Intelligent contract auditing method and device, electronic equipment and computer program product

By conducting static analysis, dynamic analysis and cross-chain consistency verification of smart contracts, the problem of incomplete auditing of smart contracts in the existing technology is solved, and the audit accuracy and security of smart contracts are improved.

CN119938487APending Publication Date: 2025-05-06HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411976564.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing smart contract audit methods cannot conduct comprehensive audits, resulting in low audit accuracy, especially the inability to conduct consistent verification of cross-chain smart contracts.

Method used

By determining the target blockchain that the smart contract is adapted to, perform static analysis and dynamic analysis, and verify the consistency of the execution results of the smart contract on each target blockchain to determine the audit results.

Benefits of technology

It realizes a comprehensive audit of smart contracts, improves audit accuracy, and ensures the security, reliability and compliance of smart contracts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938487A_ABST
    Figure CN119938487A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of block chains, and provides a smart contract auditing method and device, electronic equipment and a computer program product. The auditing method of the smart contract specifically comprises the steps of determining a target block chain adapted to a to-be-audited smart contract, and determining first contract information of the smart contract; performing static analysis on the smart contract according to the first contract information to obtain a static analysis result of the smart contract; respectively constructing a test chain corresponding to each target block chain, and dynamically analyzing the smart contract through each test chain to obtain a dynamic analysis result of the smart contract; verifying a consistency result of execution results deployed on each target block chain by the smart contract; and determining an audit result of the smart contract according to the static analysis result, the dynamic analysis result and the consistency result. Through the method provided by the invention, the intelligent contract can be audited in all directions, and the audit accuracy of the intelligent contract is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of blockchain technology, and in particular, relates to an audit method, device, electronic device and computer program product for smart contracts. Background Art

[0002] Smart contracts are widely used in the blockchain field. If there are loopholes or design problems in smart contracts, it may cause irreversible losses. Therefore, before using smart contracts, it is necessary to audit the smart contracts to ensure that they are safe, reliable and compliant.

[0003] However, existing smart contract auditing methods are usually rather one-sided. For example, some smart contract auditing methods can only perform static analysis on smart contracts, while other smart contract auditing methods can only perform dynamic analysis on smart contracts. In addition, existing smart contract auditing methods cannot perform consistency verification on cross-chain smart contracts. Therefore, it can be seen that existing smart contract auditing methods cannot conduct a comprehensive audit of smart contracts, which reduces the accuracy of smart contract audits. Summary of the invention

[0004] In view of this, the embodiments of the present application provide a smart contract audit method, device, electronic device and computer program product to solve the technical problem of low audit accuracy of existing smart contracts.

[0005] In a first aspect, an embodiment of the present application provides a smart contract auditing method, including:

[0006] Determine the target blockchain adapted by the smart contract to be audited, and determine the first contract information of the smart contract;

[0007] Performing static analysis on the smart contract according to the first contract information to obtain a static analysis result of the smart contract;

[0008] Constructing test chains corresponding to the target blockchains respectively, and dynamically analyzing the smart contract through the test chains to obtain dynamic analysis results of the smart contract;

[0009] Verifying the consistency of the execution results of the smart contract deployed on each of the target blockchains;

[0010] The audit result of the smart contract is determined according to the static analysis result, the dynamic analysis result and the consistency result.

[0011] Optionally, after determining the target blockchain adapted by the smart contract to be audited, the method further includes:

[0012] For each of the target blockchains, according to the user demand information and the characteristics of the target blockchain, determine the target chain environment corresponding to the target blockchain and adapted to the smart contract;

[0013] The consistency result of the execution result of verifying the smart contract deployed on each of the target blockchains includes:

[0014] According to the target chain environment corresponding to each of the target blockchains, the consistency of the execution results of the smart contract deployed on each of the target blockchains is verified.

[0015] Optionally, determining the first contract information of the smart contract includes:

[0016] For each of the target blockchains, according to the characteristics of the target blockchain, determine the interface adaptation layer of the target blockchain, and obtain the second contract information of the smart contract on the target blockchain through the interface adaptation layer;

[0017] The first contract information is determined according to the second contract information of the smart contract on each of the target blockchains.

