Universal cross-chain payment method with expandability and without continuous online monitoring
By using time lock and shared address technology and security calculation methods in cross-chain scenarios, the problems of difficulty in achieving universality and atomicity in the existing technology are solved, multiple settlement attacks and interleaved settlement phenomena are prevented, and the number of transactions is reduced, and cross-chain scalability and security are achieved.
Patent Information
- Application Number
- CN202510074493.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-17
AI Technical Summary
The existing technology is difficult to achieve universality and atomicity in cross-chain scenarios, resulting in "multi-settlement attacks" and "interleaved settlement phenomena". At the same time, users need to continue to monitor online to prevent malicious transactions.
The timing channel is opened by using time lock and shared address technology, combining secure computing, symmetric encryption and bit computing technology to update the funds off-chain, and based on symmetric encryption and bit computing technology, the funds are put on the chain for settlement, ensuring atomicity and universality.
It realizes scalability in cross-chain scenarios, prevents "multi-settlement attacks" and "interleaved settlement phenomena", and meets the requirements of not requiring the channel party to be continuously online.
Smart Images

Figure CN119941244A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a payment method, and in particular to a universal cross-chain payment method which is scalable and does not require continuous online monitoring. Background Art
[0002] As a decentralized distributed ledger technology, blockchain has been widely welcomed and supported in various fields since its inception for its unique security and immutability. Blockchain ensures the integrity and security of data through decentralized consensus mechanisms and cryptographic methods, which greatly promotes the exchange of digital assets. However, although the core value of blockchain lies in the exchange of assets, due to the high degree of heterogeneity of different blockchain networks in terms of technical architecture, consensus algorithms, data structures, etc., it is difficult for blockchains to communicate and collaborate with each other, thus forming the "information island" problem. This isolation limits the cross-chain circulation of assets and data, and has become one of the main bottlenecks restricting the widespread application of blockchain technology.
[0003] The first thing to consider when designing methods to solve scalability problems in cross-chain scenarios is universality. Current solutions to blockchain scalability problems are mainly concentrated in single-chain scenarios. On-chain expansion solutions are suitable for scenarios targeting specific blockchains and are not suitable for cross-chain scenarios of multiple heterogeneous blockchains. In off-chain expansion solutions, the resource requirements of side chains are expensive for individuals. Payment channel technology avoids the problems of hard forks, cross-chip communication, and interoperability brought about by on-chain expansion solutions, and has low resource requirements, becoming the dawn of solving cross-chain scalability problems.
[0004] Cross-channel and CrossChannel use payment channel technology to solve the scalability problem of cross-chain, but unfortunately Cross-channel relies on smart contracts, while CrossChannel needs to introduce a relay chain as a third party, neither of which is universal. In the payment channel method, atomicity is the guarantee for the correct execution of the method. The implementation of atomicity of Generalizedchannels and Sleepy Channels depends on the characteristics of UTXO transactions, and the solution based on Tumblebit relies on the "Tumbler" in the payment channel Hub. In the cross-chain scenario, the blockchain model should not be restricted. It should not be required to be based on the UTXO model, nor should it be expected to have a payment channel Hub. In order to achieve universality, it is key to ensure the atomicity of method execution.
[0005] In addition to the versatility issue, the user's online requirements are the second issue that needs to be focused on. The HTLC-based payment channel method represented by the Lightning Network has high requirements for the onlineness of both parties in the channel. Users need to keep an eye on the blockchain status to prevent the other party from initiating malicious transactions, which puts a great burden on users. In cross-chain scenarios, this burden is further aggravated, and users need to monitor the status of both chains at the same time to prevent malicious behavior. Existing research has not provided an ideal solution. They usually introduce third-party "watchtowers" to help channel participants monitor the blockchain. Sleepy Channel is the first bidirectional payment channel method that does not require channel parties to be online continuously, does not require additional participants (even without watchtowers) or additional trust assumptions, but unfortunately, it is only applicable to the UTXO model and requires additional collateral to meet the requirement of "not requiring channel parties to be online continuously". Summary of the invention
[0006] In order to solve the defects in the prior art, the present invention innovatively proposes a new universal cross-chain payment channel method - CCPC (Cross-Chain Payment Channels), which has the same security as the intra-chain channel and does not require the channel participants to be continuously online or rely on a third party. The technical solution is as follows: A new universal cross-chain payment channel method includes a timing channel opening stage, a payment generation and update stage, and a payment settlement stage, which is characterized by:
[0007] Opening the timed channel phase: This phase uses time lock and shared address technology to lock the amount. These amounts are used for off-chain transactions and as penalties to prevent the interacting parties from doing evil and to open the channel.
[0008] Generation and update of payment phase: In this phase, payment is continuously updated through secure computing, symmetric encryption, and bit operation technology to ensure the correctness and security of payment updates;
[0009] Settlement stage: This stage uses symmetric encryption and bit operation technology to put a valid payment on the chain and complete the settlement to ensure the correctness of the settlement.
