Dynamic trust-based block chain rewriting method supporting update traceability

By introducing a dynamic trust mechanism and a credit value screening mechanism into the blockchain system, the problem of low security of existing blockchain rewriting methods is solved, and effective protection and security improvement of blockchain information is achieved.

CN119938781AActive Publication Date: 2025-05-06NORTHWESTERN POLYTECHNICAL UNIV +2

Patent Information

Application Number
CN202411740682.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-29
Publication Date
2025-05-06
Estimated Expiration
2044-11-29

AI Technical Summary

Technical Problem

The existing blockchain rewrite method is low in security and cannot effectively prevent and predict malicious modifications to blockchain information by malicious modifyers.

Method used

By introducing a dynamic trust mechanism into the editable blockchain system, each node's trust value is determined based on the historical transactions, consensus, and modification behavior of each node, and the committee members with higher trust value are elected to perform the modification behavior. Committee members need to verify whether the modifyer's signature, reason for modification and trust value meet the conditions before they can modify the blockchain information.

Benefits of technology

By screening the modifyers through credit values, it can prevent users who have multiple malicious behaviors from modifying blockchain information, reduce the occurrence of malicious events, and improve the security performance of blockchain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938781A_ABST
    Figure CN119938781A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic trust-based block chain rewriting method supporting update traceability, the method is applied to an editable block chain system, and the method comprises the following steps: a modifier broadcasts modification suggestions to other committee members in the rth round; the rth round of committee members are obtained through election based on the trust value of each user at the rth moment, and the trust values of the user nodes at the rth moment are determined according to historical transactions, consensus and modification behaviors of the user nodes; other committee members verify the modification suggestions; and if the verification is passed, other committee members accept the modification of the original information by the modifiers, replace the original information with the modification information on an editable global account book, and store the modification signature and the modification random number. According to the invention, the safety performance of the editable block chain system can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of blockchain, and in particular relates to a blockchain rewriting method based on dynamic trust that supports update traceability. Background Art

[0002] Recently, the investigation and application of blockchain technology has attracted widespread attention from academia and industry, showing explosive growth. Blockchain combines cryptographic theory, distributed consensus, incentives, and timestamps to achieve peer-to-peer transactions, coordination, and cooperation based on decentralized credit without the need for a third-party trusted institution. Blockchain has the advantages of decentralization, transparency, and immutability, providing opportunities to solve many problems in centralized institutions, and is therefore widely used in digital currency, healthcare, the Internet of Things, and other fields.

[0003] However, as blockchain technology continues to develop, the problem of blockchain storage abuse has also emerged due to its immutability. In this case, chain participants may inadvertently contribute to the spread of inappropriate content because they may not be able to identify illegal or inappropriate information, and users may be reluctant to participate and download the chain for fear of being prosecuted for holding such information, thus hindering the growth and application of blockchain. In addition, its immutability also violates some data regulations, such as the General Data Protection Regulation and the "right to be forgotten", both of which stipulate that anyone has the right to delete personal private information. In order to alleviate the above problems, the concept of editable blockchain has been proposed and applied in the fields of Internet of Things, medical care, house rental, etc.

[0004] Most of the existing editable blockchain schemes based on chameleon hashing specify some modifiers to implement fine-grained transaction modifications, as long as these modifiers meet specific identity or modifier attribute (or access structure) requirements. Unfortunately, there are likely to be malicious modifiers among them, leading to malicious modification events, that is, modifying good content into bad content, disrupting the blockchain environment. In order to solve the above problems, some modification permission control methods, such as trapdoor periodic expiration and modification number limit, and some post-modification accountability methods, such as attribute revocability and traceability, have received attention. However, these methods only work when or after the modification event occurs, and cannot predict and prevent malicious events before they occur. Evaluating, filtering, and restricting malicious modifiers in advance is a feasible solution to reduce the risk of malicious modifications by potential malicious modifiers to a certain extent.

[0005] Therefore, current blockchain rewriting methods are less secure. Summary of the invention

[0006] The embodiment of the present invention provides a blockchain rewriting method based on dynamic trust that supports update traceability, which can solve the problem of low security of the current blockchain rewriting method.

[0007] In a first aspect, an embodiment of the present invention provides a blockchain rewriting method based on dynamic trust that supports update traceability, the method is applied to an editable blockchain system, the editable blockchain system includes multiple user nodes and an editable global ledger, the user nodes include committee members, and the method includes:

[0008] The editor broadcasts the modification suggestion to other committee members in round r, where the modification suggestion includes the original information to be modified, the modified information, the editor's signature, the reason for the modification, and the editor's trust value at the current moment;

[0009] Among them, the modifier is one of the members of the r-th round committee. The r-th round committee members are elected among all user nodes at the r-th moment based on the trust value of each user node in the editable blockchain. The r-th moment is earlier than the current moment. The election at the r-th moment is the last election before the current moment. The trust value of the user node at the r-th moment is determined based on the transaction behavior, consensus behavior and modification behavior of the user node before the r-th moment.