[0018] Optionally, the first contract information includes code information, application program interface information, and bytecode information of the smart contract; and the performing static analysis on the smart contract according to the first contract information to obtain a static analysis result of the smart contract includes:

[0019] The code information, the application program interface information, and the bytecode information are statically analyzed to obtain potential vulnerability identification results and logic problem identification results of the smart contract as static analysis results of the smart contract.

[0020] Optionally, the dynamically analyzing the smart contract through each of the test chains to obtain a dynamic analysis result of the smart contract includes:

[0021] Generate test cases corresponding to each of the test chains, where the test cases are used to test the target functions of the smart contract;

[0022] In the preset test network, the smart contract is dynamically analyzed through each of the test chains and the test cases corresponding to each of the test chains, to obtain the sub-dynamic analysis results corresponding to each of the test chains;

[0023] The dynamic analysis result of the smart contract is determined according to the sub-dynamic analysis results corresponding to each of the test chains.

[0024] Optionally, the verification of the consistency of the execution results of the smart contract deployed on each of the target blockchains includes:

[0025] For each of the target blockchains, determine the contract logic information, interface information, and state change information corresponding to the smart contract when it is deployed on the target blockchain;

[0026] According to the contract logic information, the interface information, and the state change information corresponding to each of the target blockchains, the consistency result of the execution result of the smart contract deployed on each of the target blockchains is determined.

[0027] Optionally, the audit result includes risk level information and optimization suggestion information; and determining the audit result of the smart contract according to the static analysis result, the dynamic analysis result, and the consistency result includes:

[0028] Determine security vulnerability information, logic problem information, and consistency difference information of the smart contract according to the static analysis result, the dynamic analysis result, and the consistency result;

[0029] The risk level information and the optimization suggestion information are determined according to the security vulnerability information, the logic problem information, and the consistency result difference information.

[0030] In a second aspect, an embodiment of the present application provides an auditing device for a smart contract, comprising:

[0031] An information determination unit, used to determine a target blockchain adapted by a smart contract to be audited, and to determine first contract information of the smart contract;

[0032] A static analysis unit, configured to perform a static analysis on the smart contract according to the first contract information to obtain a static analysis result of the smart contract;

[0033] A dynamic analysis unit, used to respectively construct test chains corresponding to each of the target blockchains, and dynamically analyze the smart contract through each of the test chains to obtain a dynamic analysis result of the smart contract;

[0034] A consistency result verification unit, used to verify the consistency results of the execution results of the smart contract deployed on each of the target blockchains;

[0035] An audit result determination unit is used to determine the audit result of the smart contract based on the static analysis result, the dynamic analysis result and the consistency result.

[0036] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, each step in the smart contract auditing method as described in any one of the first aspects above is implemented.

[0037] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, each step in the smart contract audit method as described in any one of the first aspects above is implemented.

[0038] In a fifth aspect, an embodiment of the present application provides a computer program product. When the computer program product is run on an electronic device, the electronic device executes each step of the smart contract audit method as described in any one of the first aspects above.

[0039] The smart contract auditing method, device, electronic device, and computer program product provided by the embodiments of the present application have the following beneficial effects:

[0040] In the audit method of the smart contract of the present application, the target blockchain adapted by the smart contract to be audited is first determined, and the first contract information of the smart contract is determined. Then, according to the first contract information, the smart contract is statically analyzed to obtain the static analysis result of the smart contract, and the test chains corresponding to each target blockchain are respectively constructed, and the smart contract is dynamically analyzed through each test chain to obtain the dynamic analysis result of the smart contract, and the consistency result of the execution result of the smart contract deployed on each target blockchain is verified. Finally, the audit result of the smart contract is determined based on the static analysis result, dynamic analysis result and consistency result. Through the method of the present application, the static analysis result, dynamic analysis result and consistency result of the execution result of the smart contract deployed on each target blockchain can be determined, so that the smart contract can be audited in an all-round way, which improves the audit accuracy of the smart contract. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0042] Figure 1 A flowchart of an implementation method of an audit of a smart contract provided in an embodiment of the present application;