[0010] The present invention also discloses a new universal cross-chain payment channel device, which is characterized by:
[0011] Open the timed channel phase module: This phase uses time lock and shared address technology to lock the amount. These amounts are used for off-chain transactions and as penalties to prevent the interacting parties from doing evil and to open the channel.
[0012] Generate and update payment phase module: This phase continuously updates payment through secure computing, symmetric encryption, and bit operation technology to ensure the correctness and security of payment updates;
[0013] Settlement payment stage module: This stage uses symmetric encryption and bit operation technology to put a valid payment on the chain and complete the settlement to ensure the correctness of the settlement.
[0014] Beneficial Effects
[0015] The present invention reduces the number of transactions on the chain by updating the funds off the chain, thereby solving the scalability problem in the cross-chain scenario. In the process of method design, it prevents "multiple settlement attacks" and "interlaced settlement phenomena" caused by atomicity destruction, while meeting the requirement of "no need for the channel party to be continuously online". BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 This is a schematic diagram of the new universal cross-chain payment channel method of the present invention; Figure 2 This is a schematic diagram of the generation and destruction modules of the present invention. DETAILED DESCRIPTION
[0017] 1. Problem Description
[0018] A payment channel is established between two users (such as channel party A and channel party B), and they each deposit a certain amount of funds to open the channel. The channel allows both parties to conduct multiple transactions off-chain, such as the first transaction, the second transaction, etc., until either party decides to close the channel, and finally broadcasts the latest transaction to the blockchain.
[0019] The correct execution of the payment channel is inseparable from atomicity, that is, the user must either honestly settle the transaction in a certain agreed state and then close the channel, or be punished for doing something malicious. In order to better illustrate the problems that may be caused by the destruction of atomicity in the cross-chain payment channel, this paper describes it through a specific cross-chain payment channel scenario. Assume that channel party A is on the blockchain. 10 coins are staked on the blockchain. 5 coins are staked on the cross-chain payment channel, thus opening a cross-chain payment channel. The current channel status can be expressed as {A:10-(10,0), B:5-(0,5)}. In this channel, channel parties A and B can perform any number of off-chain transactions to update the channel status. It is worth noting that in the process of updating the channel status, in order to ensure that at least one valid channel status exists, a short period of time will pass, during which both the i-th payment and the i+1-th payment are valid. Similar to a single-chain payment channel, in order to ensure that both parties have control over the channel status, the balance update operation will generate two versions: version A (controlled by channel party A) and version B (controlled by channel party B).
[0020] The first problem we face is called "multiple settlement attack". Assume that both parties have generated the latest channel status, that is, the i-th payment. At this time, channel party A paid 4 coins to channel party B, and channel party B paid 1 coin to channel party A. Therefore, the channel status is Normally, when channel party A wishes to settle with the i-th payment, channel party A first publishes version A. , then channel party B releases version A , thus completing the settlement. However, since the coins are located at different addresses in the two chains, channel party B can re-publish version B , so that the settlement process is repeated. Although channel party A can also re-publish version B However, this behavior of settling with twice the amount goes against the original intention of closing the channel with the settlement of the i-th payment.
[0021] The second problem is the "interlaced settlement phenomenon". Assume that in the i+1th payment, channel party A paid 5 coins to channel party B, and channel party B paid 3 coins to channel party A; at this time, the channel status is updated to During the payment update period, one party (such as channel party A) attempts to initiate a settlement application with the i-th payment (sending ), and the other party (such as channel party B) initiates a settlement application with the i+1th payment (sending ), which would lead to a situation where the channel could not be closed with the correct settlement amount.
[0022] 2. Technical solution
[0023] The CCPC method reduces the number of transactions on the chain by updating the funds off-chain, thereby solving the scalability problem in cross-chain scenarios. In the process of method design, it prevents "multiple settlement attacks" and "interlaced settlement phenomena" caused by atomicity destruction, while meeting the requirement of "no need for the channel party to be continuously online". The technical solution is as follows:
[0024] like Figure 1 As shown in the figure, the CCPC method is divided into three operations: opening a timed channel, generating and updating funds, and settling funds. Both parties pledge coins to open a timed channel, generate new funds off-chain, destroy old funds to complete the fund update, and put the latest funds on-chain to settle the funds. After the specified time, the channel is considered to be automatically closed.
[0025] Opening the timed channel phase: This phase uses time locks and shared address technology to lock the amount of money, which is used for off-chain transactions and as a penalty to prevent the two parties from doing evil and open the channel. Channel party A and channel party B first determine the time required for the channel. , , and , . It is the time when channel party A closes the settlement initiation function. It is the time when channel party B closes the settlement initiation function. is the trial time (i.e. the user can time to complete the punishment for illegal transactions), is the pledge time of the collateral (used to punish evil behavior). This time is the longest and is used to ensure the enforceability of the punishment. After that, the two parties generate a series of shared addresses on the two blockchains respectively. After the two parties pledge the agreed amount in the corresponding shared addresses, the timed channel is deemed to be successfully opened.