[0010] Other committee members verify whether the modifier’s signature is correct, whether the reason for the modification is reasonable, and whether the modifier’s current trust value is greater than or equal to the trust value threshold set by the original user, where the original user is the user node that uploaded the original message;

[0011] If the modifier's signature is correct, the reason for the modification is reasonable, and the modifier's rth trust value is greater than or equal to the original user's trust value threshold, the other committee members accept the modifier's modification of the original information and replace the original information with the modified information on the editable global ledger, saving the modified signature and modified random number generated by this modification.

[0012] In a second aspect, an embodiment of the present invention provides an editable blockchain system, the editable blockchain system comprising a plurality of user nodes and an editable global ledger, the user nodes comprising committee members, the committee members comprising modifiers and other committee members;

[0013] The editor is used to broadcast modification suggestions to other committee members in round r, where the modification suggestions include the original information to be modified, the modified information, the editor's signature, the reason for the modification, and the editor's trust value at the current moment;

[0014] Among them, the modifier is one of the members of the r-th round committee. The r-th round committee members are elected among all user nodes at the r-th moment based on the trust value of each user node in the editable blockchain. The r-th moment is earlier than the current moment. The election at the r-th moment is the last election before the current moment. The trust value of the user node at the r-th moment is determined based on the transaction behavior, consensus behavior and modification behavior of the user node before the r-th moment.

[0015] Other committee members are used to verify whether the signature of the modifier is correct, whether the reason for the modification is reasonable, and whether the trust value of the modifier at the rth moment is greater than or equal to the trust value threshold set by the original user, where the original user is the user node that uploaded the original message;

[0016] If the modifier's signature is correct, the reason for the modification is reasonable, and the modifier's current trust value is greater than or equal to the trust value of the original user node, other committee members are also used to accept the modifier's modification of the original information and replace the original information with the modified information on the editable global ledger, and save the modified signature and modified random number generated by this modification.

[0017] Compared with the prior art, the embodiments of the present invention have the following beneficial effects: according to the blockchain rewriting method provided by the present invention, the trust value of the node is determined according to the historical transactions, consensus, and modification behavior of each node, and committee members are elected according to the trust value of each node, so that the committee members can perform the modification behavior; compared with screening modifiers only by user attributes, the present invention characterizes the credibility of users and screens modifiers by credit value, which can prevent users who have repeatedly committed malicious behaviors from modifying information on the blockchain, reduce the occurrence of malicious incidents, and improve the security performance of the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 A schematic diagram of the structure of an editable blockchain system provided by an embodiment of the present invention;

[0019] Figure 2 A flowchart of a blockchain rewriting method based on dynamic trust that supports update traceability provided by an embodiment of the present invention;

[0020] Figure 3 A schematic diagram of the implementation flow of a committee member election method provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0021] In order to better illustrate the blockchain rewriting method based on dynamic trust that supports update traceability provided by the present invention, some existing concepts are first explained before listing the embodiments:

[0022] Chameleon hash algorithm

[0023] The chameleon hash algorithm allows anyone to perform chameleon hashing with a given trapdoor key tk. Users with the hash key can then generally search for hash collisions, such that Ch_Hash(m)=Ch_Hash(m′); where Ch_Hash(·) represents chameleon hashing, m is the original information, and m′ is the modified information.

[0024] Chameleon hashing algorithms can include:

[0025] CH.Setup(1 λ )→pp: Input is a safety parameter is a set of integers, and the output is the public parameter pp.

[0026] CH.KeyGen(pp)→(tk,hk): Input common parameter pp, output is trapdoor hash key pair (tk,hk), where tk is the trapdoor key and hk is the hash key.

[0027] CH.Hash(hk,m)→(h,r): Generates the message hash value h and the information random number r based on the trapdoor key hk and the original message m∈M, where M is the message space.

[0028] CH.Verify(hk,m,h,r)→b: Verify whether (h,r) is valid by inputting (hk,m,h,r). If the output is 1, the verification passes, otherwise the verification fails.

[0029] CH.Adapt(tk,m,m',h,r)→r': Calculate the collision (m',r') about (m,r) through (tk,m,h,r) and the modified message m'∈M, and output the modified random number r'. In addition, the security requirements of Chameleon Hash include: correctness, non-repeatability and anti-collision.

[0030] The purpose of using Chameleon Hash is to ensure that the modified block hash value remains unchanged in an editable blockchain system.