[0043] Figure 2A schematic diagram of the structure of an audit device for a smart contract provided in an embodiment of the present application;

[0044] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0045] It should be noted that the terms used in the embodiments of the present application are only used to explain the specific embodiments of the present application, and are not intended to limit the present application. In the description of the embodiments of the present application, unless otherwise specified, "multiple" refers to two or more than two, and "at least one", "one or more" refers to one, two or more. The terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Thus, it is defined that the "first" and "second" features can explicitly or implicitly include one or more of the features.

[0046] References to "one embodiment" or "some embodiments" etc. described in this specification mean that a particular feature, structure or characteristic described in conjunction with the embodiment is included in one or more embodiments of the present application. Thus, the phrases "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear at different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0047] The audit method for a smart contract provided in the embodiment of the present application may be an electronic device, which may execute each step of the audit method for a smart contract provided in the embodiment of the present application. Specifically, the electronic device may include but is not limited to mobile phones, tablet computers, laptop computers, and desktop computers.

[0048] The audit method of the smart contract provided in the embodiment of the present application can be applied to various application scenarios where the smart contract needs to be audited. In particular, the audit method of the smart contract provided in the embodiment of the present application can be applied to the scenario of auditing the smart contract deployed on multiple chains, wherein the smart contract deployed on multiple chains can also be deployed on multiple different blockchains.

[0049] When it is necessary to audit a smart contract, each step of the smart contract audit method provided in the embodiment of the present application can be executed by an electronic device, thereby enabling a comprehensive audit of the smart contract.

[0050] See also Figure 1 , Figure 1 The present invention provides a flowchart of an implementation method of an audit method for a smart contract. The audit method for a smart contract may include S101 to S105, which are described in detail as follows:

[0051] In S101, a target blockchain adapted by the smart contract to be audited is determined, and first contract information of the smart contract is determined.

[0052] In an embodiment of the present application, when it is necessary to audit a smart contract to be audited, the electronic device can first determine the target blockchain adapted by the smart contract to be audited, and can determine the first contract information of the smart contract. Among them, the target blockchain can be any legal and compliant blockchain.

[0053] Specifically, the electronic device can first determine the target blockchain adapted by the smart contract to be audited, and then determine the first contract information of the smart contract.

[0054] In this implementation, after determining each target blockchain, the electronic device can determine the interface adaptation layer of each target blockchain according to the characteristics of the target blockchain, and obtain the second contract information of the smart contract on the target blockchain through the interface adaptation layer, thereby obtaining the second contract information of the smart contract on each target blockchain.

[0055] After obtaining the second contract information of the smart contract on each target blockchain, the electronic device can determine the first contract information based on the second contract information of the smart contract on each target blockchain. Specifically, the electronic device can determine the set of the second contract information of the smart contract on each target blockchain as the first contract information.

[0056] Exemplarily, the second contract information may include one or more of the following: deployment address information of the smart contract on the target blockchain, application program interface information of the smart contract on the target blockchain, storage layout information of the smart contract on the target blockchain, code information of the smart contract on the target blockchain, and bytecode information of the smart contract on the target blockchain.

[0057] Based on this, the first contract information may include one or more of the following: deployment address information, application program interface information, storage layout information, code information, and bytecode information.

[0058] In S102, a static analysis is performed on the smart contract based on the first contract information to obtain a static analysis result of the smart contract.

[0059] In an embodiment of the present application, after determining the first contract information of the smart contract, the electronic device can perform a static analysis on the smart contract based on the first contract information of the smart contract to obtain a static analysis result of the smart contract.