[0026] Generation and update of payment phase: This phase continuously updates the payment through secure computing, symmetric encryption, and bit operation technology to ensure the correctness and security of the payment update. Each payment includes version A and version B. The two versions have the same structure and function. Channel party A can actively initiate a payment request through version A. Similarly, channel party B can actively initiate a payment request through version B. Each version contains three transactions. In the i-th payment, Belongs to version A, Belongs to version B. The transaction causes the sender to wait until After a certain time, you will get coins. The sender can directly obtain coins. The transaction causes the sender to end The three transactions in each version have a sequential dependency release relationship (i.e., after the send transaction is released, the Fsend transaction can be released; after the Fsend transaction is released, the payout transaction can be released), thus achieving the function of "allowing the channel party to be not continuously online". For the generation of the first payment, both parties generate , , then generate , , and finally generate , . For the subsequent update operation of the funds, both parties generate new funds and destroy old funds through the "Generation and Destruction Module". The "Generation and Destruction Module" ensures the atomicity of the update process, thereby avoiding the occurrence of "multiple settlement attacks" and "interleaved settlement phenomena". In short, corresponding penalty transactions are generated for old funds and "multiple settlement attacks". For the "interleaved settlement phenomenon", when channel party A uses the i-th payment to initiate a settlement request, channel party B is granted the right to perform the following atomic operations: "Reject the request to initiate settlement with the i-th payment, and grant the right to settle with the i+1-th payment". The detailed method design will further introduce the specific structure of this module.
[0027] Settlement stage: This stage uses symmetric encryption and bit operation technology to put a valid payment on the chain and complete the settlement to ensure the correctness of the settlement. Figure 1 The operation of using the i+1th payment for settlement is shown in Figure 1. Taking channel party A actively initiating settlement as an example, the specific operation of settlement is introduced. Channel party A first initiates the Make yourself After a while, you will get After the transaction is uploaded to the blockchain, channel party B first checks the legality of the transaction. If it is legal, channel party B sends Get it now , and channel party A sees Can be sent after being uploaded , thus ending the wait and immediately obtaining For channel party B, he can also actively initiate the settlement operation through version B.
[0028] 3. CCPC Program Implementation
[0029] 3.1 Background: Time-Verifiable Signatures (VTS)
[0030] For a generator and order Group ,Time Verifiable Signature (VTS) contains four algorithms: , as follows:
[0031] The commitment algorithm is a random process that takes as input a discrete logarithmic value and hidden time , outputs a promise and a proof In simple terms, this algorithm is equivalent to Make a "cryptographic commitment" and attach a proof.
[0032] : Verify that the input to the algorithm is a group element ,promise (including "difficulty and proof Its output is either 0 or 1 if and only if the value in the promise satisfy , output 1, otherwise output 0.
[0033] : The public algorithm is run by the committed party, and the input is the committed , the output is the value that was originally promised and the random number used to generate the commitment .
[0034] : Enforce that the input to the public algorithm is a commitment , output a discrete logarithm value .
[0035] 3.2 Method flow
[0036] The method assumes that channel party A and channel party B are in the blockchain and There is a need for cross-chain transactions between channel parties A and B. and All have accounts.
[0037] 3.2.1 Open the timing channel
[0038] Step 1: Channel A and Channel B first agree on the amount of money they will use. and , and the amount of the honesty deposit and ; Select the time required for the channel , , and ; . It is the time when channel party A closes the settlement initiation function. It is the time when channel party B closes the settlement initiation function. is the trial time (i.e. the user can The penalty for illegal transactions is completed before the time limit) is the pledge time of the collateral (used as a punishment for malicious behavior), and the channel is After this time, it is considered to be automatically closed.
[0039] Step 2: Both parties on the blockchain Generate a shared address , , ; In blockchain Generate a shared address , , .by Introduce the steps to generate a shared address:
[0040] The subscript of the shared address indicates that it is in the blockchain The superscript indicates that it belongs to channel party A after time T.
[0041] 1. On the blockchain The public and private key pair is obtained by joint calculation , both parties share the public key , channel party A holds part of the private key , channel party B holds part of the private key , Depend on and Calculated by combination.
[0042] 2. Channel B calculation -- (describe in words, this way of writing is not clear, and the meaning of VTS is not clear), where represents the commitment operation in a time-verifiable signature, is the initial time parameter. Channel party B will commit the value and proof Send to channel party A;
[0043] 3. Channel Party A uses the verification operation in the time-verifiable signature To verify, the verification algorithm converts the group elements , time parameters Commitment and proof as input, and if and only if the embedding The value in satisfy Output 1 if the address is 0. Otherwise, output 0. Once the verification is passed, it is considered a shared address. Successfully generated, That is , Then The key of
[0044] 4. When generating other shared addresses, both parties will re-specify time parameters and roles and repeat the above three steps.
