticated transactions, a special value ⊥ is reliably broadcast) and some auxiliary information in rounds, so that all nodes can use the auxiliary information to construct the reliably confirmed authenticated transactions into a directed acyclic graph, or DAG. Reliable broadcasting can ensure that when a node (correct node or Byzantine node) reliably broadcasts a message, all nodes will eventually be able to reliably confirm the message or none of them can reliably confirm any information. Node S1 locally maintains a two-bit array DAG1[][] to record the local DAG state. DAG1[r][j] represents the number of nodes from S1 in round r. j The message is that when the system is initialized, the DAG state of round 0 is hard-coded |DAG1[0]|=2f+1.
[0136] Step (3) may specifically include the following sub-steps:
[0137] If node S1 is in an even round r (i.e., r mod 2 = 0) and |DAG1[r]|>2f, S1 updates r = r+1 and starts timer timer 1, r , reliable broadcast message ⟨VEC, r, 1, H(B k, i ), C k, 1 , se, we>, update DAG1[r][1]=⟨VEC, r, 1, H(B k, 1 ), Ck, 1 , se, we>, where B k, 1 is the transaction with the largest serial number that S1 currently has and has been authenticated. If this transaction has been reliably broadcast in a previous round, it is replaced with a special value ⊥. se is the set containing all transactions in DAG1[r - 1]. As Figure 3 shown, the se set of v2 contains all transactions in DAG1[3]. we is the set containing some transactions in DAG1[r’ < r]. Each transaction in we satisfies: if this transaction is removed from we, there is no path in DAG1 from DAG1[r][i] to this transaction. As Figure 3 shown, the we set of v2 contains v1 in DAG1[2];
[0138] If node S1 is in an odd round r (i.e., r mod 2 = 1) and |DAG1[r]| > 2f, then S1 determines whether the timer timer 1, r has ended or DAG1[r][L r is not empty. If either condition is met, S1 updates r = r + 1, reliably broadcasts the message ⟨VEC, r, 1, H(B k, 1 ), C k, 1 , se, we>, updates DAG1[r][1] = ⟨VEC, r, 1, H(B k, 1 ), C k, 1 , se, we>. If the latter condition is met, it is also necessary to clear the timer 1, r , where L r is the id of the predefined leader node in the odd round r;
[0139] If node S1 is in an odd round r (i.e., r mod 2 = 1), the timer timer 1, r ends, and |DAG1[r]| > 2f, then S1 updates r = r + 1, reliably broadcasts the message ⟨VEC, r, 1, H(B k, 1 ), C k, 1 , se, we>, updates DAG1[r][1] = ⟨VEC, r, 1, H(B k, 1 ), C k, 1 , se, we>;
[0140] If node S1 is in round r and |DAG1[r’]| > 2f, r’ > r, then S1 clears the timer timer 1, r (when r is odd), updates r = r’ + 1, reliably broadcasts the message ⟨VEC, r, 1, H(B k, 1 ), C k, 1, se, we>, update DAG1[r][1]=⟨VEC, r, 1, H(B k, 1 ), C k, 1 , se, we>, if the updated r is an odd number, S1 starts the timer timer 1, r ;
[0141] If node S1 reliably confirms ⟨VEC, r, j, H(B k, j ), C k, j , se, we>, the transactions in the se and we sets already exist in DAG1, and C k, j If the signatures in are all verified, S1 updates DAG1[r][j]=⟨VEC, r, j, H(B k, j ), C k, j , se, we>.
[0142] (4) Node S1 observes the locally constructed DAG1, sorts the authenticated transactions corresponding to DAG1, and executes the transactions in the sorted order;
[0143] Step (4) can specifically:
[0144] When node S1 updates DAG1[r][j] in step (3), if DAG1[r][j] is equal to DAG1[r'][L r’ ] there is a path between them (1≤r'≤r-1), and the path contains all DAG1[r + ][L r+ ], r'≤r + ≤r, then S1 updates VOTE1[r'][r]=VOTE1[r'][r]+1, where the initial value of VOTE1[r'][r] is 0, and records the number of votes obtained by the leader node in round r' in round r;
[0145] When node S1 finds that VOTE1[r'][r]=f+1, S1 in DAG1[r'][L r’ ] among all the unexecuted ancestors of DAG1[r''][L r’’ ], and DAG1[r''][L r’’ ] and DAG1[r''][L r’’ ] are executed in a deterministic order, and this step is repeated until DAG1[r'][L r’ ] is executed, where DAG1[r'][L r’ ] means executing DAG1[r'][L r’ ] k, j ) corresponds to Bk, j ;
[0146] If node S1 needs to execute DAG1[r'][L r’ ] k, j ) corresponds to B k, j , but S1 does not receive B k, j , then S1 broadcasts ⟨FETCH, 1, k, j, H(B k, j )>, when any node receives ⟨FETCH, 1, k, j, H(B k, j )>, and the node has B k, j , then the node sends B k, j Give to S1.