[0060] In a possible implementation, the first contract information may include code information, application program interface information, and bytecode information of the smart contract. Based on this, the electronic device may perform static analysis on the code information, application program interface information, and bytecode information in the first contract information to obtain potential vulnerability identification results and logic problem identification results of the smart contract, and use the potential vulnerability identification results and logic problem identification results of the smart contract as static analysis results of the smart contract. If the potential vulnerability identification result is that there is no vulnerability, and the logic problem identification result is that there is no logic problem, then the static analysis result of the smart contract may be static analysis passed.

[0061] For example, the electronic device can perform static analysis on the code information, application program interface information, and bytecode information in the first contract information, parse and compare the function interface, event definition, and state variable in the smart contract to determine the interface consistency result of the smart contract, and identify whether the smart contract has common vulnerabilities through a preset analysis tool. Among them, common vulnerabilities may include but are not limited to: reentrancy attack vulnerabilities, integer overflow vulnerabilities, and permission management issues.

[0062] In S103, test chains corresponding to the respective target blockchains are constructed respectively, and the smart contract is dynamically analyzed through each test chain to obtain the dynamic analysis results of the smart contract.

[0063] In an embodiment of the present application, after determining the target blockchain to which the smart contract to be audited is adapted, the electronic device can respectively construct test chains corresponding to each target blockchain, and dynamically analyze the smart contract through the constructed test chain to obtain the dynamic analysis result of the smart contract.

[0064] In a possible implementation, the electronic device can obtain the dynamic analysis result of the smart contract through steps a to c. The details are as follows:

[0065] In step a, test cases corresponding to each test chain are generated, and the test cases are used to test the target functions of the smart contract.

[0066] In this implementation, after constructing the test chains corresponding to each target blockchain, the electronic device can generate test cases corresponding to each test chain.

[0067] The test case is used to test the target function of the smart contract. For example, the target function can be the core function of the smart contract, such as the transfer function, storage function, and event triggering function.

[0068] Exemplarily, the way in which an electronic device generates a test case corresponding to any test chain can be: the electronic device can first parse the smart contract, thereby extracting the functional interface information, event information, and state variable information of the smart contract deployed on the target blockchain corresponding to the test chain, and generate a test case corresponding to the test chain based on the extracted functional interface information, event information, and state variable information.

[0069] In step b, in the preset test network, the smart contract is dynamically analyzed through each test chain and the test cases corresponding to each test chain, and the sub-dynamic analysis results corresponding to each test chain are obtained.

[0070] In this implementation, after generating test cases corresponding to each test chain, the electronic device can dynamically analyze the smart contract for each test chain through the test chain and the test cases corresponding to the test chain in a preset test network to obtain the sub-dynamic analysis results corresponding to the test chain. By executing the above process for each test chain, the electronic device can obtain the sub-dynamic analysis results corresponding to each test chain.

[0071] Specifically, the process of an electronic device dynamically analyzing a smart contract in a preset test network through an arbitrary test chain and a test case corresponding to the arbitrary test chain can be: simulating the execution of the smart contract through the test chain in the preset test network, and obtaining the security risks and functional problems of the smart contract during execution through the test case corresponding to the test chain, and verifying whether the behavior of the smart contract during the execution process meets expectations, and using the security risks and functional problems of the smart contract during execution and whether the behavior of the smart contract during execution meets expectations as the sub-dynamic analysis results corresponding to the test chain.

[0072] If there are no security risks or functional problems when the smart contract is executed, and the behavior of the smart contract during the execution process is in line with expectations, the sub-dynamic analysis result corresponding to the test chain can be sub-dynamic analysis passed.

[0073] In step c, the dynamic analysis results of the smart contract are determined according to the sub-dynamic analysis results corresponding to each test chain.

[0074] In this implementation, after obtaining the sub-dynamic analysis results corresponding to each test chain, the electronic device can determine the dynamic analysis results of the smart contract based on the sub-dynamic analysis results corresponding to each test chain.

[0075] Exemplarily, if all sub-dynamic analysis results are sub-dynamic analysis passed, it can be determined that the dynamic analysis result of the smart contract is passed.

[0076] If the results of any sub-dynamic analysis show that the smart contract has security risks and functional problems during execution, or if any behavior of the smart contract during execution does not meet expectations, it can be determined that the dynamic analysis results of the smart contract have failed.