[0045] Step 3: Both parties generate the following transaction: ,This transaction means that channel party A takes out a value of Funds are deposited into the initial shared address superior. , this transaction means that channel party B takes out a value of Funds are deposited into the initial shared address Similar generation of pledge transactions is used for pledge margin , .
[0046] When the above four transactions are successfully recorded on their respective blockchains, the cross-chain payment channel is considered to be successfully opened. At this time, the initial state of the channel is: This state indicates that for channel party A, the state Indicates that he is in the channel blockchain The initial capital is , in blockchain The initial capital is 0; for channel party B, the state Indicates that he is in the channel blockchain The initial capital is 0, in the blockchain The initial capital is .
[0047] Step 4: After the specified time, both parties use the calculated sk to retrieve the remaining amount in the shared address, and the channel is closed.
[0048] 3.2.2 Generate and update funds
[0049] Each payment includes two versions, version A and version B. Each version contains three transactions. To better illustrate the following steps, we will rename the real signatures corresponding to these transactions. For example, the transaction of the i-th payment is used as an example. For version B, Make from Transfer to The corresponding real signature is ; Make from Transferred to channel party A, its corresponding real signature is ; Make from It is immediately transferred to channel party B, and its corresponding real signature is For version A, Make from Transfer to The corresponding real signature is ; Make from Transferred to channel party B, its corresponding real signature is ; Make from It is immediately transferred to the hands of channel party A, and its corresponding real signature is .
[0050] Each payment contains two versions, version A is controlled by channel party A, and version B is controlled by channel party B. Each version contains three transactions, namely , , . Used to initiate a settlement request. In response to a settlement request, Used to complete the settlement after receiving the response. The specific construction is detailed in the following steps:
[0051] Step 1: Generate the first payment off-chain.
[0052] The locked signature refers to the signature after encryption transformation. Represents one-time password encryption, where the encryption key is , the encrypted content is , H is a hash function;
[0053] The superscript indicates that it is a transaction in version A of the first payment, and the subscript indicates that it is Transaction, its transfer is from A to B, The specific content refers to the settlement amount of the first payment channel party B , from the shared address Transfer to the address controlled by channel party B;
[0054] Subsequent transactions generated with Description similar to:
[0055] The superscript indicates that it is a transaction in version B of the first payment, and the subscript indicates that it is Transaction, the funds flow of the transaction is from B to A, The specific content refers to the amount of the first payment belonging to channel party A. , from the shared address Transfer to the address controlled by channel party A;
[0056] The superscript indicates that it is a transaction in version A of the first payment, and the subscript indicates that it is Transaction, the funds flow of the transaction is from B to A, The specific content refers to the amount of the first payment belonging to channel party A. , from the shared address Transfer to shared address middle go;
[0057] The superscript indicates that it is a transaction in version B of the first payment, and the subscript indicates that it is Transaction, the flow of funds in the transaction is from A to B, The specific content refers to the amount of the first payment belonging to channel party B , from the shared address Transfer to shared address middle go;
[0058] The superscript indicates that it is a transaction in version A of the first payment, and the subscript indicates that it is Transaction, the funds flow of the transaction is from A to A, The specific content refers to the amount of the first payment belonging to channel party A. , from the shared address Transfer to the address controlled by channel party A;
[0059] The superscript indicates that it is a transaction in version B of the first payment, and the subscript indicates that it is Transaction, the funds flow of the transaction is from B to B, The specific content refers to the amount of the first payment belonging to channel party B , from the shared address Transfer to the address controlled by channel party B;
[0060] 1. Both parties are formed first (Corresponding to the real signature )、 (Corresponding to the real signature ), and their corresponding locking signatures , that is, channel party B holds, , that is, channel party A holds; generate , , and their corresponding signatures , that is, channel party A holds, , which is held by channel party B;
[0061] 2. Generate (Corresponding to the real signature )、 (Corresponding to the real signature ), and their corresponding locking signatures , channel party A holds, , held by channel party B;
[0062] Step 2: Continuously destroy old funds and generate new funds through the "Generation and Destruction Module" off-chain. The i-th "Generation and Destruction Module" is used to illustrate the destruction of the i-th payment and the generation of the i+1th payment.
[0063] The transaction generated here is similar to the transaction description in the first payment:
[0064] and The description is similar, the superscript indicates that it is a transaction in version A of the i+1th payment, and the subscript indicates that it is Transaction, its transfer is from A to B, The specific content refers to the settlement amount of the channel party B of the i+1th payment , from the shared address Transfer to the address controlled by channel party B; the meaning of subsequent transaction construction is similar to the above steps.