[0147] Reference Figure 4 , shows a schematic diagram of a Byzantine fault-tolerant consensus device based on a directed acyclic graph provided in an embodiment of the present application, which may specifically include a broadcast module 401, a marking module 402, a construction module 403, a sorting module 404 and an execution module 405, wherein:
[0148] A broadcast module 401 is used to broadcast a transaction block to all nodes, wherein the transaction block includes a transaction requested to be executed and has a transaction sequence number;
[0149] A marking module 402 is configured to mark the transaction block as an authenticated transaction block upon receiving confirmation messages fed back by at least a first number of nodes after verifying the transaction block;
[0150] A construction module 403 is used to construct a directed acyclic graph by broadcasting a message; wherein, if the consensus node generates the authenticated transaction block, the broadcasted message includes a hash value of the authenticated transaction block; if the consensus node does not generate the authenticated transaction block, the broadcasted message includes a special value; the hash value of the authenticated transaction block and / or the special value are used to determine each vertex in the directed acyclic graph, and the message also includes auxiliary information for determining each edge in the directed acyclic graph;
[0151] A sorting module 404 is used to sort the vertices in the directed acyclic graph;
[0152] The execution module 405 is used to sequentially execute the transactions contained in the transaction blocks corresponding to the sorted vertices.
[0153] In the embodiment of the present application, the construction module 403 may be specifically used for:
[0154] Determine the round that the consensus node is currently in, where the round includes an even round or an odd round;
[0155] After the round is updated, the message is broadcasted, and the currently constructed directed acyclic graph is updated according to the broadcasted message, wherein the message includes the hash value of the authenticated transaction block or the special value, and the auxiliary information.
[0156] In a possible implementation of the embodiment of the present application, the construction module 403 may also be used to:
[0157] If the current round of the consensus node is an even round, add 1 to the even round and start the timer to count down;
[0158] Broadcast the message, wherein the message includes the hash value of the authenticated transaction block with the largest transaction number owned by the consensus node and auxiliary information; wherein, if the authenticated transaction block with the largest transaction number has been broadcasted, the hash value of the authenticated transaction block with the largest transaction number is replaced by the special value; the auxiliary information includes the messages from all nodes in the even-numbered round and one or more messages from all nodes in the round before the even-numbered round;
[0159] The currently constructed directed acyclic graph is updated according to the broadcasted message.
[0160] In an embodiment of the present application, the one or more messages from all nodes in the rounds before the even-numbered rounds included in the auxiliary information all meet the following conditions:
[0161] If the message in the round before the even round is removed, there does not exist a path in the directed acyclic graph from the vertex corresponding to the message from the consensus node in the next round of the even round to the vertex corresponding to the removed message.
[0162] In another possible implementation of the embodiment of the present application, the construction module 403 may also be used to:
[0163] If the current round of the consensus node is an odd round, determine whether the timer countdown has ended or whether the vertex corresponding to the message broadcast by the leader vertex in the odd round has been added to the directed acyclic graph;
[0164] If the countdown of the timer ends or the vertex corresponding to the message broadcast by the leader vertex in the odd round has been added to the directed acyclic graph, then add 1 to the odd round;
[0165] Broadcast a message and update the currently constructed directed acyclic graph according to the broadcasted message.
[0166] In the embodiment of the present application, the construction module 403 may also be used for:
[0167] If the vertex corresponding to the message broadcast by the leader vertex in the odd round has been added to the directed acyclic graph, clearing the value of the timer;
[0168] If there are at least a second number of vertices in the directed acyclic graph corresponding to the round after the odd round, broadcast a message after clearing the value of the timer and adding 1 to the current round after the odd round; if the round after adding 1 to the current round after the odd round is an odd round, restart the timer.
[0169] In another possible implementation of the embodiment of the present application, the construction module 403 may also be used to:
[0170] If the consensus node confirms the received message and the vertex corresponding to the message in the auxiliary information already exists in the directed acyclic graph and the proofs of the transaction block by other nodes are verified, the directed acyclic graph is updated according to the confirmed message.