[0031] Dynamic Active Secret Sharing Algorithm

[0032] The dynamic active secret sharing algorithm can share the trapdoor key among the members of a committee consisting of n0 users, but the value of the trapdoor key will not change with the adjustment of the committee and can be recovered by any t or more members of the committee; where t is the recovery threshold. The membership, size and recovery threshold of the committee can be adjusted over time.

[0033] Dynamic active secret sharing algorithms may include:

[0034] The protocol is used to share a secret s among n0 members in the original committee C. It takes as input n0, s, t and another security parameter k, and outputs a secret containing each member P i Secret share and proof of correctness i ,π i >.

[0035] The protocol is used in the new and old committees (i.e. C e and C e+1 ) and update them. On input, each old member P i e Tuples to be maintained { i ,π i >}, and output each new member The new tuple of { j ',π j '>}.

[0036] DPSS.Recon({ i ,π i > i∈I})→v The protocol is used to reconstruct s in a new committee. On the input, there are at least t+1 valid tuples {s i ,π i > i∈I,|I|>t}, and output the reconstructed secret v, where I is the index set.

[0037] The present invention is further described in detail below with reference to specific embodiments, but the embodiments of the present invention are not limited thereto.

[0038] Figure 1 What is shown is a schematic diagram of the structure of an editable blockchain system provided by an embodiment of the present invention.

[0039] ​​​​As an example and not a limitation, the editable blockchain system may include multiple nodes 1 and an editable global ledger 2. Node 1 may be divided into a user 11 and a blockchain administrator 12. A committee may be elected from the user 11, and committee members 111 may modify the information on the editable global ledger 2. The committee member 111 who performs the modification behavior is the modifier 1111, and the remaining committee members are other committee members 1112. In one example, the modifier 1111 may be used to broadcast modification suggestions to other committee members 1112 in the rth round, and then other committee members 1112 verify whether the modifier's signature is correct, whether the modification reason is reasonable, and whether the modifier's trust value at the current moment is greater than or equal to the trust value threshold set by the original user. If all three are satisfied, the other committee members 1112 accept the modifier's modification of the original information and replace the original information with the modified information on the editable global ledger 2 to save the modified signature and modified random number.

[0040] Exemplarily, the modifier is one of the members of the r-th round committee, the r-th round committee members are based on the trust value of each user node in the editable blockchain at the r-th moment, and are elected among all user nodes at the r-th moment. The r-th moment is earlier than the current moment, and the election conducted at the r-th moment is the last election before the current moment. The trust value of the user node at the r-th moment is determined based on the transaction behavior, consensus behavior and modification behavior of the user node before the r-th moment.

[0041] Exemplarily, the original user is the user node that uploads the original message.

[0042] Optionally, each user node can perform editable transactions or ordinary transactions. When performing ordinary transactions, the user node can generate information signatures and information random numbers through public keys and private keys according to some traditional hash encryption methods.

[0043] In the editable blockchain system provided by the present invention, the trust value of each node is determined according to its historical transactions, consensus, and modification behavior, and committee members are elected according to the trust value of each node to allow the committee members to perform modification behaviors. Compared with screening modifiers only by user attributes, the present invention characterizes the credibility of users and screens modifiers by credit value, which can prevent users who have repeatedly committed malicious acts from modifying information on the blockchain, thereby improving the security performance of the blockchain.

[0044] Figure 2 The flowchart shown is a method for implementing a blockchain rewriting method based on dynamic trust that supports update traceability provided by an embodiment of the present invention. As an example but not a limitation, the method 200 can be applied to the above-mentioned editable blockchain system, and the method 200 can include steps S201-S209, and each step is described below.

[0045] S201, the blockchain administrator initializes the system.

[0046] In one possible implementation, a blockchain administrator can run the setup algorithm: DTCH.Setup(1 λ )→(pp), where λ is the security parameter. Select a prime number e and generate the public parameter pp for constructing a digital signature. DS =DS.Setup(1 λ )=(G,g); where G is the elliptic curve group, g is the generator of group G, DS represents the elliptic curve digital signature algorithm, DS.Setup(1 λ ) represents the setup part of the algorithm, pp DS is the implicit input of (G,g). Then an initial committee C is organized 0 , Committee C 0 It includes n0 reliable user nodes (i.e. committee members); at the same time, the lower limit of the trust value threshold is set l , so that the trust value threshold set by each user must be greater than T l The final output parameter pp = (e, G, g, C 0 ,T l ).

[0047] In one example, while the editable blockchain is running according to method 200, an election is conducted among user nodes based on trust values ​​every first preset time value according to the following committee member election method 300, and n0 user nodes with higher trust values ​​are elected as committee members, thereby dynamically updating the committee.