[0065] Represents the absolute value of the difference between the settlement amount of channel B of the i+1th payment and the settlement amount of channel B of the ith payment, used in the following The structure of the transaction; The superscript represents the i-th "generation and destruction module", and the subscript represents the transaction name. The specific content refers to the value of Amount from shared address Transfer to shared address middle go;
[0066] for The locking signature of , the encrypted content is , represents one-time password encryption, H is the hash function;
[0067] for The lock signature here Represents a symmetric encryption algorithm. The first parameter is the encryption key, which is composed of It is calculated that here It still represents one-time password encryption, H is still a hash function, the second parameter is the encrypted content, and the subsequent locking signature parameter description is similar to the above content;
[0068] 1. Both parties generate , and their corresponding locking signatures (Hold by channel party B), (Hold by channel party A).
[0069] 2. This step is to prevent This is a protective measure taken to prevent the phenomenon of atomicity being destroyed.
[0070] 2.1 Order ,like , then both parties generate a transaction ; Otherwise, generate a transaction . Then jointly generate a locking transaction , both parties hold this locking signature.
[0071] 2.2 Both parties jointly generate transactions , and its locking signature , both parties hold this locking signature.
[0072] 2.3 Both parties jointly generate transactions , and its locking signature , held by channel party B.
[0073] 2.4 Both parties jointly generate transactions , and its locking signature , held by channel party A.
[0074] 2.5 Both parties jointly generate transactions and its locking signature , , , all held by channel party B.
[0075] 2.6 Both parties jointly generate transactions , and its locking signature , held by channel party B.
[0076] 2.7 Both parties jointly generate transactions , and its locking signature , held by channel party A.
[0077] 3. Jointly generated by both parties , and its corresponding signature (held by channel party A).
[0078] 4. Both parties jointly generate a locking signature (held by channel party B), this locking signature is used to destroy .
[0079] 5. Jointly generated by both parties , and its corresponding signature (held by channel party B).
[0080] 6. Both parties jointly generate a locking signature (held by channel party A), this locking signature is used to destroy .
[0081] 7. Both parties jointly generate transactions , and their corresponding locking signatures (Hold by channel party B), (Hold by channel party A).
[0082] At this stage, both parties continuously cycle through the second step off-chain to update the funds.
[0083] 3.2.3 Settlement of Payments
[0084] The two parties agree that one party will initiate the settlement request. Assume that channel party A initiates the settlement with i+1 valid payments.
[0085] The first step is to Before time, channel party A first initiated Make from Transfer to Published to the blockchain , initiate a request for settlement with the i+1th payment.
[0086] In the second step, channel party B After the moment, Check before time The correctness of the transaction is checked by channel party B. If it is legal, channel party B can pass the signature of the transaction. Calculated , channel party B sends Can be obtained from get .
[0087] Step 3: Channel A sees After chaining, you can Signature Calculated , thus sending , so that from It is immediately transferred to channel party A.
[0088] The payment has been settled successfully.
[0089] For channel party B, he can also actively initiate the settlement operation through version B. The above settlement operation is designed to provide convenience for both parties in the channel. Before the time, check whether channel party A is malicious, and publish it after checking , both parties can complete the settlement. If the channel A reacts before the judgment moment, it can still Afterwards, get .
[0090] 3.3 Explanation of the “Creating and Destroying Modules” steps.
[0091] In the first step, both parties first generate and , these two transactions are the contents of i+1 payment.
[0092] The second step is to prevent A protective measure taken to prevent the phenomenon of atomicity being destroyed after the generation. After that, both parties have the ability to initiate settlement with the i-th payment, and channel party A also has the ability to initiate settlement with the i+1th payment. In order to prevent the occurrence of "staggered settlement phenomenon", steps 2.1-2.3 in 3.2.2 give channel party A the right to "withdraw channel party B's request for settlement with the i-th payment", and channel party B will obtain the right to settle with the i+1th payment after the request is withdrawn. Sign the corresponding penalty transaction to ensure that the atomicity of the method is not affected. Steps 2.4-2.7 in 3.2.2 are redemption transactions (recovering the money used for malicious purposes) and penalty transactions generated to prevent malicious behavior.
[0093] For 2.1-2.3: First compare and The size of , thereby generating the corresponding prepare to withdraw transaction .if , then generate , so that channel party A can first withdraw aux, and then channel party B is considered to have settled with the amount of i+1 payment. , then generate , so that channel party B can get aux again, so that channel party B settles with the amount of i+1 payments.
[0094] and Lock signature Held by two people, when aux is withdrawn or obtained, channel party B must know .
[0095] At this time, if channel party B needs to use To obtain i+1 payment again, channel party A can use When redeeming an amount i+1, both parties finally settle the account with the status of i+1.
[0096] This is a solution created to prevent the evil phenomenon of Phenomenon 1 from happening.