[0077] In S104, the consistency of the execution results of the smart contract deployed on each target blockchain is verified.

[0078] In an embodiment of the present application, after determining the target blockchain to which the smart contract to be audited is adapted, the electronic device can verify the consistency of the execution results of the smart contract deployed on each target blockchain.

[0079] In one possible implementation, after determining the target blockchain adapted for the smart contract to be audited, the electronic device can determine, for each target blockchain, the target chain environment adapted for the smart contract corresponding to the target blockchain based on user demand information and the characteristics of the target blockchain, thereby determining the target chain environment adapted for the smart contract corresponding to each target blockchain.

[0080] Among them, user demand information can be input into the electronic device in advance by the user, the characteristics of the target blockchain can be determined by the electronic device based on the blockchain, and the target chain environment adapted to the smart contract can include one or more of the following: network type, consensus mechanism, and fee model, etc.

[0081] After determining the target chain environment corresponding to each target blockchain and adapted to the smart contract, the electronic device can verify the consistency of the execution results of the smart contract deployed on each target blockchain according to the target chain environment corresponding to each target blockchain.

[0082] In a possible implementation, the electronic device can verify the consistency of the execution results of the smart contract deployed on each target blockchain through steps d to e. The details are as follows:

[0083] In step d, for each target blockchain, determine the contract logic information, interface information, and state change information corresponding to the smart contract when it is deployed on the target blockchain.

[0084] In this implementation, the electronic device can determine, for each target blockchain, the contract logic information, interface information, and state change information corresponding to the smart contract when it is deployed on the target blockchain according to the target chain environment corresponding to the target blockchain, thereby obtaining the contract logic information, interface information, and state change information corresponding to the smart contract when it is deployed on each target blockchain.

[0085] In step e, the consistency of the execution results of the smart contract deployed on each target blockchain is determined based on the contract logic information, interface information, and state change information corresponding to each target blockchain.

[0086] In this implementation, after obtaining the contract logic information, interface information, and state change information corresponding to the smart contract when it is deployed on each target blockchain, the electronic device can compare the contract logic information, interface information, and state change information corresponding to the smart contract when it is deployed on each target blockchain to determine the consistency of the execution results of the smart contract deployed on each target blockchain.

[0087] Specifically, if the electronic device determines that the contract logic information, interface information and state change information corresponding to the smart contract when it is deployed on each target blockchain are the same, then it can be determined that the consistency results of the execution results of the smart contract deployed on each target blockchain are passed. If the electronic device determines that the contract logic information, interface information and state change information corresponding to the smart contract when it is deployed on each target blockchain are different, then it can be determined that the consistency results of the execution results of the smart contract deployed on each target blockchain are not passed.

[0088] In S105, the audit result of the smart contract is determined based on the static analysis result, the dynamic analysis result and the consistency result.

[0089] In an embodiment of the present application, after determining the static analysis results of the smart contract, the dynamic analysis results of the smart contract, and the consistency results of the execution results of the smart contract deployed on each target blockchain, the electronic device can determine the audit result of the smart contract based on the static analysis results of the smart contract, the dynamic analysis results of the smart contract, and the consistency results of the execution results of the smart contract deployed on each target blockchain.

[0090] In a possible implementation, the audit result of the smart contract may include risk level information and optimization suggestion information. The risk level information is used to describe the risk level corresponding to each problem existing in the smart contract, and the optimization suggestion information is used to describe the optimization suggestion for the smart contract. Based on this, the electronic device can determine the audit result of the smart contract through steps f to g, as described in detail as follows:

[0091] In step f, the security vulnerability information, logic problem information and consistency difference information of the smart contract are determined based on the static analysis results, dynamic analysis results and consistency results.

[0092] In this implementation, the electronic device can determine the security vulnerability information and logic problem information of the smart contract based on the potential vulnerability identification results and logic problem identification results in the static analysis results, and the security risks and functional problems in the dynamic analysis results. Among them, the security vulnerability information is used to describe whether there is a security vulnerability in the smart contract, and the logic problem information is used to describe whether there is a logic problem in the smart contract.