[0171] In the embodiment of the present application, the sorting module 404 may be specifically used for:
[0172] Determining the number of votes obtained by a leader vertex in a target round of the directed acyclic graph in a current round, the target round being less than the current round;
[0173] When the number of votes reaches the first number, determining a leader vertex with the smallest round number among all unexecuted ancestors;
[0174] Sorting the leader vertices among all unexecuted ancestors in order of rounds from small to large, and sorting all vertices in the directed acyclic graph based on the sorted leader vertices;
[0175] Among them, all unexecuted ancestors refer to vertices whose corresponding transaction blocks have not been executed in the set of all vertices that can be reached from the leader vertex in the target round.
[0176] The embodiment of the present application provides a Byzantine fault-tolerant consensus device based on a directed acyclic graph, which can be a computer device, a server, or a module or unit in a computer device / server. By using the device, each step in the above-mentioned method embodiments can be implemented.
[0177] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment part.
[0178] Reference Figure 5 , shows a schematic diagram of a computer device provided by an embodiment of the present application. Figure 5As shown, the computer device 500 in the embodiment of the present application includes: a processor 510, a memory 520, and a computer program 521 stored in the memory 520 and executable on the processor 510. When the processor 510 executes the computer program 521, the steps in each embodiment of the above-mentioned Byzantine fault-tolerant consensus method based on a directed acyclic graph are implemented, for example Figure 1 Alternatively, when the processor 510 executes the computer program 521, the functions of each module / unit in the above-mentioned device embodiments are realized, for example Figure 4 Functions of modules 401 to 305 are shown.
[0179] Exemplarily, the computer program 521 may be divided into one or more modules / units, which are stored in the memory 520 and executed by the processor 510 to complete the present application. The one or more modules / units may be a series of computer program instruction segments capable of completing specific functions, which may be used to describe the execution process of the computer program 521 in the computer device 500. For example, the computer program 521 may be divided into a broadcast module, a marking module, a construction module, a sorting module, and an execution module, and the specific functions of each module are as follows:
[0180] A broadcast module, used to broadcast a transaction block to all nodes, wherein the transaction block includes the transaction requested to be executed, and the transaction block has a transaction sequence number;
[0181] A marking module, configured to mark the transaction block as an authenticated transaction block upon receiving confirmation messages fed back by at least a first number of nodes after verifying the transaction block;
[0182] A construction module, configured to construct a directed acyclic graph by broadcasting a message; wherein, if the consensus node generates the authenticated transaction block, the broadcasted message includes a hash value of the authenticated transaction block; if the consensus node does not generate the authenticated transaction block, the broadcasted message includes a special value; the hash value of the authenticated transaction block and / or the special value are used to determine each vertex in the directed acyclic graph, and the message also includes auxiliary information for determining each edge in the directed acyclic graph;
[0183] A sorting module, used for sorting each vertex in the directed acyclic graph;
[0184] The execution module is used to sequentially execute the transactions contained in the transaction blocks corresponding to the sorted vertices.
[0185] The computer device 500 may be a computer device capable of implementing the relevant steps in the above-mentioned embodiments, and the computer device 500 may be a desktop computer, a cloud server, etc. The computer device 500 may include, but is not limited to, a processor 510 and a memory 520. Those skilled in the art will understand that Figure 5 This is only an example of the computer device 500 and does not constitute a limitation of the computer device 500. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the computer device 500 may also include input and output devices, network access devices, buses, etc.
[0186] The processor 510 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0187] The memory 520 may be an internal storage unit of the computer device 500, such as a hard disk or memory of the computer device 500. The memory 520 may also be an external storage device of the computer device 500, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 500. Further, the memory 520 may also include both an internal storage unit of the computer device 500 and an external storage device. The memory 520 is used to store the computer program 521 and other programs and data required by the computer device 500. The memory 520 may also be used to temporarily store data that has been output or is to be output.
[0188] An embodiment of the present application further discloses a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the methods described in the above embodiments are implemented.
[0189] The embodiments of the present application further disclose a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the methods described in the above embodiments are implemented.
[0190] The embodiments of the present application further disclose a computer program product, including a computer program. When the computer program is run on a computer, the computer is enabled to execute the methods described in the aforementioned embodiments.
[0191] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application is described in detail with reference to the above-mentioned embodiments, a person skilled in the art should understand that the technical solutions described in the above-mentioned embodiments can still be modified, or some of the technical features can be replaced by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.