[0097] 1. Phenomenon 1: When channel party B initiates a request to settle with the i-th payment, channel party A withdraws it. After the two parties settle with the i+1th payment, channel party A sends , accept the i-th payment, thereby attempting to obtain the entire amount of the i-th payment.
[0098] Solution 1: When the above phenomenon occurs, channel party B can , to get back your portion of the i+1 payment, and by Channel A is punished. But channel B still loses the amount of i payments. To solve this problem, both parties generate a reverse withdrawal transaction. and its corresponding locking signature . As a result, after this phenomenon occurs, channel party B can still get his own amount in the i-th payment. The final settlement is made with the i-th payment, and channel party A is punished.
[0099] 2. Phenomenon 2: After both parties settle the payment using version B of the i+1th payment, channel party B releases Perform a "double settlement attack". Corresponding to 2.4
[0100] Solution 2: Generate both sides and the corresponding locking signature When channel party B publishes When , channel party A can calculate ,make coins from Back to A's hands.
[0101] 3. Phenomenon 3: After both parties settle the i-th payment with version A, channel party A releases Perform a "double settlement attack". Corresponding to 2.5
[0102] Solution 3: Generate both sides And the corresponding locking signature When channel party A publishes , channel party B can calculate ,make coins from Return to B's hands.
[0103] 4. Phenomenon 4: After both parties settle the i-th payment with version B, channel party A releases Perform a "double settlement attack". Corresponding to 2.5
[0104] Solution 4: Both parties are again Generate locking signature , When channel party A publishes , channel party B can calculate ,make coins from Return to B's hands; when channel party A releases , channel party B can calculate ,make coins from Return to B's hands.
[0105] For 2.6-2.7, and After channel party A commits a crime, channel party B publishes To get back the amount of money that was used to commit the crime, and at the same time publish To punish channel party A. and After channel party B commits a crime, channel party A publishes To get back the amount of money that was used to commit the crime, and at the same time publish To punish channel party B.
[0106] The third step is to generate This transaction contains the content of the i+1th payment. Channel party A can initiate a settlement request with the i+1th payment. Since the protection measures in the second step have been completed, the generation of this step will not destroy atomicity.
[0107] The fourth step is to destroy version A of the i-th payment. When channel party A initiates a settlement request with the i-th payment, it will receive a penalty.
[0108] Step 5: Generate This transaction contains the content of the i+1th payment. Channel party B can initiate a settlement request with the i+1th payment.
[0109] The sixth step is to destroy version B of the i-th payment. When channel party B initiates a settlement request with the i-th payment, it will be punished.
[0110] Step 7: Generate Transaction and And their corresponding locking signatures and This transaction is the content of i+1 payment.
[0111] At this point, the entire process of the i-th "Generation and Destruction Module" has been completed. Both parties have successfully destroyed the i-th payment and generated the i+1-th payment.
[0112] The present invention reduces the number of transactions on the chain by updating the funds off the chain, thereby solving the scalability problem in the cross-chain scenario. In the process of method design, it prevents "multiple settlement attacks" and "interlaced settlement phenomena" caused by atomicity destruction, while meeting the requirement of "no need for the channel party to be continuously online".
[0113] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions only describe the principles of the present invention. The present invention may be subject to various changes and improvements without departing from the spirit and scope of the present invention. These changes and improvements fall within the scope of the present invention. The scope of protection claimed by the present invention is defined by the attached claims and their equivalents.
Claims
1. A new universal cross-chain payment channel method, including the stage of opening a timed channel, the stage of generating and updating funds, and the stage of settling funds, which is characterized by: Opening the timed channel phase: This phase uses time lock and shared address technology to lock the amount. These amounts are used for off-chain transactions and as penalties to prevent the interacting parties from doing evil and to open the channel. Generation and update of payment phase: In this phase, payment is continuously updated through secure computing, symmetric encryption, and bit operation technology to ensure the correctness and security of payment updates; Settlement stage: This stage uses symmetric encryption and bit operation technology to put a valid payment on the chain and complete the settlement to ensure the correctness of the settlement.