[0093] In addition, the electronic device can determine the consistency difference information of the smart contract based on the consistency results of the execution results of the contract deployed on each target blockchain. The consistency difference information is used to describe the differences between the execution results of the smart contract deployed on each target blockchain.

[0094] In step g, risk level information and optimization suggestion information are determined based on the security vulnerability information, logic problem information, and consistency result difference information.

[0095] In this implementation, after determining the security vulnerability information, logical problem information, and consistency difference information of the smart contract, the electronic device can determine the risk level corresponding to each problem existing in the smart contract based on the security vulnerability information and logical problem information of the smart contract to determine the risk level information, and can determine optimization suggestions for the smart contract based on the security vulnerability information, logical problem information, and consistency difference information of the smart contract to determine the optimization suggestion information.

[0096] From the above, it can be seen that in the audit method of the smart contract of the present application, the target blockchain adapted by the smart contract to be audited is first determined, and the first contract information of the smart contract is determined. Then, according to the first contract information, the smart contract is statically analyzed to obtain the static analysis result of the smart contract, and the test chains corresponding to each target blockchain are respectively constructed, and the smart contract is dynamically analyzed through each test chain to obtain the dynamic analysis result of the smart contract, and the consistency result of the execution result of the smart contract deployed on each target blockchain is verified. Finally, the audit result of the smart contract is determined based on the static analysis result, dynamic analysis result and consistency result. Through the method of the present application, the static analysis result, dynamic analysis result and consistency result of the execution result of the smart contract deployed on each target blockchain can be determined, so that the smart contract can be audited in an all-round way, which improves the audit accuracy of the smart contract.

[0097] Based on the smart contract auditing method provided in the above embodiment, the present application further provides a smart contract auditing device for implementing the above method embodiment. Figure 2 , Figure 2 A schematic diagram of the structure of a smart contract auditing device provided in an embodiment of the present application. Figure 2 As shown, the audit device 20 of the smart contract may include: an information determination unit 21, a static analysis unit 22, a dynamic analysis unit 23, a consistency result verification unit 24 and an audit result determination unit 25. Among them:

[0098] The information determination unit 21 is used to determine the target blockchain adapted by the smart contract to be audited, and to determine the first contract information of the smart contract.

[0099] The static analysis unit 22 is used to perform static analysis on the smart contract according to the first contract information to obtain a static analysis result of the smart contract.

[0100] The dynamic analysis unit 23 is used to construct test chains corresponding to each target blockchain respectively, and dynamically analyze the smart contract through each test chain to obtain the dynamic analysis result of the smart contract.

[0101] The consistency result verification unit 24 is used to verify the consistency results of the execution results of the smart contract deployed on each target blockchain.

[0102] The audit result determination unit 25 is used to determine the audit result of the smart contract based on the static analysis result, the dynamic analysis result and the consistency result.

[0103] Optionally, the smart contract auditing device 20 may further include a chain environment determination unit, wherein:

[0104] The chain environment determination unit is used to determine, for each target blockchain, a target chain environment that is compatible with the smart contract and that corresponds to the target blockchain according to user demand information and the characteristics of the target blockchain.

[0105] Based on this, the consistency result verification unit 24 is specifically used to:

[0106] According to the target chain environment corresponding to each target blockchain, verify the consistency of the execution results of the smart contract deployed on each target blockchain.

[0107] Optionally, the information determining unit 21 is specifically configured to:

[0108] For each target blockchain, determine the interface adaptation layer of the target blockchain according to the characteristics of the target blockchain, and obtain the second contract information of the smart contract on the target blockchain through the interface adaptation layer;

[0109] The first contract information is determined according to the second contract information of the smart contract on each target blockchain.

[0110] Optionally, the first contract information includes code information, application program interface information, and bytecode information of the smart contract; the static analysis unit 22 is specifically used for:

[0111] Static analysis is performed on the code information, application interface information, and bytecode information to obtain the potential vulnerability identification results and logic problem identification results of the smart contract as the static analysis results of the smart contract.