Claims
1. A Byzantine fault-tolerant consensus method based on directed acyclic graph, characterized in that: Applied to any consensus node in a blockchain, the method includes: Broadcasting a transaction block to all nodes, wherein the transaction block contains the transaction requested to be executed, and the transaction block has a transaction sequence number, which is used to indicate the order of the transaction blocks broadcast by the consensus node; When receiving confirmation messages fed back by at least a first number of nodes after verifying the transaction block, marking the transaction block as an authenticated transaction block; A directed acyclic graph is constructed by broadcasting messages; wherein, if the consensus node generates the authenticated transaction block, the broadcasted message includes a hash value of the authenticated transaction block; if the consensus node does not generate the authenticated transaction block, the broadcasted message includes a special value used to replace the hash value of the authenticated transaction block; the hash value of the authenticated transaction block and / or the special value are used to determine each vertex in the directed acyclic graph, and the message also includes auxiliary information for determining each edge in the directed acyclic graph; The vertices in the directed acyclic graph are sorted, and the transactions contained in the transaction blocks corresponding to the sorted vertices are sequentially executed.
2. The method according to claim 1, characterized in that The method of constructing a directed acyclic graph by broadcasting messages includes: Determine the round that the consensus node is currently in, where the round includes an even round or an odd round; After the round is updated, the message is broadcasted, and the currently constructed directed acyclic graph is updated according to the broadcasted message, wherein the message includes the hash value of the authenticated transaction block or the special value, and the auxiliary information.
3. The method according to claim 2, characterized in that The broadcasting of the message after updating the round, and updating the currently constructed directed acyclic graph according to the broadcasted message, comprises: If the current round of the consensus node is an even round, add 1 to the even round and start the timer to count down; Broadcast the message, wherein the message includes the hash value of the authenticated transaction block with the largest transaction number owned by the consensus node and auxiliary information; wherein, if the authenticated transaction block with the largest transaction number has been broadcasted, the hash value of the authenticated transaction block with the largest transaction number is replaced by the special value; the auxiliary information includes the messages from all nodes in the even-numbered round and one or more messages from all nodes in the round before the even-numbered round; The currently constructed directed acyclic graph is updated according to the broadcasted message.
4. The method according to claim 3, characterized in that The one or more messages from all nodes in the rounds before the even-numbered rounds included in the auxiliary information all meet the following conditions: If the message in the round before the even round is removed, there does not exist a path in the directed acyclic graph from the vertex corresponding to the message from the consensus node in the next round of the even round to the vertex corresponding to the removed message.
5. The method according to claim 2, characterized in that: The broadcasting of the message after updating the round, and updating the currently constructed directed acyclic graph according to the broadcasted message, comprises: If the current round of the consensus node is an odd round, determine whether the timer countdown has ended or whether the vertex corresponding to the message broadcast by the leader vertex in the odd round has been added to the directed acyclic graph; If the countdown of the timer ends or the vertex corresponding to the message broadcast by the leader vertex in the odd round has been added to the directed acyclic graph, then add 1 to the odd round; Broadcast a message and update the currently constructed directed acyclic graph according to the broadcasted message.
6. The method according to claim 5, characterized in that Also includes: If the vertex corresponding to the message broadcast by the leader vertex in the odd round has been added to the directed acyclic graph, clearing the value of the timer; If there are at least a second number of vertices in the directed acyclic graph corresponding to the round after the odd round, broadcast a message after clearing the value of the timer and adding 1 to the current round after the odd round; if the round after adding 1 to the current round after the odd round is an odd round, restart the timer.
7. The method according to claim 2, characterized in that The method of broadcasting the message after updating the round, and updating the currently constructed directed acyclic graph according to the broadcasted message, further includes: If the consensus node confirms the received message and the vertex corresponding to the message in the auxiliary information already exists in the directed acyclic graph and the proofs of the transaction block by other nodes are verified, the directed acyclic graph is updated according to the confirmed message.
8. The method according to any one of claims 1 to 7, characterized in that: The step of sorting the vertices in the directed acyclic graph comprises: Determining the number of votes obtained by a leader vertex in a target round of the directed acyclic graph in a current round, the target round being less than the current round; When the number of votes reaches the first number, determining a leader vertex with the smallest round number among all unexecuted ancestors; Sorting the leader vertices among all unexecuted ancestors in order of rounds from small to large, and sorting all vertices in the directed acyclic graph based on the sorted leader vertices; Among them, all unexecuted ancestors refer to vertices whose corresponding transaction blocks have not been executed in the set of all vertices that can be reached from the leader vertex in the target round.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the computer device is caused to implement the method according to any one of claims 1 to 8.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed, the method according to any one of claims 1 to 8 is executed.
Citation Information
Patent Citations
Asynchronous Byzantine consensus method and system based on DAG
CN113923217A
Byzantine fault-tolerant consensus method based on layered directed acyclic graph structure
CN117220885A