[0048] Optionally, committee members may also periodically spot-check whether user nodes in the editable blockchain system and the various behaviors they perform are normal, so as to prevent malicious users from deliberately enhancing their trust value through large-scale and frequent behaviors.

[0049] S202, the blockchain administrator generates a trapdoor hash key pair according to the output parameters.

[0050] In a possible implementation, a trapdoor hash key pair may be generated according to output parameters based on a chameleon hash algorithm.

[0051] Exemplarily, a key generation algorithm may be run: DTCH.KeyGen(pp)→(tk,hk) to generate a trapdoor key tk and a hash key sk.

[0052] Specifically, the key generator RSAKGen(1 λ ) to generate two different large prime numbers p and q. Then calculate n=pq, Get parameter d; Then choose a collision-resistant hash function yes The group consisting of the modulo n congruence classes of all reversible elements in , A finite additive group consisting of n elements consisting of a set of integers modulo n for any n ≥ 1. At the same time, the second preset time value is set Generate a trapdoor key tk←d according to the parameter d. n Generate hash key hk←(n,H n ,Δt).

[0053] In one example, it can be based on a dynamic active secret sharing algorithm: Share the trapdoor key among the initial committee members.

[0054] Optionally, the recovery threshold t0 of the trapdoor key may satisfy: t0 <n0 / 2。

[0055] S203, the user node generates an information signature of the original information according to the private key in the signature key pair, the preset time, the original information, the information random number, and the trust value threshold.

[0056] In one example, the user node can run the hash algorithm: DTCH.Hash(hk,Tt,m,t)→(h,r,σ) to generate the information random number, information hash value and information signature of the original information according to the time trust value threshold Tt set by the user, the preset time t, the hash key hk, and the original message m.

[0057] Specifically, you can choose a random number for information And calculate the information hash value h=H based on the information random number n (m) t r e mod n. Then based on the key generation part in the elliptic curve digital signature algorithm: (sk, pk) ← DS.KeyGen(pp DS ), generate the public key pk and private key sk in the signature key pair. Then based on the signature part of the algorithm: σ=(y,s)←DS.Sign(sk,(Tt,m,r,t)), generate the information signature according to the private key in the signature key pair, preset time, original information, information random number, and trust value threshold. Among them, y=g w modP,s=w -1 (H d (Tt,m,r,t)+y.sk), w is from the set The random number selected, set for The non-zero elements of For a domain, H d The hash function used to generate the digital signature.

[0058] Optionally, the trust value threshold may be smaller than the trust value of each committee member and larger than the lower limit T of the trust value threshold. l , that is, T l ≤Tt≤Tr(C k ) and k≤n0, C k is the kth committee member; to avoid the situation where a malicious user sets a high trust value threshold and then uploads malicious information, but no editor who meets the conditions can modify the malicious information, thereby improving the security performance of the blockchain.

[0059] S204, the user node broadcasts the message parameters of this message upload to other user nodes.

[0060] Exemplarily, the message parameters may include a public key in a signature key pair, a preset time, a message random number, original message, a trust value advance, a message hash value, and a message signature.

[0061] Correspondingly, other user nodes receive the message parameters of this message upload.

[0062] S205: The user node that receives the message parameters verifies whether the message parameters are valid.

[0063] In one possible implementation, the user node that receives the message parameters may run a verification algorithm: DTCH.Verify(hk,Tt,m,t,r,h,σ)→{0,1} to verify whether the message parameters are valid.

[0064] Specifically, you can first verify whether the random number of the information satisfies: If it is satisfied, continue; if it is not satisfied, output 0 to stop. Then verify where h'=H n (m) t r e mod n; and based on the verification part of the elliptic curve digital signature algorithm: Verify the remaining parameters. If both equations hold, return 1 to save the message parameters in the editable global ledger, and / or broadcast the message parameters to other user nodes that have not received the message parameters; if either of them does not hold, return 0 to stop uploading the message.

[0065] S206, the modifier broadcasts the modification suggestion to other committee members in round r.

[0066] In an example, the modification suggestion ModTx may include: the modifier's information ModifierID, the located block number BlockNum, the transaction number TxNum, the original information m, the modified information m', the modifier's trust value Tc at the rth moment, the modification reason Reason, the modifier's signature Sign and the suggested state State.

[0067] Exemplarily, the suggestion status may include: active, accepted, and rejected. The initial status of the suggestion status in the modification suggestion sent by the editor may be active.

[0068] Accordingly, other committee members in round r receive the modification suggestions.

[0069] S207, the other committee members of the rth round verify whether the signature of the modifier is correct, whether the reason for the modification is reasonable, and whether the trust value of the modifier at the current moment is greater than the trust value threshold set by the original user.