[0112] Optionally, the dynamic analysis unit 23 is specifically used for:

[0113] Generate test cases corresponding to each test chain, which are used to test the target functions of smart contracts;

[0114] In the preset test network, the smart contract is dynamically analyzed through each test chain and the test cases corresponding to each test chain, and the sub-dynamic analysis results corresponding to each test chain are obtained;

[0115] Determine the dynamic analysis results of the smart contract based on the sub-dynamic analysis results corresponding to each test chain.

[0116] Optionally, the consistency result verification unit 24 is specifically used for:

[0117] For each target blockchain, determine the contract logic information, interface information, and state change information corresponding to the smart contract when it is deployed on the target blockchain;

[0118] According to the contract logic information, interface information and state change information corresponding to each target blockchain, the consistency of the execution results of the smart contract deployed on each target blockchain is determined.

[0119] Optionally, the audit result includes risk level information and optimization suggestion information; the audit result determination unit 25 is specifically used for:

[0120] Determine the security vulnerability information, logic problem information, and consistency difference information of the smart contract based on the static analysis results, dynamic analysis results, and consistency results;

[0121] Determine risk level information and optimization suggestion information based on security vulnerability information, logical problem information, and consistency result difference information.

[0122] It should be noted that the information interaction, execution process and other contents between the above-mentioned units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be specifically referred to the method embodiment part and will not be repeated here.

[0123] See also Figure 3 , Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 3 As shown, the electronic device 3 provided in this embodiment may include: a processor 30, a memory 31, and a computer program 32 stored in the memory 31 and executable on the processor 30, such as a program corresponding to the audit of a smart contract. When the processor 30 executes the computer program 32, the steps in the above-mentioned audit embodiment applied to a smart contract are implemented, such as Figure 1 Alternatively, when the processor 30 executes the computer program 32, the functions of each module / unit in the above-mentioned smart contract auditing device embodiment are realized, for example Figure 2 The functions of the units 21 to 25 are shown.

[0124] Exemplarily, the computer program 32 may be divided into one or more modules / units, one or more modules / units are stored in the memory 31 and executed by the processor 30 to complete the present application. One or more modules / units may be a series of computer program instruction segments that can complete specific functions, and the instruction segments are used to describe the execution process of the computer program 32 in the electronic device 3. For example, the computer program 32 may be divided into an information determination unit 21, a static analysis unit 22, a dynamic analysis unit 23, a consistency result verification unit 24, and an audit result determination unit 25. For the specific functions of each unit, please refer to Figure 2 The relevant descriptions in the corresponding embodiments are not repeated here.

[0125] Those skilled in the art will understand that Figure 3 This is only an example of the electronic device 3 and does not constitute a limitation on the electronic device 3 , which may include more or less components than those shown in the figure, or a combination of certain components, or different components.

[0126] The processor 30 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0127] The memory 31 may be an internal storage unit of the electronic device 3, such as a hard disk or memory of the electronic device 3. The memory 31 may also be an external storage device of the electronic device 3, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, or a flash card, etc., equipped on the electronic device 3. Further, the memory 31 may also include both an internal storage unit and an external storage device of the electronic device 3. The memory 31 is used to store computer programs and other programs and data required by the electronic device. The memory 31 may also be used to temporarily store data that has been output or is to be output.

[0128] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units is used as an example for illustration. In actual applications, the above-mentioned functions can be assigned to different functional units as needed, that is, the internal structure of the audit device of the smart contract can be divided into different functional units to complete all or part of the functions described above. The functional units in the embodiment can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.

[0129] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.

[0130] An embodiment of the present application provides a computer program product. When the computer program product is executed on a terminal device, the terminal device implements the steps in the above-mentioned various method embodiments.