2. The new universal cross-chain payment channel method according to claim 1 is characterized by: The timing channel opening phase includes the following: Step 1: Channel A and Channel B first agree on the amount of money they will use. and , and the amount of the honesty deposit and ; Select the time required for the channel , , and ; ; It is the time when channel party A closes the settlement initiation function. It is the time when channel party B closes the settlement initiation function. is the trial time, i.e. the user can Complete the punishment for illegal transactions before the deadline; It is the pledge, which is used to punish the evil behavior. The channel is After that time, it is considered to be automatically closed; Step 2: Both parties on the blockchain Generate a shared address , , ; In blockchain Generate a shared address , , ; Steps to generate a shared address: The subscript of the shared address indicates that it is in the blockchain The superscript indicates that it belongs to channel party A after time T; (1) In blockchain The public and private key pair is obtained by joint calculation , both parties share the public key , channel party A holds part of the private key , channel party B holds part of the private key , Depend on and The combined calculation results are: (2) Channel B calculation ,in represents the commitment operation in a time-verifiable signature, is the initial time parameter; channel party B will commit to the value and proof Send to channel party A; (3) Channel party A uses the verification operation in the time-verifiable signature To verify, the verification algorithm will group elements , time parameters Commitment and proof as input, and if and only if the embedding The value in satisfy Output 1 if the address is correct, otherwise output 0; after verification, it is considered a shared address Successfully generated, That is , Then The key of (4) When generating other shared addresses, both parties will re-specify the time parameters and roles and repeat the above three steps; Step 3: Both parties generate the following transaction: , this transaction means that channel party A takes out a value of Funds are deposited into the initial shared address superior; , this transaction means that channel party B takes out a value of Funds are deposited into the initial shared address Similar generation of pledge transactions is used for pledge margin , ; When the above four transactions are successfully recorded on their respective blockchains, the cross-chain payment channel is considered to be successfully opened; the initial state of the channel is: ; This state indicates that for channel party A, the state Indicates that it is in the channel blockchain The initial capital is , in blockchain The initial capital is 0; for channel party B, the state Indicates that it is in the channel blockchain The initial capital is 0, in the blockchain The initial capital is ; Step 4: After the specified time, both parties use the calculated sk to retrieve the remaining amount in the shared address, and the channel is closed.
3. The new universal cross-chain payment channel method according to claim 2 is characterized by: The generation and update of payment phase includes the following: Each payment contains two versions, version A is controlled by channel party A, and version B is controlled by channel party B. Each version contains three transactions, namely , , ; Used to initiate a settlement request. In response to a settlement request, Used to complete the settlement after receiving the response. The specific construction is detailed in the following steps: Step 1: Generate the first payment off-chain: The locked signature refers to the signature after encryption transformation. Represents one-time password encryption, where the encryption key is , the encrypted content is , H is a hash function; The superscript indicates that it is a transaction in version A of the first payment, and the subscript indicates that it is Transaction, its transfer is from A to B, The specific content refers to the settlement amount of the first payment channel party B , from the shared address Transfer to the address controlled by channel party B; Subsequent transactions generated with Description similar to: The superscript indicates that it is a transaction in version B of the first payment, and the subscript indicates that it is Transaction, the funds flow of the transaction is from B to A, The specific content refers to the amount of the first payment belonging to channel party A. , from the shared address Transfer to the address controlled by channel party A; The superscript indicates that it is a transaction in version A of the first payment, and the subscript indicates that it is Transaction, the funds flow of the transaction is from B to A, The specific content refers to the amount of the first payment belonging to channel party A. , from the shared address Transfer to shared address middle go; The superscript indicates that it is a transaction in version B of the first payment, and the subscript indicates that it is Transaction, the flow of funds in the transaction is from A to B, The specific content refers to the amount of the first payment belonging to channel party B , from the shared address Transfer to shared address middle go; The superscript indicates that it is a transaction in version A of the first payment, and the subscript indicates that it is Transaction, the funds flow of the transaction is from A to A, The specific content refers to the amount of the first payment belonging to channel party A. , from the shared address Transfer to the address controlled by channel party A; The superscript indicates that it is a transaction in version B of the first payment, and the subscript indicates that it is Transaction, the funds flow of the transaction is from B to B, The specific content refers to the amount of the first payment belonging to channel party B , from the shared address Transfer to the address controlled by channel party B; (1) Both parties first form , corresponding to the real signature , , corresponding to the real signature , and their corresponding locking signatures , that is, channel party B holds, , that is, channel party A holds; (2) Generate , , and their corresponding signatures , that is, channel party A holds, , which is held by channel party B; (3) Generate , corresponding to the real signature , , corresponding to the real signature , and their corresponding locking signatures , channel party A holds, , held by channel party B; Step 2: Continuously destroy old funds and generate new funds through the "Generation and Destruction Module" off-chain; the destruction of the i-th payment and the generation of the i+1th payment are explained with the i-th "Generation and Destruction Module": The transaction generated here is similar to the transaction description in the first payment: and The description is similar, the superscript indicates that it is a transaction in version A of the i+1th payment, and the subscript indicates that it is Transaction, its transfer is from A to B, The specific content refers to the settlement amount of the channel party B of the i+1th