[0070] For example, other committee members in the rth round can verify the correctness, rationality and feasibility of the modification by verifying whether the modified signature is correct, whether the reason for the modification is reasonable, and whether the trust value of the modifier at the current moment is greater than the trust value threshold set by the original user.

[0071] In one example, if the above three conditions are all met, then in round r, other committee members can modify the proposed status to accepted and then collectively recover the trapdoor key of the modifier.

[0072] In another example, if any of the conditions is not met, the proposed status may be modified to rejected and the modification may be stopped.

[0073] S208, the modifier recovers the trapdoor key from the committee members based on the dynamic active secret sharing algorithm.

[0074] In one example, the committee members can use the key recovery part of the dynamic active secret sharing algorithm: tk←DPSS.Recon({tk i} t+1 ), reconstruct the trapdoor key from the r-th round committee members; and send it to the modifier through a secure P2P channel.

[0075] Optionally, committee members can first The message parameters related to the original information are verified again. If the verification result is 0, the modification is stopped. Otherwise, the modification is performed when the trust value of the modifier at the rth moment is greater than the trust value threshold Tt set by the original user.

[0076] S209, the modifier generates a modified random number according to the trapdoor key and generates a modified signature according to the private key in the new signature key pair.

[0077] In one example, the modifier can calculate the modified random number r'=(h / H) based on the Chameleon hash algorithm after receiving the trapdoor key. n (m') t ) d modn. Then based on the key generation part in the elliptic curve digital signature algorithm: (sk', pk')←DS.KeyGen(PP DS ) Generate a new signature key pair, obtain a new private key sk' and a new public key pk'. And based on the signature part of the elliptic curve digital signature algorithm: σ'=(y',s')←DS.Sign(sk',(Tt,m',r',t)), generate a modified signature according to the private key in the new signature key pair.

[0078] Similarly, the modifier can run the verification algorithm: DTCH.Verify(hk,Tt,m',t,r',h,σ') to check whether the modified random number and modified signature are valid.

[0079] Optionally, method 200 may further include step S208; a modifier in the editable blockchain system may perform step S208 once every second preset time value.

[0080] S210, the modifier updates the information random number, the information signature, and / or modifies the random number, modifies the signature.

[0081] In a possible implementation, the adaptation algorithm including step S208 and step S209: DTCH.Adapt(C r ,tk,m,t,r,h,m',Tc,Tt)→(r',σ') is similar; the update algorithm first passes the verification algorithm Verify whether the current information random number, information signature, and / or modified random number, modified signature are valid. If valid, continue to update so that the verification is passed only within the fixed second preset time value; if invalid, stop updating. Then, from the jth round committee C j Based on the algorithm: tk←DPSS.Recon({tk j} t+1 ) Reconstruct the trapdoor key. After the modifier receives the trapdoor key, he calculates the updated random number r" = r / (H n (m) Δt ) d modn; based on the algorithm: (sk”, pk”)←DS.KeyGen(pp DS), build another new signature key pair; and generate the updated random number and signature according to the algorithm: σ”=(y”,s”)←DS.Sign(sk”,(Tt,m,r”,t+Δt)). Finally, run the verification algorithm: DTCH.Verify(hk,Tt,m,t+Δt,r”,h,σ”) to check whether the updated random number and signature are valid.

[0082] According to the blockchain rewriting method provided by the present invention, the trust value of each node is determined based on the historical transactions, consensus, and modification behavior of each node, and committee members are elected based on the trust value of each node, so that the committee members can perform the modification behavior; compared with only screening modifiers by user attributes, the present invention uses credit values ​​to characterize the credibility of users and screen modifiers, which can prevent users who have repeatedly committed malicious behaviors from modifying information on the blockchain and improve the security performance of the blockchain. Furthermore, when the transaction can be edited, the original user is allowed to set the trust value threshold by himself to ensure that only modifiers who meet the trust value threshold can modify it; a corresponding digital signature is generated at each transaction and modification so that the system can trace the identity of the user or modifier of the transaction through the digital signature; the security performance of the system can be further improved.

[0083] Figure 3 The figure shows a schematic diagram of the implementation process of a committee member election method provided by an embodiment of the present invention. As an example but not a limitation, the method 300 can be applied to the above-mentioned editable blockchain system, and the method 300 can include steps S301-S306, and each step is described below.

[0084] S301, determining the transaction trust value of the user node at the rth moment according to the transaction behavior of the user node before the rth moment.