[0131] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0132] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0133] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A smart contract audit method, characterized in that: include: Determine the target blockchain adapted by the smart contract to be audited, and determine the first contract information of the smart contract; Performing static analysis on the smart contract according to the first contract information to obtain a static analysis result of the smart contract; Constructing test chains corresponding to the target blockchains respectively, and dynamically analyzing the smart contract through the test chains to obtain dynamic analysis results of the smart contract; Verifying the consistency of the execution results of the smart contract deployed on each of the target blockchains; The audit result of the smart contract is determined according to the static analysis result, the dynamic analysis result and the consistency result.

2. The method according to claim 1, characterized in that After determining the target blockchain adapted by the smart contract to be audited, the method further includes: For each of the target blockchains, according to the user demand information and the characteristics of the target blockchain, determine the target chain environment corresponding to the target blockchain and adapted to the smart contract; The consistency result of the execution result of verifying the smart contract deployed on each of the target blockchains includes: According to the target chain environment corresponding to each of the target blockchains, the consistency of the execution results of the smart contract deployed on each of the target blockchains is verified.

3. The method according to claim 1, characterized in that The determining the first contract information of the smart contract includes: For each of the target blockchains, according to the characteristics of the target blockchain, determine the interface adaptation layer of the target blockchain, and obtain the second contract information of the smart contract on the target blockchain through the interface adaptation layer; The first contract information is determined according to the second contract information of the smart contract on each of the target blockchains.

4. The method according to claim 1, characterized in that: The first contract information includes code information, application program interface information, and bytecode information of the smart contract; the static analysis of the smart contract is performed according to the first contract information to obtain a static analysis result of the smart contract, including: The code information, the application program interface information, and the bytecode information are statically analyzed to obtain potential vulnerability identification results and logic problem identification results of the smart contract as static analysis results of the smart contract.

5. The method according to claim 1, characterized in that The dynamic analysis of the smart contract by each of the test chains to obtain the dynamic analysis result of the smart contract includes: Generate test cases corresponding to each of the test chains, where the test cases are used to test the target functions of the smart contract; In the preset test network, the smart contract is dynamically analyzed through each of the test chains and the test cases corresponding to each of the test chains, to obtain sub-dynamic analysis results corresponding to each of the test chains; The dynamic analysis result of the smart contract is determined according to the sub-dynamic analysis results corresponding to each of the test chains.

6. The method according to claim 1, characterized in that The consistency result of the execution result of verifying the smart contract deployed on each of the target blockchains includes: For each of the target blockchains, determine the contract logic information, interface information, and state change information corresponding to the smart contract when it is deployed on the target blockchain; According to the contract logic information, the interface information, and the state change information corresponding to each of the target blockchains, the consistency result of the execution result of the smart contract deployed on each of the target blockchains is determined.

7. The method according to any one of claims 1 to 6, characterized in that: The audit results include risk level information and optimization suggestion information; Determining the audit result of the smart contract according to the static analysis result, the dynamic analysis result, and the consistency result includes: Determine security vulnerability information, logic problem information, and consistency difference information of the smart contract according to the static analysis result, the dynamic analysis result, and the consistency result; The risk level information and the optimization suggestion information are determined according to the security vulnerability information, the logic problem information and the consistency result difference information.

8. An audit device for a smart contract, characterized in that: include: An information determination unit, used to determine a target blockchain adapted by a smart contract to be audited, and to determine first contract information of the smart contract; A static analysis unit, configured to perform a static analysis on the smart contract according to the first contract information to obtain a static analysis result of the smart contract; A dynamic analysis unit, used to respectively construct test chains corresponding to each of the target blockchains, and dynamically analyze the smart contract through each of the test chains to obtain a dynamic analysis result of the smart contract; A consistency result verification unit, used to verify the consistency results of the execution results of the smart contract deployed on each of the target blockchains; An audit result determination unit is used to determine the audit result of the smart contract based on the static analysis result, the dynamic analysis result and the consistency result.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, each step in the audit method of the smart contract as described in any one of claims 1 to 7 is implemented.

10. A computer program product, characterized in that When the computer program product is executed by a processor, each step in the audit method of a smart contract as described in any one of claims 1 to 7 is implemented.