payment , from the shared address Transfer to the address controlled by channel party B; the meaning of subsequent transaction construction is similar to the above steps; Represents the absolute value of the difference between the settlement amount of channel B of the i+1th payment and the settlement amount of channel B of the ith payment, used in the following The structure of the transaction; The superscript represents the i-th "generation and destruction module", and the subscript represents the transaction name. The specific content refers to the value of Amount from shared address Transfer to shared address middle go; for The locking signature of , the encrypted content is , represents one-time password encryption, H is the hash function; for The lock signature here Represents a symmetric encryption algorithm. The first parameter is the encryption key, which is composed of It is calculated that here It still represents one-time password encryption, H is still a hash function, the second parameter is the encrypted content, and the subsequent locking signature parameter description is similar to the above content; (1) Both parties generate 、 and their corresponding locking signatures , channel party B holds, , held by channel party A; (2). This step is to prevent The protective measures taken after the phenomenon of atomicity destruction occurred: (2-1). Order ,like , then both parties generate a transaction ; Otherwise, generate a transaction ; Then jointly generate a lock transaction , both parties hold this locking signature; (2-2) Both parties jointly generate transactions , and its locking signature , both parties hold this locking signature; (2-3) Both parties jointly generate transactions , and its locking signature , held by channel party B; (2-4) Both parties jointly generate transactions , and its locking signature , held by channel party A; (2-5) Both parties jointly generate transactions and its locking signature , , , all held by channel party B; (2-6) Both parties jointly generate transactions , and its locking signature , held by channel party B; (2-7). Both parties jointly generate transactions , and its locking signature , held by channel party A; (3) Jointly generated by both parties , and its corresponding signature , held by channel party A; (4) Both parties jointly generate a locking signature , held by channel party B, this locking signature is used to destroy ; (5) Jointly generated by both parties , and its corresponding signature , held by channel party B; (6) Both parties jointly generate a locking signature , held by channel party A, this locking signature is used to destroy ; (7) Both parties jointly generate transactions , and their corresponding locking signatures , channel party B holds, , held by channel party A; At this stage, both parties continuously cycle through the second step off-chain to update the funds.
4. The new universal cross-chain payment channel method according to claim 3 is characterized by: The settlement payment stage includes the following: The first step is to Before time, channel party A first initiated Make from Transfer to Published to blockchain , initiate a request for settlement with the i+1th payment; In the second step, channel party B After the moment, Check before time The correctness of the transaction is checked by channel party B. If it is legal, channel party B can pass the signature of the transaction. Calculated , channel party B sends Can be obtained from get ; Step 3: Channel A sees After chaining, you can Signature Calculated , thus sending , so that from It is immediately transferred to channel party A.
5. The new universal cross-chain payment channel method according to claim 3 is characterized by: The generation and destruction modules include the following: In the first step, both parties first generate and , these two transactions are the contents of i+1 payment; The second step is to prevent After the phenomenon of atomicity destruction occurs, the protective measures are taken; After that, both parties have the ability to initiate settlement with the i-th amount, and channel party A also has the ability to initiate settlement with the i+1-th amount. In order to prevent the occurrence of "staggered settlement", the above steps (2-1) to (2-3) give channel party A the right to "withdraw channel party B's request for settlement with the i-th amount". At the same time, channel party B will obtain the right to settle with the i+1-th amount after the request is withdrawn; the corresponding penalty transaction is signed to ensure that the atomicity of the method is not affected; the above steps (2-4)-(2-7) are redemption transactions and penalty transactions generated to prevent malicious behavior.
6. The new universal cross-chain payment channel method according to claim 5 is characterized in that for In the above steps (2-1) to (2-3): first compare and The size of , thereby generating the corresponding prepare to withdraw transaction ;if , then generate , so that channel party A can first withdraw aux, then channel party B is considered to have settled with the amount of i+1 payment; if , then generate , so that channel party B can get aux again, so that channel party B settles with the amount of i+1 payment; and Lock signature Held by two people, when aux is withdrawn or obtained, channel party B must know ; At this time, if channel party B needs to use To obtain i+1 payments again, channel party A can use When redeeming an amount i+1, both parties finally settle the account with the status of i+1.
7. A new universal cross-chain payment channel device, characterized by: Open the timed channel phase module: This phase uses time lock and shared address technology to lock the amount. These amounts are used for off-chain transactions and as penalties to prevent the interacting parties from doing evil and to open the channel. Generate and update payment phase module: This phase continuously updates payment through secure computing, symmetric encryption, and bit operation technology to ensure the correctness and security of payment updates; Settlement payment stage module: This stage uses symmetric encryption and bit operation technology to put a valid payment on the chain and complete the settlement to ensure the correctness of the settlement.
8. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored program, wherein when the program is executed, the device where the non-volatile storage medium is located is controlled to execute the method according to any one of claims 1 to 6.
9. An electronic device, characterized in that: It comprises a processor and a memory; the memory stores computer-readable instructions, and the processor is used to execute the computer-readable instructions, wherein the computer-readable instructions execute the method described in any one of claims 1 to 6 when executed.
Citation Information
Patent Citations
Business processing method and device applied to bank transaction block chain system
CN112330326A
Cross-chain method and system for efficient anonymous atomic exchange based on threshold signature
CN117808470A
Methods and systems for formation and termination of payment channel between distinct ledgers
US20240378600A1