[0085] In one example, the transaction trust value of the user node at time r can satisfy the following formula:

[0086]

[0087] Among them, GT(u) is the transaction trust value of the u-th user node at the r-th time, T u is the number of transactions performed by the u-th user node between the r-1th time and the rth time, ρ(T u ) is the activity value of the transaction, Δt i is the time interval between the i-th transaction and the i-1-th transaction of the u-th user node, is the trust decay of the i-th transaction relative to the r-th moment, indicating that the recent performance of the user node is more valued; f(i) is the transaction impact factor of the i-th transaction, which is used to identify the importance of the transaction. The specific value can be set according to the requirements and standards of different actual scenarios; Tr(j) is the trust value of the u-th user node fed back from the j-th user node, S i is the evaluation feedback for the i-th transaction, and DT0 is the default trust value when no transaction is performed.

[0088] in:

[0089] Exemplarily, the r-1th time is the time when the user node performs the r-1th election.

[0090] Optionally, the user may elect committee members once every first preset time value based on the trust value of each user.

[0091] S302, determining the consensus trust value of the user node at the rth moment according to the consensus behavior of the user node before the rth moment.

[0092] In one example, the formula trust value of the user node at time r may satisfy the following formula:

[0093]

[0094] Among them, CM(u) is the consensus trust value of the u-th user node at the r-th time, C u is the number of times the u-th user node reaches consensus between the r-1th time and the rth time, ρ(C u ) is the consensus activity value, and the calculation method is the same as the transaction activity value calculation method; B i′ is the behavior value of the u-th user node when performing the i′th consensus, Δt i′ is the time interval between the i′th consensus and the i′-1th consensus, is the trust decay of the i′th consensus relative to the rth moment.

[0095] in:

[0096]

[0097] Among them, the parameters ψ and φ can be defined as 0≤ψ<0.03 and 0≤φ<1 respectively.

[0098] Exemplarily, malicious behavior may include malicious feedback, transaction fraud, malicious consensus, malicious modification of on-chain data, etc.

[0099] S303: Determine the modification trust value of the user node at the rth moment according to the modification behavior of the user node before the rth moment.

[0100] In one example, if the user node completes M within the first preset time value u After the i″th modification, the user node can receive evaluation feedback from other users about this modification. If the number of other users who provide feedback exceeds half of the total number of user nodes, the user node can calculate the comprehensive value of the evaluation feedback. View i,1 represents the evaluation feedback received from user l, where N is the number of received feedback. Therefore, the modified trust value of the user node at time r can satisfy the following formula:

[0101]

[0102] Among them, MT(u) is the modified trust value of the u-th user node at the r-th time, M u The number of times the u-th user node is modified between the r-1th time and the rth time, ρ(M u ) is the activity value of the modification, V(i″) is the comprehensive value of the evaluation feedback received by the u-th user node about the i″th modification from other user nodes after the u-th user node makes the i″th modification, N is the total number of evaluation feedback received by the u-th user node about the i″th modification, Δt i″ is the time interval between the i″th modification and the i″-1th modification, The i″th modification is equivalent to the trust decay degree at the rth moment, and f(i″) is the impact factor of the i″th modification.

[0103] For example, after each transaction, modification or formula behavior of the user, the user node can update the trust value of its corresponding behavior through the above formula. Once the user has malicious behavior, the user node can be punished, otherwise a certain degree of reward will be implemented.

[0104] S304, determining the comprehensive trust value of the user node at the rth moment according to the transaction trust value of the user node at the rth moment, the consensus trust value of the user node at the rth moment, and the modified trust value of the user node at the rth moment.

[0105] In one example, the comprehensive trust value of the user node at the rth moment can be the product of the transaction trust value and the transaction weight of the user node at the rth moment, the product of the consensus trust value and the consensus weight of the user node at the rth moment, and the product of the modified trust value and the modified weight of the user node at the rth moment. That is, the comprehensive trust value of the user node at the rth moment can satisfy the following formula:

[0106] S c =α·GT(u)+β·CM(u)+γ.MT(u)

[0107] Among them, S c is the comprehensive trust value of the user node at the rth moment, α, β, and γ are the transaction weight, consensus weight, and modification weight, respectively.

[0108] S305, determining the trust value of the user node at the rth moment according to the comprehensive trust value of the user node at the rth moment and the trust value of the user node at the r-1th moment.

[0109] In one example, the trust value of the user at time r may satisfy the following formula:

[0110] Tr(u) r ←x·min(T r-1 ,S c )+y·max(T r-1 ,S c )+δ

[0111] Among them, Tr(u) r is the trust value of the user node at the rth moment, S c is the comprehensive trust value of the user node at the rth moment, x and y are two weight values, x+y=1,x>y.

[0112] in:

[0113]

[0114] Among them, η>1, η is a tuning parameter, which represents the reward for normal behavior of user nodes or the punishment for malicious behavior of user nodes. Obviously, the reward is significantly lower than the punishment for all users to motivate users to behave normally. In addition, compared with users with low trust values, users with high trust values ​​receive less rewards for normal behavior and more punishment for their malicious behavior.

[0115] S306, conducting an r-round election among all user nodes based on the credit value of the user node at the r-th moment, and electing the r-round committee members.

[0116] Exemplarily, the first n0 user nodes with higher credit values ​​at the rth moment may be determined as the rth round committee members.

[0117] According to the committee member election method provided by the present invention, the user's trust value can be updated according to the user's historical behavior, and the dynamically changing trust value can more reliably filter and limit malicious users.

[0118] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.

[0119] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine different embodiments or examples described in this specification.

[0120] Although the present invention is described herein in conjunction with various embodiments, in the process of implementing the claimed invention, those skilled in the art may understand and implement other variations of the disclosed embodiments by viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprise" does not exclude other components or steps, and "one" or "an" does not exclude multiple situations. A single processor or other unit may implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0121] The above contents are further detailed descriptions of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. For ordinary technicians in the technical field to which the present invention belongs, any modifications made without departing from the concept of the present invention should be deemed to belong to the protection scope of the present invention.

Claims

1. A blockchain rewriting method based on dynamic trust that supports update traceability, characterized in that: The method is applied to an editable blockchain system, the editable blockchain system includes multiple user nodes and an editable global ledger, the user nodes include committee members, and the method includes: The editor broadcasts the modification suggestion to other committee members in round r, where the modification suggestion includes the original information to be modified, the modified information, the editor's signature, the reason for the modification, and the editor's trust value at the current moment; The modifier is one of the members of the r-th round committee, and the r-th round committee member is elected among all user nodes at the r-th moment based on the trust value of each user node in the editable blockchain, the r-th moment is earlier than the current moment, and the election conducted at the r-th moment is the last election conducted before the current moment. The trust value of the user node at the r-th moment is determined based on the transaction behavior, consensus behavior and modification behavior of the user node before the r-th moment; The other committee members verify whether the signature of the modifier is correct, whether the reason for the modification is reasonable, and whether the trust value of the modifier at the current moment is greater than or equal to the trust value threshold set by the original user, wherein the original user is the user node that uploaded the original message; If the signature of the modifier is correct, the reason for the modification is reasonable, and the rth trust value of the modifier is greater than or equal to the trust value threshold of the original user, the other committee members accept the modification of the original information by the modifier and replace the original information with the modified information on the editable global ledger, and save the modified signature and modified random number generated by this modification.

2. The method according to claim 1, characterized in that Before the modifier broadcasts the modification suggestion to other committee members in round r, the method further includes: Determine the comprehensive trust value of the user node at time r according to the transaction trust value of the user node at time r, the consensus trust value of the user node at time r, and the modified trust value of the user node at time r; Determine the trust value of the user node at time r according to the comprehensive trust value of the user node at time r and the trust value of the user node at time r-1, wherein time r-1 is earlier than time r, time r-1 is the time when the user node conducts the r-1th round of election, the time difference between time r and time r-1 is equal to a first preset time value, and all user nodes elect committee members once every first preset time value; The first n0 user nodes with the largest trust values ​​at the rth moment are determined as the members of the rth round committee, where n0 is the total number of committee members; The trust value of the user node at the rth moment satisfies the following formula: Minus) r ←x·min(T r-1 ,S c )+y·max(T r-1 ,S c )+δ Tr(u) r is the trust value of the user node at the rth moment, T r-1 is the trust value of the user node at the r-1th moment, S c is the comprehensive trust value of the user node at the rth moment, x and y are two weight values, x+y=1, x>y; in: η>1, η is a regulation parameter, which indicates the reward for normal behavior of user nodes or the punishment for malicious behavior of user nodes.

3. The method according to claim 2, characterized in that The comprehensive trust value of the user node at the rth moment is the sum of the product of the transaction trust value and the transaction weight of the user node at the rth moment, the product of the consensus trust value and the consensus weight of the user node at the rth moment, and the product of the modified trust value and the modified weight of the user node at the rth moment.

4. The method according to claim 2 or 3, characterized in that: The transaction trust value of the user node at time r satisfies the following formula: Among them, GT(u) is the transaction trust value of the u-th user node at the r-th time, T u is the number of transactions performed by the u-th user node between the r-1th time and the rth time, ρ(T u ) is the activity value of the transaction, Δt i is the time interval between the i-th transaction and the i-1-th transaction performed by the u-th user node, is the trust decay of the i-th transaction relative to the r-th moment, f(i) is the transaction impact factor of the i-th transaction, Tr(j) is the trust value of the u-th user node fed back from the j-th user node, S i is the evaluation feedback for the i-th transaction, and DT0 is the default trust value.

5. The method according to claim 2 or 3, characterized in that: The consensus trust value of the user node at time r satisfies the following formula: Among them, CM(u) is the consensus trust value of the u-th user node at the r-th time, C u is the number of times the u-th user node reaches consensus between the r-1th moment and the rth moment, ρ(C u ) is the consensus activity value, B i′ is the behavior value of the u-th user node when performing the i′th consensus, Δt i′ is the time interval between the i′th consensus and the i′-1th consensus, is the trust decay degree of the i′th consensus relative to the rth moment, and DT0 is the default trust value.

6. The method according to claim 2 or 3, characterized in that: The modified trust value of the user node at time r satisfies the following formula: Among them, MT(u) is the modified trust value of the u-th user node at the r-th time, M u The number of times the u-th user node is modified between the r-1-th time and the r-th time, ρ(M u ) is the activity value of the modification, V(i″) is the comprehensive value of the evaluation feedback received by the u-th user node from other user nodes about the i″th modification after the u-th user node performs the i″th modification, N is the total number of evaluation feedback received by the u-th user node about the i″th modification, Δt i″ is the time interval between the i″th modification and the i″-1th modification, The i″th modification is equivalent to the trust decay degree at the rth moment, f(i″) is the impact factor of the i″th modification, and DT0 is the default trust value.

7. The method according to claim 7, characterized in that: The trapdoor key in the modified trapdoor hash key pair is shared among the r-th round committee members based on a dynamic active secret sharing algorithm.

8. The method according to claim 7, characterized in that Before the modifier broadcasts the modification suggestion to other committee members in round r, the method further includes: The user node generates an information signature of the original information according to the private key in the signature key pair, the preset time, the original information, the information random number, and the trust value threshold; The user node broadcasts the message parameters of this message upload to other user nodes, wherein the message parameters include: the public key in the signature key pair, the preset time, the information random number, the original information, the trust value threshold, the information hash value and the information signature; The user node receiving the message parameters verifies whether the message parameters are valid; If the message parameters are all valid, the user node that receives the message parameters saves the message parameters in the editable global ledger, and / or broadcasts the message parameters to user nodes that have not received the message parameters; The modifier recovers the trapdoor key from the committee members at the rth time based on the dynamic active secret sharing algorithm; Wherein, if the signature of the modifier is correct, the reason for the modification is reasonable, and the rth trust value of the modifier is greater than or equal to the trust value threshold of the original user, before the other committee members accept the modification of the original information by the modifier and replace the original information with the modified information on the editable global ledger and save the modified signature and modified random number generated by this modification, the method further includes: The modifier generates the modified random number according to the trapdoor key; The modifier generates the modified signature according to the private key in the new signature key pair.

9. The method according to claim 8, characterized in that The modifier updates the information random number, the information signature, and / or the modified random number, the modified signature every second preset time value.

10. An editable blockchain system, characterized in that: The editable blockchain system includes multiple user nodes and an editable global ledger, the user nodes include committee members, and the committee members include modifiers and other committee members; The editor is used to broadcast modification suggestions to other committee members in round r, where the modification suggestions include the original information to be modified, the modified information, the editor's signature, the reason for the modification, and the editor's current trust value; The modifier is one of the members of the r-th round committee, and the r-th round committee member is elected among all user nodes at the r-th moment based on the trust value of each user node in the editable blockchain, the r-th moment is earlier than the current moment, and the election conducted at the r-th moment is the last election conducted before the current moment. The trust value of the user node at the r-th moment is determined based on the transaction behavior, consensus behavior and modification behavior of the user node before the r-th moment; The other committee members are used to verify whether the signature of the modifier is correct, whether the reason for the modification is reasonable, and whether the trust value of the modifier at the rth moment is greater than or equal to the trust value threshold set by the original user, wherein the original user is the user node that uploaded the original message; If the signature of the modifier is correct, the reason for the modification is reasonable, and the trust value of the modifier at the current moment is greater than or equal to the trust value of the original user node, the other committee members are also used to accept the modification of the original information by the modifier and replace the original information with the modified information on the editable global ledger, and save the modified signature and modified random number generated by this modification.

Citation Information

Patent Citations

  • Trust degree calculation method based on trust blockchain nodes

    CN110519246A

  • Block chain dynamic editing method based on distributed key supervision

    CN117372015A

  • System and method of blockchain consensus mechanism with custom hardware based on geographic distribution, density, node asset and reputation

    IN201841037174A

  • Simulation Method for Salesman Consultation Training Using Augmented Reality and Virtual Reality

    KR1020220005367A

  • Block chain power transaction system, consensus method, device and storage medium

    WO2024040796A1

Cited By

  • Method, device and product for managing dynamic trap door of chameleon hash function

    CN120415714A

  • A chameleon hash function dynamic trapdoor management method, device and product

    CN120415714B